An unidentified nation-state hacking crew targeting vulnerable F5 products to break into US government networks poses an "imminent risk" to federal agencies, American cyber officials warned on Wednesday – while also blaming Democrats for the ongoing government shutdown and insisting that the staffing cuts haven't hurt cyber defenses at all.
The US Cybersecurity and Infrastructure Agency (CISA) warning and related emergency directive followed a breach disclosure, during which security vendor F5 said government-backed spies broke into its network and stole BIG-IP source code, undisclosed vulnerability details, and customer configuration data belonging to a "small percentage" of its users. It also issued security patches for a whopping 45 bugs.
Neither F5 nor CISA has attributed the attack