Delving Into the SparkRAT Remote Access Tool

Sensor Intel Series: May 2025 CVE Trends

2025/6/3
阅读更多

CASI Leaderboard Shifts: Sugar-Coated Poison, and the Expanding AI Attack Surface

AI Security Insights – March 2026

2026/3/5
阅读更多

SparkRAT: Exploiting Architectural Weaknesses in Open-Source Offensive Tools

Persistent trend in open-source offensive tooling & implications for defenders

2025/8/6
阅读更多

Fallacy Failure Attack

AI Security Insights for November 2025

2025/11/26
阅读更多

Azure-Hosted Scanning Cluster Launches WordPress Webshell Discovery Campaign

Sensor Intel Series: March 2026 CVE Trends

2026/4/15
阅读更多

More Mozilla User-Agents, Please: a Deep Dive into an Inadvertent Disclosure Scanner

Sensor Intel Series: September 2025 Trends

2025/9/15
阅读更多

F5 Labs Top CWEs & OWASP Top Ten Analysis

We expand our view to include CWE and OWASP, and we also examine the latest overall trends for June 2025.

2025/6/12
阅读更多

2026 Cybersecurity Predictions

Whatever you think will happen… will happen faster and with more acronyms than ever before.

2025/12/15
阅读更多

Drupal Core CVE-2026-9082 Active Exploitation Confirmed Within Days of Disclosure

Sensor Intel Series: June 2026 CVE Trends

2026/6/11
阅读更多

Why Critical MongoDB Library Flaws Won't See Mass Exploitation

Discover how to mitigate CVE-2024-53900 and CVE-2025-23061, which expose Node.js APIs to remote attacks.

2025/3/13
阅读更多

2025 Advanced Persistent Bots Report

Uncovering the true scale of persistent bot activity, and the advanced techniques that bot operators use in order to remain hidden from bot defenses.

2025/3/28
阅读更多

When AI Gets Bullied: How Agentic Attacks Are Replaying Human Social Engineering

AI Security Insights – January 2026

2026/1/13
阅读更多

Continued Scanning for CVE-2023-1389

TP-Link draws the attention of the US Government.

2025/1/21
阅读更多

Analyzing React2Shell Threat Actors

Sensor Intel Series: December CVE-2025-55182 Trends

2026/1/16
阅读更多

Canary Exploit Tool for CVE-2025-30065 Apache Parquet Avro Vulnerability

Investigating a schema parsing concern in the parquet-avro module of Apache Parquet Java.

2025/5/5
阅读更多

CVE-2026-63030 and CVE-2026-60137: 'wp2shell' Captured Exploit Payload

Sensor Intel Series: August 2026 CVE Trends

2026/8/8
阅读更多

NoBooze1 Malware Targets TP-Link Routers via CVE-2019-9082

Sensor Intel Series: July 2025 CVE Trends

2025/7/16
阅读更多

The Prevalence of Web-Based RCE Vulnerabilities

Sensor Intel Series: July 2025 CVE Trends

2025/8/27
阅读更多

Chinese Open-weight AI Models: Cybersecurity Risks and Rewards

Chinese models show variation from month to month, highlighting the uncertain and unstable nature of their security posture

2026/7/30
阅读更多

Analyzing the Global Increase in Vulnerability Scanning in 2024

BotPoke comes to the foreground yet again.

2025/3/21
阅读更多

CVE-2024-44000 (LiteSpeed Cache Account Takeover) Ranks in June’s Top Threats

Sensor Intel Series: July 2026 CVE Trends

2026/7/20
阅读更多

Looking at the SmarterMail API Vulnerability CVE-2026-24423

Sensor Intel Series: February 2026 CVE Trends

2026/3/12
阅读更多

Topic Bridge

CASI leaderboard shifts, and two incidents where AI was handed the keys.

2026/6/3
阅读更多

Microsoft Exchange ProxyShell Scanning Doubles in April 2026 as Two Distinct Campaign Clusters Emerge

Sensor Intel Series: April 2026 CVE Trends

2026/5/19
阅读更多

The Small Model Cliff

CASI Leaderboard, Bias Jailbreak, and Three Coordinated Supply Chain Incidents

2026/5/27
阅读更多

Analysis of a Large-Scale DDoS Attack Against a Payment Processing Platform

The two-wave attack reached a peak of 1.8 Tbps.

2025/11/19
阅读更多

Introducing the F5 Labs Weekly Threat Bulletin

F5 Labs’ Weekly Threat Bulletin delivers fast, AI‑driven insights on emerging cyber threats with IoCs, mitigation tips, and expert‑validated guidance.

2026/1/23
阅读更多

Prevent Web Scraping by Applying the Pyramid of Pain

The Bots Pyramid of Pain: a framework for effective bot defense.

