F5 has issued security updates after a breach where state hackers stole source code and undisclosed BIG-IP vulnerabilities. Although no active exploitation has been confirmed, federal agencies are mandated to apply patches by October 22, 2025. #F5 #BIGIPVulnerabilities
Keypoints
- F5 released patches for 44 vulnerabilities following a breach involving stolen source code.
- Threat actors targeted BIG-IP systems, exploiting vulnerabilities that could lead to credential and data theft.
- Federal agencies are instructed to urgently install updates and disconnect unsupported devices by October 31, 2025.
- F5 emphasizes there is no evidence of current exploitation or disclosure of critical vulnerabilities.
- Security best practices include enabling event streaming, configuring SIEM, and monitoring admin activity.