threat_intelligence1106 wordsRead on Arc Codex

SOC Threat Radar

SOC Threat Radar — August 2026 The latest Barracuda Research findings on threats facing businesses Key takeaways - Incidents mitigated in the last month by Barracuda Managed XDR highlight the continued risk of attackers exploiting trusted and legitimate software. - This includes attackers scanning for vulnerable deployments of GlobalProtect, and the risk of misconfigured firewalls and exposed trusted remote services. Attackers are scanning for vulnerable deployments of GlobalProtect (CVE-2026-0257) What’s happening: CVE-2026-0257 is a vulnerability affecting Palo Alto’s OS-agnostic GlobalProtect services. Successful exploitation could allow an attacker to bypass normal authentication controls, establish a VPN session as if they were a legitimate user, gain access to internal resources reachable through the VPN, and create a foothold for further activity such as reconnaissance, credential theft or lateral movement. Barracuda Managed XDR’s SOC team has detected two waves of inbound scanning activity originating from known attacker infrastructure and targeting publicly exposed GlobalProtect services in Belgium. The attackers are likely to be probing for vulnerable or unpatched systems following public disclosure of the CVE. Your organization may be at risk if you: - Operate internet-facing GlobalProtect gateways. - Have not applied the latest security updates addressing CVE-2026-0257. - Allow direct VPN access from the internet without additional security controls. - Lack monitoring for suspicious authentication attempts, scanning activity or unusual VPN sessions. - Rely heavily on perimeter authentication without layered access controls. The vulnerability has been exploited in the wild since May, but it does not affect every GlobalProtect deployment. According to Palo Alto Networks, exploitation requires a GlobalProtect portal or gateway to be configured, authentication override cookies to be enabled, and specific certificate configuration related to those cookies. How to stay safe: - Apply vendor security updates and patches as soon as possible. - Review exposure of GlobalProtect services and remove unnecessary internet-facing access. - Restrict access to VPN portals where possible using IP allowlists or network segmentation. - Monitor for scanning activity, unusual login attempts and unexpected VPN sessions. - Enable multifactor authentication (MFA) wherever supported. - Disable authentication override cookies if they are not required. The scanning activity was detected by the SOC team during a routine threat hunt following the public reporting of the CVE. All access attempts were blocked, and no exploitation occurred. Credential harvesting campaign against exposed remote-access services highlights risks of weak firewall rules What's happening: The SOC team detected attackers attempting to access Netility's Fortinet remote-access VPN through credential stuffing (using compromised usernames and passwords stolen in previous breaches.) The team’s investigation uncovered a critical firewall misconfiguration in a target customer’s network that allowed broad internet access to several high-risk services, including SSL VPN, Remote Desktop Protocol (RDP), and Telnet. The exposed services attracted activity from multiple, unrelated scanning clusters, demonstrating how publicly accessible administrative services can rapidly become targets for a wide range of threat actors. The misconfiguration resulted in overly permissive firewall rules. The incident shows that this can significantly expand an organization’s attack surface and increase exposure to both opportunistic and targeted attacks. Your organization may be at risk if you: - Expose SSL VPN, RDP, Telnet, or other remote-access services directly to the internet. - Use firewall rules that allow broad or unrestricted inbound access. - Rely solely on passwords for remote access authentication. - Do not actively block known malicious IP addresses or threat infrastructure. - Have not reviewed firewall configurations against the principle of least privilege. How to stay safe: - Restrict external access to business-critical services. - Remove or disable legacy protocols such as Telnet wherever possible. - Enable MFA for all remote access services. - Review firewall rules regularly and remove unnecessary internet exposure. - Limit administrative access using IP restrictions, VPNs or privileged access controls. - Monitor remote access services for brute force attacks, credential stuffing attempts and suspicious authentication activity. - Block known malicious IP addresses and threat actor infrastructure where appropriate. Attackers abuse trusted software for persistent remote endpoint access What’s happening: The SOC team identified an active Remote Access Trojan (RAT) incident involving the abuse of ScreenConnect (ConnectWise Control) software to establish persistent remote access on an endpoint. The investigation revealed multiple unauthorized ScreenConnect clients configured for unattended access and communicating with suspicious external domains over non-standard network ports. Analysts also discovered the software had been placed within the Windows System32 directory alongside command scripts. Such behavior is inconsistent with typical business deployments and strongly indicative of malicious activity. The case illustrates a growing trend in which threat actors abuse legitimate remote administration tools, often referred to as “living off trusted software,” to blend into normal activity and maintain long-term access to compromised systems. Your organization may be at risk if you: - Do not maintain an inventory of approved remote administration tools. - Allow software installations without adequate oversight or monitoring. - Have remote access tools configured for unattended access without strong security controls. - Do not require MFA for remote administration platforms. - Lack visibility into unusual software installations, outbound connections or persistence mechanisms. How to stay safe: - Maintain and regularly review an inventory of approved remote management tools. - Investigate any unexpected installation of ScreenConnect or other remote access software. - Enable MFA for all remote administration and support platforms. - Monitor for connections to unfamiliar remote management infrastructure and unusual network ports. - Review endpoints for unauthorized services, scheduled tasks, startup items, and persistence mechanisms. - Restrict local administrator privileges and application installation rights where possible. - Investigate software installed in unusual directories, particularly critical system locations such as Windows System32. - Isolate affected systems immediately if unauthorized remote access activity is detected. The SOC team isolated the vulnerable endpoint to disrupt attacker access while the team investigated and neutralized any persistence mechanisms. How Barracuda Managed XDR can help your organization Barracuda Managed XDR delivers advanced protection against the threats identified in this report by combining cutting-edge technology with expert SOC oversight. With real-time threat intelligence, automated responses, a 24/7/365 SOC team, and XDR Managed Vulnerability Security that identifies security gaps and oversights, Barracuda Managed XDR ensures comprehensive, proactive protection across your network, cloud, email, servers, and endpoints, giving you the confidence to stay ahead of evolving threats. For further information on how we can help, please get in touch with Barracuda Managed XDR. 2026 Email Threats Report Learn how AI and phishing-as-a-service are reshaping the email threat landscape and how to stay protected Subscribe to the Barracuda Blog. Sign up to receive threat spotlights, industry commentary, and more. The Managed XDR Global Threat Report Key findings about the tactics attackers use to target organizations and the security weak spots they try to exploit

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.