/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers observe hackers remotely exploiting a critical bug in BIG-IP products from F5 that act as load balancers within enterprise networks; patch available

F5 released a patch … Lindsey O'Donnell / Threatpost : Admins Urged to Patch Critical F5 Flaw Under Active Attack Robert Lemos / Dark Reading : Attackers Scan for Vulnerable BIG-IP Devices After Flaw Disclosure NCC Group Research : RIFT: F5 Networks K52145254: TMUI RCE vulnerability CVE-2020-5902 Intelligence Tweets: Catalin Cimpanu / @campuscodi : Initial attacks attempted to extract admin passwords and device settings. See here: https://www.zdnet.com/... Since Saturday, we've also seen some gangs try to infect systems with cryptomining malware, but also a few attackers trying to install webshells for future access https://twitter.com/... @wired : Any company that uses BIG-IP products sold by F5 Networks had a rude interruption to their weekend, as a critical vulnerability turned July 4 into a race to implement a fix. Those who haven't done so yet may now have a much larger problem on their hands. https://www.wired.com/... Andy Greenberg / @a_greenberg : Big thank you to all the networking folks who spent their July 4 weekend patching this very bad bug—and my sympathy to those who didn't. https://www.wired.com/...

Wired Andy Greenberg

Context & Ripple Effects

This is the disclosure-to-exploitation cycle at its fastest: researchers watch attacks against F5's BIG-IP load balancers begin almost immediately after the CVE-2020-5902 details land, with a patch available and defenders racing scanners to internet-facing devices. The early attack payloads — admin credential theft, device-settings extraction, then cryptominers and webshells — show adversaries treating the flaw less as an end goal than a foothold into enterprise interiors.

The arc around this event runs both directions. Two months later, CISA attributed exploitation of F5, Citrix, Pulse Secure, and Exchange bugs to hacking groups tied to China's Ministry of State Security (CISA linked state-backed groups exploiting the same F5 bugs), confirming the target profile. And the pattern repeats: F5 patched another actively exploited BIG-IP critical in 2022 (another actively exploited BIG-IP flaw two years later), while Fortinet's experience shows how badly remediation lags even after patches ship (most Fortinet SSL VPN interfaces stayed unpatched weeks after a fix).

First-order effects

  • Admins running internet-facing BIG-IP devices face immediate exposure: attackers are remotely executing code via the TMUI interface, harvesting admin passwords and device settings that unlock broader network access, so patching becomes an emergency rather than routine maintenance.

Second-order effects

  • Because BIG-IP sits at the traffic-control layer of enterprise networks, stolen admin credentials and webshells on these devices give attackers durable pivots into internal systems — turning one vendor's RCE into multi-vendor breach risk across every customer behind the box.

Third-order effects

  • Edge appliances — load balancers, VPN gateways, firewalls — keep proving to be the softest perimeter entry point (the same dynamic later hit VMware under a CISA patch-or-remove order and Fortinet repeatedly), pointing toward regulator-mandated patching SLAs and procurement standards for network infrastructure vendors.

The trend: Enterprise network-edge appliances are displacing endpoints as the primary initial-access target, with disclosure-to-exploitation windows compressing faster than fleet-wide patching can respond.

Discussion

  • @campuscodi Catalin Cimpanu on x
    Initial attacks attempted to extract admin passwords and device settings. See here: https://www.zdnet.com/... Since Saturday, we've also seen some gangs try to infect systems with cryptomining malware, but also a few attackers trying to install webshells for future access https:/…
  • @wired @wired on x
    Any company that uses BIG-IP products sold by F5 Networks had a rude interruption to their weekend, as a critical vulnerability turned July 4 into a race to implement a fix. Those who haven't done so yet may now have a much larger problem on their hands. https://www.wired.com/...
  • @a_greenberg Andy Greenberg on x
    Big thank you to all the networking folks who spent their July 4 weekend patching this very bad bug—and my sympathy to those who didn't. https://www.wired.com/...