logo

Hackers Exploit F5 BIG-IP Appliance to Gain SSH Access and Pivot Into Enterprise Linux Networks

ID: 28c2946f-9f1b-5c79-999b-b4a6622fcd9c

STIX ID: report--28c2946f-9f1b-5c79-999b-b4a6622fcd9c

Feed Name: cybersecurityNews.com

Threat Score
82/100

Date Published: 2026-05-23

Date Updated: 2026-05-23

Author: Guru Baran

...
...

Microsoft reported a multi-stage intrusion that began with SSH access via an end-of-life F5 BIG-IP VE, followed by internal reconnaissance, exploitation of an unpatched Atlassian Confluence RCE, credential harvesting, and Kerberos/NTLM relay attacks against Active Directory; observed IOCs include C2 206.189.27.39 and multiple file hashes, and the vendor urges urgent patching, identity hardening, and edge-appliance lifecycle management.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.