Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
third-party-vendor-breachstate-sponsored-espionageperimeter-device-exposurewidely-deployed-product-advisory

F5 Breach Involving Nation-State Attackers and Customer Configuration Data Exposure

Updated 3mo agoFirst seen Oct 29, 20252 sources

F5 disclosed that a prolonged intrusion by a nation-state threat actor resulted in unauthorized access to its internal systems, prompting emergency updates to BIG-IP software and hardware across its customer base. The company reported that configuration data belonging to a small percentage of customers was stolen during the attack, but emphasized that most customers were not significantly impacted. F5 worked rapidly with affected organizations to deploy critical patches, and a major North American technology provider was able to update over 800 devices within hours of the disclosure. The breach led to a rare emergency directive from federal cyber authorities, underscoring the seriousness of the incident.

F5's leadership stated that the attack was first detected in August and publicly disclosed in October, with ongoing investigations to determine the full scope of data exposure. The company remains optimistic that the breach has been contained and that the majority of its largest customers have completed necessary mitigations with minimal disruption. The incident highlights the persistent risk posed by advanced threat actors targeting technology vendors and the importance of rapid response and transparent communication in managing supply chain security threats.

Share:
F5 Breach Involving Nation-State Attackers and Customer Configuration Data Exposure
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Oct 28, 20258mo ago

F5 says nation-state intrusion had limited business impact

During an earnings-related disclosure, F5 said the prolonged attack on its systems had limited impact. The company publicly addressed the incident as reporting on the breach widened.

Oct 27, 20258mo ago

Defenders observe active exploitation of CVE-2025-59287

Eye Security and Huntress reported that attackers were actively exploiting the newly patched WSUS vulnerability CVE-2025-59287. The activity elevated the issue from a patching concern to an in-the-wild threat.

Oct 14, 20258mo ago

Microsoft patches critical WSUS remote code execution flaw

Microsoft released a fix for CVE-2025-59287, a critical remote code execution vulnerability in Windows Server Update Services. The flaw later became notable because defenders observed active exploitation soon after patching.

Jan 1, 20233y ago

Nation-state actor breaches F5 systems and remains undetected for years

F5 disclosed that a nation-state threat actor compromised some of its systems and maintained access for a prolonged period, reportedly spanning years. Reporting linked the intrusion to China and characterized it as a long-dwell espionage-style breach.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

118 LINKEDOpen in app
Vulnerabilities
33 linked
Unauthenticated Arbitrary Plugin Installation and File Upload in GutenKit for WordPressCSRF in SimpleHelp customer installer hostname parameterRCE in MOTEX LANSCOPE Endpoint Manager On-Premises MR/DAUnauthenticated RCE in Windows Server Update Services (WSUS) via insecure deserializationUnbound cache poisoning via promiscuous NS RRSetsAuthentication Bypass in WorkExaminer Professional ConsoleHard-coded JWT Signing Key Authentication Bypass in Moxa Network Security Appliances and RoutersUnquoted Service Path in I-O DATA NAS Management ApplicationsWindows File Explorer NTLM Credential Leak via Remote LNK Target Icon ExtractionUnauthorized WebSocket Access in Claude Code IDE ExtensionsWindows File Explorer NTLM Hash Leakage / Spoofing BypassRemote Code Execution in Apache Syncope Groovy Custom ImplementationsGitLab CE/EE Event Collection Denial of ServiceCleartext Transmission of Sensitive Information in WorkExaminer ProfessionalPath Traversal Arbitrary File Write in Atlassian Jira Software Data Center and ServerBIND 9 DNSSEC malformed DNSKEY CPU exhaustion DoSUnauthenticated HTTP takeover in Oracle E-Business Suite Marketing AdministrationWindows NTLM Hash Disclosure Spoofing via .library-ms FilesUnauthenticated Plugin Installation and Activation in Hunk Companion WordPress PluginUntrusted installer resource execution in SimpleHelpPost-authenticated command injection in Zyxel ATP/USG FLEX/USG20(W)-VPN firmwareGitLab EE Runner API project runner hijackingMissing authorization in Zyxel ZLD 2FA flow allows configuration downloadOut-of-bounds write in Dolby UDC DD+ decoderUnauthenticated takeover in Oracle E-Business Suite Marketing AdministrationPrivilege escalation via broken access control in Moxa /api/v1/setting/data endpointDenial of Service in GitLab GraphQL JSON ValidationBIND 9 DNS Cache Poisoning via Predictable Source Port and Query IDAuthentication bypass in Better Auth API keys pluginWindows NTLM Elevation of Privilege VulnerabilityHardcoded FTP Credentials in WorkExaminer Professional ServerBIND 9 Recursive Resolver Cache Poisoning via Lenient Answer Record AcceptanceUnauthenticated Plugin Installation/Activation in Hunk Companion WordPress Plugin
Affected products
22 linked
FacebookTelegramWhatsappLanscope Endpoint ManagerInstagramIosFacebook MessengerDocusignBetter AuthVisual Studio CodeFirefoxWordpressLinkedinMicrosoft Entra IdUnboundGitlabBindGoogle DocsUnboundWindows Server Update Service (Wsus)Oracle E-Business SuiteIos
Organizations
36 linked
MozillaCheck Point Software TechnologiesArctic WolfCisco SystemsEye SecurityLinkedinTechCrunchTrenchantSEC ConsultPalo Alto NetworksL3Harris TechnologiesKasperskyRecorded FutureDatadogCofenseBaoying GroupDoctor WebAtlantic CouncilMeta PlatformsiVerifyNetskopeF5ApplePerplexityMicrosoft CorporationInfobloxHuntressBloombergWordfenceBforeAIEfficientLabGoogleGraphikaApkSumAndroidPAPKPure
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.