Mandeep Gujral

All posts by Mandeep Gujral

Mandeep is a Cybersecurity Analyst at Barracuda MSP. She's a security expert, working on our Blue Team within our Security Operations Center. Mandeep supports our XDR service delivery and is highly skilled at analyzing security events to detect cyber threats, helping keep our partners and their customers protected.

Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical CrushFTP vulnerability

Cybersecurity Threat Advisory: Critical CrushFTP vulnerability

A critical CrushFTP, CVE-2025-2825, with a CVSS score of 9.8, flaw has been discovered. It enables attackers to bypass authentication on CrushFTP servers, posing a high-severity risk to corporate environments. Continue reading this Cybersecurity Threat Advisory for details on how...

/ April 10, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Apache Tomcat vulnerability

Cybersecurity Threat Advisory: Apache Tomcat vulnerability

A severe remote code execution (RCE) vulnerability in Apache Tomcat, identified as CVE-2025-24813, is actively exploited in the wild, allowing attackers to gain server control using a simple PUT request. Review the details in this Cybersecurity Threat Advisory to learn...

/ March 19, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical vulnerability in PostgreSQL

Cybersecurity Threat Advisory: Critical vulnerability in PostgreSQL

Security experts identified a critical PostgreSQL vulnerability, CVE-2025-1094, with a CVSS of 8.1. The vulnerability poses a significant risk to database integrity in enterprise and production environments. Review this Cybersecurity Threat Advisory to learn how to mitigate your risks. What...

/ February 28, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Xerox printer vulnerabilities

Cybersecurity Threat Advisory: Xerox printer vulnerabilities

Two vulnerabilities, CVE-2024-12510 and CVE-2024-12511, have been found in the Xerox VersaLink C7025 Multifunction Printer. Upon successful exploitation, bad actors can capture authentication credentials through pass-back attacks via lightweight directory access protocol (LDAP), server message block (SMB), and file transfer...

/ February 19, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical Azure vulnerabilities

Cybersecurity Threat Advisory: Critical Azure vulnerabilities

Microsoft revealed two critical vulnerabilities in Microsoft Azure AI Face Service, a cloud-based facial recognition tool. They enable attackers to bypass authentication. Review the details within this Cybersecurity Threat Advisory to discover the key steps to safeguard your environment. What...

/ February 6, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Ransomware attacks on ESXi systems

Cybersecurity Threat Advisory: Ransomware attacks on ESXi systems

New ransomware attacks were discovered targeting ESXi systems that use stealthy SSH tunnels to direct traffic to command-and-control (C2) infrastructure, enabling attackers to remain undetected. Continue reading this Cybersecurity Threat Advisory to discover the key steps to safeguard your environment....

/ January 30, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Microsoft Windows zero-click RCE vulnerability

Cybersecurity Threat Advisory: Microsoft Windows zero-click RCE vulnerability

A critical Microsoft Windows Lightweight Directory Access Protocol (LDAP) vulnerability has been discovered, identified as CVE-2024-49112. The flaw has a CVSS severity score of 9.8, representing a major threat to enterprise networks. Continue reading this Cybersecurity Threat Advisory to learn...

/ January 3, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical Apache Struts 2 vulnerability

Cybersecurity Threat Advisory: Critical Apache Struts 2 vulnerability

The Apache Software Foundation (ASF) has issued a security update to address a critical vulnerability in both end-of-life and current versions of Apache Struts 2. Under specific conditions, this vulnerability could lead to remote code execution (RCE). Review this Cybersecurity...

/ December 30, 2024
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Microsoft MFA AuthQuake flaw

Cybersecurity Threat Advisory: Microsoft MFA AuthQuake flaw

A new critical security flaw in Microsoft’s multi-factor authentication (MFA) system has been discovered. It enables attackers to easily bypass the protection and gain unauthorized access to user accounts. Review this Cybersecurity Threat Advisory to learn how to mitigate your...

/ December 19, 2024
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Active exploitation of ASA vulnerability

Cybersecurity Threat Advisory: Active exploitation of ASA vulnerability

Cisco has confirmed that a decade-old cross-site scripting (XSS) vulnerability in its Adaptive Security Appliance (ASA) software is actively being exploited in the wild. Review this Cybersecurity Threat Advisory to learn how to mitigate your risk. What is the threat?...

/ December 5, 2024