A storage appliance can become a long-lived relay into Microsoft 365 and VPN-reachable systems, so patching the box alone does not erase the access path. VerdantBamboo used the appliance as a trusted middle point, which let its traffic blend with normal corporate access instead of looking like an outside intrusion.
Volexity ties that access to Egnyte Storage Sync through a local privilege escalation flaw fixed in version 13.13, and says the group kept returning with BRICKSTORM, PLENET, and AGENTPSD. The reporting also links the campaign to compromised credentials, web SSL VPN access, and an MSP breach, showing the victim was not dealing with one isolated host.
The risk is longer-lived than a single appliance bug. Customized implants and per-victim infrastructure on Linux and BSD appliances give attackers a quiet foothold that can survive into cloud identity and adjacent systems even after the original flaw is remediated.