Delving Into the SparkRAT Remote Access Tool
Sensor Intel Series: May 2025 CVE Trends
Sensor Intel Series: May 2025 CVE Trends
AI Security Insights – March 2026
Persistent trend in open-source offensive tooling & implications for defenders
AI Security Insights for November 2025
Sensor Intel Series: March 2026 CVE Trends
Sensor Intel Series: September 2025 Trends
We expand our view to include CWE and OWASP, and we also examine the latest overall trends for June 2025.
Whatever you think will happen… will happen faster and with more acronyms than ever before.
Sensor Intel Series: June 2026 CVE Trends
Discover how to mitigate CVE-2024-53900 and CVE-2025-23061, which expose Node.js APIs to remote attacks.
Uncovering the true scale of persistent bot activity, and the advanced techniques that bot operators use in order to remain hidden from bot defenses.
AI Security Insights – January 2026
TP-Link draws the attention of the US Government.
Sensor Intel Series: December CVE-2025-55182 Trends
Investigating a schema parsing concern in the parquet-avro module of Apache Parquet Java.
Sensor Intel Series: August 2026 CVE Trends
Sensor Intel Series: July 2025 CVE Trends
Sensor Intel Series: July 2025 CVE Trends
Chinese models show variation from month to month, highlighting the uncertain and unstable nature of their security posture
BotPoke comes to the foreground yet again.
Sensor Intel Series: July 2026 CVE Trends
Sensor Intel Series: February 2026 CVE Trends
CASI leaderboard shifts, and two incidents where AI was handed the keys.
Sensor Intel Series: April 2026 CVE Trends
CASI Leaderboard, Bias Jailbreak, and Three Coordinated Supply Chain Incidents
The two-wave attack reached a peak of 1.8 Tbps.
F5 Labs’ Weekly Threat Bulletin delivers fast, AI‑driven insights on emerging cyber threats with IoCs, mitigation tips, and expert‑validated guidance.
The Bots Pyramid of Pain: a framework for effective bot defense.
Sensor Intel Series: January 2026 CVE Trends
Autonomous AI agents blur security boundaries, enabling data exfiltration, privilege abuse, and insider‑level risk in enterprises.
A competitive open-weight model, Claude Fable, and Jade Puffer
Over a dozen exploits were used to target IoT devices.
An examination of CVE trends from February 2025 scanning data.
AI Security Insights – February 2026
Explore the new AI security index for emerging trends in AI security.
Discover the latest CVE trends and a new campaign targeting websites hosted in EC2 instances on AWS.
We analyze the world’s most popular websites and most widely used web browsers to determine the current state of PQC adoption on the web.
We investigate the rise of adversarial poetry in AI security. Understand how metaphor-based exploits circumvent guardrails and the defenses we need for LLMs moving forward.
Legacy bugs continue to serve attackers.
AI Security Insights – April 2026
A new wave of client-side attacks bypasses enterprise defenses.
How much do scraper bots affect your industry?
How expired domains and improper DNS management can lead to severe security risks like MitM attacks, fraudulent TLS/SSL certifications, and more.
A competitive open-weight model, Claude Fable, and Jade Puffer.
Scans intensify, looking for a critical vulnerability in TBK DVR devices.
With “thingbots” now launching Death Star-sized DDoS attacks, hosting banking trojans, and causing physical destruction, all signs point to them becoming the attacker infrastructure of the future.
Data manipulation is a real threat to data-driven approaches at enterprises. We tested one of our own assets to see the possibilities.
Gootkit malware uses misleading code to hinder manual research and automated analysis.
What can last year’s Black Friday shopping trends teach us about expected attacker behavior during the 2024 holiday shopping season?
Threat campaign activity in December 2019 doubled from the previous month.
Learn what attackers scanned for last month so you can tune your defenses.
A new vuln popped up in our traffic this month, as well as lots of the same old CVEs—IoT and Microsoft Exchange.
27 new CVEs, and continued IoT targeting. See what's new from February 2024.
F5 Labs has released a new open-source tool to check for HTTPS misconfigurations of public and internally hosted HTTPS websites.
Apache Struts 2 Jakarta Multipart Parser RCE crypto-mining campaign is now targeting Windows, not just Linux systems.
The latest DDoS trends include the return of large volumetric DDoS attacks, the rise of application targeted attacks, and businesses in Europe and Asia are growing targets.
The latest evolution of cyber weapons is brought to you by the default passwords in Internet of Things (IoT) devices.
The new EternalBlue NSA exploit is powering a wave of virulent ransomware sweeping across Europe.
A detailed examination of application risk and cybersecurity attack chains, broken down by sector.
South Africa’s cyberattack landscape saw targeting of Scryba, PHP, and CVE-2017-9841 web vulnerabilities.
Customer engagement drives web application design, but user-generated content brings inherent security challenges.
