BRICKSTORM case from Volexity: a clear reminder that edge appliances, MSP access and trusted network paths can become long-term blind spots for cloud compromise.
https://www.volexity.com/blog/2026/06/04/verdantbamboo-just-another-brickstorm-in-the-firewall/
#ThreatIntelligence #CyberSecurity #APT #BRICKSTORM #Microsoft365 #CloudSecurity #DFIR

VerdantBamboo: Just Another BRICKSTORM in the Firewall
In September 2025, Volexity conducted an incident response engagement that began after suspicious network traffic was observed from a Linux-based virtual machine appliance on a customer’s network. The virtual machine was an Egnyte Storage Sync system, which is designed to facilitate sync local on-premise files with the cloud. Volexity discovered that instead of connecting to a domain affiliated with Egnyte, the appliance was connecting to a threat-actor-controlled domain behind Cloudflare IP addresses.
filippodb ⁂ 
