Cybercriminals are increasingly turning to legitimate tools, exposed remote-access services, and poor configurations to infiltrate corporate networks without raising suspicion. This is highlighted in Barracuda’s latest Threat Radar from the SOC, which analyzes real incidents detected and mitigated by its Managed XDR team and focuses on risks such as vulnerable or unpatched VPNs, overly permissive firewall rules, and the malicious use of remote administration software to maintain footholds in compromised systems.
CVE-2026-0257 is specifically a vulnerability that affects GlobalProtect services across numerous organizations, regardless of operating system. If successfully exploited, it could allow an attacker to bypass standard authentication controls, establish a VPN session as if they were a legitimate user, access internal resources reachable through the VPN, and create a foothold for later activities such as reconnaissance, credential theft, or lateral movement.
The Barracuda Managed XDR SOC team has detected two waves of inbound scan activity from a known attacker infrastructure targeting publicly exposed GlobalProtect services in Belgium. This demonstrates that attackers are likely scanning for vulnerable or unpatched systems following the CVE disclosure.
Credential Theft Campaign
In this context, the team also uncovered a credential theft campaign aimed at exposed remote-access services. Attackers were attempting to access a VPN via credential stuffing, using usernames and passwords compromised in prior breaches. The investigation also revealed a firewall misconfiguration that left high-risk Internet-facing services such as SSL VPN, RDP, and Telnet exposed, attracting activity from multiple scanning groups and substantially expanding the organization’s attack surface.
This kind of incident highlights the importance of limiting exposure of critical services, regularly reviewing firewall rules, and avoiding reliance solely on passwords to protect remote access.
Along with the risks stemming from a poorly configured remote-access setup, Barracuda has also identified the malicious use of legitimate remote administration tools. In one analyzed incident, attackers used ScreenConnect to maintain persistent access to a terminal, via unauthorized clients configured for unattended connections and communications with suspicious external domains. Installing the software in unusual locations on the system reinforced suspicions of malicious activity. This case reflects a growing trend: abusing trusted software to blend in with normal activity and sustain long-term access to compromised systems.
The incidents analyzed by Barracuda’s team show how cybercriminals are expanding their entry points by exploiting both vulnerabilities and misconfigurations, as well as legitimate tools that companies routinely rely on. In light of this scenario, the report emphasizes the need for a continuous, defense-in-depth security strategy that combines patching, access controls, multifactor authentication, constant monitoring, and greater visibility into the services and applications that make up the corporate environment.