Chinese Hackers Exploited New Zero-Day in Barracuda's ESG Appliances
ID: 91904820-0a3c-5e3c-9e85-1acff6f81f44
STIX ID: report--91904820-0a3c-5e3c-9e85-1acff6f81f44
Feed Name: The Hacker News
Threat Score
Barracuda disclosed that threat actor UNC4841 exploited a zero-day (CVE-2023-7102) in its Email Security Gateway to execute arbitrary code when scanning malicious Excel attachments, leading to deployment of SEASPY and SALTWATER backdoors on a limited number of appliances; Barracuda deployed automatic updates and remediation while the underlying Spreadsheet::ParseExcel library remains unpatched, and Mandiant/Google Cloud reported impacts across multiple countries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
