F5 BIG-IP Exploited in Multi-Stage Cyber Intrusion Attack

F5 BIG-IP Exploited in Multi-Stage Cyber Intrusion Attack

First seen 23 May 2026, 09:56 UTC Blogs.MicrosoftCybersecuritynewsGbhackers 76% similarity 67.5

Article Content

Browse articles
ThreatCluster

A multi-stage cyber intrusion attack exploited an exposed F5 BIG-IP edge appliance, leading to identity-focused attacks that accessed Active Directory and involved credential theft from an internal Confluence server. Microsoft Defender Security Research reported that the attack utilized techniques such as Kerberos relay and lateral movement. The incident highlights a trend where traditional security devices are targeted as entry points for broader attacks. Organizations using F5 BIG-IP appliances are particularly affected, with potential risks to their internal networks. The attack underscores the importance of securing edge devices and monitoring for unusual activity. Current mitigation efforts are underway, with Microsoft Defender actively blocking and analyzing the attack vectors used.

Key Points: • The attack exploited an exposed F5 BIG-IP edge appliance as an entry point. • Credential theft occurred via an internal Confluence server after initial access. • Microsoft Defender detected and blocked the attack, revealing advanced techniques used.

ThreatCluster AI

Timeline

2026-05-22
Multi-stage attack initiated
Threat actors exploited an exposed F5 BIG-IP edge appliance, beginning a series of attacks targeting identity and credentials.
Blogs.Microsoft
2026-05-23
Microsoft reports on the attack
Microsoft Defender Security Research detailed the attack's methods and impact, emphasizing the growing trend of targeting security devices.
Cybersecuritynews

Community

Browse all →

Tracked Entities in This Story