Everything is vulnerable to attacks but Synology patch quicker, don't hide issues and the same for the applications, the developers seem to update much quicker. QNAP are well known to hide CVEs. A lot of security people have found vulnerabilities, reported them and they've not been fixed in several months.
It has that halo factor because they generally just work and are better supported. There are so many issues with QuTS / QuTS Hero , the application support just isn't there, yes the hardware is slightly better (i.e. you can get devices with 10Gb and yes you can put in most memory sticks) but you're still not going to get anywhere near 10Gb, hell 2.5Gb isn't achievable a lot of the time even with quick drives. If you use there own applications, especially items like QuMagie for the AI photosearch, then you'd best not be doing anything else as it kills most other things.
M.