Stacey Landrum

All posts by Stacey Landrum

Stacey is a Cybersecurity Analyst at Barracuda. She's a security expert, working on our Blue Team within our Security Operations Center. Stacey supports our XDR service delivery and is highly skilled at analyzing security events to detect cyber threats, helping keep our partners and their customers protected.

Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Telnet authentication bypass flaw

Cybersecurity Threat Advisory: Telnet authentication bypass flaw

A critical security vulnerability has been identified in the GNU InetUtils Telnet daemon (telnetd) that allows unauthenticated attackers to obtain root-level access. The issue was introduced in 2015 and went undetected for nearly 11 years. Review this Cybersecurity Threat Advisory...

/ January 26, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: AdonisJS Bodyparser vulnerability

Cybersecurity Threat Advisory: AdonisJS Bodyparser vulnerability

A severe security flaw has been identified in the @adonisjs/bodyparser npm package, a core component of the AdonisJS TypeScript-first web framework. Tracked as CVE-2026-21440, the vulnerability stems from a path traversal issue in the multipart file handling mechanism. If exploited,...

/ January 7, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: MongoDB RCE vulnerability

Cybersecurity Threat Advisory: MongoDB RCE vulnerability

MongoDB has disclosed a high‑severity vulnerability, tracked as CVE‑2025‑14847, that could allow unauthenticated remote code execution (RCE). The flaw stems from the Zlib compression handler and can be exploited with low complexity, posing a serious risk to data confidentiality and...

/ December 29, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: WinRAR vulnerability exploit

Cybersecurity Threat Advisory: WinRAR vulnerability exploit

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-6218, a path traversal vulnerability in WinRAR for Windows, to its Known Exploited Vulnerabilities (KEV) catalog following confirmed exploitation by multiple advanced persistent threat (APT) groups. Read this Cybersecurity Threat Advisory...

/ December 15, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Android framework exploits

Cybersecurity Threat Advisory: Android framework exploits

Google released the December 2025 Android Security Update to address 107 vulnerabilities across the Android OS and vendor components. The most critical aspect of this release is the remediation of two high-severity vulnerabilities. Review this Cybersecurity Threat Advisory to limit...

/ December 6, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical WatchGuard Fireware vulnerability

Cybersecurity Threat Advisory: Critical WatchGuard Fireware vulnerability

CISA has added CVE-2025-9242 to its Known Exploited Vulnerabilities (KEV) catalog following confirmed exploitation in the wild. This critical flaw allows unauthenticated remote code execution (RCE) via malformed IKEv2 VPN packets in WatchGuard Fireware. Continue reading this Cybersecurity Threat Advisory...

/ November 14, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical WSUS RCE vulnerability

Cybersecurity Threat Advisory: Critical WSUS RCE vulnerability

Microsoft has released out-of-band (OOB) security updates to address a critical remote code execution (RCE) vulnerability in Windows Server Update Services (WSUS). Servers with the WSUS Server Role enabled are affected. Successful exploitation allows attackers to execute code with SYSTEM-level...

/ October 27, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical Oracle EBS flaw

Cybersecurity Threat Advisory: Critical Oracle EBS flaw

Oracle released an emergency update for its E-Business Suite to address the critical vulnerability CVE-2025-61882 ( with a CVSS of 9.8) because it was actively being exploited by threat actors, particularly the Cl0p ransomware group, in a recent wave of...

/ October 8, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: SonicWall firewall backup breach

Cybersecurity Threat Advisory: SonicWall firewall backup breach

SonicWall has reported a security breach involving unauthorized access to its MySonicWall cloud backup service. Attackers used brute-force techniques to obtain firewall preference and backup files containing full device configurations. Continue reading this Cybersecurity Threat Advisory to learn more about...

/ September 22, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Worm outbreak infects npm ecosystem

Cybersecurity Threat Advisory: Worm outbreak infects npm ecosystem

Threat actors launched a sophisticated software supply chain attack that targets the npm registry and compromises over 40 packages maintained by multiple developers. The self-replicating worm, dubbed “Shai-Hulud”, automates the infection of downstream dependencies. Review the details in this Cybersecurity...

/ September 19, 2025