• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

Barracuda Urges Swift Replacement of Vulnerable ESG Appliances

You are here: Home / General Cyber Security News / Barracuda Urges Swift Replacement of Vulnerable ESG Appliances
June 9, 2023

Organization-grade security answer company Barracuda has urged prospects to replace Email Security Gateway (ESG) no matter of patch variation degree. 

This follows attacks observed targeting a now-patched zero-working day vulnerability. The flaw (tracked CVE-2023-2868) was exploited as early as Oct 2022 and patched remotely again on May well 20, 2023. The attackers’ accessibility to the compromised appliances was reportedly slice off a single working day afterwards by deploying a devoted script.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


According to Barracuda’s authentic advisory, printed on June 1, the vulnerability that was uncovered exists within a module responsible for screening email attachments. This was current on June 6 to encourage the alternative of the ESG.

Examine far more on email-concentrated attacks: Microsoft Warns of Boost in Business Email Compromise Attacks

The agency identified that the flaw was exploited to gain unauthorized accessibility to a unique subset of ESG appliances. Malware was then identified on a portion of these appliances, making it possible for for persistent backdoor accessibility. Proof of details exfiltration has also been learned on some influenced gadgets.

Incident reaction groups from security firm Rapid7 are also investigating the ESG exploitation bug and have published a blog post on the findings on Thursday.

“The pivot from patch to full replacement of impacted products is reasonably stunning and implies the malware the threat actors deployed somehow achieves persistence at a lower sufficient degree that even wiping the system wouldn’t eradicate attacker access,” reads the Fast7 advisory.

According to insights shared by John Bambenek, principal danger hunter at Netenrich, shoppers working with virtual appliances will have an simpler time. In these types of situations, the answer is comparatively simple—provisioning and configuring a new virtual appliance and removing the aged one particular. 

“People using components appliances will have a tough road in advance of them as they require to get a new device to change it with,” Bambenek additional.

The Barracuda updates on CVE-2023-2868 occur a few months immediately after Quarks Lab exposed that two earlier found TPM 2. library vulnerabilities could have affected billions of Internet of Items (IoT) devices.


Some sections of this short article are sourced from:
www.infosecurity-magazine.com

Previous Post: «Cyber Security News Google Launches Framework to Secure Generative AI
Next Post: Asylum Ambuscade: A Cybercrime Group with Espionage Ambitions asylum ambuscade: a cybercrime group with espionage ambitions»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • New Critical Security Flaws Expose Exim Mail Servers to Remote Attacks
  • Cybercriminals Using New ASMCrypt Malware Loader Flying Under the Radar
  • Lazarus Group Impersonates Recruiter from Meta to Target Spanish Aerospace Firm
  • Post-Quantum Cryptography: Finally Real in Consumer Apps?
  • Microsoft’s AI-Powered Bing Chat Ads May Lead Users to Malware-Distributing Sites
  • Progress Software Releases Urgent Hotfixes for Multiple Security Flaws in WS_FTP Server
  • Cisco Warns of Vulnerability in IOS and IOS XE Software After Exploitation Attempts
  • GitHub Repositories Hit by Password-Stealing Commits Disguised as Dependabot Contributions
  • China’s BlackTech Hacking Group Exploited Routers to Target U.S. and Japanese Companies
  • The Dark Side of Browser Isolation – and the Next Generation Browser Security Technologies

Copyright © TheCyberSecurity.News, All Rights Reserved.