Two incidents at security vendors within two months, both attributed to state-sponsored actors: SonicWall’s configuration backup service at 25-0917, and F5’s source code and undisclosed vulnerability data at 25-1015.
Neither actor was after the vendor. Both were after what the vendor holds about everybody else.
The Material Taken Was Different, The Objective Was Identical
From SonicWall: the network topology and credentials of an entire customer base. From F5: the vulnerability backlog for appliances sitting in front of a large share of enterprise and government applications.
In both cases the value is access to third parties. The vendor is an intermediate objective, and the customer base is the target set.
Why This Is A Rational Allocation Of A State Capability
Compromising a thousand organisations individually is expensive, slow and generates a thousand opportunities for detection. Compromising the vendor that sits in front of them produces the same reach with one operation.
It is the concentration argument this database makes constantly about suppliers, applied by an adversary with the patience for long-term access rather than by one looking for a quick extortion payment.
The Customer Has Almost No Visibility
An organisation running one of these appliances cannot inspect the firmware, cannot audit the vendor’s internal network, and cannot know whether its configuration backup has been read.
It learns when the vendor discloses. Which is why the disclosure quality difference this desk noted at 25-1015 — a specific statement about what was taken versus a claim nobody confirms — is not a public-relations question. For the customer it is the entire basis on which they can act.
This is an analysis file built on the two incidents cited and the sources listed below. Attribution in both cases is as characterised by the companies and by agency reporting; no government is named by this desk. Corrections: corrections@forensicpost.com.