A recent cluster of Linux-appliance intrusions shows how attackers can mix one primary implant with lighter backup tooling to keep footholds alive on devices many defenders still underwatch.
A reported pfSense compromise shows how a perimeter device can become a quiet persistence point when attackers aim for infrastructure that security teams do not watch like a workstation.
Edge devices are becoming a favored blind spot for stealthy operators, and BRICKSTORM shows how a foothold on a network appliance can become a path into Microsoft 365.
A reported campaign ties a Chinese-nexus threat label to BRICKSTORM, a modular backdoor built to live inside appliances and move quietly through enterprise networks.
As cyber spies refine Brickstorm’s capabilities, CISA sounds the alarm on a new, harder-to-detect malware strain targeting critical infrastructure.
A deep dive into a stealthy China-linked cyber campaign targeting U.S. organizations with advanced malware tactics.