The Infrastructural Siege: Why Salt Typhoon and VerdantBamboo represent the new normal in state-level espionage
Two years after the first telecom breaches, the 2026 landscape reveals a terrifying reality: APTs are no longer just raiding our data; they are building permanent homes within our core infrastructure.
The Era of Permanent Presence
As we cross the mid-point of 2026, the cybersecurity community is grappling with a stark realization: the "smash-and-grab" era of cyber espionage has been fully replaced by deep, structural integration. Recent disclosures regarding Salt Typhoon (linked to the PRC's Ministry of State Security) and the persistent activities of UNC5221 (VerdantBamboo) have redefined our understanding of a "successful" breach.
Last week, intelligence updates confirmed that Salt Typhoon’s reach now extends to over 200 companies globally, with a specific focus on the connective tissue of the digital world—telecom providers and satellite communications like Viasat. They aren't just stealing emails; they are monitoring the wiretap systems used by law enforcement, effectively turning our own security tools against us.
The Shadow in the Cloud
Equally concerning is the recent analysis of VerdantBamboo. Reports from early June 2026 highlight their use of the Brickstorm backdoor to maintain a foothold in Microsoft 365 environments for over 18 months before detection. This wasn't a failure of a single firewall; it was a systemic compromise of Managed Service Providers (MSPs). By compromising the provider, the adversary gains a "trusted" path into thousands of downstream targets.
This "Living-off-the-Interconnect" strategy allows actors to blend into legitimate network traffic, bypassing Conditional Access policies and making traditional anomaly detection nearly obsolete. When the attacker is using your own admin credentials through a trusted partner's tunnel, the red lights don't blink.
Shifting the Defensive Paradigm
For leaders and defenders, the strategy must shift from perimeter defense to Infrastructural Resilience. The launch of CISA’s ANCHOR-CI initiative on July 2, 2026, is a step in the right direction, focusing on the security of the actual hardware and protocols that underpin the internet.
Defenders should prioritize:
- Identity as the Perimeter: Moving beyond MFA to continuous, context-aware identity verification (Zero Trust Architecture).
- Supply Chain Auditing: Rigorous security requirements for MSPs and SaaS providers. You are only as secure as your least-secure vendor.
- Egress Monitoring: If you can't stop the intrusion, you must stop the exfiltration. Focus on where the data is going, not just how it got in.
The Road Ahead
The outlook for the remainder of 2026 is one of increased friction. As APTs continue to weaponize communications metadata and administrative tools, the line between "normal operation" and "intelligence operation" will continue to blur. Survival in this landscape requires a shift from seeking total security to achieving total visibility.



