{"id":41533,"date":"2021-06-29T16:05:39","date_gmt":"2021-06-29T16:05:39","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/32416\/Hackers-Exploited-0-Day-Not-2018-Bug-To-Mass-Wipe-My-Book-Live-Devices.html"},"modified":"2021-06-29T16:05:39","modified_gmt":"2021-06-29T16:05:39","slug":"hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices\/","title":{"rendered":"Hackers Exploited 0-Day, Not 2018 Bug, To Mass-Wipe My Book Live Devices"},"content":{"rendered":"<figure class=\"intro-image intro-left\"><img decoding=\"async\" src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2021\/06\/busted-hard-drive-800x518.jpeg\" alt=\"Hackers exploited 0-day, not 2018 bug, to mass-wipe My Book Live devices\"><figcaption class=\"caption\">\n<div class=\"caption-credit\">Getty Images<\/div>\n<\/figcaption><\/figure>\n<aside id=\"social-left\" class=\"social-left\" aria-label=\"Read the comments or share this article\"><a title=\"142 posters participating\" class=\"comment-count icon-comment-bubble-down\" href=\"https:\/\/arstechnica.com\/gadgets\/2021\/06\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices\/?comments=1\"> <\/p>\n<h4 class=\"comment-count-before\">reader comments<\/h4>\n<p> <span class=\"comment-count-number\">194<\/span> <span class=\"visually-hidden\"> with 142 posters participating<\/span> <\/a> <\/p>\n<div class=\"share-links\">\n<h4>Share this story<\/h4>\n<\/p><\/div>\n<\/aside>\n<p><!-- cache hit 392:single\/related:d75ff48a337060717ff46bcc41a1b192 --><!-- empty --><\/p>\n<p>Last week\u2019s mass-wiping of Western Digital My Book Live storage devices involved the exploitation of not just one vulnerability&nbsp;but also a second critical security bug that allowed hackers to remotely perform a factory reset without a password, an investigation shows.<\/p>\n<p>The vulnerability is remarkable because it made it trivial to wipe what is likely petabytes of user data. More notable still was that, according to the vulnerable code itself, a Western Digital developer actively removed code that required a valid user password before allowing factory resets to proceed.<\/p>\n<h2>Done and undone<\/h2>\n<p>The undocumented vulnerability resided in a file aptly named system_factory_restore. It contains a PHP script that performs resets, allowing users to restore all default configurations and wipe all data stored on the devices.<\/p>\n<p>Normally, and for good reason, factory resets require the person making the request to provide a user password. This authentication ensures that devices exposed to the Internet can only be reset by the legitimate owner and not by a malicious hacker.<\/p>\n<p>As the <a href=\"https:\/\/paste.debian.net\/plainh\/7630c424\">following script<\/a> shows, however, a Western Digital developer created five lines of code to password-protect the reset command. For unknown reasons, the authentication check was cancelled, or in developer parlance, it was commented out, as indicated by the double \/ character at the beginning of each line.<\/p>\n<pre><code>function post($urlPath, $queryParams = null, $ouputFormat = 'xml') { \/\/ if(!authenticateAsOwner($queryParams)) \/\/ { \/\/ header(\"HTTP\/1.0 401 Unauthorized\"); \/\/ return; \/\/ }<\/code><\/pre>\n<p>\u201cThe vendor commenting out the authentication in the system restore endpoint really doesn&#8217;t make things look good for them,\u201d HD Moore, a security expert and the CEO of network discovery platform Rumble, told Ars. \u201cIt\u2019s like they intentionally enabled the bypass.\u201d<\/p>\n<p>To exploit the vulnerability, the attacker would have had to know the format of the XML request that triggers the reset. That\u2019s \u201cnot quite as easy as hitting a random URL with a GET request, but [it\u2019s] not that far off, either,\u201d Moore said.<\/p>\n<h2>Dude, where\u2019s my data?<\/h2>\n<p>The discovery of the second exploit comes five days after people all over the world reported that their <a href=\"https:\/\/arstechnica.com\/gadgets\/2021\/06\/mass-data-wipe-in-my-book-devices-prompts-warning-from-western-digital\/\">My Book Live devices had been compromised<\/a> and then factory-reset so that all stored data was wiped. My Book Live is a book-sized storage device that uses an Ethernet jack to connect to home and office networks so that connected computers have access to the data on it. Authorized users can also access their files and make configuration changes over the Internet. Western Digital stopped supporting the My Book Live in 2015.<\/p>\n<p>Western Digital personnel <a href=\"https:\/\/www.westerndigital.com\/support\/productsecurity\/wdc-21008-recommended-security-measures-wd-mybooklive-wd-mybookliveduo\">posted an advisory<\/a> following the mass wiping that said it resulted from attackers exploiting <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2018-18472\">CVE-2018-18472<\/a>. The remote command execution vulnerability was <a href=\"https:\/\/www.wizcase.com\/blog\/hack-2018\/\">discovered in late 2018<\/a> by security researchers Paulos Yibelo and Daniel Eshetu. Because it came to light three years after Western Digital stopped supporting the My Book Live, the company never fixed it.<\/p>\n<aside class=\"ad_wrapper\" aria-label=\"In Content advertisement\"> <span class=\"ad_notice\">Advertisement <\/span> <\/aside>\n<p>An analysis performed by Ars and Derek Abdine, CTO at security firm Censys, found that the devices hit by last week\u2019s mass hack had also been subjected to attacks that exploited the unauthorized reset vulnerability. The additional exploit is documented in log files extracted from two hacked devices.<\/p>\n<p>One of the logs was <a href=\"https:\/\/community.wd.com\/t\/help-all-data-in-mybook-live-gone-and-owner-password-unknown\/268111\/80\">posted<\/a> in the Western Digital <a href=\"https:\/\/community.wd.com\/t\/help-all-data-in-mybook-live-gone-and-owner-password-unknown\/268111\">support forum<\/a> where the mass compromise first came to light. It shows someone from the IP address 94.102.49.104 successfully restoring a device:<\/p>\n<blockquote>\n<p>rest_api.log.1:Jun 23 15:46:11 MyBookLiveDuo REST_API[9529]: 94.102.49.104 PARAMETER System_factory_restore POST : erase = none<br \/>rest_api.log.1:Jun 23 15:46:11 MyBookLiveDuo REST_API[9529]: 94.102.49.104 OUTPUT System_factory_restore POST SUCCESS<\/p>\n<\/blockquote>\n<p>A <a href=\"https:\/\/github.com\/dangoodin\/My-Book-Live\/blob\/main\/rest_log-02.txt\">second log file<\/a> I obtained from a hacked My Book Live device showed a different IP address\u201423.154.177.131\u2014exploiting the same vulnerability. Here are the telltale lines:<\/p>\n<blockquote>\n<p>Jun 16 07:28:41 MyBookLive REST_API[28538]: 23.154.177.131 PARAMETER System_factory_restore POST : erase = format<br \/>Jun 16 07:28:42 MyBookLive REST_API[28538]: 23.154.177.131 OUTPUT System_factory_restore POST SUCCESS<\/p>\n<\/blockquote>\n<p>After presenting these findings to Western Digital representatives, I received the following confirmation: \u201cWe can confirm that in at least some of the cases, the attackers exploited the command injection vulnerability (CVE-2018-18472), followed by the factory reset vulnerability. It\u2019s not clear why the attackers exploited both vulnerabilities. We\u2019ll request a CVE for the factory reset vulnerability and will update our bulletin to include this information.\u201d<\/p>\n<h2>This vulnerability has been password-protected<\/h2>\n<p>The discovery raises a vexing question: if the hackers had already obtained full root access by exploiting CVE-2018-18472, what need did they have for this second security flaw? There\u2019s no clear answer, but based on the evidence available, Abdine has come up with a plausible theory\u2014that one hacker first exploited CVE-2018-18472 and a rival hacker later exploited the other vulnerability in an attempt to wrest control of those already compromised devices.<\/p>\n<p>The attacker who exploited CVE-2018-18472&nbsp;used the code execution capability it provided to modify a file in the My Book Live stack named language_configuration.php, which is where the vulnerability is located. According to a <a href=\"https:\/\/github.com\/dangoodin\/My-Book-Live\/blob\/main\/language_configuration.txt\">recovered file<\/a>, the modification added the following lines:<\/p>\n<pre><code>function put($urlPath, $queryParams=null, $ouputFormat='xml'){ parse_str(file_get_contents(\"php:\/\/input\"), $changes); $langConfigObj = new LanguageConfiguration(); if(!isset($changes[\"submit\"]) || sha1($changes[\"submit\"]) != \"56f650e16801d38f47bb0eeac39e21a8142d7da1\") { die(); }\n<\/code><\/pre>\n<p>The change prevented anyone from exploiting the vulnerability without the password that corresponds to the cryptographic SHA1 hash 56f650e16801d38f47bb0eeac39e21a8142d7da1. It turns out that the password for this hash is p$EFx3tQWoUbFc%B%R$k@. The plaintext appears in the recovered log file <a href=\"https:\/\/github.com\/dangoodin\/My-Book-Live\/blob\/main\/rest_log-01.txt\">here<\/a>.<\/p>\n<aside class=\"ad_wrapper\" aria-label=\"In Content advertisement\"> <span class=\"ad_notice\">Advertisement <\/span> <\/aside>\n<p>A <a href=\"https:\/\/github.com\/dangoodin\/My-Book-Live\/blob\/main\/laguage_configuration-02.php\">separate modified language_configuration.php file<\/a> recovered from a hacked device used a different password that corresponds to the hash 05951edd7f05318019c4cfafab8e567afe7936d4. The hackers used a third hash\u2014b18c3795fd377b51b7925b2b68ff818cc9115a47\u2014to password-protect a separate file named accessDenied.php. It was likely done as an insurance policy in the event that Western Digital released an update that patched language_configuration.<\/p>\n<p>So far, attempts to crack these two other hashes haven\u2019t succeeded.<\/p>\n<p>According to Western Digital\u2019s advisory linked above, some of the My Book Live devices hacked using CVE-2021-18472 were infected with malware called <a href=\"https:\/\/www.virustotal.com\/gui\/file\/9f7edb6383ca58584d3c7bd038aa3bf29f0a544fe1eedb0f8c28af52245b70f0\/details\">.nttpd,1-ppc-be-t1-z<\/a>, which was written to run on the PowerPC hardware used by My Book Live devices. One user in the support forum <a href=\"https:\/\/community.wd.com\/t\/help-all-data-in-mybook-live-gone-and-owner-password-unknown\/268111\/201\">reported<\/a> a hacked My Book Live receiving <a href=\"https:\/\/www.virustotal.com\/gui\/file\/227fe3d0435a53416cf2eeb08b197a4bb671f9395047eab2ee437ae48ff80489\/detection\">this malware<\/a>, which <a href=\"https:\/\/blog.netlab.360.com\/linux-ngioweb-v2-going-after-iot-devices-en\/\">makes devices part of a botnet<\/a> called Linux.Ngioweb.<\/p>\n<h2>A theory emerges<\/h2>\n<p>So why would someone who successfully wrangled so many My Book Live devices into a botnet turn around and wipe and reset them? And why would someone use an undocumented authentication bypass when they already have root access?<\/p>\n<p>The most likely answer is that the mass wipe and reset was performed by a different attacker, very possibly a rival who either attempted to take control of the rival\u2019s botnet or simply wanted to sabotage it.<\/p>\n<p>\u201cAs for motive for POSTing to this [system_factory_restore] endpoint on a mass scale, it is unknown, but it could be an attempt at a rival botnet operator to take over these devices or render them useless, or someone who wanted to otherwise disrupt the botnet which has likely been around for some time, since these issues have existed since 2015,\u201d Abdine wrote in a <a href=\"https:\/\/censys.io\/blog\/cve-2018-18472-western-digital-my-book-live-mass-exploitation\/\">recent blog post<\/a>.<\/p>\n<p>The discovery of this second vulnerability means that My Book Live devices are even more insecure than most people thought. It adds authority to Western Digital\u2019s recommendation to all users to disconnect their devices from the Internet. Anyone using one of these devices should heed the call immediately.<\/p>\n<p>For many hacked users who lost years&#8217; or decades&#8217; worth of data, the thought of buying another Western Digital storage device is probably out of the question. Abdine, however, says that My Cloud Live devices, which replaced Western Digital\u2019s My Book Live products, have a different codebase that doesn\u2019t contain either of the vulnerabilities exploited in the recent mass wiping.<\/p>\n<p>\u201cI took a look at the My Cloud firmware, too,\u201d he told me. \u201cIt&#8217;s rewritten and bears some, but mostly little, resemblance to My Book Live code. So it doesn&#8217;t share the same issues.