Barracuda Networks has recently discovered two zero-day vulnerabilities, CVE-2023-7102 and CVE-2023-7101, which were linked to the Spreadsheet::ParseExcel library. These vulnerabilities allowed threat actors to execute arbitrary code within the Barracuda Email Security Gateway Appliance (ESG) devices through malicious Excel email attachments. The first vulnerability, CVE-2023-7102, was investigated by the Barracuda security team in collaboration with Mandiant. It allowed threat actors to execute arbitrary code within the ESG appliance’s third-party library. Barracuda responded to the vulnerabilities by deploying a security update to all active ESGs, effectively addressing the vulnerabilities and protecting its users. The swift response demonstrated Barracuda’s commitment to fortifying its technology and staying ahead of state-sponsored threats. In addition to these vulnerabilities, Barracuda also identified new variants of SEASPY and SALTWATER malware on compromised ESG devices and deployed a patch to remediate compromised devices. The discovery and mitigation of these vulnerabilities highlight the importance of proactive cybersecurity measures in protecting devices and networks from exploitation.
Barracuda Vulnerabilities: A Proactive Response that Saves the Day!
![](https://cybsecwizard.com/wp-content/uploads/2023/12/Anti-Money-Laundering-in-Fintech-copy.webp)
Latest from Blog
![](https://cybsecwizard.com/wp-content/uploads/2023/12/Demystifying-Fintech-Operations_-How-They-Work-and-Compete.jpg)
Deepfake dangers prompt urgent cybersecurity reevaluations for businesses
TLDR: AI-generated deepfake attacks are on the rise, leading companies to reassess their cybersecurity measures. Companies are developing deepfake response plans and running simulations to increase preparedness. Biometric authentication, once considered secure,
![](https://cybsecwizard.com/wp-content/uploads/2023/12/Fintech-in-Emerging-Markets.jpg)
North Korean faces charges for cyberattacks on US targets
TLDR: A North Korean military intelligence operative has been indicted for orchestrating cyberattacks on U.S. hospitals, NASA, and military bases. Rim Jong Hyok, a member of the Andariel Unit, faces charges of
![](https://cybsecwizard.com/wp-content/uploads/2023/12/The-Role-of-AI-in-Fintech.jpg)
Analysts predict cybersecurity stocks will soar after CrowdStrike’s outage
“`html TLDR: CrowdStrike outage led to potential gains for cybersecurity rivals SentinelOne, Palo Alto Networks, and Microsoft’s cybersecurity business could benefit After a defective CrowdStrike update caused a global tech outage, analysts
![](https://cybsecwizard.com/wp-content/uploads/2023/12/Fintech-in-Retail_-Enhancing-Customer-Experiences.jpg)
Bitsight’s Trust Management Hub: Revolutionizing Security Assessment Process
TLDR: Bitsight has released Trust Management Hub to streamline security assessments. The new solution reduces workload by 25% and improves the assessment cycle by 85%, helping teams close deals faster. Bitsight, a
![](https://cybsecwizard.com/wp-content/uploads/2023/12/Bridging-Financial-Inequality_-Fintechs-Role-and-Potential.jpg)
North Korean hackers pivot to ransomware attacks
TLDR: North Korean hackers from APT45 have shifted from cyber espionage to ransomware attacks APT45 has targeted critical infrastructure and is linked to ransomware families SHATTEREDGLASS and Maui A North Korea-linked threat
![](https://cybsecwizard.com/wp-content/uploads/2023/12/Fintech-in-Emerging-Markets.jpg)
Europe’s telecom, electricity sectors evaluated in new EU cybersecurity report
TLDR: EU releases risk assessment report on cybersecurity in telecommunications and electricity sectors Report highlights supply chain risks, shortage of cybersecurity professionals, and threats from cybercriminals and state-sponsored actors Summary: The European
![](https://cybsecwizard.com/wp-content/uploads/2023/12/Near-Field-Communication-NFC-Explained.jpg)
Cyber insurance evolves to cover all your online needs
TLDR: Cyber insurance coverage is evolving to help raise security baselines across businesses. Only one-quarter of companies have a standalone cyber insurance policy. In today’s evolving cybersecurity landscape, cyber insurance coverage is
![](https://cybsecwizard.com/wp-content/uploads/2023/12/Decoding-Fintech-Licenses.jpg)
Study: CrowdStrike slashes losses, Fortune 500 set to save $54B
TLDR: Key Points: CrowdStrike outage will cost Fortune 500 $5.4 billion Cyber insurance will only cover 10-20% of losses In a report by Parametrix, it is estimated that the global IT outage
![](https://cybsecwizard.com/wp-content/uploads/2023/12/Impact-of-GDPR-on-Fintech-Companies.jpg)
Get ready for a cyber attack with NewsRadio 740 KTRH
TLDR: A cyber attack recently caused a global outage of numerous Microsoft business products, highlighting the vulnerability of our technology infrastructure. Cyber security expert Matt Malone believes that the incident could serve
![](https://cybsecwizard.com/wp-content/uploads/2023/12/Impact-of-GDPR-on-Fintech-Companies.jpg)
Prepare for heightened US cybersecurity threats with Project 2025 risks
TLDR: Project 2025, a report by The Heritage Foundation, proposes dismantling the Cybersecurity and Infrastructure Security Agency (CISA), which experts say would increase cybersecurity risks and endanger more Americans. The report also