詳細検索

What is a state-sponsored hacker attack on F5's BIG-IP? Leaked information and what companies should do

Avatar
by 似里
3 min read

What is a state-sponsored hacker attack on F5's BIG-IP? Leaked information and what companies should do
Translated from 日本語 • View original
似里
似里

I'm a Colorkrew infrastructure and security engineer. I am pleased to announce that I have joined the writing team of the Blog Security Blog, and this blog will be the first to commemorate! We will continue to work input and writing so that we can deliver useful security information to our readers!

This time, regarding a series of cyber attacks and breach incidents surrounding F5, Inc. (F5) and its product line "BIG-IP", which we are also using in some of our projects, we will discuss public information by the Cybersecurity and Infrastructure Security Agency (CISA) and U.S. Securities and This report is based on reports to the Exchange Commission (SEC), public information from FedRAMP, and public information from F5 (as of October 2025). For those of you who are in charge of security operations at companies, we have also summarized the points you want to keep in mind from an operational perspective, so please take advantage of them.

Timing and background of discovery and publication

On August 9, 2025, F5 disclosed in a report to the SEC on October 15 of the same year that "highly sophisticated state-level attackers have made unauthorized access."

On September 12 of the same year, the U.S. Department of Justice (DOJ) decided to delay disclosure due to national security reasons.

On October 15 of the same year, CISA issued Emergency Directive 26-01: Mitigate Vulnerabilities in F5 Devices, ordering the Federal Civilian Executive Branch (FCEB) to immediately conduct inventory and updates of F5 products.

Key points of the incident

Affected Targets

ED 26-01 specifies the following product groups as affected products: Regardless of whether it is a hardware product or a software product, many BIG-IP-related products are affected.

Hardware Products

  • BIG-IP iSeries
  • BIG-IP rSeries
  • Other devices that are not supported

Software Products

  • BIG-IP (F5OS)
  • BIG-IP (TMOS)
  • Virtual Edition (VE)
  • BIG-IP Next
  • BIG-IQ
  • BIG-IP Next for Kubernetes (BNK)/Cloud-Native Network Functions (CNF)

Threat Intelligence

  • We observed that the attacker had long-term access to BIG-IP's product development environment and knowledge base for engineers.
  • It is said that "part of the source code of BIG-IP", "undisclosed vulnerability information", and "configuration and implementation information related to some customers" may have been stolen through access by the attacker.
  • We have not been able to confirm any undisclosed critical vulnerabilities, remote code execution vulnerabilities, or cases of exploitation.

Countermeasures against this incident

The leak of source code and undisclosed vulnerability information suggests that attackers are likely to analyze and prepare for zero-day attacks. Therefore, immediate action is required for operators.

Actions to be taken in response to this incident Based on public information by F5 and CISA, security operators are required to respond to this incident as follows:

1. Identification of Relevant Equipment

  • Identify all BIG-IP hardware products.
  • Identify the equipment that runs all BIG-IP software products.

2. Check Network Connection Status

  • After the identification of the related device is completed, check whether the target device is connected to the Internet (public network).

3. Patching Covered Products

  • Consider obsolescence or replacement of EOS devices and older versions of devices whenever possible.
  • Update the affected F5 products to the latest version provided by F5.

4. Preparing for Detection of Cyber Attacks

  • Enhance Threat Intelligence
  • Strengthen the authentication system
  • Integrate into SIEM and enhance monitoring operations

Conclusion

The scope of the F5/BIG-IP incident is significant in that it goes beyond simply addressing product vulnerabilities, and that "the development environment and knowledge management platform of network infrastructure products may have been compromised, and source code and undisclosed vulnerability information may have been leaked."


Colorkrew Security provides SOC operation, monitoring, and CSIRT support for BIG-IP, so please contact us.

Related Articles