Barracuda warns users about possible email compromise attacks - here's what you need to know

best free email services
Best Free Email Services (Image credit: Image by Gerd Altmann from Pixabay)

Email and network security solutions provider Barracuda has reached out to a number of firms that were targeted via a zero-day vulnerability found in some of the company’s appliances. 

The company recently found a zero-day vulnerability in its Email Security Gateway (ESG) appliances. The vulnerability tracked as CVE-2023-2868, is described as a remote command injection flaw. 

Over the weekend, Barracuda applied two fixes, effectively addressing the issue. However, on Tuesday, the company learned that some of its clients were still compromised by unnamed threat actors. 

Reviewing the environment

"Based on our investigation to date, we've identified that the vulnerability resulted in unauthorized access to a subset of email gateway appliances," the company said. "Users whose appliances we believe were impacted have been notified via the ESG user interface of actions to take. Barracuda has also reached out to these specific customers.”

Barracuda’s other products were not affected by the flaw, the company said. 

The flaw only affected the ESG product, and not its customers’ corporate networks, which is why Barracuda advised its clients to review their environment and make sure the attackers did not move laterally into other endpoints. 

"If a customer has not received notice from us via the ESG user interface, we have no reason to believe their environment has been impacted at this time and there are no actions for the customer to take," Barracuda told BleepingComputer

The company did not want to discuss the issue further, leaving a few unanswered questions. Namely, we don’t know the identity of the attackers or that of the victims. We don’t know how many companies Barracuda believes were compromised, either. 

According to the firm, more than 200,000 organizations worldwide are using its enterprise-grade security solutions, including high-profile names such as Samsung, Mitsubishi, Kraft Heinz, Delta Airlines, and others. 

Via: BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
An abstract image of padlocks overlaying a digital background.
BeyondTrust says hackers hit its remote support products
Data leak
Details of over 15,000 FortiGate devices leaked online, so be on your guard
Representational image depecting cybersecurity protection
Hackers are breaking SonicWall products to target business networks
Best free Linux firewalls
Fortinet warns a critical vulnerability in its systems could let attackers breach company networks
A person's fingers type at a keyboard, with a digital security screen with a lock on it overlaid.
Veeam backup software has a serious security flaw - here's how to stay safe
The best free firewall
Palo Alto warns another major firewall hack has been detected
Latest in Security
A graphic showing fleet tracking locations over a city.
Lost & Found tracking site hit by major data breach - over 800,000 could be affected
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop
Web DDoS attacks see major surge as AI allows more powerful attacks
Polish space agency says it was hit by a cyberattack
Illustration of a hooked email hovering over a mobile phone
AWS misconfigurations reportedly used to launch phishing attacks
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
Microsoft Teams and other Windows tools hijacked to hack corporate networks
Latest in News
Google Gemini iPhone Lock Screen
You can now access Gemini from your iPhone's lock screen
Michelle, Keats, and Doctor Amherst looking unimpressed and worried in The Electric State
Netflix drops trailer for The Electric State, and I'm getting serious District 9 vibes
YouTube TV
YouTube TV might be planning a big Netflix update that puts the best streaming services first
Google Pixel 9 Pro
Here are the 7 best Pixel 9 and Pixel Watch 3 features landing in March’s Pixel Feature Drop
Bang & Olufsen Beogram 4000C Saint Laurent Rive Droite Edition
Bang & Olufsen's latest reworked turntable is a masterpiece of retro revival, in a breathtaking wooden presentation box
Apple Watch Series 10
Apple unveils new Apple Watch bands – here's what's in the Spring 2025 collection