logo

CISA: Hackers abuse F5 BIG-IP cookies to map internal servers

ID: c3022c58-2b26-5ca2-94e7-2d151a7f0770

STIX ID: report--c3022c58-2b26-5ca2-94e7-2d151a7f0770

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2024-10-11

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

CISA warns that threat actors are abusing unencrypted F5 BIG-IP LTM persistence cookies—which contain encoded internal IPs, ports, and server mappings—to enumerate non-internet-facing devices for follow-on attacks; administrators are urged to enable cookie encryption (Required mode) and use F5 diagnostic tools to detect and remediate misconfigurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.