'Significant' threat to US networks after hackers steal F5 source code, CISA warns


  • CISA warns FCEB agencies to patch F5 products after nation-state breach
  • The attackers stole BIG-IP source code and vulnerability data, risking discovery and exploitation on day zero.
  • F5 released updates; No confirmed exploitation yet, but federal networks face imminent threat

The US Cybersecurity and Infrastructure Security Agency (CISA) is urging Federal Civil Executive Branch (FCEB) agencies to catalog and patch F5 products in their technology stack, after hackers broke into the company and stole the source code along with other sensitive information.

In emergency directive ED 26-01, CISA said that a “nation-state-affiliated cyber threat actor” exfiltrated F5 files, including a portion of its BIG-IP source code and vulnerability information. With this intelligence, attackers can analyze F5 products, potentially discover zero-day vulnerabilities, and develop exploits and malware.



© 2024 Telegraph247. All rights reserved.
Designed and developed by Telegraph247
scroll to top