Doris Au

All posts by Doris Au

Doris is a product marketing manager at Barracuda. In this position, she is responsible for connecting managed service providers with multi-layered security and data protection products that can protect their customers from today’s advanced cyber threats.

Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Google Releases First Patches for 37 Chrome Vulnerabilities

Cybersecurity Threat Advisory: Google Releases First Patches for 37 Chrome Vulnerabilities

Threat Update In response to a critical use-after-free vulnerability and 36 more potential exploits, Google has released a series of updates to its Internet browser, Chrome. Barracuda MSP recommends that you update your browsers immediately to prevent cyber criminals from...

/ January 10, 2022
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: VMware Patches Bug Affecting ESXi, Workstation and Fusion

Cybersecurity Threat Advisory: VMware Patches Bug Affecting ESXi, Workstation and Fusion

Threat Update VMWare has released patches and workarounds for various products (including ESXi 6.5, 6.7 and 7, Fusion 12.x, Workstation 16.x, and VMware Cloud Foundation) to address a key security vulnerability that could be exploited by threat actors to gain...

/ January 10, 2022
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Continued Log4j Scanning Activity

Cybersecurity Threat Advisory: Continued Log4j Scanning Activity

Threat Update In recent weeks, Microsoft has observed continued attempts by nation-state adversaries and commodity attackers to exploit security vulnerabilities uncovered in the Log4j open-source logging framework. Barracuda MSP’s Security Operation Center (SOC) is also observing scanning activity and exploit...

/ January 7, 2022
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Microsoft Patch Tuesday, December 2021

Cybersecurity Threat Advisory: Microsoft Patch Tuesday, December 2021

Threat Update Microsoft’s Patch Tuesday release for December 2021 comes with a Windows update that will apply patches for 67 different vulnerabilities. This update includes fixes for 7 critical vulnerabilities, and included fixes that prevented Denial of Service, Remote Code...

/ December 20, 2021
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Second Log4j vulnerability patch released

Cybersecurity Threat Advisory: Second Log4j vulnerability patch released

As we know, a significant Log4j Remote Code Execution (RCE) vulnerability has had a patch released and tracked as CVE-2021-44228. However, the patch was not entirely effective at mitigating the risk due to CVE-2021-45046, the lack of completion in some...

/ December 17, 2021
Barracuda Networks and Apache Log4j vulnerability

Barracuda Networks and Apache Log4j vulnerability

The Log4j vulnerability has recently made headlines around the world. Concerns around this vulnerability center on the fact that an attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message...

/ December 16, 2021
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Surge in Attacks Against WordPress Sites

Cybersecurity Threat Advisory: Surge in Attacks Against WordPress Sites

Threat Update WordFence, a WordPress security platform, stated that they have blocked 13.7 million attacks against WordPress sites in the span of 36 hours. The number of attacks reflects a dramatic increase in activity from threat actors, originating from 16,000...

/ December 13, 2021
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical Java Zero-Day Vulnerability

Cybersecurity Threat Advisory: Critical Java Zero-Day Vulnerability

A critical remote code vulnerability has emerged in Log4j, a Java Logging package that is used in a number of software products and platforms from organizations like Apache, Apple, Twitter, Tesla and Steam. This vulnerability impacts almost every Java application...

/ December 10, 2021
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: SonicWall Patches Critical Vulnerabilities in VPN Appliances

Cybersecurity Threat Advisory: SonicWall Patches Critical Vulnerabilities in VPN Appliances

Threat Update SonicWall, a widely-used network security company, has released patches to address several critical vulnerabilities within their SMA 100 Series VPN appliances. These vulnerabilities could allow attackers to execute arbitrary code, modify/delete files, bypass firewall rules, and even gain...

/ December 10, 2021
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Cyber Threats Targeting Consumers During Holiday Season

Cybersecurity Threat Advisory: Cyber Threats Targeting Consumers During Holiday Season

The holiday season is once again upon us, and with it comes the busiest time of the year for shopping and traveling. Specifically, from late November to early January of the new year is a time where attackers will be...

/ December 6, 2021