Blogs.Microsoft
F5 BIG-IP Exploited in Multi-Stage Cyber Intrusion Attack
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A multi-stage cyber intrusion attack exploited an exposed F5 BIG-IP edge appliance, leading to identity-focused attacks that accessed Active Directory and involved credential theft from an internal Confluence server. Microsoft Defender Security Research reported that the attack utilized techniques such as Kerberos relay and lateral movement. The incident highlights a trend where traditional security devices are targeted as entry points for broader attacks. Organizations using F5 BIG-IP appliances are particularly affected, with potential risks to their internal networks. The attack underscores the importance of securing edge devices and monitoring for unusual activity. Current mitigation efforts are underway, with Microsoft Defender actively blocking and analyzing the attack vectors used.
Key Points: • The attack exploited an exposed F5 BIG-IP edge appliance as an entry point. • Credential theft occurred via an internal Confluence server after initial access. • Microsoft Defender detected and blocked the attack, revealing advanced techniques used.