Live data from Hacker News

F5 says hackers stole undisclosed BIG-IP flaws, source code

bleepingcomputer.com

61–70 of 109 posts

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#61

[flagged]

There's huge incentive for nation-state level actors to recruit, train and spend oodles on extremely sophisticated hacking programs with little legal oversight and basically endless resources. I have no idea why you're incredulous about this. If I were running a country practically my highest priority would be cyberattacks and defense. The ability to arbitrarily penetrate even any corporate network, let alone militar…

It doesn't matter who hacks me. If my job is on the line I'm going to claim it's someone impossible to defend against like a state actor.

There's a thousand things to point at that would make it plausible. I might even convince myself of it out of sheer embarrassment.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#62
post #3

I wonder if they’re just saying “nation-state” to make it seem less bad that they were compromised, without having proof that it was an actual nation state. (I mean it could well be a nation state, but just a thought.)

I mean the traffic came from a nation soo it must be

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#64

I'm slightly questioning the security of a cybersecurity company that has systems that allow people long term access.

Yes, i raise my eyebrow too. "F5 is a Fortune 500 tech giant specializing in cybersecurity" and "the attackers had gained long-term access to its system" doesn't seem to agree with each other.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#65

Earlier quoted context omitted.

There's huge incentive for nation-state level actors to recruit, train and spend oodles on extremely sophisticated hacking programs with little legal oversight and basically endless resources. I have no idea why you're incredulous about this. If I were running a country practically my highest priority would be cyberattacks and defense. The ability to arbitrarily penetrate even any corporate network, let alone militar…

It doesn't matter who hacks me. If my job is on the line I'm going to claim it's someone impossible to defend against like a state actor. There's a thousand things to point at that would make it plausible. I might even convince myself of it out of sheer embarrassment.

I don't lie generally but most of all about things that could precipitate FBI involvement in what you're doing.

This is a fantasy.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#66

[flagged]

If there was some government program I was previously unaware of that pays organizations that were compromised by nation state hackers then I’m going to be upgrading all my networking infrastructure to F5 products and start reading up on BIG-IP migrations.

That is to say, sometimes nation state hackers _were_ behind the compromise. F5 is a very believable and logical target for such groups.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#67
post #63

[flagged]

Is there an example of a company getting money from the government in response to a statement like this?

I don't believe Equifax received money, just a long list of demands to be allowed to continue as a viable business.

That it was a nation-state actor may have allowed them some grace, as it didn't result in individuals' details being wholesale sold on the dark web, and the fallout was most-likely a national security issue.

It would definitely have helped the CCP target individuals who were vulnerable to recruitment due to their financial status. Especially when combined with the Office of Personnel Management data hack.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#68

“No one will ever find these vulns without source access! Fix deferred” oh wait…

Yeah, I was trying to make sense of what was described here. Is it that (through some mechanism) an actor gained access to F5's sytems, and literally found undisclosed vulnerabilities documented within F5's source control / documentation that affects F5's products? If so, lol.

A simple search across a codebase for "TODO" will find all sorts of things left undone, but having access to source control and commit messages, who knows what you might find.

"Here be dragons" is also a good search if you're responsible for security hardening legacy code.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#69
post #38

F5 claims that the threat actors' access to the BIG-IP environment did not compromise its software supply chain or result in any suspicious code modifications. Why would anyone have confidence in F5’s analysis?

I mean, because it depends where the attack happened. Working with large companies like this in CI/CD there are a number of tools that the source code gets checked on, but not fed back into the system that could have been the source of the attack.

Re: F5 says hackers stole undisclosed BIG-IP flaws, source code

#70

[flagged]

> Something about this statement screams that companies are setting themselves up for free money from big old gov'ment welfare titties.

From the published CISA mitigation[0]:

  A nation-state affiliated cyber threat actor has 
  compromised F5’s systems and exfiltrated files, which 
  included a portion of its BIG-IP source code and 
  vulnerability information. The threat actor’s access to 
  F5’s proprietary source code could provide that threat 
  actor with a technical advantage to exploit F5 devices and 
  software. 
> Its the boogyman [sic] like terrorism.

Or maybe it is a responsible vulnerability disclosure whose impact is described thusly[0]:

  This cyber threat actor presents an imminent threat to 
  federal networks using F5 devices and software. Successful 
  exploitation of the impacted F5 products could enable a 
  threat actor to access embedded credentials and Application 
  Programming Interface (API) keys, move laterally within an 
  organization’s network, exfiltrate data, and establish 
  persistent system access. This could potentially lead to a 
  full compromise of target information systems.
0 - https://www.cisa.gov/news-events/directives/ed-26-01-mitigat...
Post reply on HN