[HN Gopher] F5 says hackers stole undisclosed BIG-IP flaws, sour...
       ___________________________________________________________________
        
       F5 says hackers stole undisclosed BIG-IP flaws, source code
        
       https://www.sec.gov/ix?doc=/Archives/edgar/data/1048695/0001...
        
       Author : WalterSobchak
       Score  : 113 points
       Date   : 2025-10-15 13:33 UTC (9 hours ago)
        
 (HTM) web link (www.bleepingcomputer.com)
 (TXT) w3m dump (www.bleepingcomputer.com)
        
       | tru3_power wrote:
       | "No one will ever find these vulns without source access! Fix
       | deferred" oh wait...
        
         | bangaladore wrote:
         | Yeah, I was trying to make sense of what was described here.
         | 
         | Is it that (through some mechanism) an actor gained access to
         | F5's sytems, and literally found undisclosed vulnerabilities
         | documented within F5's source control / documentation that
         | affects F5's products?
         | 
         | If so, lol.
        
           | tru3_power wrote:
           | Yeah that's what I'm understanding is the case. That's why
           | they're harping on no known (unreleased) vulns. But it's
           | kinda funny, a lot of times bugs that fall under this
           | category are constantly shuffled around/not fixed because
           | there is no public pressure to address them.
        
       | sevg wrote:
       | I wonder if they're just saying "nation-state" to make it seem
       | less bad that they were compromised, without having proof that it
       | was an actual nation state. (I mean it could well be a nation
       | state, but just a thought.)
        
         | verdverm wrote:
         | This def seems like corpo disaster PR copy. Not the kind of
         | content I expected and love HN for
        
         | scotho3 wrote:
         | BIG-IP runs DPI (not as good as Sandvine Active Logic), but
         | it's an authoritarian states best friend. Want to compromise
         | another nation state that runs all their traffic through it?
         | These vulns aren't a bad place to start...
        
           | vel0city wrote:
           | This is why I don't understand this strong desire for
           | security auditors to have centralized TLS decryption be
           | important to having some high security stance. You're just
           | creating a _massive_ single point of failure and potentially
           | massively weakening encryption.
        
             | palmotea wrote:
             | It seems like its a place were there are some serious
             | tradeoffs. You can choose to have visibility into your
             | network traffic or can choose not to. If you choose yes,
             | you create a single point of failure but have the ability
             | to detect breaches elsewhere; if you choose no, you avoid
             | the single point of failure but make it easier for an
             | attacker to exfiltrate data undetected.
        
               | vel0city wrote:
               | I'm down for endpoints having to report whatever metrics
               | to whatever servers and have their transactions highly
               | audited. I'm down for their connectivity to be highly
               | locked down. It's important to know what's happening on
               | your systems and where data is flowing, I agree!
               | 
               | But in the end of I want Alice to talk to Bob and _know
               | they and only them are talking_ I 'd like to guarantee
               | that. Instead companies are spending tons of money and
               | work hours doing Eve's work for her, installing her tools
               | and getting it all nicely configured for when she logs
               | in.
               | 
               | How many times do we have to backdoor our crypto systems
               | to realize we're not building doors for just us but for
               | everyone else as well?
        
             | toast0 wrote:
             | > You're just creating a massive single point of failure
             | and potentially massively weakening encryption.
             | 
             | It need not be a single point of failure. You can set these
             | things up with redundancy. There's certainly an element of
             | adding risk, your interception box is a big target to do
             | unauthorized interception or tampering; but there's also an
             | element of reducing risk --- you'd be potentially able to
             | see and respond to traffic that would be opaque otherwise.
        
               | vel0city wrote:
               | > You can set these things up with redundancy
               | 
               | Yes, so instead of one box with the keys to decrypt all
               | the traffic flowing through the network I'll have
               | _multiple_ boxes that have the ability to decrypt all the
               | traffic. Multiple machines to update and secure and guard
               | against those getting attacked or else everything gets
               | broken.
        
           | mpyne wrote:
           | Perhaps more importantly to a non-U.S. nations is that there
           | are a lot of military networks that touch the public Internet
           | whose security from outside attack is more or less premised
           | on F5's implementation of mutual TLS to CACs.
           | 
           | Finding a way to subvert that authentication or, better yet,
           | bypass it entirely, could put U.S. military networks that can
           | be reached over the public Internet at risk of remote
           | exploitation. Those networks can often also reach other
           | military networks not directly exposed to the public
           | Internet.
        
             | wbl wrote:
             | The same F5 responsible for the existence of the padding
             | extension in TLS? And that still has predictable TCP
             | sequence numbers by default.
        
         | zamadatix wrote:
         | Even if it was actually an honest to god nation-state I can't
         | see why security circles get hyperfixated on the term. Does it
         | really matter at all if it's a nation, state, or nation-state?
         | Of course not, but "nation-state" sounds really cool so that's
         | the go to, even when it's not actually a nation-state.
        
           | kakacik wrote:
           | Lowers the percieved incompetence on hacked side, and its
           | hard to argue against (how do you prove it wasnt?). Stock
           | price fall distaster mitigation via simple PR.
           | 
           | But I agree experts should know better when of any solid
           | proof is lacking. Or any proof at all.
        
             | zamadatix wrote:
             | What I'm saying is they often actually mean "country", but
             | that is less fancy sounding. A nation-state is just one
             | specific type of polity, certainly not the only type which
             | organize attacks.
        
               | dandelany wrote:
               | You're overthinking it. "Country" is simply more
               | ambiguous when used as an adjective. "F5 announces attack
               | from country hackers" sounds silly and confusing.
        
           | ecshafer wrote:
           | Because "We got hacked by the concerted efforts of
           | China/Russia" sounds much better than "We literally never
           | update php or linux, and John Script Kiddy Jones pwnd us".
        
           | habinero wrote:
           | No, it's a real thing with a real meaning. Nation-state
           | actors are, in general, _very_ well-funded and sophisticated,
           | and therefore much more difficult (and expensive) to defend
           | against and clean up after. They tend to have different
           | motivations than the normal crime groups, and therefore go
           | after different things.
        
           | roywiggins wrote:
           | It's a bit like copspeak's fondness for mentioning
           | "individuals" (otherwise known as "people.") It's just a kind
           | of shibboleth. "State actors" is just as clear and means the
           | same thing.
        
           | bsder wrote:
           | Personally, I think its worse. The whole point of employing a
           | company like F5 is precisely to protect against those kind of
           | "nation-state" actors.
           | 
           | If F5 can't do that, what is their actual value proposition?
        
         | resfirestar wrote:
         | Often it can be like that. This a case where the kind of
         | attacker seems highly relevant, though. Imagine a group like
         | Shiny Hunters were the ones to steal these vulns from F5, you'd
         | know if they hit your F5s because they'd have already dumped
         | all your databases and bragged about it. The attacker being a
         | "nation-state" warrants a more careful investigation of
         | historical activity if you're the kind of organization that
         | gets targeted by espionage motivated attacks.
        
         | joshred wrote:
         | BRB, changing handle to 'nation-state'. Need the resume fodder.
        
         | habinero wrote:
         | Nation-state actors do this kind of stuff all the time, and
         | they're difficult to defend against because they tend to be
         | well-funded and therefore able to hire talent, have resources,
         | and spend money on intelligence and 0days. And they're immune
         | from prosecution unless they're stupid enough to travel to a
         | hostile state.
         | 
         | North Korea really does spend a lot of money on this, and so
         | does Russia and China. And US and Israel, for that matter.
        
       | ChrisArchitect wrote:
       | Source: https://my.f5.com/manage/s/article/K000154696
        
         | wobfan wrote:
         | > highly sophisticated nation-state threat actor
         | 
         | Sure thing. It's so hard not to hate this PR stuff when they
         | can't even be a tiny bit humble. "The hackers were so
         | sophisticated and organized, we didn't even have a change! They
         | could've hacked everyone!"
         | 
         | > In response to this incident, we are taking proactive
         | measures to protect our customers
         | 
         | Such as, fixing the bugs or the structural problems that led to
         | you being hacked and leaking information about even more bugs
         | that you left undisclosed and just postponed to fix it? This
         | wording sounds like they're now going the extra mile to protect
         | their customers and makes it sound like a good thing, when
         | keeping your systems secure and fixing known bugs should've
         | been the first meters they should've gone.
         | 
         | Just be honest, you fucked up twice. It's shit, but it happens.
         | I just hate PR.
        
           | reactordev wrote:
           | Especially considering who they are, Agreed. There's not an
           | ounce of empathy I have for them. They are a backbone of the
           | internet and should know better.
        
         | zingababba wrote:
         | The NCC attestation letter is wild:
         | 
         | F5, Inc. ("F5") engaged NCC Group to perform (i) a security
         | assessment of critical F5 software source code, including
         | critical software components of the BIG-IP product, as provided
         | by F5, and (ii) a review of portions of the software
         | development build pipeline related to the same, and designated
         | as critical by F5 (collectively, the "In-Scope Items"). NCC
         | Group's assessment included a source code security review by 76
         | consultants over a total of 551 person-days of effort.
         | 
         | Wonder what the bill was?
        
       | navidr1 wrote:
       | cisa just released: ED 26-01: Mitigate Vulnerabilities in F5
       | Devices.
       | 
       | https://www.cisa.gov/news-events/directives/ed-26-01-mitigat...
        
         | fn-mote wrote:
         | This report seems empty of useful information. It's just
         | "contact us under these circumstances".
         | 
         | Is it just me?
        
           | shakna wrote:
           | It reads more like, "find, update, and prepare to
           | decommission all of these products" to me.
        
       | ZeroConcerns wrote:
       | I'm not sure if item #2 in the linked advisory ("identify if the
       | networked management interface is accessible directly from the
       | public internet") indicates whether compromise is only likely in
       | that situation or not, but... lots of remote workers are going to
       | have some time for offline reflection in the next week, it seems
       | regardless.
        
       | bananapub wrote:
       | oh that's handy, they can add them to the big pile of disclosed
       | BIG-IP flaws
        
       | fn-mote wrote:
       | I am having a hard time believing that an attacker maintained
       | long term access to their system and never used it.
       | 
       | It seems more likely that we do not KNOW how the access was used.
        
         | bangaladore wrote:
         | They say the attacker exfiltrated data, including source code.
         | 
         | They claim the vulnerabilities discovered through the
         | exfiltration were not used though.
        
           | bangaladore wrote:
           | Not sure why I'm downvoted. Literally quoted from their
           | incident page.
           | 
           | > We have confirmed that the threat actor exfiltrated files
           | from our BIG-IP product development environment and
           | engineering knowledge management platforms. These files
           | contained some of our BIG-IP source code and information
           | about undisclosed vulnerabilities we were working on in BIG-
           | IP.
           | 
           | > We have no knowledge of undisclosed critical or remote code
           | vulnerabilities, and we are not aware of active exploitation
           | of any undisclosed F5 vulnerabilities.
           | 
           | https://my.f5.com/manage/s/article/K000154696
        
             | Veserv wrote:
             | No, they claimed: "We have no _knowledge_ " and "we are not
             | _aware_ " which does not mean "the vulnerabilities
             | discovered through exfiltration were _not used_ ".
             | 
             | That admits nearly every possible class of outcome as long
             | they did not actively already know about it and chose to
             | say they did not. The specific words that their lawyers
             | intentionally drafted explicitly even allow them to
             | intentionally spend effort to destroy any evidence that
             | would lead them to learn if the vulnerabilities were used
             | and still successfully claim that they were telling the
             | truth in a court of law. You should not assume their highly
             | paid lawyers meant anything other than the most tortured
             | possible technically correct statement.
             | 
             | PR statements drafted by legal are a monkey's paw. Treat
             | them like it.
        
               | bangaladore wrote:
               | Fair point, I certainly missed a word in my summary.
        
             | stronglikedan wrote:
             | > Not sure why I'm downvoted.
             | 
             | I downvoted you for complaining about downvotes, so at
             | least you know the reason for one of them now.
        
       | citizenpaul wrote:
       | >F5 disclosed that nation-state hackers
       | 
       | Something about this statement screams that companies are setting
       | themselves up for free money from big old gov'ment welfare
       | titties. I keep seeing it pop up again and again and it only
       | makes sense in that context.
       | 
       | Its the boogyman like terrorism. We need infinite money to fight
       | the bad guys.
        
         | catigula wrote:
         | There's huge incentive for nation-state level actors to
         | recruit, train and spend oodles on extremely sophisticated
         | hacking programs with little legal oversight and basically
         | endless resources. I have no idea why you're incredulous about
         | this.
         | 
         | If I were running a country practically my highest priority
         | would be cyberattacks and defense. The ability to arbitrarily
         | penetrate even any corporate network, let alone military
         | network, is basically infinite free IP.
        
           | tiahura wrote:
           | You can get a lot of fat kids on a computer in a bedroom for
           | the cost of building and maintaining a 6th Gen fighter.
        
           | citizenpaul wrote:
           | > I have no idea why you're incredulous about this.
           | 
           | I understand human nature.
        
         | sickofparadox wrote:
         | Nation-states sponsored hackers make up a huge amount of known
         | targeted intrusion groups. This is not some random company
         | tilting at windmills, these are real threats that hit American
         | and American-aligned companies daily.
        
         | marcusb wrote:
         | > I keep seeing it pop up again and again and it only makes
         | sense in that context.
         | 
         | Not saying that these companies would turn down corporate
         | welfare given the chance, but I'll offer an alternative
         | explanation: it shifts accountability away from the company by
         | positing a highly resourced attacker the company could not
         | reasonably be expected to protect against.
         | 
         | If you have a physical security program that you've spent
         | millions of dollars on, and a random drug addict breaks in and
         | steals your deepest corporate secrets people are going to ask
         | questions.
         | 
         | If a foreign spy does the same, you have a bit more room to
         | claim there's nothing you could have done to prevent the theft.
         | 
         | I've seen a bunch of incident response reports over the years.
         | It is _extremely common_ for IR vendors to claim that an attack
         | has some hallmark or another of a nation-state actor. While
         | these reports get used to fund the security program, I always
         | read those statements as a "get out of jail free" card for the
         | CISOs who got popped.
        
           | citizenpaul wrote:
           | >it shifts accountability away
           | 
           | I agree. I think what we are split on is purpose/intent.
           | 
           | >could not reasonably be expected to protect against.
           | 
           | Why not? If I'm hiring a cybersec thats probably in my top 3
           | reasons to hire them, if not them then who? Number one is
           | probably compliance/regulation.
           | 
           | > "get out of jail free"
           | 
           | This is one of my red flags I also keep seeing. Whoops we
           | can't do the thing we say we do. The entire sec industry
           | seems shady AF. Which is why I think they are a huge future
           | rent seek lobby. Once the insurance industry catches on.
           | 
           | > these reports get used to fund the security program
           | 
           | So we agree?
        
             | marcusb wrote:
             | > I agree. I think what we are split on is purpose/intent.
             | 
             | I... don't think so? Your original comment was that
             | companies claim nation state attack was a way to get
             | government funding. That has nothing to do with assessing
             | blame for an attack.
             | 
             | > Why not? If I'm hiring a cybersec thats probably in my
             | top 3 reasons to hire them, if not them then who?
             | 
             | If you think you as a private entity can defend against a
             | tier 1 nation state group like the NSA or Unit 8200, you
             | are gravely mistaken. For one thing, these groups have zero
             | day procurement budgets bigger than most company market
             | caps.
             | 
             | That's why companies reflexively blame nation state actors.
             | It isn't to get government funding. It is to avoid blame
             | for an attack by framing it as something they could not
             | have prevented.
             | 
             | > So we agree?
             | 
             | No, I don't believe we do.
        
         | wyldberry wrote:
         | This is a mean-spirited interpretation of what happens when you
         | claim nation state.
         | 
         | Generally the government (as of now) is not paying private (but
         | maybe some Critical Infrastructure companies) companies to
         | secure things. We are in the very early stages of figuring out
         | how to hold companies accountable for security breaches, and
         | part of that is figuring out if they _should_ have stopped it.
         | 
         | A lot of that comes down to a few principles:
         | 
         | * How resourced is the defender versus the attacker? * Who was
         | the attacker (attribution matters - (shoutout @ImposeCost on
         | Twitter/X) * Was the victim of the attack performing all
         | reasonable steps to show the cause wasn't some form of gross
         | negligence.
         | 
         | Nation state attacker jobs aren't particularly different from
         | many software shops.
         | 
         | * You have teams of engineers/analysts whose job it is to
         | analyze nearly every piece of software under the sun and find
         | vulnerabilities.
         | 
         | * You have teams whose job it is to build the infrastructure
         | and tooling necessary to run operations
         | 
         | * You have teams whose job it is to turn vulnerabilities into
         | exploits and payloads to be deployed along that infrastructure
         | 
         | * You have teams of people whose job it is to be hands on
         | keyboard running the operation(s)
         | 
         | Depending on the victim organization, if a top-tier country
         | wants what you have, they are going to get it and you'll
         | probably never know.
         | 
         | F5 is, at least by q2 revenue[0], we very profitable, well
         | resourced company that has seen some things and been victims of
         | some high profile attacks and vulns over the years. It's
         | _likely_ that they were still outmatched because there 's been
         | a team of people who found a weakness and exploited it.
         | 
         | When they use verbage like nation-state, it's to give a signal
         | that they were doing most/all the right things and they got
         | popped. The relevant government officials already know what
         | happened, this is a signal to the market that they did what
         | they were supposed to and aren't negligent.
         | 
         | [0] -https://www.f5.com/company/news/press-
         | releases/earnings-q2-f...
        
       | ktallett wrote:
       | I'm slightly questioning the security of a cybersecurity company
       | that has systems that allow people long term access.
        
       | wallaBBB wrote:
       | > undisclosed F5 vulnerabilities
       | 
       | I don't know why, but this sounds a bit like backdoors.
        
       | tiahura wrote:
       | _F5 claims that the threat actors ' access to the BIG-IP
       | environment did not compromise its software supply chain or
       | result in any suspicious code modifications._
       | 
       | Why would anyone have confidence in F5's analysis?
        
       | weeha wrote:
       | Looks like they rotated all signings keys a day earlier:
       | 
       | https://my.f5.com/manage/s/article/K000157005
       | 
       | In October 2025, F5 rotated its signing certificates and keys
       | used to cryptographically sign F5-produced digital objects.
       | 
       | As a result:                   BIG-IP and BIG-IQ TMOS product
       | versions released in October 2025 and later are signed with new
       | certificates and keys         BIG-IP and BIG-IQ TMOS product
       | versions released in October 2025 and later contain new public
       | keys used to verify certain F5-produced objects released in
       | October 2025 and later         BIG-IP and BIG-IQ TMOS product
       | versions released in October 2025 and later may not be able to
       | verify certain F5-produced objects released prior to October 2025
       | BIG-IP and BIG-IQ TMOS product versions released prior to October
       | 2025 may not be able to verify certain F5-produced objects
       | released in October 2025 and later
        
         | brunoTbear wrote:
         | I wonder if there's a bet to be made on future 8K disclosures
         | following quietly updated signing keys. A bet against F5 placed
         | this morning would've only made 3.6%.
        
       | Fokamul wrote:
       | Aka outsourcing work to third world countries has come back to
       | bite us ;-)
        
       | elzbardico wrote:
       | "We have no knowledge the vulnerabilities discovered through
       | exfiltration were not used"
       | 
       | Translated =>
       | 
       | We don't know whether they have used or are going to use our NSA-
       | mandated backdoors.
        
       ___________________________________________________________________
       (page generated 2025-10-15 23:00 UTC)