Barracuda security reports expose three remote-access risks

DQChannels Bureau
DQChannels Bureau
Barracuda security reports expose three remote-access risks

The latest Barracuda security reports highlight a common thread across three different security incidents: remote access remains an attractive path for attackers. VPN gateways, loose firewall rules and legitimate remote-management tools all came under scrutiny, with each case showing how attackers can turn routine access points into opportunities.

The incidents were detected by Barracuda Managed XDR’s SOC team during threat hunting and monitoring. While the activity differed, the risks were closely tied to exposed services, weak access controls and limited visibility.

VPN scanning puts exposed systems in focus

The first incident involved CVE-2026-0257, a vulnerability affecting Palo Alto’s OS-agnostic GlobalProtect services. Successful exploitation can bypass normal authentication controls and allow attackers to establish a VPN session as a legitimate user.

Barracuda’s SOC team detected two waves of inbound scanning from known attacker infrastructure targeting publicly exposed GlobalProtect services in Belgium. The attempts were blocked and no exploitation occurred.

The report notes that the vulnerability does not affect every deployment. However, organisations using internet-facing GlobalProtect gateways should apply security updates, review exposure, monitor unusual VPN activity and enable MFA where supported.

Weak firewall rules can widen the attack surface

A second case involved credential stuffing against Netility's Fortinet remote-access VPN. The investigation found overly broad firewall rules exposing SSL VPN, RDP and Telnet services directly to the internet.

That exposure attracted activity from multiple unrelated scanning clusters. The lesson is fairly simple: a firewall can protect a network only when its rules are properly restricted.

Regular rule reviews, MFA, network restrictions and removing legacy protocols such as Telnet can reduce unnecessary exposure.

Trusted software can become an attacker’s foothold

The third incident involved ScreenConnect being abused to establish persistent remote access. Unauthorised clients were configured for unattended access and communicated with suspicious external domains over unusual ports.

The software was also found in the Windows System32 directory alongside command scripts. Barracuda describes this as an example of attackers using legitimate software to blend into normal activity while maintaining access.

Organisations need to know which remote-management tools are approved, monitor unusual installations and investigate unexpected persistence mechanisms.

Read More:

Genesys International CTO appointment brings Dhiman Basu Ray onboard

Huawei and HP Agreement Puts Wi-Fi Patents in Focus

AWS and NVIDIA partnership pushes AI beyond GPUs

Salesforce Partners: Why AI is changing the channel opportunity

Latest Stories