/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Western Digital says some My Book Live devices are being compromised by malware leading to a factory reset erasing all data, believes its servers weren't hacked

Western Digital My Book NAS owners worldwide found that their devices have been mysteriously factory reset and all of their files deleted.

BleepingComputer Lawrence Abrams

Context & Ripple Effects

My Book Live owners are facing data loss from remote compromises, while Western Digital initially separated the incident from a breach of its own servers. Follow-up code analysis pointed to removed authentication code, shifting attention from the vendor's central systems to the security of the devices themselves.

First-order effects

  • My Book Live owners whose devices are reset lose locally stored files, making recovery and support the immediate issue for Western Digital.
  • The apparent authentication gap gives attackers a route to trigger destructive actions on exposed devices, rather than requiring access to Western Digital's servers.

Second-order effects

  • Western Digital's response must address both erased-device remediation and the product-code weakness identified in the subsequent analysis of the wipes.
  • NAS buyers and administrators have a concrete reason to reassess whether internet-accessible storage devices remain safely authenticated and supported.

Third-order effects

  • The episode points to a broader security burden for connected storage vendors: device-level authentication and long-term maintenance can determine customer data safety even when central servers are not breached.

The trend: Connected storage is becoming a security-lifecycle product, with device software protections carrying as much weight as the vendor's central infrastructure.

Discussion

  • @avast_antivirus Avast on x
    The My Book Live is an older device (last update 2015), mainly used by consumers and SMBs. If you, your business or someone you know use one of these devices you should disconnect it immediately and follow the official @WD advisory here: https://community.wd.com/...
  • @thomasareed Thomas Reed on x
    NEVER rely on only one single backup, or one single backup system. Keep at least two separate backups, created with two different backup systems. Even better, make sure at least one set of backups is off-site at all times. https://twitter.com/...
  • @vickerysec Chris Vickery on x
    That's funny— I have a lot of encrypted storage containers on a pair of large Western Digital “My Book” devices. It's a good thing I would never run the default factory-software they come with. Also good that I would never use cloud services in combination with them. https://twit…
  • @lonseidman Lon Seidman on x
    The last firmware update for this discontinued product was 2015 - another reason why I believe nothing on your network should be exposed directly to the Internet. Turn off upnp on your router and use a VPN if you need to access from the outside. https://twitter.com/...