Quantum computing is coming. What should your strategy be today to deal with what’s on the horizon?
Creating an encrypted HTTPS website depends on a lot more than simply throwing a digital certificate at it and hoping for the best. In fact, Transport Layer Security (TLS) and HTTPS misconfigurations are now so commonplace that in the 2021 OWASP Top 10, Cryptographic Failures now comes in second place.
Learn which vulnerabilities attackers preferred in November.
With a growth rate of 1,473% in 2016, the hunt for vulnerable IoT devices rages on...
Ransomware is ramping up, especially in the public sector. The key to stopping these attacks is to focus on the ransomware attack vectors.
Website logins are under constant assault, with attackers quickly modifying their bots to evade simplistic defenses.
Attacks against exchanges, exit scams and nation-state threats mean that cryptocurrencies retain their Wild West character in 2019.
A deconstruction of FluBot 5.0’s new communication protocol and other capabilities FluBot uses to hide, making it difficult for researchers and security solutions to detect.
Cryptocurrency exchanges and their supporting application systems are being attacked at an unprecedented level. As the value of cryptocurrency has climbed, so has the incentive to steal.
Similar to April and May, threat actors in June continued targeting the deserialization vulnerabilities found in Oracle WebLogic to mine cryptocurrency.
As the possibility of quantum computing draws nearer, changes to today’s TLS key exchange algorithms will be required.
BackSwap demonstrates unique behavior in its manipulation of user input fields and its handling of International Bank Account Numbers (IBANs).
APIs have become critical for business online, but they are also leading to more security incidents, most of which should have been preventable.
The Ramnit banking Trojan continues to evolve, this time with the intent of making the malware harder to detect.
The same countries that attacked the rest of the world also attacked systems in Russia, but from different networks and IP addresses.
The log4j security vulnerability is one of the most widespread cybersecurity vulnerabilities in recent years. Here's a non-technical explanation of it.
European systems saw large volumes of attack traffic coming from in-region IP addresses attempting to conduct abusive port scanning.
Despite how they sound, Spring4Shell and the related vulnerabilities in the Spring Framework aren’t exactly like Log4Shell. Learn how they work and what you can do.
By targeting critical infrastructure, cyberwarfare attackers can plunge a nation into chaos without ever firing a single shot.
Critical apps are the ones that must never go down or be hacked. They are also the hardest to defend because they are often massive, ancient, and touch everything.
Attackers targeted applications and conducted credential stuffing attacks against systems in Asia during the fall of 2019.
Analyzing a single attack in detail yields interesting findings about attacker sophistication, living off the land, and architectural risk.
Learn the latest trends in bots and malicious automation so you can compare with attacks against your own organizations.
The tactic that featured most prominently in U.S. data breaches in 2018 was access attacks, such as phishing or credential stuffing. We identified the changing patterns, and provided some tips on how to prevent them.
When it comes to IoT threats, we’re nowhere near being out of the woods yet; we’ve just barely entered the forest.
In this report, we demystify the complexities of apps, explore how and where they’re attacked, and provide practical steps to take now to start winning the app protection battle.
Organizations often overlook the many ways in which their own systems put useful information right into the hands of attackers building cyber scams.
In March, threat actors focused on targeting vulnerabilities released in the last few months. WordPress Easy SMTP Plugin Authentication Bypass vulnerability attacks had the most impact during that time frame.
Attackers continue to exploit old vulnerabilities, use new methods to kill competing crypto-miners, and survive removal by administrators.
A few formerly popular CVEs fell in traffic in August, leaving an old router vuln to resume its normal position at the top. Plus seven new CVEs added to the list of signatures.
Over 700 survey respondents from different generations shared their views about the IoT and the tradeoffs between privacy and convenience.
Attackers are exploiting new vulnerabilities almost as quickly as they're being discovered.
Bleichenbacher attacks will likely continue to pop up until TLS 1.3 is fully adopted, which could take years.
TP-Link Archer AX21 Wifi Router targeting, plus a handful of new CVEs! See what mass scanning looks like in March 2024.
This is the full version of the 2019 Application Protection Report. It contains research and data from all of the 2019 volumes, updated with 2019 breach trends that paint a clearer picture of where application threats are heading.
From spoofing device fingerprints to hijacking authenticated sessions, attackers use a range of techniques to bypass multifactor authentication.
Providers and manufacturers could go a long way toward reducing the very real threat of IoT.
The 2021 version of F5’s continuing analysis of the application security threat landscape explores ransomware, payment card theft, and account takeover.
Recent NSA and CIA leaks exposed advanced new techniques for building automated malware factories that churn out threats like SambaCry and Petya/NotPetya, which deploy over untraceable networks.
Vulnerable web servers are the top target for threat actors, who continue to exploit known vulnerabilities with the goal of running commands remotely.
In just four short years, encryption estimates have gone from almost non-existent (in the low single digits before 2013) to just over 50% by the end of 2016. How much of a victory is this?
Analysis of public breach reports showed a relationship between business models and breach vectors, with injection and phishing the leading causes.
IP addresses assigned in Russia launched significantly more attacks against Middle East systems than any other regions of the world.
A previously undisclosed misconfiguration vulnerability in the rTorrent client is being exploited in the wild to mine Monero.
Attackers used two top ASNs to broadly distribute IP addresses in an attempt to camouflage attack traffic targeting Middle Eastern systems.
Three years of data shows DDoS attacks against service providers are growing while brute force and other authentication attacks are slowly waning.
How this cloud startup met its goals for security and availability right out of the gate by setting goals, doing a risk analysis, and examining tradeoffs.
Combating this vulnerability might mean you have to force updates on employees’ personal devices or deny them access altogether.
Seventeen years after the opportunity for abuse was made public, attackers are finding new ways to make use of this unpatched web crawler service.
A detailed look at an 840-Gbps DDoS attack on a financial services provider and a deeper dive into attacking nodes.
The Gootkit banking trojan is still active and protecting itself in Italy using a dedicated redirection defense.
Find out why we care so much about application security, how applications have grown into the weird beasts that they are today, and how our work fits into the bigger picture of securing and running an application.
Dyre malware requires little introduction as it has been the focus of many publications, and it is a well-known threat. One of the reasons for it being so infamous is the frequent changes the authors incorporate in...
The U.S. and Canada have 95% of top source traffic countries in common.
US-CERT TL18-106A alert underscores how insecure Internet systems really are and that ignoring the problem only increases the collateral damage.
Privacy today isn’t just about staying away from prying eyes. The very act of communicating across the Internet with open, non-confidential protocols invites exposure to multiple threat types.
We detail the steps for decrypting and decompressing IcedID webinject files, enabling researchers to analyze IcedID samples and pull out target and web injection files.
As quickly as attackers commandeer IoT devices to build more “thingbots,” they continue to evolve their attack types and functionality.
The TP-Link Archer AX21 Wifi Router vulnerability CVE-2023-1389 experiences massive targeting along with a rather old critical RCE in PHPUnit.
HEIST is an example of how risk and threat are different, and why the distinction matters.
We added another signature (for CVE-2020-0618) and we take a look at a cred stuffing attack from last month. One formerly prevalent CVE has disappeared entirely, and we investigate why that happened.
Security breaches in the news serve as a good reminder to check and make sure you have a solid application protection strategy in place, starting with never trusting user input.
A new Python-based botnet that mines Monero spreads via SSH and leverages Pastebin to publish new C&C server addresses.
The fourth and final part of a series investigating how automation is used to create fake accounts for fraud, disinformation, scams, and account takeover.
F5 Labs analysts discovered a target pattern in the IBAN number formats as well as weekly changes to the script injection content. In May 2016, the F5 Security Operations Center (SOC) detected a generic form grabber and IBAN (International Bank...
In terms of attacker interest, it was more about continuity than change in June, with many of the same old CVEs being targeted.
Our top talker changes up their infrastructure, and CVE-2023-1389 continues to hold the top spot.
Is the Intel AMT vulnerability as bad as we all first thought? Either way, here are some suggestions for protecting yourself.
Attackers are targeting financial services organizations with brute force, credential stuffing, and DoS attacks. See how you can mitigate the risks.
The Canadian threat landscape was characterized by a large amount of attack traffic from in-county systems, which can be the most difficult to filter.
Even URLs that look legitimate can be fake, so train, train, train your users to verify links before they click.
Malicious actors and eavesdroppers are forcing Internet communication into a single cryptographic protocol: SSL.
Notorious hacker of Anonymous and LulzSec fame is challenged by rival hacker, The Jester, to reveal his identity.
Seriously, how many colors are there? And how many of us share the same love of one of those limited choices?
Asian systems saw a large amount of SMB attack traffic during this time period, mainly driven from in-region IP addresses.
If you aren’t aware of Drupalgeddon 2, then you’ve either been living off the grid or don’t use the popular content management system (CMS).
TrickBot kicked into high gear coming into August with the most targeted URLs since its launch. It released a new worm module, shifted its focus towards the US, and soared past the one thousand target URL mark in a single configuration.
Welcome to the fun-size version of our 2023 Identity Threat Report! If you only have 5 minutes to spare this is the place to start - and you can always download the full PDF for later.
With simple exploits plaguing Windows and Linux SMB week over week, do yourself a favor and patch for CVE-2017-7494 now to avoid having to do it in panic mode.
India’s attack landscape saw focus on Port 5900 and the highest number of scans from the UK.
While Reaper might be considered an “object lesson” today, it should serve as a blistering warning that IoT security needs to be fixed now.
One IoT vulnerability stops growing, and another one starts. See what attackers are up to this month.
