Skip to main content

Barracuda ESG Appliances Compromised


dips
Forum|alt.badge.img+7
  • Veeam Legend
  • 808 comments

Another day, another breach. 

This time threat actors have breached Barracuda ESG Appliances. If any folk as using these appliances, it might be worth giving them a check under direction of the vendor.

More here: Threat Actors Compromise Barracuda Email Security Appliances (darkreading.com)

9 comments

Chris.Childerhose
Forum|alt.badge.img+21

Thanks for sharing Dips.


replicatius
Forum|alt.badge.img+4
  • Veeam Vanguard
  • 7 comments
  • May 26, 2023

Thanks for the heads up.

"resulted in unauthorized access to a subset of email gateway appliances," -- big yikes ðŸ˜“


regnor
Forum|alt.badge.img+14
  • Veeam MVP
  • 1352 comments
  • May 29, 2023

Taking over an email security appliance with an attachment 😖

Thanks for sharing this @dips 


dips
Forum|alt.badge.img+7
  • Author
  • Veeam Legend
  • 808 comments
  • June 1, 2023

No problem @regnor 

Turns out its been exploited since October 2022.

They’ve published more information here: https://www.barracuda.com/company/legal/esg-vulnerability

IOC’s are also available


coolsport00
Forum|alt.badge.img+20
  • Veeam Legend
  • 4133 comments
  • June 8, 2023

Used to use Barracuda at my previous job...over 10yrs ago. Semi-decent appliance back in the day, tho was a bit simplistic (needed way more features). I don’t handle content-filtering in my current role/org..thankfully. Thanks for the share Dipen.


dips
Forum|alt.badge.img+7
  • Author
  • Veeam Legend
  • 808 comments
  • June 8, 2023

No problem. It does look quite bad. They are now recommending that the ESG appliances are replaced. 

 


coolsport00
Forum|alt.badge.img+20
  • Veeam Legend
  • 4133 comments
  • June 8, 2023

Eeek!


Geoff Burke
Forum|alt.badge.img+22
  • Veeam Legend, Veeam Vanguard
  • 1318 comments
  • June 9, 2023

Wow Email Security Gateway too, talk about a bad place to get hit!


dips
Forum|alt.badge.img+7
  • Author
  • Veeam Legend
  • 808 comments
  • June 9, 2023
Geoff Burke wrote:

Wow Email Security Gateway too, talk about a bad place to get hit!

There is no safe space anywhere! 😱


Comment