Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Barracuda Alerts Of Breaches In Email Gateways From Zero-Day Flaws
News & Analysis Attacks Data Breach Data Loss Prevention Data Protection Security Threats and Vulnerabilities Zero Day

Barracuda Alerts Of Breaches In Email Gateways From Zero-Day Flaws

Olivia WilliamBy Olivia WilliamMay 24, 2023Updated:August 20, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Barracuda Alerts Of Breaches In Email Gateways From Zero-Day Flaws
Barracuda Alerts Of Breaches In Email Gateways From Zero-Day Flaws
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Barracuda, a provider of email and network security solutions, issued a warning to its customers today that a zero-day vulnerability had been exploited to compromise some of their Email Security Gateway (ESG) equipment last week.

The email attachment scanning module had a flaw that was uncovered on Friday, May 19th. On May 20 and 21, two security fixes were implemented to fix the problem. Even though the vulnerability was fixed over the weekend, Barracuda informed on Tuesday that some of its customers ESG equipment had been breached.

According to the company’s findings, the flaws lead to unauthorized access to a subset of email gateway appliances.” We have informed users whose appliances may have been affected by this through the ESG user interface. Barracuda has also contacted these customers directly.

Other products, like as the company’s SaaS email security services, were not vulnerable. Barracuda claimed that the scope of the probe did not extend to the client’s internal networks but only to their ESG product. As a result, the firm recommends that affected firms do an environmental evaluation to ensure that the threat actors have not migrated to additional network devices.

Barracuda did not respond to a follow-up email inquiring about the number of customers whose ESG appliances were compromised or whether or not their data was compromised. Barracuda fixed a login problem for EGD appliances and a flawed spam scoring algorithm that improperly rejected customer emails today.

Over 200,000 enterprises, including Samsung, Mitsubishi, Kraft Heinz, Delta Airlines, and others, employ Barracuda’s enterprise-grade security solutions, the company claims.

Barracuda Email Protection 

Barracuda is a reputable security provider that offers a suite of user-friendly, cloud-based solutions, delivering security for emails, networks, data, and applications for a global customer base. Among its myriad services, Barracuda Essentials is a comprehensive email security solution that incorporates email protection, continuity, encryption, and optional additions like email archiving and Office 365 backup.

The email protection component serves as a secure gateway, blocking potential email threats before they infiltrate your network, Office 365, or G-Suite. This package is primarily targeted at small to medium-sized businesses, offering a unified solution for email security and data protection.

Key Features of Barracuda Email Protection

This cloud-hosted email security service boasts an array of features, providing extensive protection. It includes granular policy controls for administrators and robust filtering through virus scanning, spam scoring, and real-time analysis. Included within the core service is Advanced Threat Protection and URL scanning – features for which other providers might charge extra.

Barracuda Email Protection integrates seamlessly with Office 365, serving as an excellent supplementary service. Its pricing is cost-effective, and it provides robust technical support and management features. Additional Barracuda offerings, such as the Sentinel service, offer multi-layered defense against phishing and business email compromise.

Outbound Filtering and encryption safeguards businesses against data loss, while optional add-on modules, like Archiving and Continuity, enhance functionality. Customers have the ability to dictate the location of their data. The platform’s AI systems offer real-time protection against phishing attacks by recognizing and learning from business communication patterns. Administrators receive real-time notifications of security threats, and any malicious emails are promptly quarantined.

Conclusion

Barracuda Networks, a network security company, warned customers of a compromise in some Email Security Gateway (ESG) appliances. Threat actors exploited CVE-2023-2868, a zero-day vulnerability that was patched. The vulnerability was found in the email attachment screening module on May 19. Barracuda quickly released security updates on May 20 and 21. “On May 19, 2023, Barracuda identified a vulnerability in our Email Security Gateway appliance (ESG). On Saturday, May 20, 2023, all ESG appliances globally were patched to eradicate the vulnerability. The report added that “The vulnerability existed in a module which initially screens the attachments of incoming emails.”

Since hundreds of thousands of organizations, including some high-profile enterprises, use ESG equipment, this issue could have far-reaching ramifications. Barracuda says the issue does not affect its other products or SaaS email security services. The business found that the bug targeted a subset of email gateway appliances. Barracuda notified consumers via the ESG user interface of affected appliances. Users of affected appliances were notified via the ESG user interface. Barracuda also contacted these customers. Barracuda’s ESG product assessment did not include customers’ settings. The business advises affected organizations to check their networks for attacker-compromised systems.

Olivia William
  • Olivia William
    Ciso Playbook: Cyber Resilience Strategy
  • Olivia William
    Apple Responds Swiftly to Active Security Threats with iOS 16.5.1 Update
  • Olivia William
    Zacks Investment Research Faces Larger Data Breach Affecting 8.8 Million Users
  • Olivia William
    British Airways and Boots Battling Data Breaches, Millions of Customers Affected

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Foxconn confirms cyberattack following Nitrogen ransomware claims

May 14, 20263 Mins Read

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}