8 ms·
F5 says hackers stole undisclosed BIG-IP flaws, source code
https://www.sec.gov/ix?doc=/Archives/edgar/data/1048695/000104869525000149/ffiv-20251015.htm https://www.sec.gov/ix?doc=/Archives/edgar/data/1048695/0001...
- tru3_power 1y ago“No one will ever find these vulns without source access! Fix deferred” oh wait…
- bangaladore 1y agoYeah, I was trying to make sense of what was described here. Is it that (through some mechanism) an actor gained access to F5's sytems, and literally found undisclosed vulnerabilities documented within F5's source control / documentation that affects F5's products? If so, lol.
- tru3_power 1y agoYeah that’s what I’m understanding is the case. That’s why they’re harping on no known (unreleased) vulns. But it’s kinda funny, a lot of times bugs that fall under this category are constantly shuffled around/not fixed because there is no public pressure to address them.
- dwd 1y agoA simple search across a codebase for "TODO" will find all sorts of things left undone, but having access to source control and commit messages, who knows what you might find. "Here be dragons" is also a good search if you're responsible for security hardening legacy code.
- bangaladore 1y agoYeah, it's unclear if this is something like TODO or an internal Jira tracking bugs. Either way though, this is not a small company. DoD/Navy utilizes this all over their systems. TODO shouldn't be getting pushed to main, nor should there be security issues swept under the rug for later. Maybe they disclosed this to some vendors previously, but I doubt.
- sevg 1y agoI wonder if they’re just saying “nation-state” to make it seem less bad that they were compromised, without having proof that it was an actual nation state. (I mean it could well be a nation state, but just a thought.)
- verdverm 1y agoThis def seems like corpo disaster PR copy. Not the kind of content I expected and love HN for
- scotho3 1y agoBIG-IP runs DPI (not as good as Sandvine Active Logic), but it's an authoritarian states best friend. Want to compromise another nation state that runs all their traffic through it? These vulns aren't a bad place to start...
- vel0city 1y agoThis is why I don't understand this strong desire for security auditors to have centralized TLS decryption be important to having some high security stance. You're just creating a massive single point of failure and potentially massively weakening encryption.
- palmotea 1y agoIt seems like its a place were there are some serious tradeoffs. You can choose to have visibility into your network traffic or can choose not to. If you choose yes, you create a single point of failure but have the ability to detect breaches elsewhere; if you choose no, you avoid the single point of failure but make it easier for an attacker to exfiltrate data undetected.
- vel0city 1y agoI'm down for endpoints having to report whatever metrics to whatever servers and have their transactions highly audited. I'm down for their connectivity to be highly locked down. It's important to know what's happening on your systems and where data is flowing, I agree! But in the end of I want Alice to talk to Bob and know they and only them are talking I'd like to guarantee that. Instead companies are spending tons of money and work hours doing Eve's work for her, installing her tools and getting it all nicely configured for when she logs in. How many times do we have to backdoor our crypto systems to realize we're not building doors for just us but for everyone else as well?
- ChrisArchitect 1y agoSource: https://my.f5.com/manage/s/article/K000154696 https://my.f5.com/manage/s/article/K000154696
- wobfan 1y ago> highly sophisticated nation-state threat actor Sure thing. It's so hard not to hate this PR stuff when they can't even be a tiny bit humble. "The hackers were so sophisticated and organized, we didn't even have a change! They could've hacked everyone!" > In response to this incident, we are taking proactive measures to protect our customers Such as, fixing the bugs or the structural problems that led to you being hacked and leaking information about even more bugs that you left undisclosed and just postponed to fix it? This wording sounds like they're now going the extra mile to protect their customers and makes it sound like a good thing, when keeping your systems secure and fixing known bugs should've been the first meters they should've gone. Just be honest, you fucked up twice. It's shit, but it happens. I just hate PR.
- reactordev 1y agoEspecially considering who they are, Agreed. There's not an ounce of empathy I have for them. They are a backbone of the internet and should know better.
- zingababba 1y agoThe NCC attestation letter is wild: F5, Inc. (“F5”) engaged NCC Group to perform (i) a security assessment of critical F5 software source code, including critical software components of the BIG-IP product, as provided by F5, and (ii) a review of portions of the software development build pipeline related to the same, and designated as critical by F5 (collectively, the “In-Scope Items”). NCC Group’s assessment included a source code security review by 76 consultants over a total of 551 person-days of effort. Wonder what the bill was?
