F5 incident (Incident)
ID: 75db8391-8c50-53df-ad3f-80f03822356f
STIX ID: report--75db8391-8c50-53df-ad3f-80f03822356f
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-10-15
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
F5 disclosed that in August 2025 a nation-state actor maintained persistent access to internal systems, exfiltrated portions of BIG-IP source code and details of ongoing vulnerability research, and accessed limited customer configuration data; F5 and third-party responders found no evidence of code tampering or compromised build pipelines, implemented containment measures (credential rotation, access hardening, segmentation, patching and monitoring), and CISA directed federal agencies to immediately mitigate affected F5 devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
