back to article Chinese spies blamed for data-harvesting raids on Barracuda email gateways

Chinese spies are behind the data-stealing malware injected into Barracuda's Email Security Gateway (ESG) devices globally as far back as October 2022, according to Mandiant. Barracuda discovered a critical bug, tracked as CVE-2023-2868, in these appliances on May 19, we're told, and pushed a patch to all affected products the …

  1. Version 1.0 Silver badge
    Unhappy

    Email Security Gateway safety

    You can make your Email Security Gateway very secure by reducing the external access rate to about 1200bps, high speed internet access is also high speed attack enabling these days. Yes, it would be a pain in the butt for everyone but slow access will make the criminal access much harder.

  2. Anonymous Coward
    Anonymous Coward

    Need some more explanation

    The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape archives). The vulnerability stems from incomplete input validation of a user-supplied .tar file as it pertains to the names of the files contained within the archive. As a consequence, a remote attacker can specifically format these file names in a particular manner that will result in remotely executing a system command through Perl's qx operator with the privileges of the Email Security Gateway product. This issue was fixed as part of BNSF-36456 patch.

    Hope nobody left the back door open ... accidentally.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like