China-Linked Hackers Target Barracuda Email Security Gateway Appliances with New Zero-Day Vulnerability

China-linked hackers have continued their relentless targeting of Barracuda Email Security Gateway (ESG) appliances, exploiting a newly discovered zero-day vulnerability. In a recent series of attacks, the group known as UNC4841, believed to be sponsored by the Chinese government, has been identified as the culprit. This latest exploit follows a similar incident in June, where the same cyber espionage group was found to have targeted Barracuda devices.

Attribution of the attacks

Mandiant, a renowned cybersecurity firm, has confidently attributed the attacks to UNC4841. With high confidence, they believe this group to be backed by the Chinese government. The attacks were initially reported back in June, shedding light on the persistent threat posed by these state-sponsored hackers.

Exploitation of CVE-2023-2868

In their pursuit of compromising Barracuda devices, the hackers exploited a critical vulnerability identified as CVE-2023-2868. The initial access was gained by sending specially crafted emails to targeted organizations. Barracuda responded swiftly by releasing patches to address the vulnerability. However, the hackers proved to be unfazed by these countermeasures and continued their relentless targeting of Barracuda appliances.

Identification of a new zero-day vulnerability

Barracuda has recently issued a warning that UNC4841 has discovered yet another zero-day vulnerability affecting ESG appliances. This newly identified flaw, CVE-2023-7102, directly impacts the ‘Spreadsheet::ParseExcel’ library utilized by the Amavis virus scanner present in ESG devices. This discovery further amplifies concerns surrounding the security of Barracuda appliances.

Exploitation of the new vulnerability

Acting swiftly upon discovering the zero-day vulnerability, the hackers exploited CVE-2023-7102 to deliver new variants of the SeaSpy and SaltWater malware. Although the attacks were targeted at a limited number of devices, the potential impact and scope of the exploitation are causes for concern.

Response and Ongoing Investigation

Barracuda has assured its customers that no immediate action is required on their part. Nevertheless, the company has initiated a thorough investigation into the new vulnerability. The ongoing investigation aims to understand the full extent of the vulnerability’s impact and devise appropriate countermeasures.

Patch Availability

The company has acknowledged that currently, there is no patch available for the vulnerability found in the ‘Spreadsheet::ParseExcel’ library. The specific CVE identifier for this vulnerability is CVE-2023-7101. This lack of an immediate solution complicates the mitigation efforts and highlights the urgency required in addressing the issue effectively.

Previous targeting of UNC4841

Mandiant’s previous investigations into UNC4841 revealed that the cyberespionage group has actively targeted entities across 16 countries. Their victims include government organizations, high-ranking officials, academic institutions, academic research organizations, and foreign trade offices. The sustained targeting of high-profile entities underscores the motive and persistence of this state-sponsored group.

The enduring threat posed by China-linked hackers targeting Barracuda Email Security Gateway appliances highlights the need for constant vigilance and proactive security measures. The discovery of a new zero-day vulnerability, CVE-2023-7102, adds to the ongoing concern surrounding the security of ESG appliances. Barracuda’s prompt response to these attacks and their commitment to ongoing investigations provide a glimpse of hope amidst the escalating cyber threats. To effectively mitigate the risks, continued monitoring, future patches, and proactive security practices are imperative for organizations relying on Barracuda products.

Explore more

Xiaomi Redmi K100 – Review

The transition from affordable mid-range devices to sophisticated powerhouses that rival high-end flagships has reached a critical tipping point with recent hardware revelations. This evolution reflects a broader industry move toward democratizing premium features for a global audience. The focus has shifted from mere cost-cutting to delivering uncompromising performance. Evolution of the Redmi K-Series and the Rise of the K100

Should You Say Please and Thank You to AI?

Dominic Jainy’s extensive background in artificial intelligence and machine learning offers a sophisticated perspective on one of the most curious behavioral shifts in the modern erthe habit of treating software with human-level courtesy. As an expert who navigates the complexities of blockchain and neural networks, Jainy understands that while a chatbot might feel like a “helpful colleague” who remembers past

Trend Analysis: Agentic AI Security Governance

The rapid evolution of autonomous agents from simple scripts into high-authority digital entities has created a new frontier where the distinction between a software tool and an independent decision-maker has effectively vanished. As these agents transition from experimental environments to production-grade users of infrastructure, they introduce a paradigm shift in how organizations perceive security. The boundary between a contained piece

OnePlus Unveils Turbo 6X Pro With Massive 8,000mAh Battery

Dominic Jainy is an IT professional with deep expertise in the shifting landscape of mobile hardware and system architecture. He has spent years tracking how high-end technology eventually becomes accessible to the broader public through mid-range devices. In this conversation, he discusses the upcoming launch of the OnePlus Turbo 6X Pro, examining how its massive 8,000mAh battery and record-breaking display

China-Linked OP-512 Group Targets Legacy IIS Servers

The ongoing evolution of cyber espionage has recently revealed a highly sophisticated threat cluster that prioritizes surgical precision and long-term stealth over the immediate disruption of its targets. Known as OP-512, this actor has demonstrated a profound ability to exploit the often-overlooked vulnerabilities inherent in legacy Internet Information Services (IIS) web servers. By focusing on these older environments, the group