A patch for the vulnerability, which has been exploited since October 2022, had been issued by Barracuda last month to stop the exploit from allowing ESG backdooring. Credit: Barracuda Enterprise security company Barracuda has warned its customers against using email security gateway (ESG) appliances impacted by a recently disclosed zero-day exploit and to replace them immediately.A patch for the vulnerability, which has been exploited since October 2022, had been issued by Barracuda last month to stop the exploit from allowing ESG backdooring.“The vulnerability existed in a module which initially screens the attachments of incoming emails,” the company had said previously. “No other Barracuda products, including our SaaS email security services, were subject to the vulnerability identified.” Users whose appliances Barracuda believed were impacted are being notified via the ESG user interface of actions to take. Barracuda has also reached out to these specific customers. Replacement advised despite patchesThe vulnerability, dubbed CVE-2023-2868, was identified on May 19, 2023, and reportedly affected versions 5.1.3.001 through 9.2.0.006, allowing a remote attacker to achieve code execution on susceptible installations.Consequently, Barracuda released patches on May 20 and May 21 for all ESG appliances worldwide. In the latest update on the incident, however, the company has advised to replace the appliance irrespective of their patch status. “Impacted ESG appliances must be immediately replaced regardless of patch version level,” the company said in an update, adding that its “remediation recommendation at this time is a full replacement of the impacted ESG.”Multistrained malware usedThree different malware strains have been discovered to date on a subset of appliances allowing for persistent backdoor access, according to the company. Evidence of data exfiltration was identified on a subset of impacted appliances, the company said in a previous update.The different strains used — Saltwater, Seaspy, and Seaside — were all backdoor modules affecting data exfiltration. While both Saltwater and Seaside help establish a hack for the Barracuda SMTP daemon (bsmtpd) equipped to upload and download arbitrary files, execute commands, and tunnel malicious traffic, Seasspy is an x64 executable and linkable format (ELF) backdoor offering persistence capabilities, activated through a magic (remote, wake-on-LAN) packet. Mandiant, the Google-owned cybersecurity intelligence firm investigating the incident, has revealed source code overlaps between SEASPY and an open source backdoor called cd00r. Attacks have not been attributed to any known threat actor or group. Related content news CISA, FBI urge developers to patch path traversal bugs before shipping The advisory highlights how developers can follow best practices to fix these vulnerabilities during production. By Shweta Sharma May 03, 2024 3 mins Vulnerabilities news Microsoft continues to add, shuffle security execs in the wake of security incidents The company has appointed new product security chiefs as well as a customer-facing CISO as it continues to respond to high-profile attacks on its products and own network. By Elizabeth Montalbano May 03, 2024 4 mins CSO and CISO feature Malware explained: How to prevent, detect and recover from it What are the types of malware? How does malware spread? How do you know if you’re infected? We've got answers. By Josh Fruhlinger May 03, 2024 18 mins Ransomware Phishing Malware brandpost Sponsored by Cyber NewsWire LayerX Security Raises $26M for its Browser Security Platform, Enabling Employees to Work Securely from Any Browser, Anywhere Early adoption by Fortune 100 companies worldwide, LayerX already secures more users than any other browser security solution and enables unmatched security, performance and experience By Cyber NewsWire May 02, 2024 4 mins Cyberattacks Security PODCASTS VIDEOS RESOURCES EVENTS SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe