Hackers stole F5 BIG-IP source code and bug details, and CISA orders emergency patching

Reading Time: 5 min
18
techkahwa.net | 16 October 2025

F5, whose BIG-IP devices sit at the front door of many corporate and government networks, has disclosed that attackers broke into its systems and took parts of the BIG-IP source code along with information about vulnerabilities that had not yet been made public. The US cybersecurity agency CISA responded on 15 October with an emergency directive ordering federal agencies to find and patch their F5 equipment within a week.

What happened

According to F5’s disclosure, reported by The Hacker News, the company discovered the intrusion on 9 August 2025. It did not announce it until now because the US Department of Justice asked it to delay disclosure.

The attackers exfiltrated parts of the BIG-IP source code and information about undisclosed vulnerabilities, meaning flaws F5 knew about but had not yet published. That combination is what makes this breach unusual. F5 said it had “not observed any indication that the vulnerabilities have been exploited in a malicious context,” and added: “We have taken extensive actions to contain the threat actor.”

F5 brought in Google Mandiant and CrowdStrike to investigate, and it rotated credentials and certificates. The company has not publicly named the attacker. Some press reports have pointed to a particular country and group, but neither F5 nor CISA has confirmed that, so I am not repeating it here.

On 15 October, CISA issued Emergency Directive ED 26-01. According to The Hacker News, it requires US federal agencies to inventory their F5 devices and apply updates by 22 October 2025, then report back by 29 October.

Who is affected

BIG-IP is not consumer software. It is network equipment and software that large organisations place in front of their applications. It sits at the edge of banks, governments and large firms, often facing the internet directly.

If you work in IT at a company that runs F5 products, whether hardware appliances, virtual editions or related software, this is for you this week. If you are a regular user, you will not need to do anything on your own devices, but many services you rely on may run behind this kind of equipment.

By the numbers

Item Detail
Intrusion discovered by F5 9 August 2025
CISA Emergency Directive ED 26-01, issued 15 October 2025
Federal patch deadline 22 October 2025
Federal reporting deadline 29 October 2025
Outside firms engaged by F5 2: Google Mandiant and CrowdStrike
Malicious use of stolen bug data observed by F5 None so far, per F5

What to do now

CISA’s directive and F5’s guidance set out clear steps. They are written for US federal agencies, but I would treat them as the checklist for any organisation using F5:

  1. Inventory all F5 BIG-IP hardware, virtual editions and related software. You cannot patch what you do not know you have, and forgotten test or branch devices are a common blind spot.
  2. Apply the updates in F5’s October 2025 Quarterly Security Notification. Do it now rather than at the next maintenance window.
  3. Remove management interfaces from public internet exposure. The admin panel of a network device should be reachable only from a trusted internal network.
  4. Disconnect and decommission F5 devices that are past end of support. They will not receive the fixes, and they are the weakest link.
  5. Review logs and follow F5’s threat-hunting guide to look for signs of unusual activity on your devices.

Why it matters

Many breaches expose customer data. This one exposed knowledge. Source code and details of unpublished bugs can give an attacker a head start in finding ways into devices that protect some of the most sensitive networks in the world. What caught my attention is the gap between discovery in August and disclosure in October: it tells you the case was serious enough for the Justice Department to step in.

F5 says it has seen no sign that the stolen vulnerability information has been used against customers, and that is genuinely good news. In my view it should not slow anyone down. The safe assumption is that whoever took this data will study it, and the organisations that inventory, patch and lock down their management interfaces this week will be in a much stronger position than those who wait.

Sources

  • The Hacker News, report on the F5 breach exposing BIG-IP source code, October 2025, https://thehackernews.com/2025/10/f5-breach-exposes-big-ip-source-code.html
  • CISA, Emergency Directive ED 26-01 on mitigating vulnerabilities in F5 devices, 15 October 2025, https://www.cisa.gov/news-events/directives/ed-26-01-mitigate-vulnerabilities-f5-devices
  • CISA, alert directing federal agencies to mitigate vulnerabilities in F5 devices, 15 October 2025, https://www.cisa.gov/news-events/alerts/2025/10/15/cisa-directs-federal-agencies-mitigate-vulnerabilities-f5-devices
  • F5, security notification K000154696, October 2025, https://my.f5.com/manage/s/article/K000154696