Aniket Kapoor

All posts by Aniket Kapoor

Aniket is a Cybersecurity Analyst at Barracuda MSP. He's a security expert, working on our Blue Team within our Security Operations Center. Aniket supports our XDR service delivery and is highly skilled at analyzing security events to detect cyber threats, helping keep our partners and their customers protected.

Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical NetScaler ADC and Gateway vulnerability

Cybersecurity Threat Advisory: Critical NetScaler ADC and Gateway vulnerability

Citrix has released security updates to address a critical information disclosure vulnerability affecting NetScaler ADC and NetScaler Gateway. The flaw allows unauthenticated remote attackers to retrieve sensitive information from vulnerable appliances via the HTTP/HTTPS interface. Read this Cybersecurity Threat Advisory...

/ March 26, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Interlock targets Cisco Secure FMC in zero-day

Cybersecurity Threat Advisory: Interlock targets Cisco Secure FMC in zero-day

Recent reporting from Amazon Threat Intelligence and multiple security researchers confirms that the Interlock ransomware group is actively exploiting a critical remote code execution vulnerability in Cisco Secure Firewall Management Center (FMC) Software. Read this Cybersecurity Threat Advisory to protect...

/ March 24, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: APT28 targets Windows and Office via MSHTML zero‑day

Cybersecurity Threat Advisory: APT28 targets Windows and Office via MSHTML zero‑day

Multiple security researchers and Microsoft have confirmed that the threat actor APT28 (Fancy Bear / Forest Blizzard) actively exploited a zero‑day vulnerability in the Microsoft MSHTML framework (CVE‑2026‑21513) prior to its fix in the February 2026 Patch Tuesday release. Read...

/ March 4, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Warlock (Storm-2603) exploits SmarterMail vulnerability

Cybersecurity Threat Advisory: Warlock (Storm-2603) exploits SmarterMail vulnerability

SmarterTools has confirmed that the Warlock ransomware group (Storm‑2603) breached its environment by exploiting an unpatched SmarterMail instance. Current intelligence indicates the same SmarterMail vulnerability is being actively used in the wild to gain initial access and deploy Warlock ransomware....

/ February 12, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Compromised OpenVSX delivering GlassWorm malware

Cybersecurity Threat Advisory: Compromised OpenVSX delivering GlassWorm malware

A new GlassWorm malware campaign is targeting macOS developer systems through compromised OpenVSX extensions. Continue reading this Cybersecurity Threat Advisory to learn more about this threat and how to protect your environment. What is the threat? A threat actor gained...

/ February 5, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: FreePBX critical vulnerabilities

Cybersecurity Threat Advisory: FreePBX critical vulnerabilities

Several vulnerabilities in the FreePBX platform have been disclosed and patched, including a critical authentication bypass and flaws enabling SQL injection and arbitrary file upload. Read this Cybersecurity Threat Advisory for an analysis, remediation steps, and detection guidance. What is...

/ December 17, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Cisco and Citrix zero-day exploits

Cybersecurity Threat Advisory: Cisco and Citrix zero-day exploits

An advanced threat actor is exploiting two previously disclosed zero-day vulnerabilities in Cisco Identity Services Engine (ISE) and Citrix NetScaler ADC to deploy custom malware and maintain persistence on targeted networks. Reports indicate the attacker is chaining appliance exploits to...

/ November 17, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical vulnerability in Dell UnityVSA

Cybersecurity Threat Advisory: Critical vulnerability in Dell UnityVSA

Cybersecurity researchers at WatchTowr have disclosed a critical vulnerability in Dell UnityVSA (and related Unity platforms) tracked as CVE-2025-36604. The flaw allows an attacker with no authentication to issue arbitrary OS commands on vulnerable appliances by abusing the login redirection...

/ October 9, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: VMware zero-day vulnerability exploited

Cybersecurity Threat Advisory: VMware zero-day vulnerability exploited

Threat actors have actively exploited a zero-day vulnerability in Broadcom VMware Tools and VMware Aria Operations (CVE-2025-41244) in the wild. The China-linked group UNC5174 (aka Uteus/Uetus) has exploited the flaw for privilege escalation in VMware-targeted attacks. Continue reading this edition...

/ October 1, 2025 / 1 Comment
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Fortinet authentication vulnerability

Cybersecurity Threat Advisory: Fortinet authentication vulnerability

A critical Fortinet authentication bypass vulnerability, CVE-2024-55591, is actively exploited in the wild. This vulnerability impacts FortiOS and FortiProxy, with a CVSS score of 9.6. Continue reading this Cybersecurity Threat Advisory to learn the necessary steps to protect your environment....

/ January 27, 2025