“No one will ever find these vulns without source access! Fix deferred” oh wait…
Yeah, I was trying to make sense of what was described here. Is it that (through some mechanism) an actor gained access to F5's sytems, and literally found undisclosed vulnerabilities documented within F5's source control / documentation that affects F5's products? If so, lol.
F5 says hackers stole undisclosed BIG-IP flaws, source code
41–50 of 109 posts
Re: F5 says hackers stole undisclosed BIG-IP flaws, source code
#42Earlier quoted context omitted.
Not sure why I'm downvoted. Literally quoted from their incident page. > We have confirmed that the threat actor exfiltrated files from our BIG-IP product development environment and engineering knowledge management platforms. These files contained some of our BIG-IP source code and information about undisclosed vulnerabilities we were working on in BIG-IP. > We have no knowledge of undisclosed critical or remote cod…
No, they claimed: "We have no knowledge " and "we are not aware " which does not mean "the vulnerabilities discovered through exfiltration were not used ". That admits nearly every possible class of outcome as long they did not actively already know about it and chose to say they did not. The specific words that their lawyers intentionally drafted explicitly even allow them to intentionally spend effort to destroy an…
Re: F5 says hackers stole undisclosed BIG-IP flaws, source code
#43https://my.f5.com/manage/s/article/K000157005
In October 2025, F5 rotated its signing certificates and keys used to cryptographically sign F5-produced digital objects.
As a result:
BIG-IP and BIG-IQ TMOS product versions released in October 2025 and later are signed with new certificates and keys
BIG-IP and BIG-IQ TMOS product versions released in October 2025 and later contain new public keys used to verify certain F5-produced objects released in October 2025 and later
BIG-IP and BIG-IQ TMOS product versions released in October 2025 and later may not be able to verify certain F5-produced objects released prior to October 2025
BIG-IP and BIG-IQ TMOS product versions released prior to October 2025 may not be able to verify certain F5-produced objects released in October 2025 and laterRe: F5 says hackers stole undisclosed BIG-IP flaws, source code
#44Re: F5 says hackers stole undisclosed BIG-IP flaws, source code
#45Earlier quoted context omitted.
BIG-IP runs DPI (not as good as Sandvine Active Logic), but it's an authoritarian states best friend. Want to compromise another nation state that runs all their traffic through it? These vulns aren't a bad place to start...
This is why I don't understand this strong desire for security auditors to have centralized TLS decryption be important to having some high security stance. You're just creating a massive single point of failure and potentially massively weakening encryption.
It need not be a single point of failure. You can set these things up with redundancy. There's certainly an element of adding risk, your interception box is a big target to do unauthorized interception or tampering; but there's also an element of reducing risk --- you'd be potentially able to see and respond to traffic that would be opaque otherwise.
Re: F5 says hackers stole undisclosed BIG-IP flaws, source code
#46Earlier quoted context omitted.
This is why I don't understand this strong desire for security auditors to have centralized TLS decryption be important to having some high security stance. You're just creating a massive single point of failure and potentially massively weakening encryption.
> You're just creating a massive single point of failure and potentially massively weakening encryption. It need not be a single point of failure. You can set these things up with redundancy. There's certainly an element of adding risk, your interception box is a big target to do unauthorized interception or tampering; but there's also an element of reducing risk --- you'd be potentially able to see and respond to tr…
Yes, so instead of one box with the keys to decrypt all the traffic flowing through the network I'll have multiple boxes that have the ability to decrypt all the traffic. Multiple machines to update and secure and guard against those getting attacked or else everything gets broken.
Re: F5 says hackers stole undisclosed BIG-IP flaws, source code
#47Re: F5 says hackers stole undisclosed BIG-IP flaws, source code
#48Earlier quoted context omitted.
This is why I don't understand this strong desire for security auditors to have centralized TLS decryption be important to having some high security stance. You're just creating a massive single point of failure and potentially massively weakening encryption.
It seems like its a place were there are some serious tradeoffs. You can choose to have visibility into your network traffic or can choose not to. If you choose yes, you create a single point of failure but have the ability to detect breaches elsewhere; if you choose no, you avoid the single point of failure but make it easier for an attacker to exfiltrate data undetected.
But in the end of I want Alice to talk to Bob and know they and only them are talking I'd like to guarantee that. Instead companies are spending tons of money and work hours doing Eve's work for her, installing her tools and getting it all nicely configured for when she logs in.
How many times do we have to backdoor our crypto systems to realize we're not building doors for just us but for everyone else as well?
Re: F5 says hackers stole undisclosed BIG-IP flaws, source code
#49cisa just released: ED 26-01: Mitigate Vulnerabilities in F5 Devices. https://www.cisa.gov/news-events/directives/ed-26-01-mitigat...
This report seems empty of useful information. It’s just “contact us under these circumstances”. Is it just me?
Re: F5 says hackers stole undisclosed BIG-IP flaws, source code
#50I wonder if they’re just saying “nation-state” to make it seem less bad that they were compromised, without having proof that it was an actual nation state. (I mean it could well be a nation state, but just a thought.)
BIG-IP runs DPI (not as good as Sandvine Active Logic), but it's an authoritarian states best friend. Want to compromise another nation state that runs all their traffic through it? These vulns aren't a bad place to start...
Finding a way to subvert that authentication or, better yet, bypass it entirely, could put U.S. military networks that can be reached over the public Internet at risk of remote exploitation. Those networks can often also reach other military networks not directly exposed to the public Internet.