Over 266,000 F5 BIG-IP instances exposed to remote attacks
ID: 8da923ad-aa6b-5d8c-844d-006044a6813a
STIX ID: report--8da923ad-aa6b-5d8c-844d-006044a6813a
Feed Name: Bleeping Computer
Shadowserver and F5 disclosed a nation-state intrusion into F5 that exfiltrated source code and details of undisclosed BIG-IP vulnerabilities; F5 released patches for 44 vulnerabilities and urged immediate updates while Shadowserver identified ~266,978 Internet-exposed BIG-IP instances worldwide. CISA issued emergency directives to federal agencies to patch or remove affected devices, and F5 privately linked the activity to a China-nexus group (UNC5291) and the Brickstorm backdoor, noting the attackers were present in F5’s network for at least a year.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
