logo

CISA warns of imminent risk posed by thousands of F5 products in federal agencies

ID: f9b8c867-9711-5930-94cb-17c65abc6768

STIX ID: report--f9b8c867-9711-5930-94cb-17c65abc6768

Feed Name: CyberScoop

Threat Score
85/100

Date Published: 2025-10-15

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

Federal cyber authorities issued an emergency directive after F5 reported unauthorized access to its internal systems on Aug. 9 that resulted in theft of BIG-IP source code and details of vulnerabilities. The Cybersecurity and Infrastructure Security Agency (CISA) directed federal agencies to apply F5 patches, disconnect unsupported devices, and provide inventories by Oct. 22; officials say a nation-state actor maintained long-term persistent access but have not disclosed how access was gained or named the actor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.