- navidr1 1y agocisa just released: ED 26-01: Mitigate Vulnerabilities in F5 Devices. https://www.cisa.gov/news-events/directives/ed-26-01-mitigate-vulnerabilities-f5-devices https://www.cisa.gov/news-events/directives/ed-26-01-mitigat...
- ZeroConcerns 1y agoI'm not sure if item #2 in the linked advisory ("identify if the networked management interface is accessible directly from the public internet") indicates whether compromise is only likely in that situation or not, but... lots of remote workers are going to have some time for offline reflection in the next week, it seems regardless.
- bananapub 1y agooh that's handy, they can add them to the big pile of disclosed BIG-IP flaws
- fn-mote 1y agoI am having a hard time believing that an attacker maintained long term access to their system and never used it. It seems more likely that we do not KNOW how the access was used.
- bangaladore 1y agoThey say the attacker exfiltrated data, including source code. They claim the vulnerabilities discovered through the exfiltration were not used though.
- bangaladore 1y agoNot sure why I'm downvoted. Literally quoted from their incident page. > We have confirmed that the threat actor exfiltrated files from our BIG-IP product development environment and engineering knowledge management platforms. These files contained some of our BIG-IP source code and information about undisclosed vulnerabilities we were working on in BIG-IP. > We have no knowledge of undisclosed critical or remote code vulnerabilities, and we are not aware of active exploitation of any undisclosed F5 vulnerabilities. https://my.f5.com/manage/s/article/K000154696 https://my.f5.com/manage/s/article/K000154696
- Veserv 1y agoNo, they claimed: "We have no knowledge" and "we are not aware" which does not mean "the vulnerabilities discovered through exfiltration were not used". That admits nearly every possible class of outcome as long they did not actively already know about it and chose to say they did not. The specific words that their lawyers intentionally drafted explicitly even allow them to intentionally spend effort to destroy any evidence that would lead them to learn if the vulnerabilities were used and still successfully claim that they were telling the truth in a court of law. You should not assume their highly paid lawyers meant anything other than the most tortured possible technically correct statement. PR statements drafted by legal are a monkey's paw. Treat them like it.
- 1y ago
- citizenpaul 1y ago[flagged]
- catigula 1y agoThere's huge incentive for nation-state level actors to recruit, train and spend oodles on extremely sophisticated hacking programs with little legal oversight and basically endless resources. I have no idea why you're incredulous about this. If I were running a country practically my highest priority would be cyberattacks and defense. The ability to arbitrarily penetrate even any corporate network, let alone military network, is basically infinite free IP.
- tiahura 1y agoYou can get a lot of fat kids on a computer in a bedroom for the cost of building and maintaining a 6th Gen fighter.
- citizenpaul 1y ago> I have no idea why you're incredulous about this. I understand human nature.
- cindyllm 1y ago[dead]
- behringer 1y agoIt doesn't matter who hacks me. If my job is on the line I'm going to claim it's someone impossible to defend against like a state actor. There's a thousand things to point at that would make it plausible. I might even convince myself of it out of sheer embarrassment.
- catigula 1y agoI don't lie generally but most of all about things that could precipitate FBI involvement in what you're doing. This is a fantasy.
- 1y ago
- ktallett 1y agoI'm slightly questioning the security of a cybersecurity company that has systems that allow people long term access.
- xcf_seetan 1y agoYes, i raise my eyebrow too. "F5 is a Fortune 500 tech giant specializing in cybersecurity" and "the attackers had gained long-term access to its system" doesn't seem to agree with each other.
- wallaBBB 1y ago> undisclosed F5 vulnerabilities I don’t know why, but this sounds a bit like backdoors.
- Templeton2X 1y ago[dead]
- tiahura 1y agoF5 claims that the threat actors' access to the BIG-IP environment did not compromise its software supply chain or result in any suspicious code modifications. Why would anyone have confidence in F5’s analysis?
- pixl97 1y agoI mean, because it depends where the attack happened. Working with large companies like this in CI/CD there are a number of tools that the source code gets checked on, but not fed back into the system that could have been the source of the attack.
- ExoticPearTree 1y agoI think it is more valuable for the attackers to have exfiltrated their code and analyze it for vulnerabilities. Adding some malicious code to the BIG-IP software would require a long time for the attackers to persist in f5's systems undetected until they understood the current code. Not a zero percent chance, but pretty unlikely.
