Barracuda fixed a new ESG zeroSecurity Affairs·Dec 27, 14:13 UTC · Dec 27, 2023Data breach in the wildCVE-2023-7102CVE-2023-7101CVE-2023-286860
FBI: Patches for Barracuda ESG CVE-2023Security Affairs·Aug 25, 06:44 UTC · Aug 25, 2023Vulnerability in the wildCVE-2023-286860
UNC4841 threat actors hacked US government email servers exploiting Barracuda ESG flawSecurity Affairs·Aug 29, 20:15 UTC · Aug 29, 2023Threat actorCVE-2023-286860
Barracuda ESG zero-day exploited by ChinaSecurity Affairs·Aug 24, 23:02 UTC · Aug 24, 2023Exploit / PoC in the wildCVE-2023-286860
CISA discovered a new backdoor, named Whirlpool, used in Barracuda ESG attacksSecurity Affairs·Aug 10, 17:28 UTC · Aug 10, 2023MalwareCVE-2023-286860
Threat actors are exploiting Barracuda ESG bug since October 22Security Affairs·May 31, 13:36 UTC · May 31, 2023Threat actor in the wildCVE-2023-286860
China-linked threat actors stole 10% of Belgian State Security Service (VSSE)'s staff emailsSecurity Affairs·Feb 28, 07:54 UTC · Feb 28, 2025Threat actorCVE-2023-286860
CISA warns about SUBMARINE Backdoor employed in Barracuda ESG attacksSecurity Affairs·Jul 29, 22:58 UTC · Jul 29, 2023MalwareCVE-2023-286860
Barracuda Email Security Gateway (ESG) hacked via zeroSecurity Affairs·May 24, 18:13 UTC · May 24, 2023Data breachCVE-2023-286860
Barracuda Urges Replacing — Not Patching — Its Email Security GatewaysKrebs on Security·Jun 8, 21:40 UTC · Jun 8, 2023RansomwareCVE-2023-286860
Attackers hacked Barracuda ESG appliances via zero-day since October 2022Help Net Security·Jun 9, 15:34 UTC · Jun 9, 2023Exploit / PoCCVE-2023-286860
Barracuda ESG appliances impacted by CVE-2023Security Affairs·Jun 8, 07:21 UTC · Jun 8, 2023Data breach in the wildCVE-2023-286860
New persistent backdoor used in attacks on Barracuda ESG appliancesHelp Net Security·Jul 31, 00:00 UTC · Jul 31, 2023MalwareCVE-2023-286860
Replace Barracuda ESG appliances, company urgesHelp Net Security·Jun 19, 09:04 UTC · Jun 19, 2023Data breachCVE-2023-286860
Urgent FBI Warning: Barracuda Email Gateways Vulnerable Despite Recent PatchesThe Hacker News·Aug 25, 14:51 UTC · Aug 25, 2023VulnerabilityCVE-2023-286860
FBI: Barracuda Appliances Still Being Exploited By ChinaInfosecurity Magazine·Aug 25, 09:30 UTC · Aug 25, 2023Exploit / PoCCVE-2023-286860
How will recent risk trends shape the future of GRCHelp Net Security·Mar 24, 00:00 UTC · Mar 24, 2022Ransomware60
Barracuda Urges Swift Replacement of Vulnerable ESG AppliancesInfosecurity Magazine·Jun 9, 12:30 UTC · Jun 9, 2023Exploit / PoCCVE-2023-286860
CISA: New Whirlpool Backdoor Used in Barracuda ESG CampaignInfosecurity Magazine·Aug 11, 10:00 UTC · Aug 11, 2023MalwareCVE-2023-286860
Barracuda Urges Immediate Replacement of Hacked ESG AppliancesThe Hacker News·Jun 9, 05:07 UTC · Jun 9, 2023Exploit / PoCCVE-2023-286860
U.S. CISA adds Adminer, Cisco IOS, Fortra GoAnywhere MFT, Libraesva ESG, and Sudo flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Sep 30, 09:07 UTC · Sep 30, 2025Exploit / PoC in the wildCVE-2021-21311CVE-2025-20352CVE-2025-10035+3 CVEs60
Libraesva ESG zero-day vulnerability exploited by attackers (CVE-2025-59689)Help Net Security·Sep 24, 00:00 UTC · Sep 24, 2025Exploit / PoCCVE-2025-5968960
Hackers Deploy "SUBMARINE" Backdoor in Barracuda Email Security Gateway AttacksThe Hacker News·Aug 2, 03:14 UTC · Aug 2, 2023MalwareCVE-2023-286860
Attacks on Barracuda Networks linked to ChinaThe Record·Jun 15, 17:24 UTC · Jun 15, 2023Data breachCVE-2023-286860
Barracuda email security appliances hacked via zero-day vulnerability (CVE-2023-2868)Help Net Security·May 30, 17:14 UTC · May 30, 2023Exploit / PoCCVE-2023-286860
Chinese UNC4841 Group Exploits Zero-Day Flaw in Barracuda Email Security GatewayThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2023Exploit / PoCCVE-2023-286860
CISA adds recently patched Barracuda zero-day to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 28, 04:17 UTC · May 28, 2023Exploit / PoC in the wildCVE-2023-286860
State-Sponsored Hackers Exploiting Libraesva Email Security Gateway VulnerabilityThe Hacker News·Sep 24, 06:24 UTC · Sep 24, 2025Vulnerability in the wildCVE-2025-5968960
Barracuda thought it drove 0-day hackers out of customers’ networks. It was wrong.Ars Technica · Security·Aug 30, 17:31 UTC · Aug 30, 2023VulnerabilityCVE-2023-286860
Black Kite releases two modeling solutions for ransomware and business interruption scenariosHelp Net Security·Jun 20, 00:00 UTC · Jun 20, 2023Ransomware60
Beyond the Code: Unearthing the Subtle Business Ramifications of Six Months in VulnerabilitiesRecorded Future·Jun 23, 00:00 UTC · Jun 23, 2026VulnerabilityCVE-2022-41082CVE-2023-0669CVE-2023-286860
Nation-State hackers exploit Libraesva Email Gateway flawSecurity Affairs·Sep 24, 19:54 UTC · Sep 24, 2025Threat actorCVE-2025-5968960
CISA warns federal agencies of exploited Google Chrome and openThe Record·Jan 3, 21:36 UTC · Jan 3, 2024Advisory in the wildCVE-2023-7101CVE-2023-702460
CISA ADDS CHROME AND PERL LIBRARY FLAWS TO ITS KNOWN EXPLOITED VULNERABILITIES CATALOGSecurity Affairs·Jan 3, 19:14 UTC · Jan 3, 2024Exploit / PoC in the wildCVE-2023-7024CVE-2023-7101CVE-2023-710260
Chinese Hackers Exploited New ZeroThe Hacker News·Dec 28, 11:07 UTC · Dec 28, 2023Exploit / PoC in the wildCVE-2023-7102CVE-2023-2868CVE-2023-710160
ThreatNG open-source datasets aim to improve cybersecurity practicesHelp Net Security·Dec 13, 00:00 UTC · Dec 13, 2023Data breach60
Chinese Hackers Target US, Other Govts With Barracuda FlawInfosecurity Magazine·Aug 30, 16:30 UTC · Aug 30, 2023Exploit / PoCCVE-2023-286860
Chinese Hacking Group Exploits Barracuda Zero-Day to Target Government, Military, and TelecomThe Hacker News·Aug 29, 15:43 UTC · Aug 29, 2023Exploit / PoCCVE-2023-286860