logo

Over 266,000 F5 BIG-IP instances exposed to remote attacks

ID: 8da923ad-aa6b-5d8c-844d-006044a6813a

STIX ID: report--8da923ad-aa6b-5d8c-844d-006044a6813a

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-10-17

Date Updated: 2026-07-18

Author: Sergiu Gatlan

...
...

Shadowserver and F5 disclosed a nation-state intrusion into F5 that exfiltrated source code and details of undisclosed BIG-IP vulnerabilities; F5 released patches for 44 vulnerabilities and urged immediate updates while Shadowserver identified ~266,978 Internet-exposed BIG-IP instances worldwide. CISA issued emergency directives to federal agencies to patch or remove affected devices, and F5 privately linked the activity to a China-nexus group (UNC5291) and the Brickstorm backdoor, noting the attackers were present in F5’s network for at least a year.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.