bleepingcomputer · Crawled Jul 25, 2026
Over 266,000 F5 BIG-IP instances exposed to remote attacks
1 Actors 1 Malware
Read original article ↗
AI Summary
Over 266,000 F5 BIG-IP instances are exposed online following a breach of F5's network by suspected China-nexus threat actor UNC5291, which stole source code and information on undisclosed vulnerabilities. F5 has released patches for 44 vulnerabilities and urged immediate customer action, while CISA issued an emergency directive for federal agencies to patch or disconnect exposed systems. The attackers used the Go-based Brickstorm malware and had access to F5's network for at least a year. Threat actors are targeting these devices to breach networks, steal credentials, and establish persistence.
AI-extracted · verify before operational use
Extracted Entities 2 found
MITRE ATT&CK TTPs 7 techniques
T1059 Command and Scripting Interpreter · Execution T1068 Exploitation for Privilege Escalation · Privilege Escalation T1078 Valid Accounts · Defense Evasion T1082 System Information Discovery · Discovery T1133 External Remote Services · Persistence T1484 Domain or Tenant Policy Modification · Defense Evasion T1490 Inhibit System Recovery · Impact