Gigabyte Rolls Out BIOS Updates to Remove Backdoor From Motherboards

Taiwanese computer components maker Gigabyte has announced BIOS updates meant to remove a backdoor feature that was recently found in hundreds of its motherboards.

The issue, disclosed last week by firmware and hardware security company Eclypsium, is that the firmware of more than 270 Gigabyte motherboards drops a Windows binary that is executed at boot-up to fetch and execute a payload from Gigabyte’s servers.

A feature related to the Gigabyte App Center, the backdoor does not appear to have been exploited for malicious purposes, but threat actors are known to have abused such tools in previous attacks.

When it made its findings public, Eclypsium said it was unclear whether the backdoor was the result of a malicious insider, a compromise of Gigabyte’s servers, or a supply chain attack.

Shortly after Eclypsium published its report, Gigabyte announced the release of BIOS updates that address the vulnerability.

“Gigabyte engineers have already mitigated potential risks and uploaded the Intel 700/600 and AMD 500/400 series Beta BIOS to the official website after conducting thorough testing and validation of the new BIOS on Gigabyte motherboards,” the company announced late last week.

BIOS updates for Intel 500/400 and AMD 600 series chipset motherboards and for previously released motherboards were set to be released late last week as well.

Advertisement. Scroll to continue reading.

The update resolves “the download assistant vulnerabilities reported by Eclypsium”, read the release notes for the latest BIOS available for the A520 Aorus Elite rev 1.0 motherboards.

The update implements stricter security checks during system boot, including improved validation for files downloaded from remote servers and standard verification of remote server certificates.

The new security enhancements, the company says, should prevent attackers from inserting malicious code during boot and should guarantee that any files downloaded during this process come from servers with valid and trusted certificates.

Organizations and end users alike should review Eclypsium’s list of more than 270 affected motherboard models and, if impacted, should head to Gigabyte’s support website to check for and download any BIOS update released after June 1, 2023.

Related: MSI Confirms Cyberattack, Issues Firmware Download Guidance

Related: BMC Firmware Vulnerabilities Expose OT, IoT Devices to Remote Attacks

Related: Intel Patches High-Severity Vulnerabilities in BIOS, Boot Guard

https://www.securityweek.com/gigabyte-rolls-out-bios-updates-to-remove-backdoor-from-motherboards/




In Other News: Government Use of Spyware, New Industrial Security Tools, Japan Router Hack 

SecurityWeek is publishing a weekly cybersecurity roundup that provides a concise compilation of noteworthy stories that might have slipped under the radar.

We provide a valuable summary of stories that may not warrant an entire article, but are nonetheless crucial for a comprehensive understanding of the cybersecurity landscape.

Each week, we will curate and present a collection of noteworthy developments, ranging from the latest vulnerability discoveries and emerging attack techniques to significant policy changes and industry reports.

By bringing these stories to your attention, we empower you to stay informed, enhance your security posture, and make well-informed decisions to protect your organization.

Here are this week’s stories:

Spyware used in Israel, the Middle East and the US

Separate reports published this week detail the spyware used by Israeli Police (Echo tool offered by Israeli firm Rayzone), Arab intelligence services (spying tools offered by Swiss company In The Cyber), and the US Drug Enforcement Agency (spyware called Paragon Graphite).

Advertisement. Scroll to continue reading.

Google shuts down YouTube channels used for influence operations

Google in April shut down many YouTube channels that were part of coordinated influence operations linked to Russia, Turkey, Iran, China, Azerbaijan, and Uzbekistan. The Chinese operation was powered by roughly 3,500 channels. 

Iranian government websites and networks targeted by local hacktivists

An Iranian hacktivist group called GhyamSarnegouni (‘Rise to Overthrow’ or ‘Uprising till Overthrow’) has been targeting the Iranian government, defacing websites and breaching networks in an effort to steal and leak what appears to be highly sensitive data. 

90 organizations notify UK ICO of data breaches related to Capita hack

The BBC reported that 90 organizations in the UK have informed the country’s privacy and data watchdog about being hit by the recent data breach at British business process outsourcing firm Capita. The impacted organizations handle the data of millions of people. Capita said recently it expects the ransomware attack to cost it up to $25 million. 

Linux routers in Japan targeted with GobRAT malware

Japan’s JPCERT/CC issued a warning about Linux routers in the country being targeted with the GobRAT malware since February. The attackers are using a loader to disable the device’s firewall function, download GobRAT, and ensure persistence on a device. Compromised routers can be abused for various types of malicious purposes. 

‘Migraine’ macOS vulnerability discovered by Microsoft 

Microsoft has disclosed the details of CVE-2023-32369, a recently patched macOS vulnerability that could allow an attacker with root access to automatically bypass System Integrity Protection (SIP) and perform arbitrary operations on the targeted computer. Microsoft has dubbed the flaw ‘Migraine’.

Vulnerabilities patched in OpenSSL and VMware

The latest OpenSSL updates patch CVE-2023-2650, a medium-severity vulnerability that can be exploited to cause a DoS condition.

In addition, VMware announced that it has fixed a medium-severity information disclosure vulnerability in Workspace One Access and Identity Manager. The issue is tracked as CVE-2023-20884.

RAIDForums database leaked

Someone has leaked a database allegedly containing the information of roughly 479,000 users of the RaidForums cybercrime forum. Threat intelligence company Kela has an analysis of the leak, which includes email addresses, usernames, IPs, and credentials. Leaked hacker forum databases can be useful for identifying cybercriminals. 

Mass scanning of popular GitHub repositories for misconfigurations

Checkmarx reported seeing a GitHub user forking nearly 2,000 repositories (with 319,000 total stars) as part of what appeared to be a bug bounty hunting attempt for finding misconfigurations in CI pipelines.

Secureworks announces two new offerings for industrial organizations

Secureworks has announced two new cybersecurity offerings for industrial organizations. The first is Taegis XDR for OT, an XDR platform for MSSPs and organizations that manage their own SOC, which combines OT intelligence with IT security telemetry. The second is Taegis ManagedXDR for OT, a fully managed security offering for IT and OT environments.

https://www.securityweek.com/in-other-news-government-use-of-spyware-new-industrial-security-tools-japan-router-hack/




High-Severity Vulnerabilities Patched in Splunk Enterprise

Splunk on Thursday announced Splunk Enterprise security updates that resolve multiple high-severity vulnerabilities, including some impacting third-party packages used by the product.

The most severe of these is CVE-2023-32707, a privilege escalation issue that allows low-privileged users with the ‘edit_user’ capability to escalate privileges to administrator, via a specially crafted web request.

“This is because the ‘edit_user’ capability does not honor the ‘grantableRoles’ setting in the authorize.conf configuration file, which prevents this scenario from happening,” Splunk explains in an advisory.

Next in line is CVE-2023-32706, a denial-of-service (DoS) flaw in the Splunk daemon, which occurs when an incorrectly configured XML parser receives specially-crafted messages within SAML authentication.

The input contains a reference to an entity expansion and recursive references may cause the XML parser to use all available memory on the machine, leading to the daemon’s crash or to process termination.

Another high-severity vulnerability addressed in Splunk Enterprise is CVE-2023-32708, an HTTP response splitting issue that allows a low-privileged user to access other REST endpoints on the system and view restricted content.

On Thursday, Splunk also resolved multiple severe issues in third-party packages used in Splunk Enterprise, such as Libxml2, OpenSSL, Curl, Libarchive, SQLite, Go, and many others. Some of these vulnerabilities have been public for more than four years.

Advertisement. Scroll to continue reading.

All these flaws were addressed with the release of Splunk Enterprise versions 8.1.14, 8.2.11, and 9.0.5. The updates resolve multiple medium-severity vulnerabilities as well.

On Thursday, Splunk also announced patches for high-severity bugs in Splunk App for Lookup File Editing and Splunk App for Stream, and fixes for severe issues in third-party packages used in Splunk Universal Forwarders and Splunk Cloud.

Additional information on the patched vulnerabilities can be found on Splunk’s security advisories page.

Related: Splunk Enterprise Updates Patch High-Severity Vulnerabilities

Related: Splunk Patches 9 High-Severity Vulnerabilities in Enterprise Product

Related: Quarterly Security Patches Released for Splunk Enterprise

https://www.securityweek.com/high-severity-vulnerabilities-patched-in-splunk-enterprise/




Zero-Day in MOVEit File Transfer Software Exploited to Steal Data From Organizations

A zero-day vulnerability affecting Progress Software’s MOVEit Transfer product has been exploited to hack organizations and steal their data.

Progress Software warned on May 31 that its MOVEit Transfer managed file transfer (MFT) software is affected by a critical SQL injection vulnerability that can be exploited by an unauthenticated attacker to access MOVEit Transfer databases.

“Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements,” the vendor said. 

A CVE identifier is in the process of being assigned to the vulnerability. 

Progress’ advisory is confusing as it states that the company is working on patches, but it also lists updated versions that should fix the security hole. Patches should be included in versions 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5) and 2023.0.1 (15.0.1). The cloud version of the product appears to be impacted as well.

The company’s advisory does not clearly state that the vulnerability has been exploited in the wild, but it does tell customers that patching is extremely important and it does provide indicators of compromise (IoCs) associated with the observed attacks.

Several cybersecurity firms have reported seeing attacks involving the MOVEit zero-day, including Huntress, Rapid7, TrustedSec, GreyNoise, and Volexity.

Advertisement. Scroll to continue reading.

TrustedSec reported that mass exploitation started on May 28, with the attackers likely taking advantage of Memorial Day to increase their chances of being able to steal data without being detected. There is also some indication of limited exploitation prior to the holiday weekend. 

GreyNoise reported seeing scanning activity that could be related to this vulnerability as early as March 3. 

In the attacks observed in recent days, threat actors seem to have exploited the zero-day to deploy a webshell/backdoor in a file named ‘human2.aspx’ in the ‘wwwroot’ folder of the MOVEit software. This backdoor allows them to obtain a list of files and users associated with the MFT product, download files within MOVEit, and add a backdoor admin user.

Google-owned Mandiant has been investigating intrusions related to the zero-day attack and the company told SecurityWeek that it has seen “mass exploitation and broad data theft” in the past few days. 

Major organizations appear to be impacted. It’s unclear exactly how many are affected, but a Shodan search shows roughly 2,500 internet-exposed instances of MOVEit Transfer, and the vendor says its products are used by hundreds of thousands of enterprises, including 1,700 software firms.

Researcher Kevin Beaumont pointed out that one of the exposed MOVEit instances appears to belong to the US Department of Homeland Security (DHS). The DHS’s Cybersecurity and Infrastructure Security Agency (CISA) on Thursday issued an alert to warn organizations about the zero-day. A vast majority of the internet-exposed instances are indeed located in the United States. 

The attackers appear to be using the exploit to steal potentially valuable data, which, as Beaumont noted, indicates that a ransomware or extortion group is behind the attacks. 

If confirmed, this would be the second popular MFT product targeted by cybercriminals in recent months. A vulnerability affecting Fortra’s GoAnywhere software has been used by a ransomware group to steal data from many organizations.

Related: GoAnywhere Zero-Day Attack Hits Major Orgs  

Related: Barracuda Zero-Day Exploited to Deliver Malware for Months Before Discovery

https://www.securityweek.com/zero-day-in-moveit-file-transfer-software-exploited-to-steal-data-from-organizations/




Google Temporarily Offering $180,000 for Full Chain Chrome Exploit

Google today announced significantly higher bug bounty rewards for vulnerability reports containing full chain exploits leading to a sandbox escape in Chrome.

Until December 1, 2023, the first report to contain a full chain exploit leading to a Chrome sandbox escape, Google says, may receive up to $180,000, or even more if cumulated with other bonuses, which is triple the current reward amount.

Subsequent full chain exploits that are submitted during the timeframe may receive up to $120,000, which is double the current reward amount. All reports should be submitted through the Chrome vulnerability rewards program.

“We’re always interested in explorations of new and novel approaches to fully exploit Chrome browser and we want to provide opportunities to better incentivize this type of research. These exploits provide us valuable insight into the potential attack vectors for exploiting Chrome, and allow us to identify strategies for better hardening specific Chrome features,” the internet giant says.

According to Google, interested researchers may submit the vulnerability report in advance, but need to provide a functional exploit by December 1 to be eligible for the increased rewards.

The first functional full chain exploit submitted during the timeframe, which demonstrates attacker control or code execution outside the Chrome sandbox, is eligible for the triple reward amount.

The exploit chain should be performed remotely and require no or very limited user interaction. Furthermore, it should target an active Chrome release channel “at the time of the initial reports of the bugs in that chain”.

Advertisement. Scroll to continue reading.

Exploits targeting publicly disclosed bugs in past versions of Chrome are not eligible for the reward.

Related: Chrome 114 Released With 18 Security Fixes

Related: Google Launches Bug Bounty Program for Mobile Applications

Related: Google Announces New Rating System for Android and Device Vulnerability Reports

https://www.securityweek.com/google-temporarily-offering-180000-for-full-chain-chrome-exploit/




Moxa Patches MXsecurity Vulnerabilities That Could Be Exploited in OT Attacks

Organizations using Moxa’s MXsecurity product have been informed about two potentially serious vulnerabilities that could be exploited by malicious hackers targeting operational technology (OT) networks.

MXsecurity is an industrial network security management software designed for OT environments. 

Security researcher Simon Janz discovered recently that the product is impacted by a critical vulnerability that can be exploited remotely to bypass authentication (CVE-2023-33235) and a high-severity flaw in the SSH command-line interface that can lead to remote command execution (CVE-2023-33236).

Moxa patched the security holes with the release of version 1.0.1. The industrial networking, computing and automation solutions provider has published an advisory describing the vulnerabilities. 

Advisories for the two bugs have also been published by the US Cybersecurity and Infrastructure Security Agency (CISA), which noted that the impacted product is used worldwide in multiple sectors, as well as by the Zero Day Initiative (ZDI), which coordinated the disclosure process. 

A Chinese researcher seems to have also found the same vulnerabilities and last week disclosed technical details. 

The critical vulnerability exists in the configuration of the MXsecurity web-based interface and is related to a hardcoded JWT secret. 

Advertisement. Scroll to continue reading.

Janz told SecurityWeek that an attacker can leverage the hardcoded secret key to forge valid JWT tokens and gain access to the web panel with admin privileges.

In the case of the high-severity vulnerability, the researcher noted that an attacker would need to know or guess SSH admin credentials for exploitation. Once authenticated, the attacker can execute arbitrary commands and gain a foothold in the targeted network. 

Related: Moxa NPort Device Flaws Can Expose Critical Infrastructure to Disruptive Attacks

Related: Moxa MXview Vulnerabilities Expose Industrial Networks to Attacks

Related: Flaws in Moxa Railway Devices Could Allow Hackers to Cause Disruptions

https://www.securityweek.com/moxa-patches-mxsecurity-vulnerabilities-that-could-be-exploited-in-ot-attacks/




Adobe Inviting Researchers to Private Bug Bounty Program

Adobe on Wednesday called out for all researchers on the HackerOne vulnerability reporting platform to join its VIP private bug bounty program.

The private program builds on the public Vulnerability Disclosure Program (VDP) that Adobe runs on the hacker-powered platform and promises higher rewards for the identified vulnerabilities and tighter collaboration with the research community.

Maintained by Adobe’s Product Security Incident Response Team (PSIRT), the VIP program will reward researchers helping the company identify and quickly address issues in a broad range of products.

Over the past year, the company has added all Adobe desktop and mobile applications to the private program and doubled the maximum bug bounty rewards, which are now paid out faster to the reporting researchers.

Additionally, Adobe is running monthly bounty multiplier campaigns as part of the VIP program, including a bonus campaign that rewards researchers for proof-of-concept (PoC) demonstrations exploiting new vulnerabilities in CISA’s Known Exploited Vulnerabilities (KEV) catalog on Adobe’s products.

“As a member of Adobe-VIP, you’ll have the opportunity to work closely with our world-class team of security experts to help safeguard the digital experiences of millions of people around the globe, and on a much wider set of products than in our public program,” the company notes.

The company’s public program currently covers vulnerabilities in Adobe Commerce, Commerce B2B, and Magento and offers bug bounty rewards of up to $10,000 for critical-severity issues.

Advertisement. Scroll to continue reading.

Qualified security researchers interested in joining Adobe’s VIP private bug bounty program need to submit an application.

