---
title: Out of date software leaves you vulnerable
description: Two weeks ago, Der Spiegel wrote an article highlighting that out of
  date software on private clouds was leaving government and political party information
  vulnerable to being hacked. Given that political organisations being targeted is
  currently such a hot topic, it is somewhat of a surprise how widespread this issue
  appears to be. After […]
url: https://canonical.com/blog/out-of-date-software-leaves-you-vulnerable?format=md
---

1. [Blog](https://canonical.com/blog)
2. Article

---

[Canonical](https://canonical.com/blog/author/canonical "More about Canonical")

23 March 2017

# Out of date software leaves you vulnerable

[Cloud security](https://canonical.com/blog/tag/cloud-security)
[iot security](https://canonical.com/blog/tag/iot-security)
[nextcloud](https://canonical.com/blog/tag/nextcloud)

---

Share the article

Two weeks ago, [Der Spiegel](http://www.spiegel.de/netzwelt/netzpolitik/afd-gruene-und-uno-lassen-daten-ungeschuetzt-im-internet-a-1137444.html) wrote an article highlighting that out of date software on private clouds was leaving government and political party information vulnerable to being hacked. Given that political organisations being targeted is currently such a hot topic, it is somewhat of a surprise how widespread this issue appears to be. After discovering the size and scope of the problem through their own investigations, Nextcloud decided to take a proactive approach and help organisations’ awareness and address potential vulnerabilities.

The large number of insecure servers came to light as a result of a tool that Nextcloud was developing. Given their findings, Nextcloud took the somewhat unusual industry step to proactively work with Computer Emergency Response Teams in various countries to notify affected people of the risks, in an effort to help keep their data as secure as possible.

The Der Spiegel article and [Nextcloud’s response](https://nextcloud.com/blog/nextcloud-releases-security-scanner-to-help-protect-private-clouds/) which chose transparency over secrecy and following security best practices are a must read for everyone in the industry and a timely reminder to us all of the importance of updating our software on a regular basis.

As mentioned in NextCloud’s blog response, they have now released the [Nextcloud Private Cloud Security Scanner](https://scan.nextcloud.com/) as a quick and simple tool to enable users to regularly check their servers and ensure always up to date software. However the ideal scenario is for software updates to happen automatically and reduce the risk of a security threat as a result, especially so for [smaller organisations and consumers](https://pages.ubuntu.com/IoT-Security-whitepaper.html#utm_source=Insights&utm_medium=Post&utm_campaign=2)%20Device_FY17_IOT_PR&utm_content=Nextcloud_Scanner), which often lack the technical know-how to maintain their system up to date . This is a feature that’s built into snaps, the universal Linux application packaging format, which is why Nextcloud uses snaps to distribute their software as part of their Nextcloud Box offering. Users of the box will get automated updates of their Nextcloud software whenever a new release is made available in the store. As a matter of fact the NextCloud Box is built on Ubuntu core, the version of Ubuntu entirely built out of snaps. This means that the entire software on the box is seamlessly updated without administrator involvement, and it literally takes no effort to keep your storage secure.

[Get in touch

Interested in running Ubuntu in your organization?](https://ubuntu.com/about/contact-us/form)

## Sign up for our newsletter

Get the latest Canonical news and updates in your inbox.

Work email:

\*I agree to receive information about Canonical's
products and services.

By submitting this form, I confirm that I have read and agree to [Canonical's Privacy Policy](https://canonical.com/legal/dataprivacy).

Sign up

## Share on

---

## Related posts

[### Achieving Performant Single-Tenant Cloud Isolation with IBM Cloud Bare Metal Servers, Ubuntu Core, Snaps, and AMD Pensando Elba Data Processing Unit](https://canonical.com/blog/cloud-isolation-ibm-bare-metal-ubuntu-core)

Discover how IBM Cloud’s bare metal servers offer highly confined and high-performing single-tenant cloud isolation through the use of Ubuntu Core and Snaps, supported by the...

[Benjamin Ryzman](https://canonical.com/blog/author/benjaminryzman)

22 April 2024

[### 도커(Docker) 컨테이너 보안: 우분투 프로(Ubuntu Pro)로 FIPS 지원 컨테이너 이해하기](https://canonical.com/blog/docker-container-security-demystifying-fips-enabled-containers-with-ubuntu-pro-kr)

오늘날 급변하는 디지털 환경에서 강력한 도커 컨테이너 보안 조치의 중요성은 아무리 강조해도 지나치지 않습니다. 컨테이너화된 계층도 규정 준수 표준의 적용을 받기 때문에 보안 문제 및 규정 준수 요구 사항이 발생합니다. 도커 컨테이너 보안 조치는 경량의 어플라이언스 유형 컨테이너(각 캡슐화 코드 및 해당 종속성)를...

[Canonical](https://canonical.com/blog/author/canonical)

5 September 2023

[### Strengthen your cloud cyber security with Ubuntu Pro and confidential VMs](https://canonical.com/blog/cloud-cyber-security-with-ubuntu-pro-confidential-vms)

Strengthen your cloud cyber security with Ubuntu Pro and confidential VMs. This blog dives into the crucial role your OS plays in cloud security and highlights the extensive...

[Ijlal Loutfi](https://canonical.com/blog/author/ijlal-loutfi)

28 June 2023

[### Docker container security: demystifying FIPS-enabled containers with Ubuntu Pro](https://canonical.com/blog/docker-container-security-demystifying-fips-enabled-containers-with-ubuntu-pro)

In today’s rapidly changing digital environment, the significance of robust Docker container security measures cannot be overstated. Even the containerised layer is subject to...

[Valentin Viennot](https://canonical.com/blog/author/valentinviennot)

2 June 2023
