Image: Bing Image Creator
Email and network security company Barracuda is working to resolve a persistent issue that is triggering invalid login errors and preventing Email Gateway Defense users from logging into their accounts.
The root cause of login issues showing “The login link is invalid” errors has already been identified, and the company says this known issue will be resolved until next Friday according to the current planned schedule.
“We are investigating connection issues users are experiencing and have identified the issue. We are working to resolve the issue with a tentative schedule for the patch to be released no later than July 14,” Barracuda said. said.
“We appreciate your understanding and support as we work through this issue and sincerely apologize for any inconvenience this may cause.”
The company has yet to reveal details about the cause of these connection issues and their extent.
A Barracuda spokesperson was not immediately available for comment when contacted by BleepingComputer earlier today.
Zero-day ESG exploited for data theft
This incident follows a series of data theft attacks in which a suspected pro-China hacker group followed by Mandiant as UNC4841 compromised Barracuda ESG (Email Security Gateway) appliances using a now fixed zero-day bug (CVE-2023-2868).
On May 19, Barracuda disclosed that the vulnerability was in active operation. As a precautionary measure, CISA has also issued an alert for US federal agencies, ordering them to secure their networks from attack.
CVE-2023-2868 was exploited since at least October 2022 to remove previously unknown malware and steal data from hacked appliances.
In a rather unconventional move early last month, Barracuda provided affected customers with free replacement devicesrather than simply re-imaging existing devices with new firmware after warning that all hacked ESG appliances must be replaced immediately.
Barracuda says its products and services are used by more than 200,000 organizations worldwide, including leading companies such as Samsung, Delta Airlines, Mitsubishi and Kraft Heinz.