Anonymous commoditizes well-known DDoS attacks by making easy-to-use tools, available to even the most unsophisticated user.
With Mirai rearing its ugly head again, we’re revealing its C&C hostnames so organizations can update their denylists and protect themselves.
Threat actors continue to find creative yet relatively unsophisticated ways to launch new campaigns to reap profits from crypto-mining operations.
How a Jenkins dynamic routing vulnerability becomes an attacker’s infection vector for installing and executing a cryptominer.
Latin American systems received more attacks from IP addresses within the region that coincidentally did not attack anywhere else in the world.
F5 threat intelligence reports attackers are still doing DNS water torture DDoS, DNS reflection DDoS, expired domain takeover, and using DNS requests for covert channels.
If configured incorrectly, cellular IoT gateways can give attackers access to critical infrastructure, threatening human life in ways only Hollywood has conceived.
Last issue, we observed huge amounts of scanning for the rather old CVE-2017-9841, an RCE in PHPUnit. This time it’s fallen off nearly as sharply. We look into why!
A newcomer to the malware scene, Golang-based malware has been seen installing cryptominers specifically targeting Moreno cryptocurrency.
Memcached is just one of many application infrastructure systems that could launch the same types of attacks if they were also misconfigured.
FireEye tools show attackers aren’t worried about your defenses.
One old favorite CVE declined by more than half in July, and a new one (to us) was so heavily targeted it ended up ranked fifth out of 72.
Some IoT vulnerabilities, some Microsoft Exchange vulnerabilities, but not too much going on in March.
Plus a few interesting changes in the CVEs we track, and some notes on just what kinds of malware stagers we see.
Businesses, critical systems, infrastructure, and even human life are more threatened than ever as attackers target the Internet-connected “things” that run the modern world.
Cyber crooks use several common URL disguising techniques to trick users into thinking their sham sites are legitimate.
Threat actors shift focus away from cryptominers and back to remote code execution—this month with a new zero-day exploits.
In this five-part blog series, we look at how cyber scammers vacuum up information across the Internet to build profiles for phishing and other kinds of social engineering attacks.
Vulnerability assessment of IoT devices in Ireland detailing the biggest threats, most at-risk and highly exposed devices.
Overall scanning for CVEs we track is down, but one specific scanner caught our attention. We dig into what it’s doing.
Singapore saw a sharp rise in attacks targeting a variety of ports, from SIP clear-text (5060), Telnet, SQL, and host-to-host ports to those used for remote router management and proxy servers and caching.
Attackers continue to find new and creative ways to carry out malicious crypto-mining operations, employing multiple exploits in a single campaign.
Speed to market means IoT and mobile apps are being released with known vulnerabilities.
Learn which CVEs are top of mind for attackers this autumn.
Personally identifiable information and user credentials are the primary nuggets attackers are after when they exploit known vulnerabilities in web applications.
Tuyul bot targets vulnerable PHPUnit systems to install an Internet Relay Chat (IRC) bot.
Marcher targets focused on European, Australian, and Latin American banks, along with PayPal, eBay, Facebook, WhatsApp, Viber, Gmail, and Yahoo—all in the month of March.
The Summary of the 2019 F5 Labs TLS Telemetry Report expands the scope of our research to bring deeper insights into encryption on the web, including ciphers, SSL/TLS versions, and digital certificates.
Since the Internet can’t survive without DNS, let’s make our best effort to defend it.
An undercover interview of two infamous Russian hackers speak volumes about skills, passion, and motivation of some of the world’s most dangerous cybercriminals.
One vulnerability took all the headlines in January, and, well, it probably won’t shock you.
We’re still thinking of Internet of Things devices as low risk when reality tells us exactly the opposite.
Europe was Canada’s primary source of attack traffic targeting VoIP systems and web applications.
The same rTorrent XML-RPC function configuration error that was targeted to mine Monero in February was also targeted in January in a campaign apparently spoofing user-agents for RIAA and NYU.
Putting off fixing low-severity vulnerabilities can have high-impact effects.
Analysis of sensor data from 2018 revealed a big focus on PHP generally, and specifically a large, unsophisticated reconnaissance campaign looking for unsecured databases with PHP front ends.
Like many other financial Trojans, the notorious Dridex malware keeps evolving and strengthening its presence.
Attackers using IP addresses in Vietnam, China, and Russia focused on attacking applications over Samba, SSH, and HTTP.
A deep dive into a wide variety of cloud-related security data breaches, both maliciously caused and accidental.
DDoS attacks have been common since the late 2000s, but average attack peaks have increased to 100+ Gbps.
A new DDoS attack vector that leverages LDAP for reflection-amplification attacks is seeing increased usage.
New Mirai variant references the COVID-19 pandemic with a filename change and two targets: Huawei routers and TeamSpeak.
Organizations need to provide clear and specific guidance to employees who travel across national borders when it comes to giving up passwords and surrendering devices.
