F5, whose BIG-IP products are widely used for network traffic management and security, disclosed that a highly sophisticated nation-state threat actor had maintained long-term access to parts of its systems, including its BIG-IP product development environment, and stolen source code and details of undisclosed vulnerabilities.
What happened
- F5 said it detected the intrusion on 9 August 2025 and that the US Department of Justice had allowed it to delay public disclosure on national security grounds.
- The same day, CISA issued Emergency Directive 26-01 ordering US federal agencies to inventory F5 devices and apply updates by 22 October.
- The UK NCSC also confirmed the compromise and issued an advisory for F5 customers.
- F5 released security updates for BIG-IP, F5OS, BIG-IQ, and related products alongside its disclosure, and said it had no evidence its software supply chain had been modified.
Why it mattered
Theft of source code and vulnerability details from a security vendor gives attackers a head start on finding and exploiting flaws in devices at the edge of many networks. Because F5 products are used by many governments and large companies, the potential impact was very wide.
Lessons for organisations
Keep a complete inventory of network appliances, remove management interfaces from the internet, and apply vendor updates quickly. Retire end-of-support devices that no longer receive fixes.
Sources: CISA, CyberScoop
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.