F5 says hackers stole undisclosed BIG-IP flaws, source code
1–10 of 109 posts
Re: F5 says hackers stole undisclosed BIG-IP flaws, source code
#2Re: F5 says hackers stole undisclosed BIG-IP flaws, source code
#3Re: F5 says hackers stole undisclosed BIG-IP flaws, source code
#4I wonder if they’re just saying “nation-state” to make it seem less bad that they were compromised, without having proof that it was an actual nation state. (I mean it could well be a nation state, but just a thought.)
Re: F5 says hackers stole undisclosed BIG-IP flaws, source code
#5Re: F5 says hackers stole undisclosed BIG-IP flaws, source code
#6https://www.cisa.gov/news-events/directives/ed-26-01-mitigat...
Re: F5 says hackers stole undisclosed BIG-IP flaws, source code
#7Re: F5 says hackers stole undisclosed BIG-IP flaws, source code
#8I wonder if they’re just saying “nation-state” to make it seem less bad that they were compromised, without having proof that it was an actual nation state. (I mean it could well be a nation state, but just a thought.)
Re: F5 says hackers stole undisclosed BIG-IP flaws, source code
#9Source: https://my.f5.com/manage/s/article/K000154696
Sure thing. It's so hard not to hate this PR stuff when they can't even be a tiny bit humble. "The hackers were so sophisticated and organized, we didn't even have a change! They could've hacked everyone!"
> In response to this incident, we are taking proactive measures to protect our customers
Such as, fixing the bugs or the structural problems that led to you being hacked and leaking information about even more bugs that you left undisclosed and just postponed to fix it? This wording sounds like they're now going the extra mile to protect their customers and makes it sound like a good thing, when keeping your systems secure and fixing known bugs should've been the first meters they should've gone.
Just be honest, you fucked up twice. It's shit, but it happens. I just hate PR.
Re: F5 says hackers stole undisclosed BIG-IP flaws, source code
#10“No one will ever find these vulns without source access! Fix deferred” oh wait…
Is it that (through some mechanism) an actor gained access to F5's sytems, and literally found undisclosed vulnerabilities documented within F5's source control / documentation that affects F5's products?
If so, lol.