Site navigation

Major Firms Face ‘Imminent Threat’ After F5 Hack

Tom Quinn

,

F5 hack
The breach, described as “long-term and persistent,” has prompted urgent warnings from US cyber agency, CISA.

Cyber giant F5 has disclosed a major security breach, with nation-state hackers stealing the firm’s BIG-IP source code along with information about undisclosed vulnerabilities for its widely used products.

Issuing a statement, the company said that it first learned about the breach in August, writing that the unnamed nation-state threat actor had gained ‘long-term, persistent access’ to F5’s network and had downloaded files.

“We have confirmed that the threat actor exfiltrated files from our BIG-IP product development environment and engineering knowledge management platforms,” the firm said.

“These files contained some of our BIG-IP source code and information about undisclosed vulnerabilities we were working on in BIG-IP. 

“We have no knowledge of undisclosed critical or remote code vulnerabilities, and we are not aware of active exploitation of any undisclosed F5 vulnerabilities.”

F5 claims its tech provides the backbone of 85% of Fortune 500 networks, not to mention critical infrastructure networks and government systems (including the Scottish Government), meaning the hack has raised serious concerns over supply chain security.

Issuing an emergency directive, US cybersecurity agency CISA warned that the hacker’s access to F5’s proprietary source code could provide them with a technical advantage to exploit F5 devices and software, allowing them to find zero-day vulnerabilities and develop targeted exploits.

“This cyber threat actor presents an imminent threat to federal networks using F5 devices and software,” said CISA.

“Successful exploitation of the impacted F5 products could enable a threat actor to access embedded credentials and Application Programming Interface (API) keys, move laterally within an organization’s network, exfiltrate data, and establish persistent system access. 

“This could potentially lead to a full compromise of target information systems.”

Likewise, the UK’s National Cyber Security Centre issued its own caution, though reiterated F5’s claim that, so far, there has been no indication that any customer networks were impacted via the compromise and no suggestion that NGINX, an open-source web server owned by F5, has been affected.

Despite that, however, questions remain. Those include basic issues, including when the hack first occurred, and exactly what customer data has been lost.


Recommended reading


However, F5’s actions after the fact have also raised some industry eyebrows. In a statement shared with The Stack, Ryan Dewhurst, head of threat intelligence at watchTowr, said that the firm’s rotation of signing certificates and cryptographic keys was “not a routine update”.

“Older software signed with the previous keys may now warrant closer scrutiny. For a vendor whose products sit deep in enterprise and government networks, this is a serious breach of trust,” said Dewhurst. 

“If those compromised keys were stolen, and F5 hasn’t ruled that out, malicious software updates signed by ‘F5’ could be indistinguishable from the real thing.”

Another issue is who these unnamed threat actors are. Already, fingers are pointing to China, with Bloomberg reporting that sources familiar with the matter are blaming Chinese state-backed hacking groups, which have in the past been known for targeting major software companies to find undisclosed vulnerabilities.

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data