- weeha 1y agoLooks like they rotated all signings keys a day earlier: https://my.f5.com/manage/s/article/K000157005 https://my.f5.com/manage/s/article/K000157005 In October 2025, F5 rotated its signing certificates and keys used to cryptographically sign F5-produced digital objects. As a result: BIG-IP and BIG-IQ TMOS product versions released in October 2025 and later are signed with new certificates and keys BIG-IP and BIG-IQ TMOS product versions released in October 2025 and later contain new public keys used to verify certain F5-produced objects released in October 2025 and later BIG-IP and BIG-IQ TMOS product versions released in October 2025 and later may not be able to verify certain F5-produced objects released prior to October 2025 BIG-IP and BIG-IQ TMOS product versions released prior to October 2025 may not be able to verify certain F5-produced objects released in October 2025 and later
- brunoTbear 1y agoI wonder if there's a bet to be made on future 8K disclosures following quietly updated signing keys. A bet against F5 placed this morning would've only made 3.6%.
- Fokamul 1y agoAka outsourcing work to third world countries has come back to bite us ;-)
- elzbardico 1y ago"We have no knowledge the vulnerabilities discovered through exfiltration were not used" Translated => We don't know whether they have used or are going to use our NSA-mandated backdoors.
- knappe 1y agoIt took them 67 days to disclose that their premier product, which is used heavily in the industry, had been compromised. Does anyone know why it seems like we're seeing disclosures like this take longer and longer to be disclosed? I would think the adage "Bad news travels fast" would apply more often in these cases, if only to limit the scope of the damage.
- worthless-trash 1y agoJust to be clear, the attackers had access to the systems well before this date. Sometimes when a company engages law enforcement, law enforcement can request that they not divulge that the company knows about the problem so that forensics can begin tracking the problem. I won't speak how often or how competent law enforcement are though, but it can happen.
- lucideer 1y agoI can't help thinking that a part of it is that the supreme court has proactively & progressively been watering down the threat of class actions (in general, not specific to tech) since the early 2010s. Sony & many others have proved pretty comprehensively that brand reputation isn't really impacted by breaches, even in high profile consumer facing businesses. That trickles down to B2B: if your clients don't care, why should you. That leaves legal risk as the only other motivating factor. If that's been effectively neutered, it doesn't make economic sense for companies to do due diligence with breaches. As far as I'm aware, Yahoo were the last company to suffer any significant impact from the US legal system due to a breach.
- ojosilva 1y agoTheir customer base are enterprise, so the issue can be addressed in private channels. There's little to be gained from making this particular breach public, from their point view. If anything, it's F5 customers who should advise their own customers downstream about the risks, when risks apply. Disclosure: I'm affected by this breach downstream at several sites and we have not been informed of risks by anyone but have been fighting fires where F5 was involved, but not necessarily blamed for anything. But you are right, at F5's size and moneys, incentives for public disclosure are not aligned in the public's favor. Damage control, in all its meanings, has taken priority lately over transparency.
- x1unix 1y agoA cybersecurity company was hacked — what an irony
- vasco 1y agoNot so much irony as it's a great vector to get inside an org. Security / monitoring agents that you deploy everywhere and don't suspect when you see they exfiltrate data, since you're expecting the telemetry anyway.
- x3n0ph3n3 1y agoEvery time some security compliance goon comes by telling me to install an agent on all of our servers to meet some security compliance requirement, I remind them that they are asking me to install a backdoor on our servers and handing the keys to a 3rd party.
- natebc 1y agoThe Crowdstrike Falcon Sensor agent (with a kernel module) establishes TLS connections to several random AWS endpoints. I really have no idea how security people think this is a good thing aside from checkbox compliance but man-o-man do they love it.
- neffy 1y agoWell honestly, this security person thinks its a terrible idea - but needless to say the people selling those systems disagree - and for non-technical management, it ticks the compliance box and they get back to their jobs.
- goalieca 1y agoThey are also telling you how to cover-your-ass once a breach happens.
- ExoticPearTree 1y agoYou will not be faulted for anything if the security company gets hacked and you get hacked through it. Probably a lot of sleepless nights to fix your infra, but that's it.
- wonderwonder 1y agoThis is an excellent argument against the British style request for a state level back door to encrypted data. It will be exploited and it will likely be quite some time until they learn of the exploit and even longer if ever until we do.
- hoodguy 1y agoIf the orgs/products responsible for saving the orgs are getting their source code exfiltrated then we all are on the mercy of hackers.
- hoodguy 1y ago[dead]
- wdb 1y agoI have only heard bad things about F5 XC
- gilberthelen 11mo ago[dead]
- marcuskoss9 11mo ago[dead]