Sign in

F5 Labs

@f5labs.bsky.social
47 followers 14 following 154 posts

Data driven cyber security threat research from the appsec experts at @f5inc.bsky.social f5.com/labs

PostsRepliesMedia
F5 Labs @f5labs.bsky.social · 29/12/2025
The “HashJack” attack poses a significant threat as it manipulates AI browser assistants via URL fragments. As URL fragments are processed solely on the client-side & not sent to servers, traditional security measures are ineffective. Discover how to protect your system. go.f5.net/0xso68yh
000
F5 Labs @f5labs.bsky.social · 26/12/2025
A key insight from last month’s data is that the RondoDox actor isn’t just targeting Shellshock; they’ve also shifted their attention toward high-value web applications. Find out what the pivot signals & more about the CVE here: go.f5.net/29iyco86
000
F5 Labs @f5labs.bsky.social · 22/12/2025
Our updated CASI and ARS scores are now live! 📊 🤖 Find out how top AI providers like Anthropic, OpenAI, and Microsoft scored in this month’s AI threats recap. 🔗 go.f5.net/w8gf9x2j
000
F5 Labs @f5labs.bsky.social · 19/12/2025
For the second consecutive month, our monitoring has revealed an increase in activities attributed to the #RondoDox threat actor. This time, focusing heavily on the #Shellshock vulnerability. ➡️ Get a full breakdown on the vulnerability & how to protect your web apps. go.f5.net/cphdedmp
000
F5 Labs @f5labs.bsky.social · 17/12/2025
The HashJack prompt injection technique marks a pivotal moment in #cybersecurity. By using seemingly innocent URL fragments, attackers can bypass traditional security measures & exploit #AI assistants. Discover actionable strategies to protect yourself. go.f5.net/gpn7uoyx
000
F5 Labs @f5labs.bsky.social · 16/12/2025
📈 New month, new data! Our December CASI Leaderboard is now live, featuring new data that showcases how leading AI models stack up on risk, performance, and resilience. ⬇️ Check out the results: go.f5.net/4peguclq
000
F5 Labs @f5labs.bsky.social · 15/12/2025
2025 confirmed what we have been saying for years: AI-driven automation, identity verification mandates, and PQC hype have all reshaped the threat landscape.
100
F5 Labs @f5labs.bsky.social · 12/12/2025
As LLMs gain traction, the security landscape is shifting rapidly. Our latest article reveals how new attack classes and emerging vulnerabilities impact the defenses of #AI systems. ➡️ Read our full article as we analyze the adversarial metaphor attack. go.f5.net/6lmghn5y
000
F5 Labs @f5labs.bsky.social · 11/12/2025
ShellShock (CVE-2014-6271) analysis: Last month, we saw a notable resurgence in exploitation attempts, with 900+ attempts. This highlights the ongoing risks posed by legacy vulnerabilities. View the full ShellShock breakdown: go.f5.net/6axv05yx
000
F5 Labs @f5labs.bsky.social · 10/12/2025
Learn how to protect yourself against the HashJack vulnerability, which malicious actors can exploit using URL fragments to inject harmful commands into #AI assistants. 👉 View key insights: go.f5.net/pbvoo0bq
000
F5 Labs @f5labs.bsky.social · 05/12/2025
Earlier this year, attackers launched a massive #DDoS attack using PSH-ACK floods against a payment platform. The tactic aimed to evade detection & maximize impact on network resources showed us that attackers can adapt their techniques in real-time. View details here: go.f5.net/vglroq6d
000
F5 Labs @f5labs.bsky.social · 04/12/2025
The #AI landscape is evolving rapidly, and with millions of models available, understanding the associated risks is more crucial than ever. Find out how our CASI leaderboard works. 🔗 go.f5.net/ox6fy625
010
F5 Labs @f5labs.bsky.social · 03/12/2025
As cyber threats are becoming increasingly sophisticated, a recent #DDoS attack on a European payment platform is a striking reminder of the challenges organizations can face. With attackers shifting tactics in real time, how can businesses stay ahead? Find out ➡️ go.f5.net/8o1qxtqc
000
F5 Labs @f5labs.bsky.social · 01/12/2025
As we enter a new phase of #AI risk where systems can be breached without direct user action, the team reviews a sophisticated new attack vector called Fallacy Failure. Find out more about this vulnerability in our recent write-up. 🔗 go.f5.net/n6jxi53e
000
F5 Labs @f5labs.bsky.social · 26/11/2025
Our #AI insights are live! See how the top AI models performed this month and: 1️⃣ How one AI provider claimed the entire top tier of CASI 2️⃣ Attack spotlight: The Fallacy Attack (FFA) 3️⃣ AI trends & news 🔗go.f5.net/o6m119ld
020
F5 Labs @f5labs.bsky.social · 25/11/2025
A payment processor was hit by a two-stage #DDoS campaign leveraging PSH-ACK floods, first with unique packet sizes and later with standard-sized packets to saturate network bandwidth and disrupt service. Explore the full details on methods, impact, and defenses. go.f5.net/53pj3q6e
000
F5 Labs @f5labs.bsky.social · 24/11/2025
The #F5Labs team focuses on a threat actor attempting to distribute the Rondodox malware, a modified Mirari-based botnet aimed at #IoT devices. Check out our full analysis on the Rondodox malware 🔗 go.f5.net/di8zwxud
F5 Labs chart shows 'Total Events per Malware Distribution IP Address.' IP 74.194.191.52 had the most events, nearly 3,000. Followed by 83.252.42.112 with approximately 300. 38.59.219.27 and 192.183.232.142 had minimal events.
000
F5 Labs @f5labs.bsky.social · 21/11/2025
See what the #F5Labs team uncovered on a recent analysis of a two-wave #DDoS attack on a payment processing platform. The attackers used a Push-Acknowledgement (PSH-ACK) flood to overwhelm the network with high-bandwidth traffic. Dive into the details: go.f5.net/ulby4m5d
000
F5 Labs @f5labs.bsky.social · 14/11/2025
This is the perfect moment to move #PQC from “later” to “now.” With #QDay possible by ~2030 and a 5-year protection window, the time to act is now. View our checklist below to get you started.
Preparing for PQC Checklist: Inventory where crypto lives (TLS, VPNs, APIs); Update libraries, HSMs, load balancers, proxies; validate PQC support; Pilot hybrid TLS with key partners. An illustration of a checklist board.
100
F5 Labs @f5labs.bsky.social · 12/11/2025
Join #F5Labs Director, David Warburton, for the F5 User Groups in the Nordics, where the discussion will revolve around streamlining operations, enhancing scalability, and the latest in threat intel. Register today: ➡️ go.f5.net/mat0wtuu
000
F5 Labs @f5labs.bsky.social · 10/11/2025
Let’s take a second to discuss the evolution of encryption methods. With quantum threats by ~2030, now's the time to adopt hybrid #PQC. Dive into the team’s research. go.f5.net/shehdfco #Cybersecurity #PostQuantum
000
F5 Labs @f5labs.bsky.social · 09/10/2025
As #AI usage scales, which of the following issues hits you the hardest? Is there another issue you’ve seen? Let us know below! 🔸 Bot abuse inflating inference costs 🔸 Scraping of AI-generated content/data 🔸 L7 DDoS against inference/tool endpoints 🔸 Fragile rate limits ➡️ SLO/SLA breaches
Blue background with white text asking, "As AI usage scales, which issue hits you the hardest?" Below, the "f5 Labs Threat Research" logo appears. The background has a subtle dotted pattern.
000
F5 Labs @f5labs.bsky.social · 07/10/2025
As AI moves into production, risks evolve fast. What’s your top concern when deploying #AI apps? Let us know below! 1️⃣ Prompt injection 2️⃣ Data abuse 3️⃣ Scaling & cost risks 4️⃣ Compliance/audit gaps #CybersecurityAwarenessMonth #AISecurity #AppSec
What's your top concern when deploying AI apps?
100
F5 Labs @f5labs.bsky.social · 06/10/2025
Meet the CASI Leaderboard: a security-first ranking of #AI models by their Comprehensive AI Security Index (CASI). See scores, methods, and how to compare risk across models. 🔗 go.f5.net/yjaoge44 #AppSec #AITrust #AISecurity #AICompliance #F5Labs
000
F5 Labs @f5labs.bsky.social · 01/10/2025
#CybersecurityAwarenessMonth is here! We’ll be sharing research-driven insights to help reduce risk across web apps, #APIs, #bots, and preparing for #PQC. Stay tuned for more!
