On 15 October 2025 F5 disclosed that a nation-state threat actor had conducted a significant long-term compromise of its corporate networks. The actor stole source code from the BIG-IP product suite and information about vulnerabilities that had been discovered but not yet disclosed or patched.
BIG-IP appliances sit in front of a very large share of enterprise and government applications, terminating traffic and handling authentication. US authorities issued directives to federal agencies in response.
The Undisclosed Vulnerabilities Are The Whole Story
This desk was careful at Trellix in 26-0504 to say that source code is not a signing key, and that reading code does not let anyone push an update. That remains true here.
What is different is the second category. A vendor’s internal list of known-but-unpatched vulnerabilities is a set of working zero-days with the analysis already done. It removes the expensive part of vulnerability research and hands the actor a queue of flaws whose fixes are, by definition, not yet deployed anywhere.
This Is The Edge-Appliance Argument At Its Source
The multi-vendor perimeter campaign filed at 26-0311 described why this device class keeps failing: internet-facing by necessity, parsing hostile input before authentication, running firmware customers cannot inspect, excluded from endpoint monitoring.
An actor holding the vendor’s own vulnerability backlog for that class of device is positioned upstream of every one of those campaigns.
The Disclosure Itself Is The Useful Precedent
A security vendor stating publicly that a state actor was inside its network long-term, and that undisclosed vulnerability data was taken, is a disclosure with obvious commercial cost and no regulatory requirement to be that specific.
It is what let customers act. Compare the Trellix claim at 26-0504, which this desk graded low precisely because nothing was confirmed — the difference between the two files is entirely a difference in what the vendor was willing to say.
Compiled from the company’s disclosure, agency material and published analysis, listed below. The actor is described as nation-state in that reporting; we reproduce the assessment rather than naming a government. Corrections: corrections@forensicpost.com.
- Threat brief: nation-state threat actor steals F5 source code and undisclosed vulnerabilitiesUnit 42, Palo Alto Networks
- Nation-state hackers breached sensitive F5 systems, stole customer dataCybersecurity Dive