Cyber Security News

F5 Breached – Hackers Stole BIG-IP Source Code and Undisclosed Vulnerabilities Data

F5, a leading provider of application security and delivery solutions, disclosed a major security incident. The company revealed that a sophisticated nation-state threat actor had gained long-term access to internal systems, exfiltrating sensitive files including BIG-IP source code and details on undisclosed vulnerabilities.

While F5 emphasized that no critical exploits or active attacks on customers have been detected, the breach underscores the vulnerabilities in even the most secure development environments.

The intrusion, discovered in August 2025, involved persistent access to F5’s BIG-IP product development environment and engineering knowledge management platforms.

According to the company’s official statement, the actor downloaded files containing proprietary source code for its flagship BIG-IP software, which powers load balancing and security for millions of enterprise applications worldwide.

Additionally, the stolen data included information on vulnerabilities that F5 was actively researching and patching. However, the firm stressed that these were not critical remote code execution flaws and showed no signs of exploitation in the wild.

Breach Details

F5’s investigation, aided by cybersecurity CrowdStrike and Mandiant, found no evidence of tampering with the software supply chain, including build pipelines or released code.

Independent audits by NCC Group and IOActive corroborated this, ruling out modifications that could have introduced backdoors into customer deployments. The breach also spared key areas like NGINX source code, F5 Distributed Cloud Services, and Silverline DDoS protection systems.

However, some fallout reached customers. A small subset of exfiltrated files from the knowledge platform held configuration details for certain BIG-IP implementations.

F5 plans to notify affected users directly after reviewing the data. Crucially, no customer records from CRM, financial systems, support portals, or the iHealth monitoring tool were compromised, limiting broader privacy risks.

F5 acted swiftly to contain the threat, rotating credentials, bolstering access controls, and deploying advanced monitoring tools. No further unauthorized activity has occurred since containment.

To safeguard users, the company rolled out urgent patches for BIG-IP, F5OS, BIG-IP Next for Kubernetes, BIG-IQ, and APM clients in its October 2025 Quarterly Security Notification. Customers are urged to apply these updates immediately, even in the absence of known exploits.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

5 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago