I recently told you about an extremely serious vulnerability with Barracuda’s Email Security Gateway Appliance (ESG) that has alarm bells ringing all over Hell’s half acre.
Barracuda has a full description of the incident so far in their advisory, including extensive indicators of compromise, additional vulnerability details, and information on the backdoored module for Barracuda’s SMTP daemon. Now this I give Barracuda credit for as there’s a lot of detail here so that if you have one of these ESG Appliances, you can in theory address any vulnerabilities quickly and effectively. But at the same time that document says this right at the top of it:
ACTION NOTICE: Impacted ESG appliances must be immediately replaced regardless of patch version level. If you have not replaced your appliance after receiving notice in your UI, contact support now (support@barracuda.com).
Barracuda’s remediation recommendation at this time is full replacement of the impacted ESG.
That’s right. You need to replace your ESG Appliance to address this actively exploited vulnerability. Even if you’ve patched it. I’ve been in this space for over 25 years and I have never, ever seen a recommendation like this before. The only reason that I can come up with for this recommendation is that whatever threat actor did this has managed to gain persistence on the device. Or put into layman’s terms, they’ve pitched the tent, started the campfire, and built a very high wall around the campsite along with a moat that would make it next to impossible to get them out. That’s the holy grail for any threat actor and that’s really, really, bad if you have an ESG Appliance.
Here’s the problem with that, replacing devices wholesale isn’t something that can be scaled to a level that Barracuda customers can work with as we are not talking about a consumer router that can be reconfigured in an hour or less. We’re talking about an email gateway that is actively scanning for email based threats, and in today’s world not only can’t be out of service for a lengthy period, but these sorts of appliances are often tied into a much larger security setup that company have. And you have to wonder if Barracuda can scale to meet the demands of customers who are going to email them with requests to replace this gear quickly. As in next day or same day replacements in some cases. This is a very bad situation and I am sure this is going to cost Barracuda some customers. Because even though there are exploits out there that threaten everyone, this is above and beyond anything that I have ever seen before. And that will make some of Barracuda’s customers wonder if the company was asleep at the switch when it came to the security of their devices.
Apollo To Shut Down As Of June 30th Because Of Reddit’s API Changes
Posted in Commentary with tags Reddit on June 8, 2023 by itnerdI recently told you about the fact that Reddit was going to start charging for access to its API, and that had many upset enough to plan to black out Reddit on June 12th. Related to this, it now seems that Apollo which is the most popular third party Reddit client is going to shut down on June 30th:
Eight years ago, I posted in the Apple subreddit about a Reddit app I was looking for beta testers for, and my life completely changed that day. I just finished university and an internship at Apple, and wanted to build a Reddit client of my own: a premier, customizable, well-designed Reddit app for iPhone. This fortunately resonated with people immediately, and it’s been my full time job ever since.
Today’s a much sadder post than that initial one eight years ago. June 30th will be Apollo’s last day.
I’ve talked to a lot of people, and come to terms with this over the last weeks as talks with Reddit have deteriorated to an ugly point, and in the interest of transparency with the community, I wanted to talk about how I arrived at this decision, and if you have any questions at the end, I’m more than happy to answer. This post will be long as I have a lot of topics to cover.
Please note that I recorded all my calls with Reddit, so my statements are not based on memory, but the recorded statements by Reddit over the course of the year. One-party consent recording is legal in my country of Canada. Also I won’t be naming names, that’s not important and I don’t want to doxx people.
I encourage you to read the full post, but to be honest, this post does not paint Reddit in the best light as you can make an argument that Reddit is simply using charing for access to their API as cover to kill third party clients. That makes Reddit a way less appealing place to be. Much like Twitter. Minus the Twitter levels of hate, bigotry and everything else. This is sure to generate a lot of negativity towards Reddit, and you have to wonder if this will force Reddit to course correct. Or they simply don’t care and are going to push ahead with this ill conceived idea to kill third party clients.
Leave a comment »