Alex Brostowin

All posts by Alex Brostowin

Alex is a Cybersecurity Analyst at Barracuda MSP. He's a security expert, working on our Blue Team within our Security Operations Center. Alex supports our XDR service delivery and is highly skilled at analyzing security events to detect cyber threats, helping keep our partners and their customers protected.

Cybersecurity Threat Advisory: Atlassian zero-day vulnerability patch

Atlassian has recently announced a patch for a new zero-day vulnerability which allows for privilege escalation on affected versions of Confluence Data Center and Confluence Server. This Cybersecurity Threat Advisory explains the exploitation of this vulnerability, which could allow attackers...

/ October 6, 2023
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Updated Bumblebee malware loader discovered

Cybersecurity Threat Advisory: Updated Bumblebee malware loader discovered

Today’s Cybersecurity Threat advisory discusses the update to the popular Bumblebee malware loader that increases its defense evasion capabilities. The loader is commonly distributed via “.lnk” (softlink/shortcut) files attached to an email or compressed in a .zip archive attached to...

/ September 21, 2023
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Cyberattacks on MGM Resorts

Cybersecurity Threat Advisory: Cyberattacks on MGM Resorts

This Cybersecurity Threat Advisory highlights cyberattacks on MGM Resorts, a $33 billion hospitality and entertainment company operating out of Las Vegas. On Monday, September 11th, 2023, MGM Resorts experienced a ransomware attack that encrypted over 100 ESXi hypervisors and exfiltrated...

/ September 15, 2023 / 1 Comment
Cybersecurity Threat Advisory
Critical vulnerabilities found in Fortinet and SonicWall products

Critical vulnerabilities found in Fortinet and SonicWall products

In this cybersecurity threat advisory, Fortinet and SonicWall both advised of vulnerabilities found in their products. Fortinet shared that FortiOS and FortiProxy has a critical vulnerability where successful exploitation of the vulnerability allows an attacker to perform remote arbitrary code...

/ July 13, 2023
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical VMware Aria Operations vulnerabilities

Cybersecurity Threat Advisory: Critical VMware Aria Operations vulnerabilities

Two vulnerabilities were discovered in older versions of VMware Aria Operations for Networks and VMware Aria Operations for Logs. The vulnerabilities allow bad actors to perform remote code execution as the root user. Remote code execution can lead to system...

/ July 12, 2023
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Supply chain attack compromised 3CXDesktopApp

Cybersecurity Threat Advisory: Supply chain attack compromised 3CXDesktopApp

A recent compromise has caused trojanized versions of the 3CXDesktopApp executable to be distributed on 3CX’s website as well as pushed through updates. The malicious version of the 3CX application is used to sideload malicious .DLL files. These .DLL files...

/ March 30, 2023 / 11 Comments