Related: Adobe Patches 14 Vulnerabilities in Substance 3D Painter

Related: Adobe Plugs Gaping Security Holes in Reader, Acrobat

Related: Adobe Acrobat Sign Abused to Distribute Malware

https://www.securityweek.com/adobe-inviting-researchers-to-private-bug-bounty-program/




Researchers tell owners to “assume compromise” of unpatched Zyxel firewalls

Researchers tell owners to “assume compromise” of unpatched Zyxel firewalls
Getty Images

Firewalls made by Zyxel are being wrangled into a destructive botnet, which is taking control of them by exploiting a recently patched vulnerability with a severity rating of 9.8 out of a possible 10.

“At this stage if you have a vulnerable device exposed, assume compromise,” officials from Shadowserver, an organization that monitors Internet threats in real time, warned four days ago. The officials said the exploits are coming from a botnet that’s similar to Mirai, which harnesses the collective bandwidth of thousands of compromised Internet devices to knock sites offline with distributed denial-of-service attacks.

According to data from Shadowserver collected over the past 10 days, 25 of the top 62 Internet-connected devices waging “downstream attacks”—meaning attempting to hack other Internet-connected devices—were made by Zyxel as measured by IP addresses.

A 9.8-severity vulnerability in default configurations

The software bug used to compromise the Zyxel devices is tracked as CVE-2023-28771, an unauthenticated command injection vulnerability with a severity rate of 9.8. The flaw, which Zyxel patched on April 25, can be exploited to execute malicious code with a specially crafted IKEv2 packet to UDP port 500 on the device.

The critical vulnerability exists in default configurations of the manufacturer’s firewall and VPN devices. They include Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35.

Affected series Affected version Patch availability
ATP ZLD V4.60 to V5.35 ZLD V5.36
USG FLEX ZLD V4.60 to V5.35 ZLD V5.36
VPN ZLD V4.60 to V5.35 ZLD V5.36
ZyWALL/USG ZLD V4.60 to V4.73 ZLD V4.73 Patch 1

On Wednesday, the Cybersecurity and Infrastructure Security Agency placed CVE-2023-28771 on its list of known exploited vulnerabilities. The agency has given federal agencies until June 21 to fix any vulnerable devices in their networks.

Security researcher Kevin Beaumont has also been warning of widespread exploitation of the vulnerability since last week.

“This #Zyxel vuln is being mass exploited now by Mirai botnet,” he wrote on Mastodon. “A fuck ton of SMB VPN boxes are owned.”

Measurements from the Shodan search engine show almost 43,000 instances of Zyxel devices exposed to the Internet.

“This number only includes devices that expose their web interfaces on the WAN, which is not a default setting,” Rapid7 said, using the abbreviation for wide area network, the part of a company’s network that can be accessed over the Internet. “Since the vulnerability is in the VPN service, which is enabled by default on the WAN, we expect the actual number of exposed and vulnerable devices to be much higher.”

A VPN—short for virtual private network—doesn’t need to be configured on a device for it to be vulnerable, Rapid7 said. Zyxel devices have long been a favorite for hacking because they reside at the edge of a network, where defenses are typically lower. Once infected, attackers use the devices as a launch pad for compromising other devices on the Internet or as a toe-hold that can be used to spread to other parts of the network they belong to.

While most of the focus is on CVE-2023-28771, Rapid7 warned of two other vulnerabilities—CVE-2023-33009 and CVE-2023-33010 — that Zyxel patched last week. Both vulnerabilities also carry a 9.8 severity rating.

With infections from CVE-2023-28771 still occurring five weeks after Zyxel fixed it, it’s clear many device owners aren’t installing security updates in a timely manner. If the poor patching hygiene carries over to the more recently fixed vulnerabilities, there likely will be more Zyxel compromises occurring soon.

https://arstechnica.com/?p=1943400




Millions of WordPress Sites Patched Against Critical Jetpack Vulnerability

An automatic update pushed to roughly five million WordPress sites over the past few days addresses a critical vulnerability introduced in 2012.

Maintained by Automattic, Jetpack is a WordPress plugin providing security features such as malware scan, real-time backup and restore, spam and brute-force attack protection, and more.

The suite of security tools has more than five million active installations, making it one of the most popular plugins for the content management system.