IoT botnet Gafgyt targets popular routers through RCE vulnerabilities, and even removes competing malware.
Learn which CVEs attackers scanned for most in the first half of 2022.
A review of 2018-2020 cyberattacks at brokerages, investment funds, payment processors, and financial services organizations as well as API security incidents and open banking.
Threat actors double down with their botnet building efforts. Vulnerable Netgear routers join exploitable TP-Link and other IoT devices, expanding attacker DDoS capabilities.
It’s easy to brush off low-risk vulnerabilities as trivial—until they’re combined to create a deep-impact attack.
Tinba, also known as "Tinybanker", "Zusy" and "HµNT€R$", is a banking Trojan.
Denial-of-service attacks are increasing and becoming more complex. We look at how attackers are attempting to bring down services around the world.
Despite being around since 2005, perlb0t is still being used against unpatched servers.
An F5 Labs researcher snoops on Tor exit node traffic from a load balancer. What he finds will shock you. SHOCK YOU.
New information sheds light on Sabu’s activities following the revelation of his identity.
Known for redirection attacks, recent Trickbot banking trojan campaigns use server-side injection and target fewer victims.
Recently there have been several reports of a financial malware named TrickBot; this malware's code looks similar to Dyre.
F5 Labs covered a multitude of threats, vulnerabilities, botnets, attackers, and attacks in 2017. Here are just some of the highlights you might have missed.
Cloud sprawl isn’t just a budget sinkhole; it’s quickly becoming a security blind spot and potential attack vector for data theft.
Nearly 50% of observed traffic is looking for accidentally exposed data.
Panda malware is back in full force with three currently active campaigns that extend its targets beyond banking to new industries and organizations worldwide.
Insights into Genesis Marketplace, a black market trading in digital identity.
It looked like a simple XSS in the Outlook Android app, but the app developers couldn’t reproduce it so they didn’t fix it. Then things got interesting. Here’s the story of how I discovered CVE-2019-1105.
This episode in The Hunt for IoT Volume 6 series focuses on the threat actors building IoT botnets, how easy IoT devices are to exploit, recent thingbot discoveries, and the status of Mirai infections worldwide.
We add 6 CVEs to our list and do a brief roundup of some stats from 2023.
Expect a breach If you have basic, vendor default SSH credentials active on any system.
Readily available hacking tools provide new ways for civil disobedience groups to antagonize their targets anonymously.
With billions of data records compromised, it’s time to reconsider whether passwords are our best means for authenticating users.
Seven steps for improving the security of critical infrastructure systems—and protecting the public from unnecessary risk.
A common infection vector used by botnet creators is scanning the Internet for web vulnerabilities to exploit for malware or back doors. The advantage of hitting servers over personal consumer devices is the ability to leverage powerful hardware that is...
Fighting sophisticated scrapers requires advanced detection methods. Discover the techniques needed to identify and manage these hidden threats outlined in our investigation.
F5 Labs summer intern describes her experiences building a Python-based HTTPS scanning library for security research and release as an open source tool.
Relative stability in attacker activity this past month serves to highlight the ongoing importance of Exchange Server vulnerabilities and poorly-secured IoT devices to attackers.
Part two of a series investigating how automation is used to create fake accounts for fraud, disinformation, scams, and account takeover.
According to DARPA, it takes an average of 312 days for security pros to discover software vulnerabilities such as viruses, malware, and other attacks. In hacker time, that’s a virtual eternity in which bad actors can wreak havoc.
Slave is financial malware written in Visual Basic. Since 2015 it has evolved from relatively simple IBAN swapping.
U.S. systems were heavily targeted by IP addresses in Russia, Moldova, and France that launched credential stuffing attacks on VNC port 5900 beginning in June 2019.
Real estate scams are big business for attackers. Be on the lookout for this one, which can leave home buyers destitute if not caught in time.
We found a novel malware strain that is targeting financial sites in Italy and Spain... so far.
How platform business models are at an increased risk of fraud when two or more separate parties collude.
Gray hats might have good intentions launching their “vigilante” botnets, but are they really helping us win the war against Death Star-sized thingbots?
A Mirai variant named Echobot appeared mid-2019. Echobot has been seen expanding its arsenal to 71 exploits, targeting SCADA systems and IoT devices.
F5 Labs researched 433 breach cases spanning 12 years, 37 industries, and 27 countries to discover patterns in the initial attacks that lead to the breach.
Precision agriculture leveraging IoT and API technology is both a great boon and a huge cybersecurity risk.
In our 2019 edition of the Phishing and Fraud Report, we look at the latest methods and trends attackers are using to exploit the most vulnerable part of your defensive posture: your users.
The Qbot banking trojan is back, targeting American banks with dedicated campaigns followed by stealth and evasion techniques.
SETTINGS frame abuse and Slow POST attacks in HTTP/2 can lead to CPU and memory exhaustion.
Threat actors wasted no time jumping on this new exploit to launch new campaigns for reconnaissance, uploading back doors, and deploying variants of the Mirai botnet.
New Apache Struts campaign, Zealot, targets vulnerabilities in Windows, Linux, and the DotNetNuke CMS, then leverages leaked NSA exploits to move laterally through internal networks and mine Monero.
How a token-based authorization model can help organizations dramatically reduce credential stuffing attacks.
The Russian threat landscape is unique from other regions of the world in that it had the most unique attacking IP addresses.
Now that we’ve explored cloud security failures, we’re going to explain defensive strategies laid out by deployment model.
Definitive steps individuals and organizations can take today to deal with the impact of Cloudbleed.
Plus, the 7 Weirdest CVEs (You won’t believe number 6!)
Attackers using IP addresses in China, the United States, and the Netherlands focus on attacking applications over SSH, SMB and HTTP.
So far, we’ve seen IoT DDoS attacks on a Death Star scale. What's next for those of us that may be caught in the blast?
If you’re running Apache Struts 2 and the vulnerable component, stop reading and update now.
API use has grown tremendously as applications grow more decentralized. Some large apps have hundreds of APIs, and mobile apps depend on them completely.
Every week another bug, vulnerability, or exploit is released - we need a multi-layered security strategy (beyond our standard patch “spin cycles”) to deal with threats like Spectre and Meltdown.
Web injection represents an even greater risk than it did previously, thanks to the growth of third-party content and increasingly complex attack surfaces.
The personal and job-related information that employees often innocently post on various websites makes it easy for phishers to pull off their scams.
Continuing the trend from January, threat actor activity in February focused heavily on exploiting a ThinkPHP remote code execution vulnerability.
Ramnit’s latest configuration targets Europe leading up to tax season, focusing on Italian banks and international online advertisers.
How automated fraudsters tried to ruin a restaurant’s promotional contest.
January threat actor activity focused heavily on exploiting a ThinkPHP remote code execution vulnerability and infecting vulnerable Oracle WebLogic systems with a Mirai variant.
Ransomware now includes data leakage, stealth, attack delay, anti-security, and ransomware as a service. CI Security’s John-Luke Peck shares his thoughts.
New campaign activity for remote code execution (RCE) vulnerabilities disclosed this year picked up in the month of November.
August 2019 was slowest month on record F5 researchers have seen in new threat activity. But while active exploitation slowed, new reconnaissance campaigns grew.
Part one of a series investigating how automation is used to create fake accounts for fraud, disinformation, scams, and account takeover.
And we're watching Dridex. Here's the latest in this malware's evolution.
Shellshock can take advantage of HTTP headers as well as other mechanisms to enable unauthorized access to Bash.
Broken API authentication is leading to avoidable security incidents and unusual impacts. Learn what you can do to control the risk.
Europe saw more in-region attack traffic—the hardest kind to filter out—than any of the 8 regions of the world we analyzed.
Learn about the tricks attackers use to dupe unsuspecting users and how you can help protect them—and your organization.
Despite an overall downward trend, an old favorite comes back into play.
How cybercriminals use credential stuffing attack tools OpenBullet and MailRanger to bypass CAPTCHA, compromise mailboxes, and reset passwords.
Similar to April, threat actors in May continued targeting the deserialization vulnerabilities found in Oracle WebLogic to mine cryptocurrency.
There are three primary avenues to hack a U.S. election: voter registration, voting machines, and the voters themselves. We’ll dig into each and see which offers the most bang for the buck.
In this companion podcast, the 2019 F5 Labs Application Protection Report researchers examine how both apps and threats are changing, and what security practitioners can do to stay ahead of these changes.
See which vulnerabilities caught attackers’ eyes in December 2022.
More IoT Targeting, plus a bunch of new CVEs! See what attackers went after in January 2024.
As Christmas quickly approaches, seasonal phishing trends once again show that attackers are taking advantage of increased online shopping. Fraudsters doubled their efforts in November attacking ecommerce giants such as Amazon. The real attacker focus, however, was cryptocurrency with fraudulent sites attempting to steal crypto-exchange credentials.
JWT brings performance to identity assertion and is being widely adopted, but it’s also garnering the attention of cybercriminals.
While DDoS attack rates hold, tensions rise for organizations trying to mitigate app-targeted attack that can be easily launched by script kiddies.
Standard mobile banking trojans post their own fraudulent content over banking applications. Yasuo-Bot goes further.
Three years of reported security incidents shows continued growth in denial-of-service and password login attacks such as brute force and credential stuffing.
TA551 (AKA Shathak) deploys the IcedID banking trojan using COVID-19 in Microsoft Word documents containing a malicious macro that drops an installer.
The Australian threat landscape closely mirrored the threats we observed in Asia, with an added focus on NetBIOS port 139.
