Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

F5 Released Security Updates Covering Multiple Products Following Recent Hack

F5 Networks has issued critical security updates in response to a security breach involving a nation-state threat actor. The breach, detected in August 2025, resulted in unauthorized access to internal systems and the theft of BIG-IP source code and…

F5 Networks has issued critical security updates in response to a security breach involving a nation-state threat actor. The breach, detected in August 2025, resulted in unauthorized access to internal systems and the theft of BIG-IP source code and vulnerability data.

The breach was identified on August 9, 2025, when F5 detected suspicious activity within its BIG-IP product development environment. The threat actor maintained persistent access, exfiltrating sensitive files, including portions of source code and configuration details for a limited number of customers. No evidence suggests alterations to the software supply chain or impacts on production systems. However, the stolen intellectual property raises concerns about potential zero-day exploits targeting unpatched deployments.

F5 has implemented patches across BIG-IP, F5OS, BIG-IQ, APM clients, and BIG-IP Next for Kubernetes to protect customers. The company engaged cybersecurity firms CrowdStrike and Mandiant for investigation support and collaborated with law enforcement and government agencies. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued Emergency Directive ED 26-01, requiring federal agencies to patch and isolate affected F5 assets immediately.

On October 15, 2025, F5 released its Quarterly Security Notification, addressing 44 vulnerabilities, many linked to the breach. High-severity CVEs, with scores up to 8.7 under CVSS v3.1, affect components like SCP/SFTP in BIG-IP (CVE-2025-53868) and F5OS platforms (CVE-2025-61955). These flaws can lead to denial-of-service, privilege escalation, and remote code execution, especially in appliance modes.

CVE ID CVSS Score (v3.1 / v4.0) Affected Products Affected Versions Fixes Introduced In

CVE-2025-53868​ 8.7 / 8.5 BIG-IP (all modules) 17.5.0, 17.1.0-17.1.2, 16.1.0-16.1.6, 15.1.0-15.1.10 17.5.1, 17.1.3, 16.1.6.1, 15.1.10.8

F5 Networks has issued critical security updates in response to a security breach involving a nation-state threat actor.
Paige Monroe · Thehackingpost

CVE-2025-61955​ 7.8 (standard) / 8.8 (appliance) / 8.5 F5OS-A, F5OS-C F5OS-A: 1.8.0^3, 1.5.1-1.5.3; F5OS-C: 1.8.0-1.8.1, 1.6.0-1.6.2^3 F5OS-A: 1.8.3, 1.5.4; F5OS-C: 1.8.2, 1.6.4

CVE ID CVSS Score (v3.1 / v4.0) Affected Products Affected Versions Fixes Introduced In

CVE-2025-59481​ 6.5 (standard) / 8.7 (appliance) / 8.5 BIG-IP (all modules) 17.5.0-17.5.1, 17.1.0-17.1.2, 16.1.0-16.1.6, 15.1.0-15.1.10 17.5.1.3, 17.1.3, 16.1.6.1, 15.1.10.8

CVE ID CVSS Score (v3.1 / v4.0) Affected Products Affected Versions Fixes Introduced In

CVE-2025-58424 ​ 3.7 / 6.3 BIG-IP (all modules), F5 Silverline (all services) BIG-IP: 17.1.0-17.1.2, 16.1.0-16.1.5, 15.1.0-15.1.10; Silverline: N/A BIG-IP: 17.1.2.2^3, 16.1.6^3, 15.1.10.8^3; Silverline: N/A

Advertisement

Exposure ID Affected Products Affected Versions Fixes Introduced In

K000150010: BIG-IP AFM security exposure BIG-IP AFM 17.5.0-17.5.1, 17.1.0-17.1.2, 16.1.0-16.1.6, 15.1.0-15.1.10 17.5.1.1, 17.1.3

F5 emphasizes the necessity of applying these updates promptly to avoid potential lateral movement and data exfiltration in customer networks. Decommissioning end-of-life products further reduces exposure. Organizations are encouraged to enable event streaming to SIEM tools and isolate management interfaces from public access.

For comprehensive details, refer to F5’s official notification.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories