Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Egnyte

Egnyte Vendor Cyber Rating & Cyber Score

egnyte.com

Egnyte is a leader in secure content collaboration, intelligence, and governance, trusted by more than 23,000 customers to increase employee productivity, drive operational efficiencies, and secure mission-critical content. Egnyte's AI-powered platform empowers organizations to create, share, and protect their information at scale, with specialized solutions designed to meet the unique needs of organizations in architecture, engineering, and construction (AEC), financial services, life sciences, and other industries.


Egnyte A.I CyberSecurity Scoring

Egnyte
Company Information
Website:http://www.egnyte.com
Employees number:1,292
Number of followers:220,549
NAICS:5112
Industry Type:Software Development
Homepage:egnyte.com
Egnyte Risk Score (AI oriented)
Between 750 and 799
logo
EgnyteSoftware Development
Updated:
08/06/2026
755/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Egnyte Global Score (TPRM)
xxxx
logo
EgnyteSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Egnyte
EgnyteFair
Current Score
755Baa (FAIR)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
755Before Incident
MAY 2026
755Before Incident
APRIL 2026
755Before Incident
MARCH 2026
754Before Incident
FEBRUARY 2026
754Before Incident
JANUARY 2026
754Before Incident
DECEMBER 2025
753Before Incident
NOVEMBER 2025
753Before Incident
OCTOBER 2025
752Before Incident
SEPTEMBER 2025
752Before Incident
AUGUST 2025
751Before Incident
JULY 2025
751Before Incident
DECEMBER 2024
764Before Incident
Cyber Attack
01 Dec 2024Egnyte
Egnyte and pfSense: pfSense Firewall Compromised in VerdantBamboo Cyberattack Deploying BRICKSTORM

VerdantBamboo Exploits pfSense Firewall in Long-Running Cyberattack

747After Incident
CRITICAL-17
NETEGN1780907044
VerdantBamboo Exploits pfSense Firewall in Long-Running Cyberattack VerdantBamboo (also tracked as WARP PANDA and UNC5221) compromised a pfSense firewall and deployed a FreeBSD variant of the BRICKSTORM backdoor, granting the threat actor persistent access to a managed service provider’s (MSP) network. The breach was uncovered during a Volexity incident response investigation, which linked the attack to a broader campaign targeting edge devices with limited security monitoring. The investigation began after suspicious traffic was detected from a Linux-based Egnyte Storage Sync virtual appliance, which was communicating with attacker-controlled infrastructure behind Cloudflare IP addresses. Volexity later confirmed the appliance was infected with BRICKSTORM, a remote access Trojan (RAT) used by VerdantBamboo. The attackers leveraged valid credentials and malware proxy features to access the victim’s Microsoft 365 environment, blending into normal traffic and bypassing Conditional Access rules. The compromise had persisted for at least 18 months. After an initial cleanup, VerdantBamboo re-entered the network using stolen administrative credentials, enabled web SSL VPN access on the firewall, and deployed additional malware on a Synology NAS device. Further analysis of the MSP’s infrastructure revealed the pfSense firewall had been compromised, with a BSD-compatible BRICKSTORM implant (named blocklist) deployed in the /usr/local/libexec/ipsec/ directory. Persistence was achieved by modifying /etc/rc.d/cron to execute the implant automatically. BRICKSTORM, primarily written in Golang (with Rust variants observed), supports remote command execution, SOCKS5 proxying, and file system access via a web interface, enabling lateral movement and traffic obfuscation. Volexity also identified two additional malware families: AGENTPSD (a Python reverse shell) and PLENET/GRIMBOLT (a .NET Native AOT backdoor for Linux systems). The campaign highlights how advanced threat actors target firewalls, storage appliances, VPNs, and NAS devices systems often lacking robust endpoint detection and response (EDR) coverage.
INCIDENT DETAILS -
TYPE
Cyber Espionage, Persistent Access, Data Exfiltration
MOTIVATION
Cyber espionage, persistent network access, data exfiltration
IMPACT
pfSense firewallLinux-based Egnyte Storage Sync virtual applianceSynology NAS deviceMicrosoft 365 environmentOperational Impact: Persistent unauthorized access, lateral movement, traffic obfuscation

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Egnyte ?
?
What was Egnyte's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Egnyte's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Egnyte's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Egnyte's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Egnyte's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Egnyte's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Egnyte's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Egnyte's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Egnyte's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Egnyte's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Egnyte's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Egnyte's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Egnyte ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Egnyte's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Egnyte Cyber Scoring History | Rankiteo