Dark Mode Light Mode

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use

F5 Networks Suffers Cyberattack: Source Code & Customer Data Stolen ๐Ÿšจ

Cybersecurity firm F5 Networks says government-backed hackers had โ€œlong-term, persistent accessโ€ to its network, which allowed them to steal the companyโ€™s source code and customer information.

In a filing with the U.S. Securities and Exchange Commission on Wednesday, F5 said it now โ€œbelieves its containment actions have been successful,โ€ after first discovering the hackers in its network on August 9.

The Seattle, Washington-based company, which specializes in providing application security and cybersecurity defenses for large companies and governments, said the hackers had access to its BIG-IP product development environment and its knowledge management systems, which included source code and publicly undisclosed security vulnerabilities.

F5 said it wasnโ€™t aware of any modifications to its software while in development, nor was it aware of any exploitation of the vulnerabilities. The company published several updates on Wednesday for its BIG-IP platform to fix the undisclosed security flaws and urged customers to patch them.

The company also said the hackers downloaded configurations and implementation information about some of its customersโ€™ systems, files that could help hackers find and exploit potential design weaknesses, and potentially hack into those customersโ€™ systems.

F5 said in the notice that the U.S. Department of Justice allowed the company to delay its public disclosure. An F5 spokesperson would not say for what reason the delay was allowed, but the DOJ can allow companies to hold off on notifying the public if there is a โ€œsubstantial risk to national security or public safety.โ€

F5 has over 1,000 corporate customers and serves more than 85% of the Fortune 500, the largest public companies by revenue, including banks, tech companies, and critical infrastructure companies.

The U.K.โ€™s National Cyber Security Centre warned on Wednesday, following F5โ€™s disclosure, that hackers could โ€œenable a threat actor to exploit F5 devices and software.โ€

CISA said in an email on Wednesday that it has ordered civilian federal agencies under an emergency directive to patch their systems by October 22, citing the security risks.

The company did not attribute the attacks to a particular government or nation-state-affiliated hacking group, and F5 spokesperson Dan Sorensen declined to answer TechCrunchโ€™s questions beyond the companyโ€™s published statement, including how many customers are affected and if it was known how the hackers broke in to begin with.ย 

F5 is the latest tech company in recent years to have been hacked by government hackers, including Microsoft โ€” by China, and Russia, at least twice; cloud and enterprise technology firm Hewlett Packard Enterprise, and several other companies as part of the broader Russian cyberattack on the software maker SolarWinds.

Source link

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use
Add a comment Add a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Post

๐Ÿš€ Google's Veo 3.1: Revolutionizing Video Editing with Move Editor!

Next Post

X to Reveal More User Details for Enhanced Trust ๐Ÿค