bleepingcomputer · Crawled Jul 25, 2026

Over 266,000 F5 BIG-IP instances exposed to remote attacks

1 Actors 1 Malware
Read original article ↗

AI Summary

Over 266,000 F5 BIG-IP instances are exposed online following a breach of F5's network by suspected China-nexus threat actor UNC5291, which stole source code and information on undisclosed vulnerabilities. F5 has released patches for 44 vulnerabilities and urged immediate customer action, while CISA issued an emergency directive for federal agencies to patch or disconnect exposed systems. The attackers used the Go-based Brickstorm malware and had access to F5's network for at least a year. Threat actors are targeting these devices to breach networks, steal credentials, and establish persistence.

AI-extracted · verify before operational use

Extracted Entities 2 found