Desk live·
ForensicPost
Nation-state/Vendors/File 25-1015

F5 Says Nation-State Actor Held Long-Term Access and Took BIG-IP Source Code

F5 disclosed in October 2025 that a nation-state actor had maintained long-term access to its corporate networks, stealing BIG-IP source code and information on undisclosed vulnerabilities.

Constructed geometry · not a chart of case data
TargetF5
ActorNation-state
D. Kennedy14 min readConfidence: high2 sources reviewed

On 15 October 2025 F5 disclosed that a nation-state threat actor had conducted a significant long-term compromise of its corporate networks. The actor stole source code from the BIG-IP product suite and information about vulnerabilities that had been discovered but not yet disclosed or patched.

BIG-IP appliances sit in front of a very large share of enterprise and government applications, terminating traffic and handling authentication. US authorities issued directives to federal agencies in response.

The Undisclosed Vulnerabilities Are The Whole Story

This desk was careful at Trellix in 26-0504 to say that source code is not a signing key, and that reading code does not let anyone push an update. That remains true here.

What is different is the second category. A vendor’s internal list of known-but-unpatched vulnerabilities is a set of working zero-days with the analysis already done. It removes the expensive part of vulnerability research and hands the actor a queue of flaws whose fixes are, by definition, not yet deployed anywhere.

This Is The Edge-Appliance Argument At Its Source

The multi-vendor perimeter campaign filed at 26-0311 described why this device class keeps failing: internet-facing by necessity, parsing hostile input before authentication, running firmware customers cannot inspect, excluded from endpoint monitoring.

An actor holding the vendor’s own vulnerability backlog for that class of device is positioned upstream of every one of those campaigns.

The Disclosure Itself Is The Useful Precedent

A security vendor stating publicly that a state actor was inside its network long-term, and that undisclosed vulnerability data was taken, is a disclosure with obvious commercial cost and no regulatory requirement to be that specific.

It is what let customers act. Compare the Trellix claim at 26-0504, which this desk graded low precisely because nothing was confirmed — the difference between the two files is entirely a difference in what the vendor was willing to say.

How we reported this

Compiled from the company’s disclosure, agency material and published analysis, listed below. The actor is described as nation-state in that reporting; we reproduce the assessment rather than naming a government. Corrections: corrections@forensicpost.com.

Sources
  1. Threat brief: nation-state threat actor steals F5 source code and undisclosed vulnerabilitiesUnit 42, Palo Alto Networks
  2. Nation-state hackers breached sensitive F5 systems, stole customer dataCybersecurity Dive
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary