Barracuda XDR Release Notes — July 2026

Barracuda XDR Release Notes — July 2026

Prepare for Self-Service Onboarding and MSP App Integration 

Barracuda Managed XDR will soon enable self-service onboarding for MSP Partners and be integrated into the MSP App, providing a more streamlined customer onboarding and account management experience. 

As part of this enhancement, customer accounts in the MSP App and the XDR Dashboard will be linked. To help ensure a smooth transition, please create MSP App accounts for any customers that currently exist only in the XDR Dashboard.  

To add an SMB account

  1. Navigate to BarracudaONE.

  1. In the left navigation menu, click MSP Managed > Accounts.

  1. Select your MSP account, then click Add Account

Need help? Visit Barracuda Campus for step-by-step instructions.  

Thank you for helping us prepare for this service enhancement. 

The Barracuda Managed XDR Team 

The July release of Barracuda XDR includes:

  • New Dashboard features

  • Dashboard bug fixes

  • Rule changes

New Dashboard features

Home page redesign

The XDR Dashboard Home page has been redesigned with a modern design and improved organization to provide a more intuitive, consistent flow across the BarracudaONE platform. This new design better highlight items that need addressing and summarize your XDR environment.

For more information, see https://documentation.campus.barracuda.com/wiki/x/DYACI.

XDR Dashboard URL has now changed

The dashboard is now available at xdr.barracudanetworks.com. Users accessing through the legacy URL, are redirected automatically.

Update your bookmarks, firewall rules, and allow lists to the new URL.

Automated Threat Response (ATR) for Duo

Barracuda Managed XDR now includes Automated Threat Response (ATR) for Duo, enabling automatic identity threat containment.

When XDR Cloud Security detects high-confidence account compromise, such as logins from anomalous locations or user-reported MFA fraud, ATR instantly disables the affected Duo user. 

This is the first identity-focused ATR capability in Barracuda Managed XDR, stopping attackers before they can persist, escalate privileges or move laterally. 

For more information, see https://documentation.campus.barracuda.com/wiki/x/Y4A7K.

Automated Threat Response (ATR) for WatchGuard for Network Security users

WatchGuard ATR is now live for Network Security users. This ATR integration automatically blocks malicious IP addresses when specific rules are triggered.

For more information, see https://documentation.campus.barracuda.com/wiki/x/EgA6JQ.

Certain integration cards renamed

The word “Collector” has been removed from certain integration cards. This doesn’t affect former or current integrations and there’s no need to re-integrate existing integrations.

Timeline analysis now includes the reason for closure

The reason for closure has been added to the Timeline Analysis. You can also filter by the closure code.

Dashboard bug fixes

Issue

Description

Issue

Description

9288

Resolved an issue where the Create Incident button was broken.

10914

Resolved an issue where a new page loaded as if the user had already scrolled down.

10596

Resolved an issue where selecting “pfSense” as the data source didn’t display any results.

10621

Resolved an issue where the Help button on the Endpoint Security Overview was broken.

10626

Resolved an issue where certain Autotask issues didn’t appear due to being mapped to the “inactive” priority.

10658

Resolved an issue where the Help button on the Juniper Secure Services Gateway (SSG) Firewall integration page was broken.

11079

Updated the Help button on the Barracuda IDS integration page.

11088

Updated the Help button on the Alarms & Alerts page.

Rule changes

New Rules

  • Fortigate

    • FortiGate Distributed Brute Force Attack

    WaaS

    • Barracuda WaaS Brute Force Attack Detected

    • Barracuda WaaS DDoS Bot Campaign Detected

    • Barracuda WaaS Directory Traversal Campaign Detected

    • Barracuda WaaS XSS CSRF Attack Campaign Detected

    • Barracuda WaaS Session Hijacking Campaign Detected

    • Barracuda WaaS Geo Blocked IP Persistence Detected

    • Barracuda WaaS TOR Exit Node Access Detected

    • Barracuda WaaS Identity Theft Pattern Detected

    Sophos

    • GLB.EB.EPP Sophos Central Malware Cleanup Failed

Tuning and Bug Fixes

  • Stormshield

    • Stormshield Configuration Change from External IP

      • Logic on this detection has been updated to be more accurate.

      • Issues with rule have been fixed which previously prevent rule from firing

    • Stormshield Blocked Trafic Major Alarm

      • Renamed rule -> Stormshield Major Alarm Allowed Traffic

      • Removed internal IPs from being excluded on this detection

      • Issues with rule have been fixed which previously prevent rule from firing

    • Stormshield User Login from Threat IP

      • The logic on this detection was updated to be more accurate.

