Barracuda XDR Release Notes — July 2026
Prepare for Self-Service Onboarding and MSP App Integration
Barracuda Managed XDR will soon enable self-service onboarding for MSP Partners and be integrated into the MSP App, providing a more streamlined customer onboarding and account management experience.
As part of this enhancement, customer accounts in the MSP App and the XDR Dashboard will be linked. To help ensure a smooth transition, please create MSP App accounts for any customers that currently exist only in the XDR Dashboard.
To add an SMB account
Navigate to BarracudaONE.
In the left navigation menu, click MSP Managed > Accounts.
Select your MSP account, then click Add Account.
Need help? Visit Barracuda Campus for step-by-step instructions.
Thank you for helping us prepare for this service enhancement.
The Barracuda Managed XDR Team
The July release of Barracuda XDR includes:
New Dashboard features
Dashboard bug fixes
Rule changes
New Dashboard features
Home page redesign
The XDR Dashboard Home page has been redesigned with a modern design and improved organization to provide a more intuitive, consistent flow across the BarracudaONE platform. This new design better highlight items that need addressing and summarize your XDR environment.
For more information, see https://documentation.campus.barracuda.com/wiki/x/DYACI.
XDR Dashboard URL has now changed
The dashboard is now available at xdr.barracudanetworks.com. Users accessing through the legacy URL, are redirected automatically.
Update your bookmarks, firewall rules, and allow lists to the new URL.
Automated Threat Response (ATR) for Duo
Barracuda Managed XDR now includes Automated Threat Response (ATR) for Duo, enabling automatic identity threat containment.
When XDR Cloud Security detects high-confidence account compromise, such as logins from anomalous locations or user-reported MFA fraud, ATR instantly disables the affected Duo user.
This is the first identity-focused ATR capability in Barracuda Managed XDR, stopping attackers before they can persist, escalate privileges or move laterally.
For more information, see https://documentation.campus.barracuda.com/wiki/x/Y4A7K.
Automated Threat Response (ATR) for WatchGuard for Network Security users
WatchGuard ATR is now live for Network Security users. This ATR integration automatically blocks malicious IP addresses when specific rules are triggered.
For more information, see https://documentation.campus.barracuda.com/wiki/x/EgA6JQ.
Certain integration cards renamed
The word “Collector” has been removed from certain integration cards. This doesn’t affect former or current integrations and there’s no need to re-integrate existing integrations.
Timeline analysis now includes the reason for closure
The reason for closure has been added to the Timeline Analysis. You can also filter by the closure code.
Dashboard bug fixes
Issue | Description |
|---|---|
9288 | Resolved an issue where the Create Incident button was broken. |
10914 | Resolved an issue where a new page loaded as if the user had already scrolled down. |
10596 | Resolved an issue where selecting “pfSense” as the data source didn’t display any results. |
10621 | Resolved an issue where the Help button on the Endpoint Security Overview was broken. |
10626 | Resolved an issue where certain Autotask issues didn’t appear due to being mapped to the “inactive” priority. |
10658 | Resolved an issue where the Help button on the Juniper Secure Services Gateway (SSG) Firewall integration page was broken. |
11079 | Updated the Help button on the Barracuda IDS integration page. |
11088 | Updated the Help button on the Alarms & Alerts page. |
Rule changes
New Rules
Fortigate
FortiGate Distributed Brute Force Attack
WaaS
Barracuda WaaS Brute Force Attack Detected
Barracuda WaaS DDoS Bot Campaign Detected
Barracuda WaaS Directory Traversal Campaign Detected
Barracuda WaaS XSS CSRF Attack Campaign Detected
Barracuda WaaS Session Hijacking Campaign Detected
Barracuda WaaS Geo Blocked IP Persistence Detected
Barracuda WaaS TOR Exit Node Access Detected
Barracuda WaaS Identity Theft Pattern Detected
Sophos
GLB.EB.EPP Sophos Central Malware Cleanup Failed
Tuning and Bug Fixes
Stormshield
Stormshield Configuration Change from External IP
Logic on this detection has been updated to be more accurate.
