More

    ‘Significant’ threat to US networks after hackers stole F5 source code, CISA warns




    • CISA warns FCEB agencies to patch F5 products after a nation-state breach
    • Attackers stole BIG-IP source code and vulnerability data, risking zero-day discovery and exploitation
    • F5 released updates; no confirmed exploitation yet, but federal networks face imminent threat

    The US Cybersecurity and Infrastructure Security Agency (CISA) is urging Federal Civilian Executive Branch (FCEB) agencies to catalog and patch F5 products in their tech stack, after hackers broke into the company and stole source code along with other sensitive information.

    In the ED 26-01 emergency directive, CISA said that a “nation-state affiliated cyber threat actor” exfiltrated F5 files, including a portion of its BIG-IP source code, and vulnerability information. With this intelligence, the attackers can analyze F5’s products, potentially discover zero-day vulnerabilities, and develop exploits and malware.


    https://cdn.mos.cms.futurecdn.net/pQX7vZftvp4kjZhuJkt7yR-782-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img