Barracuda ESG Appliances Compromised


Userlevel 7
Badge +7
  • Veeam Legend
  • 716 comments

Another day, another breach. 

This time threat actors have breached Barracuda ESG Appliances. If any folk as using these appliances, it might be worth giving them a check under direction of the vendor.

More here: Threat Actors Compromise Barracuda Email Security Appliances (darkreading.com)


9 comments

Userlevel 7
Badge +20

Thanks for sharing Dips.

Userlevel 2
Badge +3

Thanks for the heads up.

"resulted in unauthorized access to a subset of email gateway appliances," -- big yikes 😓

Userlevel 7
Badge +14

Taking over an email security appliance with an attachment 😖

Thanks for sharing this @dips 

Userlevel 7
Badge +7

No problem @regnor 

Turns out its been exploited since October 2022.

They’ve published more information here: https://www.barracuda.com/company/legal/esg-vulnerability

IOC’s are also available

Userlevel 7
Badge +17

Used to use Barracuda at my previous job...over 10yrs ago. Semi-decent appliance back in the day, tho was a bit simplistic (needed way more features). I don’t handle content-filtering in my current role/org..thankfully. Thanks for the share Dipen.

Userlevel 7
Badge +7

No problem. It does look quite bad. They are now recommending that the ESG appliances are replaced. 

 

Userlevel 7
Badge +17

Eeek!

Userlevel 7
Badge +22

Wow Email Security Gateway too, talk about a bad place to get hit!

Userlevel 7
Badge +7

Wow Email Security Gateway too, talk about a bad place to get hit!

There is no safe space anywhere! 😱

Comment