Egnyte A.I CyberSecurity Scoring
Egnyte
Company Information
Website:http://www.egnyte.com
Employees number:1,292
Number of followers:220,549
NAICS:5112
Industry Type:Software Development
Homepage:egnyte.com
Egnyte Risk Score (AI oriented)
Between 750 and 799
EgnyteSoftware Development
Updated:
08/06/2026
08/06/2026
755/1000
Fair
Baa
Egnyte Global Score (TPRM)
xxxx
EgnyteSoftware Development
Score locked

EgnyteFair
Current Score
755Baa (FAIR)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
755
MAY 2026
755
APRIL 2026
755
MARCH 2026
754
FEBRUARY 2026
754
JANUARY 2026
754
DECEMBER 2025
753
NOVEMBER 2025
753
OCTOBER 2025
752
SEPTEMBER 2025
752
AUGUST 2025
751
JULY 2025
751
DECEMBER 2024
764
Cyber Attack
01 Dec 2024 • Egnyte
Egnyte and pfSense: pfSense Firewall Compromised in VerdantBamboo Cyberattack Deploying BRICKSTORM
VerdantBamboo Exploits pfSense Firewall in Long-Running Cyberattack
747
CRITICAL-17
NETEGN1780907044
VerdantBamboo Exploits pfSense Firewall in Long-Running Cyberattack
VerdantBamboo (also tracked as WARP PANDA and UNC5221) compromised a pfSense firewall and deployed a FreeBSD variant of the BRICKSTORM backdoor, granting the threat actor persistent access to a managed service provider’s (MSP) network. The breach was uncovered during a Volexity incident response investigation, which linked the attack to a broader campaign targeting edge devices with limited security monitoring.
The investigation began after suspicious traffic was detected from a Linux-based Egnyte Storage Sync virtual appliance, which was communicating with attacker-controlled infrastructure behind Cloudflare IP addresses. Volexity later confirmed the appliance was infected with BRICKSTORM, a remote access Trojan (RAT) used by VerdantBamboo. The attackers leveraged valid credentials and malware proxy features to access the victim’s Microsoft 365 environment, blending into normal traffic and bypassing Conditional Access rules.
The compromise had persisted for at least 18 months. After an initial cleanup, VerdantBamboo re-entered the network using stolen administrative credentials, enabled web SSL VPN access on the firewall, and deployed additional malware on a Synology NAS device.
Further analysis of the MSP’s infrastructure revealed the pfSense firewall had been compromised, with a BSD-compatible BRICKSTORM implant (named blocklist) deployed in the /usr/local/libexec/ipsec/ directory. Persistence was achieved by modifying /etc/rc.d/cron to execute the implant automatically.
BRICKSTORM, primarily written in Golang (with Rust variants observed), supports remote command execution, SOCKS5 proxying, and file system access via a web interface, enabling lateral movement and traffic obfuscation. Volexity also identified two additional malware families: AGENTPSD (a Python reverse shell) and PLENET/GRIMBOLT (a .NET Native AOT backdoor for Linux systems).
The campaign highlights how advanced threat actors target firewalls, storage appliances, VPNs, and NAS devices systems often lacking robust endpoint detection and response (EDR) coverage.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Egnyte ??
What was Egnyte's A.I Rankiteo Cyber Score in May 2026 ??
What was Egnyte's A.I Rankiteo Cyber Score in April 2026 ??
What was Egnyte's A.I Rankiteo Cyber Score in March 2026 ??
What was Egnyte's A.I Rankiteo Cyber Score in February 2026 ??
What was Egnyte's A.I Rankiteo Cyber Score in January 2026 ??
What was Egnyte's A.I Rankiteo Cyber Score in December 2025 ??
What was Egnyte's A.I Rankiteo Cyber Score in November 2025 ??
What was Egnyte's A.I Rankiteo Cyber Score in October 2025 ??
What was Egnyte's A.I Rankiteo Cyber Score in September 2025 ??
What was Egnyte's A.I Rankiteo Cyber Score in August 2025 ??
What was Egnyte's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Egnyte's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Egnyte ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Egnyte's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?