f5
China Steals Defense Secrets ‘on Industrial Scale’
Richi Jennings | | china, china espionage, China-linked Hackers, Chinese, Chinese Communists, chinese government, chinese hacker, Chinese hackers, Chinese Intelligence, Chinese state-sponsored hacking group, Chinese Threat Actors, ConnectWise, ConnectWise Vulnerabilities, CVE-2022-0185, CVE-2022-3052, CVE-2023-22518, CVE-2024-1709, Data Stolen By China, Dawn Calvary, f5, F5 BIG-IP, F5 BIG-IP vulnerability, Genesis Day, gov.uk, Mandiant, MSS, MSS Hackers, Peoples Republic of China, PRC, PRC Espionage, SB Blogwatch, ScreenConnect, Teng Snake, uk, UNC302, UNC5174, Uteus, Xiaoqiying
UNC5174 ❤ UNC302: CVSS 10 and 9.8 vulnerabilities exploited by Chinese threat actor for People’s Republic ...
Security Boulevard
BIG-IP Vulnerability Alert: Remote Code Execution Risk
Wajahat Raja | | BIG-IP, CISA Advisory, cve-2022-1388, Cybersecurity, Cybersecurity News, Cybersecurity Protocols, f5, mitigation, Remote Code Execution, security alert, vulnerability
In recent news, F5 has issued a critical security alert regarding a significant BIG-IP vulnerability that poses a severe risk to their BIG-IP systems. This vulnerability, rated at 9.8 out of 10 ...
F5 BIG-IP Remote Code Execution Vulnerability (CVE-2023-46747) Notification
Overview Recently, NSFOCUS CERT monitored that F5 had released a security announcement to fix a remote code execution vulnerability in BIG-IP (CVE-2023-46747). Due to the problem of F5 BIG-IP forwarding AJP protocol ...
F5 Adds More ML Algorithms to Better Secure APIs
F5 this week extended the ability of its cloud security platforms and services to secure application programming interfaces (APIs) by adding additional machine learning (ML) algorithms to make it easier to both ...
Security Boulevard
F5 Delivers on Cybersecurity Integration Promise
Michael Vizard | | APIs, Application Infrastructure Protection, Cloud Security, f5, security platform
F5 has extended the reach of its cloud security platform to include the infrastructure that applications are deployed on using technology it gained with the acquisition of ThreatStack in late 2021. Chris ...
Security Boulevard
CVE-2022-1388: Critical security vulnerabilities in F5 Big-IP allows attackers to execute arbitrary code
Ivanwallarm | | API exploit, API security, BIG-IP, cve-2022-1388, Different attack types, f5, Network Security, rce, Researcher Corner, Web Application Security
On May 5, 2022, MITRE published CVE-2022-1388, an authentication bypass vulnerability in the BIG-IP modules affecting the iControl REST component. The vulnerability was assigned a CVSSv3 score of 9.8 The vulnerability was ...
Honeypot Network Forensics
Erik Hjelmvik | | 185.160.24.70, 45.12.206.76, BIG-IP, BigIP, CapLoader, CVE-2020-5902, deserialization, f5, Honeypot, Java, NCC, NetworkMiner, pcap, SerializationDumper, tmui, User-Agent, utilCmdArgs, VPN, X-Forwarded-For
NCC Group recently released a 500 MB PCAP file containing three months of honeypot web traffic data related to the F5 remote code execution vulnerability CVE-2020-5902. In a blog post the NCC ...
Honeypot Network Forensics
Erik Hjelmvik | | 185.160.24.70, 45.12.206.76, BIG-IP, BigIP, CapLoader, CVE-2020-5902, deserialization, f5, Honeypot, Java, NCC, NetworkMiner, pcap, SerializationDumper, tmui, User-Agent, utilCmdArgs, VPN, X-Forwarded-For
NCC Group recently released a 500 MB PCAP file containing three months of honeypot web traffic data related to the F5 remote code execution vulnerability CVE-2020-5902. In a blog post the NCC ...
Together is faster: Zeek for vulnerabilities
gregorybellcorelight | | BIG-IP, CallStranger, Curveball, CVE-2020-0601, CVE-2020-12695, CVE-2020-1350, CVE-2020-13777, CVE-2020-5902, f5, GitHub, GnuTLS, John Lambert, Jupyter, MITRE ATT&CK, Open Source Community, pcap, Ripple20, Sigma, SIGRed, SOC, Zeek
“There is an open approach that is currently rippling across the infosec industry that could give defenders the acceleration they need.” – John Lambert (Distinguished Engineer, Microsoft) By Greg Bell, CEO of ...
Zeek in it’s sweet spot: Detecting F5’s Big-IP CVE10 (CVE-2020-5902)
Ben Reardon | | BIG-IP, cisa, Corelight Labs, CVE-2020-5902, CVE10, f5, GitHub, http, HTTPS, NCC Group, open source, rce, Remote Code Execution, Sigma, Suricata, Uncategorized, Zeek
By Ben Reardon, Corelight Security Researcher Having a CVE 10 unauthenticated Remote Code Execution vulnerability on a central load balancing device? That’s bad… Not being able to detect when a threat actor ...