Issues with rule have been fixed which previously prevent rule from firing
Stormshield Blocked Trafic Major Alarm
Renamed rule -> Stormshield Major Alarm Allowed Traffic
Removed internal IPs from being excluded on this detection
Issues with rule have been fixed which previously prevent rule from firing
Stormshield User Login from Threat IP
The logic on this detection was updated to be more accurate.
Stormshield Brute Force Authentication Attempt
Logic on this detection was updated to be more accurate. We also removed internal IPs from being excluded from alerts.
Stormshield Password Spraying Activity
Updated logic on this detection to be more accurate.
Threshold and number of users required to fire an alert was lowered.
Removed internal IPs from being excluded from alerts.
Google Workspace
Google Workspace Suspicious Login Detected
Tuned logic to reduce false positive on reauthentication events
Barracuda Impersonation Protection
Barracuda Impersonation Protection - Account Takeover - Email
Removed threshold rule and kept only query rule with detection severity as HIGH
This change ensures every high confidence ATO alerts are treated with high severity
Barracuda Impersonation Protection - Account Takeover - Inbox Rule
Removed threshold rule and kept only query rule with detection severity as HIGH
This change ensures every high confidence ATO alerts are treated with high severity
Fortinet FortiGate
Fortigate SSL VPN Password Spraying Activity
Logic on this detection is updated to limit sending alarms (low severity alerts) to maximum 5 within 12hour window
This will solve customer concerns regarding repeated/burst of low severity alerts
Windows
Windows User Added To The Local Privilege Group
Logic modified to reduce intentional delays, which are used to corelate other data points
This change makes sure that we are sending alerts within SLA limits
Bug Fixes
A Databricks Runtime update caused rules to fail that had specific configurations applied. This has been fixed.
New Features
Improved Detection Pipeline Architecture
Detection pipeline architecture has been improved providing the following benefits:
Containerized jobs reduce impact to all datasources and reduces impact of compute constraints
Reduced single points of failure
Alleviates issues with SLA impact when restarting detection pipelines
Rules that are now fully automated
Azure User Added to Administrator Role
Azrure Suspicious Device Registration Potentially Via Device Code Phishing
Azure Deactivated User Reactivated
Azure Brute Force RDP Activity to VM
Azure App Assigned Full Access to Exchange API
Azure Possible Vulnerability to SQL Injection
Azure Password Policy Changed
Azure App Services Unusual Activity
Azure Firewall Policy Deletion
Azure Blob Container Access Level Modification
Azure Full Network Packet Capture Detected
Azure Resource NMAP Scan Detected
Azure Internal Bound Traffic From Suspicious IP
Cryptomining Activity Detected
Azure WordPress Theme Invocation Detected
Azure Directory PowerShell Sign-in from Suspicious Country
Azure MFA Disabled for User
Azure Successful Brute Force Attack
Azure Suspicious client communication
Azure Connection to web page from anomalous IP address detected
Azure Anti Malware Action Failed
New Datasources
Azure Migration
Azure Active Directory High Risk Sign-in
Azure Administrator Role Addition to PIM User
Azure Administrator Role Removed From User
Azure Anti Malware Action Failed
Azure App Assigned Full Access to Exchange API
Azure App Services Unusual Activity
Azure Blob Container Access Level Modification
Azure Brute Force RDP Activity to VM
Azure Conditional Access Policy Modified
Azure Connection to Web Page from Anomalous IP Address Detected
Azure Cryptomining Activity Detected
Azure Deactivated User Reactivated
Azure Firewall Policy Deletion
Azure Full Network Packet Capture Detected
Azure Internal Bound Traffic From Suspicious IP
Azure MFA Disabled for User
Azure New Service Principal Created
Azure Owner Added to Group
Azure Password Policy Changed
Azure Possible Vulnerability to SQL Injection
Azure Privilege Identity Management Role Modified
Azure Resource NMAP Scan Detected
Azure Risk Event Detected for User Account
Azure Service Principal Credentials Added
Azure Service Principal Granted High Risk Permissions
Azure Successful Brute Force Attack
Azure Suspicious Active Directory PowerShell Sign-in
Azure Suspicious Authentication Activity
Azure Suspicious Client Communication
Azure Suspicious WordPress Theme Invocation Detected
Azure User Added as Owner for Application
Azure User Added as Owner for Service Principal
Azure User Added to Administrator Role
Azure Possible MFA Fatigue Attempt