On Tuesday, Automattic announced that it has started rolling out a critical security update that addresses a vulnerability impacting all plugin versions since Jetpack 2.0.

“During an internal security audit, we found a vulnerability with the API available in Jetpack since version 2.0, released in 2012. This vulnerability could be used by authors on a site to manipulate any files in the WordPress installation,” Automattic says.

A total of 102 Jetpack versions were updated this week, and the patches were automatically rolled out to users. Over the past two days, the plugin has amassed close to five million downloads, meaning that almost all impacted websites have received the update.

According to Automattic, there is no evidence that the vulnerability has been exploited in malicious attacks. However, vulnerabilities in popular WordPress plugins are known to represent an attractive target for cybercriminals, given the potential damage successful exploitations could cause.

Advertisement. Scroll to continue reading.

Site owners are advised to ensure that their Jetpack installations are up to date. Automattic has provided a complete list of the 102 plugin versions released this week.

Related: WordPress Field Builder Plugin Vulnerability Exploited in Attacks Two Days After Patch

Related: 1 Million WordPress Sites Impacted by Exploited Plugin Vulnerability

Related: Vulnerability in Field Builder Plugin Exposes Over 2M WordPress Sites to Attacks

https://www.securityweek.com/millions-of-wordpress-sites-patched-against-critical-jetpack-vulnerability/




Barracuda Zero-Day Exploited to Deliver Malware for Months Before Discovery

A zero-day vulnerability affecting Barracuda Networks email security appliances has been exploited to deploy malware and steal data from organizations for several months before it was discovered.

The zero-day, tracked as CVE-2023-2868 and described as a remote command injection issue, impacts Email Security Gateway (ESG) appliances running versions 5.1.3.001 through 9.2.0.006. 

“The vulnerability stemmed from incomplete input validation of user supplied .tar files as it pertains to the names of the files contained within the archive. Consequently, a remote attacker could format file names in a particular manner that would result in remotely executing a system command through Perl’s qx operator with the privileges of the Email Security Gateway product,” Barracuda explained.

Barracuda became aware of attacks targeting its product on May 18 and confirmed the existence of a new vulnerability the next day. A patch was rolled out to ESG devices on May 20 and the vendor released an additional script one day later to contain the incident and neutralize unauthorized access methods. Additional fixes are also being deployed as part of the company’s containment strategy.

The vulnerability only appears to impact the ESG product, specifically a module designed for the initial screening of email attachments.

In an update shared on Tuesday, Barracuda provided additional information on the attack and the actions carried out by the attackers. An investigation conducted with the help of Mandiant revealed that CVE-2023-2868 has been exploited in attacks since at least October 2022.

The threat actor exploited the zero-day to hack ‘a subset’ of ESG devices and deploy malware that gave them persistent backdoor access. In some cases, data exfiltration was also detected. 

Advertisement. Scroll to continue reading.

Three types of malware were discovered on compromised Barracuda devices. One of them, named SaltWater, has been described as a trojanized module for the Barracuda SMTP daemon. It allows attackers to upload or download files, execute commands, and use it for proxy or tunneling purposes. Mandiant is currently analyzing the malware for links to known threats.

Another piece of malware involved in the attack is SeaSpy, a persistence backdoor that poses as a legitimate Barracuda service. It monitors traffic and provides backdoor functionality activated by a ‘magic packet’. Mandiant did find some code overlap between this malware and a publicly available backdoor named cd00r. 

The third piece of malware is named Seaside and it has been described as a Lua-based module that also targets the Barracuda SMTP daemon. It receives a command and control (C&C) IP address and port that are passed on to an external binary that establishes a reverse shell. 

Barracuda has shared indicators of compromise (IoCs) for both endpoints and networks, as well as Yara rules that can be used for threat hunting. 

Customers have been advised to ensure that their devices are up to date and to stop using compromised appliances — Barracuda is providing new virtual or hardware appliances to impacted users.

Related: Fortinet Admits Many Devices Still Unprotected Against Exploited Vulnerability

Related: Custom Chinese Malware Found on SonicWall Appliance

Related: Sophos Firewall Zero-Day Exploited in Attacks on South Asian Organizations

https://www.securityweek.com/barracuda-zero-day-exploited-to-deliver-malware-for-months-before-discovery/