VerdantBamboo Targets MSPs Via BRICKSTORM Backdoor

Researchers at Volexity have published a report on a cyber-espionage campaign in which a group believed to be linked to China and tracked as VerdantBamboo

CyberSecureFox
VerdantBamboo: Just Another BRICKSTORM in the Firewall

In September 2025, Volexity conducted an incident response engagement that began after suspicious network traffic was observed from a Linux-based virtual machine appliance on a customer’s network. The virtual machine was an Egnyte Storage Sync system, which is designed to facilitate sync local on-premise files with the cloud. Volexity discovered that instead of connecting to a domain affiliated with Egnyte, the appliance was connecting to a threat-actor-controlled domain behind Cloudflare IP addresses.

Volexity
Heute morgen hat sich endlich eine Lücke in den Wolken aufgetan, so konnte ich Jupiter zu seiner besten Zeit aufnehmen.

This morning, a gap finally opened up in the clouds, allowing me to photograph Jupiter at its best.
#astrofotografie
#planets
#planet