×
Why the F5 Hack Created an ‘Imminent Threat’ for Thousands of Networks

Why the F5 Hack Created an ‘Imminent Threat’ for Thousands of Networks

Thousands of networks—many of them operated by the US government and Fortune 500 companies—face an “imminent threat” of being breached by a nation-state hacking group following the breach of a major maker of software, the federal government warned on Wednesday.

F5, a Seattle-based maker of networking software, disclosed the breach on Wednesday. F5 said a “sophisticated” threat group working for an undisclosed nation-state government had surreptitiously and persistently dwelled in its network over a “long term.” Security researchers who have responded to similar intrusions in the past took the language to mean the hackers were inside the F5 network for years.

Unprecedented

During that time, F5 said, the hackers took control of the network segment the company uses to create and distribute updates for BIG IP, a line of server appliances that F5 says is used by 48 of the world’s top 50 corporations. Wednesday’s disclosure went on to say the threat group downloaded proprietary BIG-IP source code information about vulnerabilities that had been privately discovered but not yet patched. The hackers also obtained configuration settings that some customers used inside their networks.

Control of the build system and access to the source code, customer configurations, and documentation of unpatched vulnerabilities has the potential to give the hackers unprecedented knowledge of weaknesses and the ability to exploit them in supply-chain attacks on thousands of networks, many of which are sensitive. The theft of customer configurations and other data further raises the risk that sensitive credentials can be abused, F5 and outside security experts said.

Customers position BIG-IP at the very edge of their networks for use as load balancers and firewalls, and for inspection and encryption of data passing into and out of networks. Given BIG-IP’s network position and its role in managing traffic for web servers, previous compromises have allowed adversaries to expand their access to other parts of an infected network.

F5 said that investigations by two outside intrusion-response firms have yet to find any evidence of supply-chain attacks. The company attached letters from firms IOActive and NCC Group attesting that analyses of source code and build pipeline uncovered no signs that a “threat actor modified or introduced any vulnerabilities into the in-scope items.” The firms also said they didn’t identify any evidence of critical vulnerabilities in the system. Investigators, which also included Mandiant and CrowdStrike, found no evidence that data from its CRM, financial, support case management, or health systems was accessed.

The company released updates for its BIG-IP, F5OS, BIG-IQ, and APM products. CVE designations and other details are here. Two days ago, F5 rotated BIG-IP signing certificates, though there was no immediate confirmation that the move is in response to the breach.

Source link
#Hack #Created #Imminent #Threat #Thousands #Networks

SAVE 26%: As of July 27, you can get the Ecovacs Goat A3000 LiDAR Pro robotic lawn mower for $1,849 at Amazon, down from $2,499.99. That’s a 26% discount or $650.99 in savings.


$1,849 at Amazon
$2,499.99 Save $650.99

 

Pushing a heavy lawn mower through thick grass in the peak of summer heat is nobody’s idea of a good weekend. If you’ve been waiting for a reason to hand off your yard chores to a robot, now’s the time to pull out your wallet.

Amazon’s running a limited-time deal (you have about 14 hours left) on the Ecovacs Goat A3000 LiDAR Pro robotic lawn mower. Right now, you can get it for $1,849 at Amazon, down from $2,499.99. That’s a 26% discount or $650.99 in savings.

Unlike older robotic mowers that require you to bury perimeter wires around your property, the Goat A3000 uses wire-free HoloScope 360 Dual-LiDAR navigation and an AI camera. It automatically maps yards up to 3/4 acre and maintains positioning accuracy within less than an inch, even under dense tree cover or along shaded fences.

It also features a built-in TruEdge trimmer to clean up borders along driveways and garden beds, a 32V power system designed for thick grass types like Bermuda or St. Augustine, and a 7,500 mAh battery that recharges in 70 minutes.

#Ecovacs #Goat #A3000 #robot #lawn #mower #deal">Ecovacs Goat A3000 robot lawn mower deal
                                                            SAVE 26%: As of July 27, you can get the Ecovacs Goat A3000 LiDAR Pro robotic lawn mower for ,849 at Amazon, down from ,499.99. That’s a 26% discount or 0.99 in savings.
    
    
                                                        
    
                                        
    
        
                                        
                                        
                    
                                                    ,849
                                                             at Amazon
                                                        ,499.99
                                                                                         Save 0.99
                                                                        
                
                                         
                    
        
    

Pushing a heavy lawn mower through thick grass in the peak of summer heat is nobody’s idea of a good weekend. If you’ve been waiting for a reason to hand off your yard chores to a robot, now’s the time to pull out your wallet. 
        SEE ALSO:
        
            If you’re heading off-grid this summer, grab DJI’s portable power station while it’s half price
            
        
    
Amazon’s running a limited-time deal (you have about 14 hours left) on the Ecovacs Goat A3000 LiDAR Pro robotic lawn mower. Right now, you can get it for ,849 at Amazon, down from ,499.99. That’s a 26% discount or 0.99 in savings.
        
            Mashable Trend Report
        
        
    
Unlike older robotic mowers that require you to bury perimeter wires around your property, the Goat A3000 uses wire-free HoloScope 360 Dual-LiDAR navigation and an AI camera. It automatically maps yards up to 3/4 acre and maintains positioning accuracy within less than an inch, even under dense tree cover or along shaded fences. 
It also features a built-in TruEdge trimmer to clean up borders along driveways and garden beds, a 32V power system designed for thick grass types like Bermuda or St. Augustine, and a 7,500 mAh battery that recharges in 70 minutes.

                    
                                    #Ecovacs #Goat #A3000 #robot #lawn #mower #deal

Ecovacs Goat A3000 LiDAR Pro robotic lawn mower for $1,849 at Amazon, down from $2,499.99. That’s a 26% discount or $650.99 in savings.


$1,849 at Amazon
$2,499.99 Save $650.99

 

Pushing a heavy lawn mower through thick grass in the peak of summer heat is nobody’s idea of a good weekend. If you’ve been waiting for a reason to hand off your yard chores to a robot, now’s the time to pull out your wallet.

Amazon’s running a limited-time deal (you have about 14 hours left) on the Ecovacs Goat A3000 LiDAR Pro robotic lawn mower. Right now, you can get it for $1,849 at Amazon, down from $2,499.99. That’s a 26% discount or $650.99 in savings.

Unlike older robotic mowers that require you to bury perimeter wires around your property, the Goat A3000 uses wire-free HoloScope 360 Dual-LiDAR navigation and an AI camera. It automatically maps yards up to 3/4 acre and maintains positioning accuracy within less than an inch, even under dense tree cover or along shaded fences.

It also features a built-in TruEdge trimmer to clean up borders along driveways and garden beds, a 32V power system designed for thick grass types like Bermuda or St. Augustine, and a 7,500 mAh battery that recharges in 70 minutes.

#Ecovacs #Goat #A3000 #robot #lawn #mower #deal">Ecovacs Goat A3000 robot lawn mower deal

SAVE 26%: As of July 27, you can get the Ecovacs Goat A3000 LiDAR Pro robotic lawn mower for $1,849 at Amazon, down from $2,499.99. That’s a 26% discount or $650.99 in savings.


$1,849 at Amazon
$2,499.99 Save $650.99

 

Pushing a heavy lawn mower through thick grass in the peak of summer heat is nobody’s idea of a good weekend. If you’ve been waiting for a reason to hand off your yard chores to a robot, now’s the time to pull out your wallet.

Amazon’s running a limited-time deal (you have about 14 hours left) on the Ecovacs Goat A3000 LiDAR Pro robotic lawn mower. Right now, you can get it for $1,849 at Amazon, down from $2,499.99. That’s a 26% discount or $650.99 in savings.

Unlike older robotic mowers that require you to bury perimeter wires around your property, the Goat A3000 uses wire-free HoloScope 360 Dual-LiDAR navigation and an AI camera. It automatically maps yards up to 3/4 acre and maintains positioning accuracy within less than an inch, even under dense tree cover or along shaded fences.

It also features a built-in TruEdge trimmer to clean up borders along driveways and garden beds, a 32V power system designed for thick grass types like Bermuda or St. Augustine, and a 7,500 mAh battery that recharges in 70 minutes.

#Ecovacs #Goat #A3000 #robot #lawn #mower #deal
Nvidia on Monday said it is joining forces with Microsoft, SpaceX, IBM, and other tech companies to build and share open-source AI security tools.

The new Open Secure AI Alliance said open tools are required to effectively defend against attacks from frontier models. The initiative is a direct response to mounting concerns over the safety of advanced AI systems after a rogue OpenAI model escaped containment and attacked another company during testing. That company, Hugging Face, said it was forced to use a Chinese open-weight model to defend itself due to the strict safety guardrails limiting the usefulness of top US models.

Founding members include Palantir, OpenClaw, the Linux Foundation, Cloudflare, Cloudera, Dell, Cisco, Adobe, Siemens, and DoorDash. Conspicuously absent are leading US AI companies, including OpenAI, Google, and Anthropic.

The alliance arrives amid growing tensions over whether the world’s most capable AI models should remain open. Chinese companies have released increasingly powerful open-weight models, notably Moonshot AI’s Kimi K3, challenging the strategy pursued by US labs that have largely kept frontier systems closed and proprietary. Nvidia and its partners argue that securing AI requires access to both closed and open models, stressing that defenders need the tools to counter emerging threats.

The announcement also follows reports that the Trump administration considered restricting access to cutting-edge Chinese models and an industry movement — again spearheaded by Nvidia — defending the need for openness in AI. Google and OpenAI signed that letter belatedly, too, though Anthropic remains absent.

#Nvidia #Microsoft #launch #open #security #alliance #OpenAI #Google #AnthropicAI,News,Nvidia,Tech">Nvidia, Microsoft launch open AI security alliance — without OpenAI, Google, or AnthropicNvidia on Monday said it is joining forces with Microsoft, SpaceX, IBM, and other tech companies to build and share open-source AI security tools.The new Open Secure AI Alliance said open tools are required to effectively defend against attacks from frontier models. The initiative is a direct response to mounting concerns over the safety of advanced AI systems after a rogue OpenAI model escaped containment and attacked another company during testing. That company, Hugging Face, said it was forced to use a Chinese open-weight model to defend itself due to the strict safety guardrails limiting the usefulness of top US models.Founding members include Palantir, OpenClaw, the Linux Foundation, Cloudflare, Cloudera, Dell, Cisco, Adobe, Siemens, and DoorDash. Conspicuously absent are leading US AI companies, including OpenAI, Google, and Anthropic.The alliance arrives amid growing tensions over whether the world’s most capable AI models should remain open. Chinese companies have released increasingly powerful open-weight models, notably Moonshot AI’s Kimi K3, challenging the strategy pursued by US labs that have largely kept frontier systems closed and proprietary. Nvidia and its partners argue that securing AI requires access to both closed and open models, stressing that defenders need the tools to counter emerging threats.The announcement also follows reports that the Trump administration considered restricting access to cutting-edge Chinese models and an industry movement — again spearheaded by Nvidia — defending the need for openness in AI. Google and OpenAI signed that letter belatedly, too, though Anthropic remains absent.#Nvidia #Microsoft #launch #open #security #alliance #OpenAI #Google #AnthropicAI,News,Nvidia,Tech

said it is joining forces with Microsoft, SpaceX, IBM, and other tech companies to build and share open-source AI security tools.

The new Open Secure AI Alliance said open tools are required to effectively defend against attacks from frontier models. The initiative is a direct response to mounting concerns over the safety of advanced AI systems after a rogue OpenAI model escaped containment and attacked another company during testing. That company, Hugging Face, said it was forced to use a Chinese open-weight model to defend itself due to the strict safety guardrails limiting the usefulness of top US models.

Founding members include Palantir, OpenClaw, the Linux Foundation, Cloudflare, Cloudera, Dell, Cisco, Adobe, Siemens, and DoorDash. Conspicuously absent are leading US AI companies, including OpenAI, Google, and Anthropic.

The alliance arrives amid growing tensions over whether the world’s most capable AI models should remain open. Chinese companies have released increasingly powerful open-weight models, notably Moonshot AI’s Kimi K3, challenging the strategy pursued by US labs that have largely kept frontier systems closed and proprietary. Nvidia and its partners argue that securing AI requires access to both closed and open models, stressing that defenders need the tools to counter emerging threats.

The announcement also follows reports that the Trump administration considered restricting access to cutting-edge Chinese models and an industry movement — again spearheaded by Nvidia — defending the need for openness in AI. Google and OpenAI signed that letter belatedly, too, though Anthropic remains absent.

#Nvidia #Microsoft #launch #open #security #alliance #OpenAI #Google #AnthropicAI,News,Nvidia,Tech">Nvidia, Microsoft launch open AI security alliance — without OpenAI, Google, or Anthropic

Nvidia on Monday said it is joining forces with Microsoft, SpaceX, IBM, and other tech companies to build and share open-source AI security tools.

The new Open Secure AI Alliance said open tools are required to effectively defend against attacks from frontier models. The initiative is a direct response to mounting concerns over the safety of advanced AI systems after a rogue OpenAI model escaped containment and attacked another company during testing. That company, Hugging Face, said it was forced to use a Chinese open-weight model to defend itself due to the strict safety guardrails limiting the usefulness of top US models.

Founding members include Palantir, OpenClaw, the Linux Foundation, Cloudflare, Cloudera, Dell, Cisco, Adobe, Siemens, and DoorDash. Conspicuously absent are leading US AI companies, including OpenAI, Google, and Anthropic.

The alliance arrives amid growing tensions over whether the world’s most capable AI models should remain open. Chinese companies have released increasingly powerful open-weight models, notably Moonshot AI’s Kimi K3, challenging the strategy pursued by US labs that have largely kept frontier systems closed and proprietary. Nvidia and its partners argue that securing AI requires access to both closed and open models, stressing that defenders need the tools to counter emerging threats.

The announcement also follows reports that the Trump administration considered restricting access to cutting-edge Chinese models and an industry movement — again spearheaded by Nvidia — defending the need for openness in AI. Google and OpenAI signed that letter belatedly, too, though Anthropic remains absent.

#Nvidia #Microsoft #launch #open #security #alliance #OpenAI #Google #AnthropicAI,News,Nvidia,Tech

Post Comment