Cybersecurity Awareness Month with F5 Labs. Text reads "Research-backed tips on Web Apps, APIs, Bots, PQC all month long." Graphic of cloud with the word "app" on a square and a shield with a checkmark in it.
000
F5 Labs @f5labs.bsky.social · 29/09/2025
This month, we focus on a scanner exploiting inadvertent disclosure vulnerabilities. This actor, originating from a UK-based ISP, has shown distinct patterns of behavior that we thought warranted scrutiny. View analysis here: go.f5.net/ubxcndil #ThreatIntelligence
F5 Labs image titled, "THREATS: Insights on How Attackers Exploit Accidental Exposure Flaws." It features a hooded figure using a laptop with a globe and arrows, alongside an orange warning sign.
000
F5 Labs @f5labs.bsky.social · 26/09/2025
From #CVE trends to malicious scanners, our latest SIS analysis explores: 1️⃣ Top targeted CVEs for the month 2️⃣ A scanner using 12k+ unique User-Agents 3️⃣ Steps to help protect your organization See our analysis: go.f5.net/2818h4yr #Cybersecuirty #ThreatIntelligence
A graph titled "THREATS Top CVEs: August 2025" from Labs THREAT RESEARCH, shows colored lines trending from August 2024 to August 2025. A purple line peaks in February/March 2025. Green peaks in September 2024.
000
F5 Labs @f5labs.bsky.social · 25/09/2025
Our recent analysis examined a specific malicious scanner (IP: 78.153.140.203) known for targeting exposed environment files (.env). This scanner displays a staggering 12k+ unique User-Agent strings, originating from a UK-based ISP. View analysis here: go.f5.net/741mwjdd #ThreatIntelligence
Threat analysis from F5 Labs shows the top 5 URLs targeted by IP 78.153.140.203. URLs ending in /.env are highly targeted, with the base /.env having nearly 1800 counts of unique URLs.
000
F5 Labs @f5labs.bsky.social · 24/09/2025
Banks hold sensitive data, such as transactions and credit card information. With quantum on the horizon, adopting #PQC is urgent. Without it, breaches could hit by 2030. Benchmark readiness & plan your transition with our PQC report: go.f5.net/0pffk41s #QuantumRisk #DataProtection
000
F5 Labs @f5labs.bsky.social · 19/09/2025
Check out some highlights from our latest monthly SIS overview as we uncover the latest CVE trends! 🔗 go.f5.net/e3p0jv7g #Cybersecurity #ThreatIntelligence #MalwareProtection
000
F5 Labs @f5labs.bsky.social · 18/09/2025
Quantum computing is reshaping the crypto roadmap. #NIST has finalized its first #PQC standards with clear roles for each algorithm family. View them below. ⬇️ Learn more about PQC standards ➡️ go.f5.net/ve0f60cg #Cybersecurity #QuantumSecurity #AppSec #Cryptography
FIPS203 defines encryption standard, keeping data private during transmission. The algorithm, CRYSTALS-Kyber, is now ML-KEM. "Swipe for more >". F5 Labs Threat Research logo in the upper-right corner.FIPS 204 defines the standard for digital signatures, which provide the ability to detect tampering. It is based on CRYSTALS-Dilithium algorithm and has been renamed ML-DSA. Swipe for more.FIPS 205 is an additional standard for digital signatures that uses a different class of algorithm than ML-DSA. Originally SPHINCS+, it's now standardized as SLH-DSA. Find out more on PQC standards via link in comments.
001
F5 Labs @f5labs.bsky.social · 17/09/2025
We published an article on #SparkRAT highlighting its architecture and potential vulnerabilities. We also have some #YARA rules to help identify SparkRAT in your environments. Check out the article here: go.f5.net/o3k1rbep Check out the YARA rules here: go.f5.net/v7bc0ake
000
F5 Labs @f5labs.bsky.social · 11/09/2025
As #QDay draws closer than expected. Is your data secure? Join David Warburton, Director at #F5Labs, at this year’s IDC Security Summit in Sweden as he explores “Q-Day and the Quantum Deadline: Are We Ready?” Get the full details: go.f5.net/aaz6088r #IDCSecuritySummit #PQC
010
F5 Labs @f5labs.bsky.social · 05/09/2025
Did you know that 24% of the entries in CISA’s Known Exploited Vulnerabilities (KEV) list are RCE vulnerabilities? No surprise that of the top 10 #CVEs we track, CVE-2017-9841, a PHPUnit eval-stdin.php RCE came in top. Check out our analysis. go.f5.net/27nmlgj6 #MalwareProtection
Senor Intel Series: CVE-2017-9841 saw a 36% increase in scanning traffic in July, vs. June 2025. Donut chart illustrates PHPUNIT EVAL-STDIN.PHP in blue, gray fill. F5 Labs logo in upper right.
000
F5 Labs @f5labs.bsky.social · 04/09/2025
Finance, healthcare, & government: the sectors with the most to lose are among the slowest to adopt #PQC. So, what can your organization do? ✅ Establish a crypto bill of materials. ✅ Enable hybrid KEM or transition to TLS 1.3. Find more helpful tips: go.f5.net/dgwc3hb1 #QuantumReadiness
000
F5 Labs @f5labs.bsky.social · 02/09/2025
TLS 1.3 is strong today, but tomorrow’s #quantumattacks could break it. That’s why it’s vital to understand hybrid post-quantum TLS handshakes. Stay ahead of the curve with our #PQC report. 🔗 go.f5.net/toh1o17n
010
F5 Labs @f5labs.bsky.social · 31/08/2025
Looking into last month’s top scanned #CVEs, we saw a striking commonality across vulnerabilities: nearly all rely on HTTP-based vectors and culminate in command injection. See what other trends the team uncovered: go.f5.net/fof1d9ew #Cybersecurity #MalwareProtection
Senior Intel Series: Heading the Prevalence of Web-Based RCE Vulnerabilities. HTTP Vectors Lead the Latest CVE Scans. It shows a blue cloud with an arrow and a red shield with a checkmark.
000
F5 Labs @f5labs.bsky.social · 29/08/2025
Validation matters. So, we tested our #SparkRAT YARA rules against 4 years of Malware Bazaar samples (2020-02 to 2024-04) with zero positives. Check out our #YARA rules on #Github: go.f5.net/pishckzt
SparkRAT. YARA Rules for Detecting the SparkRAT Client. A grey gear graphic on the right, with blue cloud design including a white rat with a lightning bolt.
000
F5 Labs @f5labs.bsky.social · 28/08/2025
In our latest SIS analysis, we dive into: 1️⃣ Top targeted CVEs for the month 2️⃣ Long-term CVE trends, and 3️⃣ Deep dive into web-based RCE vulnerabilities Find out what the team uncovered: go.f5.net/mn5bmol8 #Cybersecurity #MalwareProtection #Threats
Graph titled "THREATS Top CVEs: July 2025," from F5 Labs, shows fluctuations of threats from July to July. One threat surges dramatically from Jan to Apr, dwarfing others, while several other threats remain consistently low.
000
F5 Labs @f5labs.bsky.social · 27/08/2025
Quantum is coming! Only ~3% of banking sites support #PQC, far too low for sensitive data. Legacy encryption will crack under quantum, putting assets at risk. See where you stand and how to start the PQC transition: go.f5.net/zwkq3got #QuantumRisk #DataProtection
000
F5 Labs @f5labs.bsky.social · 26/08/2025
Traditional defenses like #CAPTCHAs are no longer enough! Check out David Warburton’s op-ed in #Tahawultech as he lists key insights into combating advanced bot attacks effectively. <link> #BotDefense #Cyberthreats
F5 Labs post with text: "In today's digital landscape, where applications and APIs are the lifeblood of businesses, a silent threat lurks: sophisticated bot adversaries." It also features David Warburton, Director of F5 Labs.
000
F5 Labs @f5labs.bsky.social · 25/08/2025
Find out how the #F5Labs team examines the growing sophistication of bot adversaries & how they exploit application vulnerabilities without triggering traditional alarms. 🔗 ➡️ go.f5.net/l6nk6bsj #CISOs #Cybersecurity
Black background with a blue globe graphic surrounded by blue and orange dots and orange robot icons. Text states: 'Bots are responsible for over 50% of website & API traffic.' F5 Labs logo in corner.
000
F5 Labs @f5labs.bsky.social · 25/08/2025
As software engineers & security architects, staying ahead of the curve in encryption protocols is critical for safeguarding sensitive data. ⬇️ Check out 3 reasons why you should care about #TLS 1.3. #Cybersecurity #Cryptography #DataProtection
002
F5 Labs @f5labs.bsky.social · 22/08/2025
The impending arrival of #QDay is closer than ever! What does this mean? Find out as the #F5labs team evaluates the state of #PQC and steps you can take to make sure your website and data are safe! www.f5.com/labs/article...
A graphic with the text "ENCRYPTION Preparing for Q-Day: What You Need to Know" along with "Explore our evaluation of PQC & learn essential steps to protect your data.", with the F5 labs logo.
000
F5 Labs @f5labs.bsky.social · 21/08/2025
Many #SparkRAT rules rely on brittle strings like “Spark/client/config.GetBaseURL,” which attackers can rename using software engineering refactoring tools.   Our approach is as follows ⬇️   #F5Labs #YARA #AppSec #ThreatDetection
100
F5 Labs @f5labs.bsky.social · 20/08/2025
During the team’s research for the 2025 Advanced Persistent Bots Report, they noticed increasing sophistication of bot adversaries & three major trends. Check them out below ⬇️ See the full report: go.f5.net/gyamm3io
Credential Stuffing: This prevalent attack exploits stolen credentials to gain access to user accounts. Many organizations experience significant login traffic leading to compromised accounts despite low success rates. F5 Labs logo.A "BOTS REPORT" from F5 Labs indicates the "Hospitality Industry [is] Under Siege," citing a surge in bot attacks that target gift card systems and loyalty programs. Cybercriminals are using bots for "carding".Bots Report: Bots Bypassing Traditional Defenses. Traditional methods like CAPTCHAs and IP blocking are ineffective against advanced bot tactics. Bot operators use residential proxies to hide their traffic origins, resembling legitimate users.
010
F5 Labs @f5labs.bsky.social · 18/08/2025
CISOs: The quantum computing era is approaching rapidly, with #QDay predicted as early as 2029. Yet only 5% prioritize #PQC now. This gap poses serious risks. Check out our PQC report for actionable insights to protect your data. go.f5.net/kiv2y8s5 #QuantumComputing
Horizontal bar graph showing 'Proportion of PQC Enabled Sites per Business Sector'. Orange bars represent 'Non-PQC', blue bars 'PQC Enabled'. Sectors include Oil & Gas, Utilities, and Consumer Services with varying percentages.
000
F5 Labs @f5labs.bsky.social · 15/08/2025
In our latest article, the #F5Labs team explores global use of open-source malware and digs into the specifics of #SparkRAT. Plus, we built a YARA rule to help you detect SparkRAT in your environment. Check it out: go.f5.net/bymhwb26 #Cybersecurity
Diagram of SparkRAT architecture. A computer labeled "SparkRAT Infected Host" connects to a cloud labeled "SparkRAT C2 Server" which connects to a person next to a skull and crossbones labeled "SparkRAT Operator Console."
000
F5 Labs @f5labs.bsky.social · 14/08/2025
While many industries are seeing a decline in #bot attacks, hospitality & Quick Service Retail are facing increased automation attempts. This surge reflects not a lapse in defenses but heightened attacker motivation. Find out more here: go.f5.net/l6xl3tc2 #BotDefense
F5 Labs presents: "Bots and Automated Attacks - Staying Ahead of the Curve: Combatting Bot Attacks in Vulnerable Industries." Learn about evolving security and adaptations against threats. The background has scattered blue and bronze dots.
000
F5 Labs @f5labs.bsky.social · 13/08/2025
Curious about #PQC standards? As of last year, NIST has established new standards for encryption and digital signatures. Learn why ML-KEM and ML-DSA are crucial for PQC adoption. go.f5.net/b5a5y4zx #F5Labs #QuantumSecurity
000