We analyzed the last three years of DDoS data, and found attackers shifting to more complex approaches, and shifting up the stack.
Kazakhstan is now asking its citizens to install digital certificates so that it can decrypt all online communications. Their methods, however, may leave the population vulnerable to cyber attacks for many years to come.
Cyber attackers seem to follow President Trump to every important international meeting, but Russia was not the main source of cyber attacks during the recent Trump-Putin meeting, China was.
Ongoing campaign analysis has revealed that Dridex malware's latest focus has strongly shifted in recent months to US banks.
With the vast availability of new exploits and the competition for victims’ resources, the multi-exploit trend continues to be popular among attackers.
TrickBot shows no signs of slowing down as new targets are added and command and control servers hide within web hosting providers’ networks.
This is the quick espresso-style rundown on the 2018 threat landscape. This summary boils down the trends in the application threats, as well as our recommendations for managing application risk as it evolves.
DanaBot makes a strong resurgence at the end of 2019, using new tactics and techniques and expanding beyond its traditional banking targets.
Gozi authors, who targeted banks in Canada, France, and the US in January 2019, shifted their targets to Italian banks in February 2019.
Cybersecurity attacks surged during the pandemic, with large jumps in DDoS and password login attacks against online retailers and APIs.
TrickBot, the latest arrival to the banking malware scene and successor to the infamous Dyre botnet, is in constant flux.
The Internet is full of information about your company that’s easily accessible to anyone and particularly useful to attackers.
Webinject crafting is a separate profession now. Hackers write webinjects and sell them to fraudsters, who use them to weaponize Trojans.
A look at cybersecurity incidents at banks, credit unions, insurance companies, government-sponsored financial institutions, and stock exchanges.
Gozi “banking” trojan continues to shift its targets beyond banking as it employs client-side and server-side evasion techniques via time-tested web injection.
The virtual kidnapping scam is on the rise because of the excessive amount of personal information people volunteer on social media.
Safeguarding TLS against attack in the quantum computing age will require changes to today’s TLS key exchange algorithms.
How certificate transparency can help you spot fraudulently registered TLS certificates that exploit your domain or brand name.
Phishing attack? Absolutely. Success? Likely. Risk of incident? High. Breach costs? About $6.5 million.
As security professionals, we often feel like we’re fighting a losing battle when it comes to cyber security.
Cloud security breaches happen, but how prevalent and dangerous are they? More than you might think.
Did automation targeting retail companies rise towards Black Friday 2022?
The rather old CVE-2017-9841, an RCE in PHPUnit, suddenly jumps to the top of our list, with an increase of nearly 400% since last month. We dig into the scanning infrastructure.
Credential stuffing is a multifaceted and enduring risk to organizations of all types and sizes. This report is a comprehensive examination of the entire life cycle of stolen credentials—from their theft, to their resale, and their repeated use in credential stuffing attacks.
While app usage and breach costs differ by industry, most organizations, in the face of growing app dependence, still struggle with who owns responsibility for protecting them.
As TrickBot evolves, we examine version 24, which heavily targets Nordic financial institutions, and we take a close look at the Dyre–TrickBot connection.
Learn which CVEs attackers scanned for the most in July 2022, and how it compares with the rest of the year.
Nearly 200,000 servers are still vulnerable to Heartbleed—and the organizations who own them might surprise you.
Bot traffic for the first half of 2023 was fairly typical, some rapid change in a few industries notwithstanding. Learn who got hit hard and who got off easy.
An F5 Labs survey of Gen Z-ers revealed they are not much more security savvy online than Millennials.
The Mirai botnet has infected hundreds of thousands of Internet of Things (IoT) devices, specifically security cameras, by using vendor default passwords for Telnet access.
The attack landscape targeting US systems was characterized by a large amount of traffic directed at web applications and web app databases.
Your data is at risk. Are you equipped to combat the risks posed by BlackGuard?
The same drop zone server used last week to mine Monero on compromised Jenkins automation servers is now being used in a new Monero mining campaign targeting Oracle Web Logic servers.
Cyberattacks in Q3 2020 targeted WordPress and other content management systems, IoT devices, and the State of Israel.
Unveiling the rise of Hacktivism in a tense global climate.
Attackers are using IP addresses in the Netherlands, United States, and China to target systems in Europe over SIP, Microsoft SMB, and SSH.
In April, threat actors focused on targeting vulnerabilities that had the highest impact: this month it was a recently released deserialization vulnerability in Oracle WebLogic Server.
We are excited to announce a new report covering threats to digital identities. This report goes into detail on credential stuffing, phishing, and multifactor authentication bypass techniques.
Application programming interfaces (APIs) are a growing attack surface, offering predators unprecedented access to large data stores. As serverless, mobile, and online platforms grow, API attacks will surely rise.
IoT attacks show no signs of decreasing while infected IoT devices go un-remediated, and discovery of new thingbots is at a decade-long high.
Not all bots are bad, but for those that are, you need a multi-pronged strategy for keeping them off your network.
The title of this report is not a typo. “The State of the State of Application Exploits in Security Incidents” is a meta-analysis of several prominent industry reports, each of which covers the state of application security.
VBKlip has evolved significantly from searching for IBAN data in copy-paste functionality to MITB techniques.
Email has become such an ordinary part of our daily lives that we can forget how vulnerable it is.
We dig into the credential stuffing attack tool OpenBullet and look at configuring combolists, proxies, parse tokens, and check blocks for launching attacks.
First detected in May 2018, DanaBot is a fraud trojan that has since shifted its targets from banks in Australia to banks in Europe, as well as global email providers such as Google, Microsoft and Yahoo for the holiday phishing season.
As the black-market price for stolen data declines, attackers turn to cryptojacking schemes to maximize their profits—all at your expense.
Learn how the threat landscape evolved in 2021 so you can tune your defenses to suit.
Explore a highly automated attack against a sneaker manufacturer and learn how resellers optimize their bots for success, and profit!
A simple search of public records confirms the astounding number of potentially vulnerable cellular gateways in use in many cities’ emergency services vehicles.
Rental scams are getting more sophisticated and are making it harder for legitimate landlords and renters to find each other.
Webinject attacks modify webpages to allow fraudsters to collect credentials, or act more directly against user accounts.
Most security researchers have good intentions, but ethics must play a central role in the decisions they make.
In our 2020 edition of the Phishing and Fraud Report, we focus on how cybercriminals build and host phishing sites, the tactics they use to avoid detection, and how they’ve capitalized this year on the COVID-19 pandemic.
Latin America’s cyberattack landscape saw continued focus on port 5900 and the targeting of common web vulnerabilities.
Panda malware is back with a March 2019 campaign that targets U.S. companies, and moves from cryptocurrencies to targeting web giants.
We spotted a new Microsoft Exchange zero day and more security infrastructure vulns, as well as all of the usual suspects, in this month’s installment on vulnerability targeting.
Attackers probed Australian applications for vulnerabilities on the most commonly used ports, and credential stuffing attacks were prevalent.
We add two IoT CVEs and discuss the other sorts of traffic we see regularly.
Part three of a series investigating how automation is used to create fake accounts for fraud, disinformation, scams, and account takeover.
Stop feeding attackers every piece of the puzzle they need to pull off their scams.
In this companion podcast, the researchers who created the F5 Labs Application Protection Report discuss their findings, and share the details and backstories that helped shape the final report.
Attacks are back to targeting a Windows IIS vulnerability first disclosed a year ago to mine Electroneum.
Data miners and scraper bots are everywhere, feeding AI LLMs and more, and many of them are NOT harmless.
A detailed look at the cybersecurity threats to the COVID-19 vaccine rollout pipeline
In July, vulnerable web servers continued to be the target of threat actors attempting to install cryptominers.
Using existing protocols and tools to begin building a robust phishing and fraud mitigation strategy.
Scans continue against remote logins like VNC, RDP, and SSH, as well as MySQL and Elasticsearch. And what’s going on in Malaysia and Lithuania?
Trickbot authors gain precious time to defraud unsuspecting victims by adding an encryption layer that slows down the malware investigation process.
Ramnit’s latest twist includes targeting the most widely used web services during the holidays: online retailers, entertainment, banking, food delivery, and shipping sites.
Distributed denial-of-service attacks soared in complexity and size during 2021. While the overall number of DDoS attacks declined marginally compared with 2020, the F5 Silverline team saw the largest attack in 2021 peak at nearly 1.4 Tbps, 5.5 times larger than the largest attack in 2020.
Dyre is one of the most sophisticated banking malware agents in the wild.
These are the top threats you should know about this week.
These are the top threats you should know about this week.
These are the top threats you should know about this week.
These are the top threats you should know about this week.
These are the top threats you should know about this week.
These are the top threats you should know about this week.
These are the top threats you should know about this week.
These are the top threats you should know about this week.
These are the top threats you should know about this week.
These are the top threats you should know about this week.
These are the top threats you should know about this week.
These are the top threats you should know about this week.
These are the top threats you should know about this week.
These are the top threats you should know about this week.
These are the top threats you should know about this week.
These are the top threats you should know about this week.
These are the top threats you should know about this week.
These are the top threats you should know about this week.
These are the top threats you should know about this week.
These are the top threats you should know about this week.
These are the top threats you should know about this week.
These are the top threats you should know about this week.
These are the top threats you should know about this week.
These are the top threats you should know about this week.
These are the top threats you should know about this week.
These are the top threats you should know about this week.
These are the top threats you should know about this week.
These are the top threats you should know about this week.
These are the top threats you should know about this week.
These are the top threats you should know about this week.