\u201d<\/p>\n<p> READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/32416\/Hackers-Exploited-0-Day-Not-2018-Bug-To-Mass-Wipe-My-Book-Live-Devices.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":41534,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[277],"tags":[145],"class_list":["post-41533","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-blogs","tag-headlinehackerdata-lossflaw"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Hackers Exploited 0-Day, Not 2018 Bug, To Mass-Wipe My Book Live Devices 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Hackers Exploited 0-Day, Not 2018 Bug, To Mass-Wipe My Book Live Devices 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-06-29T16:05:39+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/06\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"800\" \/>\n\t<meta property=\"og:image:height\" content=\"518\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Hackers Exploited 0-Day, Not 2018 Bug, To Mass-Wipe My Book Live Devices\",\"datePublished\":\"2021-06-29T16:05:39+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices\\\/\"},\"wordCount\":1330,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices.jpg\",\"keywords\":[\"headline,hacker,data loss,flaw\"],\"articleSection\":[\"CyberSecurity Blogs\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices\\\/\",\"name\":\"Hackers Exploited 0-Day, Not 2018 Bug, To Mass-Wipe My Book Live Devices 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices.jpg\",\"datePublished\":\"2021-06-29T16:05:39+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices.jpg\",\"width\":800,\"height\":518},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,hacker,data loss,flaw\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinehackerdata-lossflaw\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Hackers Exploited 0-Day, Not 2018 Bug, To Mass-Wipe My Book Live Devices\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Hackers Exploited 0-Day, Not 2018 Bug, To Mass-Wipe My Book Live Devices 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices\/","og_locale":"en_US","og_type":"article","og_title":"Hackers Exploited 0-Day, Not 2018 Bug, To Mass-Wipe My Book Live Devices 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-06-29T16:05:39+00:00","og_image":[{"width":800,"height":518,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/06\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Hackers Exploited 0-Day, Not 2018 Bug, To Mass-Wipe My Book Live Devices","datePublished":"2021-06-29T16:05:39+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices\/"},"wordCount":1330,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/06\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices.jpg","keywords":["headline,hacker,data loss,flaw"],"articleSection":["CyberSecurity Blogs"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices\/","url":"https:\/\/www.threatshub.org\/blog\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices\/","name":"Hackers Exploited 0-Day, Not 2018 Bug, To Mass-Wipe My Book Live Devices 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/06\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices.jpg","datePublished":"2021-06-29T16:05:39+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/06\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/06\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices.jpg","width":800,"height":518},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,hacker,data loss,flaw","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinehackerdata-lossflaw\/"},{"@type":"ListItem","position":3,"name":"Hackers Exploited 0-Day, Not 2018 Bug, To Mass-Wipe My Book Live Devices"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/41533","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=41533"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/41533\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/41534"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=41533"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=41533"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=41533"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}