8 June 2023

Orgs urged to immediately replace hacked Barracuda ESG appliances


Orgs urged to immediately replace hacked Barracuda ESG appliances

Email and network security solutions provider Barracuda Networks has urged its customers to immediately replace compromised Email Security Gateway (ESG) appliances.

“Impacted ESG appliances must be immediately replaced regardless of patch version level. Barracuda’s remediation recommendation at this time is full replacement of the impacted ESG,” the company said in an update to its initial security alert.

The advisory pertains to a series of attacks using a zero-day vulnerability in ESG devices disclosed in the beginning of June 2023.

Tracked as CVE-2023-2868, the flaw is an OS command injection issue that can be exploited by a remote hacker to execute arbitrary Perl commands on the target system. The vulnerability was identified on May 19 and a security patch to address the bug was applied to all ESG appliances worldwide on May 20, 2023. The vulnerability resided in a module which initially screens the attachments of incoming emails. Other Barracuda’s products, including SaaS email security services, are not affected.

An investigation into the incident revealed that threat actors had been exploiting said zero-day since October 2022 to backdoor devices using at least three malware families, namely, Saltwater, Seaspy, and Seaside.


Back to the list

Latest Posts

BreachForums seized in law enforcement op, admin reportedly arrested

BreachForums seized in law enforcement op, admin reportedly arrested

Authorities have yet to make official statement regarding the shutdown.
16 May 2024
Google fixes yet another Chrome zero-day

Google fixes yet another Chrome zero-day

This is a third zero-day flaw patched by Google within two weeks.
16 May 2024
Russian cyberspies Turla target European MFA with new backdoors

Russian cyberspies Turla target European MFA with new backdoors

Both backdoors implement a loader that decrypts payloads using DNS domain names, as well as the ability to execute Lua scripts.
15 May 2024