    • Stormshield Brute Force Authentication Attempt

      • Logic on this detection was updated to be more accurate. We also removed internal IPs from being excluded from alerts.

    • Stormshield Password Spraying Activity

      • Updated logic on this detection to be more accurate.

      • Threshold and number of users required to fire an alert was lowered.

      • Removed internal IPs from being excluded from alerts.

  • Google Workspace

    • Google Workspace Suspicious Login Detected

      • Tuned logic to reduce false positive on reauthentication events

  • Barracuda Impersonation Protection

    • Barracuda Impersonation Protection - Account Takeover - Email

      • Removed threshold rule and kept only query rule with detection severity as HIGH

      • This change ensures every high confidence ATO alerts are treated with high severity

    • Barracuda Impersonation Protection - Account Takeover - Inbox Rule

      • Removed threshold rule and kept only query rule with detection severity as HIGH

      • This change ensures every high confidence ATO alerts are treated with high severity

  • Fortinet FortiGate

    • Fortigate SSL VPN Password Spraying Activity

      • Logic on this detection is updated to limit sending alarms (low severity alerts) to maximum 5 within 12hour window

      • This will solve customer concerns regarding repeated/burst of low severity alerts

  • Windows

    • Windows User Added To The Local Privilege Group

      • Logic modified to reduce intentional delays, which are used to corelate other data points

      • This change makes sure that we are sending alerts within SLA limits

  • Bug Fixes

    • A Databricks Runtime update caused rules to fail that had specific configurations applied. This has been fixed.

New Features

  • Improved Detection Pipeline Architecture

    • Detection pipeline architecture has been improved providing the following benefits:

      • Containerized jobs reduce impact to all datasources and reduces impact of compute constraints

      • Reduced single points of failure

      • Alleviates issues with SLA impact when restarting detection pipelines

Rules that are now fully automated

  • Azure User Added to Administrator Role

    • Azrure Suspicious Device Registration Potentially Via Device Code Phishing

    • Azure Deactivated User Reactivated

    • Azure Brute Force RDP Activity to VM

    • Azure App Assigned Full Access to Exchange API

    • Azure Possible Vulnerability to SQL Injection

    • Azure Password Policy Changed

    • Azure App Services Unusual Activity

    • Azure Firewall Policy Deletion

    • Azure Blob Container Access Level Modification

    • Azure Full Network Packet Capture Detected

    • Azure Resource NMAP Scan Detected

    • Azure Internal Bound Traffic From Suspicious IP

    • Cryptomining Activity Detected

    • Azure WordPress Theme Invocation Detected

    • Azure Directory PowerShell Sign-in from Suspicious Country

    • Azure MFA Disabled for User

    • Azure Successful Brute Force Attack

    • Azure Suspicious client communication

    • Azure Connection to web page from anomalous IP address detected

    • Azure Anti Malware Action Failed


New Datasources

  • Azure Migration

    • Azure Active Directory High Risk Sign-in

    • Azure Administrator Role Addition to PIM User

    • Azure Administrator Role Removed From User

    • Azure Anti Malware Action Failed

    • Azure App Assigned Full Access to Exchange API

    • Azure App Services Unusual Activity

    • Azure Blob Container Access Level Modification

    • Azure Brute Force RDP Activity to VM

    • Azure Conditional Access Policy Modified

    • Azure Connection to Web Page from Anomalous IP Address Detected

    • Azure Cryptomining Activity Detected

    • Azure Deactivated User Reactivated

    • Azure Firewall Policy Deletion

    • Azure Full Network Packet Capture Detected

    • Azure Internal Bound Traffic From Suspicious IP

    • Azure MFA Disabled for User

    • Azure New Service Principal Created

    • Azure Owner Added to Group

    • Azure Password Policy Changed

    • Azure Possible Vulnerability to SQL Injection

    • Azure Privilege Identity Management Role Modified

    • Azure Resource NMAP Scan Detected

    • Azure Risk Event Detected for User Account

    • Azure Service Principal Credentials Added

    • Azure Service Principal Granted High Risk Permissions

    • Azure Successful Brute Force Attack

    • Azure Suspicious Active Directory PowerShell Sign-in

    • Azure Suspicious Authentication Activity

    • Azure Suspicious Client Communication

    • Azure Suspicious WordPress Theme Invocation Detected

    • Azure User Added as Owner for Application

    • Azure User Added as Owner for Service Principal

    • Azure User Added to Administrator Role

    • Azure Possible MFA Fatigue Attempt


We value your feedback.
If you have questions, suggestions, or feedback on our documentation, contact the Campus Product Documentation team.
For general product inquiries or technical support, please contact the global Barracuda Support team.