Live data from Hacker News

F5 says hackers stole undisclosed BIG-IP flaws, source code

bleepingcomputer.com

11–20 of 109 posts

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#11
post #3

I wonder if they’re just saying “nation-state” to make it seem less bad that they were compromised, without having proof that it was an actual nation state. (I mean it could well be a nation state, but just a thought.)

Even if it was actually an honest to god nation-state I can't see why security circles get hyperfixated on the term. Does it really matter at all if it's a nation, state, or nation-state? Of course not, but "nation-state" sounds really cool so that's the go to, even when it's not actually a nation-state.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#12
post #3

I wonder if they’re just saying “nation-state” to make it seem less bad that they were compromised, without having proof that it was an actual nation state. (I mean it could well be a nation state, but just a thought.)

Even if it was actually an honest to god nation-state I can't see why security circles get hyperfixated on the term. Does it really matter at all if it's a nation, state, or nation-state? Of course not, but "nation-state" sounds really cool so that's the go to, even when it's not actually a nation-state.

Lowers the percieved incompetence on hacked side, and its hard to argue against (how do you prove it wasnt?). Stock price fall distaster mitigation via simple PR.

But I agree experts should know better when of any solid proof is lacking. Or any proof at all.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#14
post #3

I wonder if they’re just saying “nation-state” to make it seem less bad that they were compromised, without having proof that it was an actual nation state. (I mean it could well be a nation state, but just a thought.)

Often it can be like that. This a case where the kind of attacker seems highly relevant, though. Imagine a group like Shiny Hunters were the ones to steal these vulns from F5, you'd know if they hit your F5s because they'd have already dumped all your databases and bragged about it. The attacker being a "nation-state" warrants a more careful investigation of historical activity if you're the kind of organization that gets targeted by espionage motivated attacks.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#16
post #8
post #3

I wonder if they’re just saying “nation-state” to make it seem less bad that they were compromised, without having proof that it was an actual nation state. (I mean it could well be a nation state, but just a thought.)

BIG-IP runs DPI (not as good as Sandvine Active Logic), but it's an authoritarian states best friend. Want to compromise another nation state that runs all their traffic through it? These vulns aren't a bad place to start...

This is why I don't understand this strong desire for security auditors to have centralized TLS decryption be important to having some high security stance. You're just creating a massive single point of failure and potentially massively weakening encryption.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#17
post #6

cisa just released: ED 26-01: Mitigate Vulnerabilities in F5 Devices. https://www.cisa.gov/news-events/directives/ed-26-01-mitigat...

This report seems empty of useful information. It’s just “contact us under these circumstances”.

Is it just me?

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#18
post #15

I am having a hard time believing that an attacker maintained long term access to their system and never used it. It seems more likely that we do not KNOW how the access was used.

They say the attacker exfiltrated data, including source code.

They claim the vulnerabilities discovered through the exfiltration were not used though.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#19
post #9

Source: https://my.f5.com/manage/s/article/K000154696

> highly sophisticated nation-state threat actor Sure thing. It's so hard not to hate this PR stuff when they can't even be a tiny bit humble. "The hackers were so sophisticated and organized, we didn't even have a change! They could've hacked everyone!" > In response to this incident, we are taking proactive measures to protect our customers Such as, fixing the bugs or the structural problems that led to you being h…

Especially considering who they are, Agreed. There's not an ounce of empathy I have for them. They are a backbone of the internet and should know better.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#20
post #15

I am having a hard time believing that an attacker maintained long term access to their system and never used it. It seems more likely that we do not KNOW how the access was used.

They say the attacker exfiltrated data, including source code. They claim the vulnerabilities discovered through the exfiltration were not used though.

Not sure why I'm downvoted. Literally quoted from their incident page.

> We have confirmed that the threat actor exfiltrated files from our BIG-IP product development environment and engineering knowledge management platforms. These files contained some of our BIG-IP source code and information about undisclosed vulnerabilities we were working on in BIG-IP.

> We have no knowledge of undisclosed critical or remote code vulnerabilities, and we are not aware of active exploitation of any undisclosed F5 vulnerabilities.

https://my.f5.com/manage/s/article/K000154696

Post reply on HN