2025/3/28
阅读更多

GeoServer Targeting on the Rise

Sensor Intel Series: January 2026 CVE Trends

2026/2/11
阅读更多

The Ghost in the Shell: Why Agentic AI is a Corporate Security Nightmare

Autonomous AI agents blur security boundaries, enabling data exfiltration, privilege abuse, and insider‑level risk in enterprises.

2026/2/24
阅读更多

Adversarial Tales

A competitive open-weight model, Claude Fable, and Jade Puffer

2026/7/14
阅读更多

Tracking RondoDox: Malware Exploiting Many IoT Vulnerabilities

Over a dozen exploits were used to target IoT devices.

2025/11/24
阅读更多

Enterprises Should Consider Replacing Employees’ Home TP-Link Routers

An examination of CVE trends from February 2025 scanning data.

2025/3/6
阅读更多

AI Capabilities Are Advancing Faster Than AI Security

AI Security Insights – February 2026

2026/2/26
阅读更多

Introducing the CASI Leaderboard

Explore the new AI security index for emerging trends in AI security.

2025/9/29
阅读更多

Campaign Targets Amazon EC2 Instance Metadata via SSRF

Discover the latest CVE trends and a new campaign targeting websites hosted in EC2 instances on AWS.

2025/4/8
阅读更多

The State of Post-Quantum Cryptography (PQC) on the Web

We analyze the world’s most popular websites and most widely used web browsers to determine the current state of PQC adoption on the web.

2025/6/26
阅读更多

Adversarial Poetry and the Efficacy of AI Guardrails

We investigate the rise of adversarial poetry in AI security. Understand how metaphor-based exploits circumvent guardrails and the defenses we need for LLMs moving forward.

2025/12/11
阅读更多

ShellShock Makes a Comeback and RondoDox Changes Tactics

Legacy bugs continue to serve attackers.

2025/12/8
阅读更多

CASI Leaderboard Shifts: Developer Role Attack, and Three Concerning Incidents

AI Security Insights – April 2026

2026/4/9
阅读更多

HashJack Attack Targets AI Browsers and Agentic AI Systems

A new wave of client-side attacks bypasses enterprise defenses.

2025/12/5
阅读更多

2025 Advanced Persistent Bot Report: Scraper Bots Deep-Dive

How much do scraper bots affect your industry?

2025/3/29
阅读更多

The Dangers of DNS Hijacking

How expired domains and improper DNS management can lead to severe security risks like MitM attacks, fraudulent TLS/SSL certifications, and more.

2025/1/9
阅读更多

Capability Is Closing the Open-Closed Gap; Security Is Not

A competitive open-weight model, Claude Fable, and Jade Puffer.

2026/8/12
阅读更多

2024 Vulnerability Scanning Surges 91%

Scans intensify, looking for a critical vulnerability in TBK DVR devices.

2025/2/18
阅读更多

The Hunt for IoT: The Rise of Thingbots

With “thingbots” now launching Death Star-sized DDoS attacks, hosting banking trojans, and causing physical destruction, all signs point to them becoming the attacker infrastructure of the future.

2017/8/9
阅读更多

Can Bots Manipulate Data and Change Facts to Fiction?

Data manipulation is a real threat to data-driven approaches at enterprises. We tested one of our own assets to see the possibilities.

2021/1/13
阅读更多

Tackling Gootkit's Traps

Gootkit malware uses misleading code to hinder manual research and automated analysis.

2018/7/11
阅读更多

Black Friday Versus The Bots

What can last year’s Black Friday shopping trends teach us about expected attacker behavior during the 2024 holiday shopping season?

2024/11/21
阅读更多

Vulnerabilities, Exploits, and Malware Driving Attack Campaigns in December 2019

Threat campaign activity in December 2019 doubled from the previous month.

2020/1/31
阅读更多

Sensor Intel Series: Top CVEs in August 2022

Learn what attackers scanned for last month so you can tune your defenses.

2022/9/20
阅读更多

Sensor Intel Series: Top CVEs in April 2023

A new vuln popped up in our traffic this month, as well as lots of the same old CVEs—IoT and Microsoft Exchange.

2023/5/19
阅读更多

Sensor Intel Series: Top CVEs in February 2024

27 new CVEs, and continued IoT targeting. See what's new from February 2024.

2024/3/28
阅读更多

Introducing the Cryptonice HTTPS Scanner

F5 Labs has released a new open-source tool to check for HTTPS misconfigurations of public and internally hosted HTTPS websites.

2020/7/17
阅读更多

Old Dog, New Targets: Switching to Windows to Mine Electroneum

Apache Struts 2 Jakarta Multipart Parser RCE crypto-mining campaign is now targeting Windows, not just Linux systems.

2018/3/28
阅读更多

The Global Playing Field is Leveling Out as Europe and Asia Take on More DDoS Attacks

The latest DDoS trends include the return of large volumetric DDoS attacks, the rise of application targeted attacks, and businesses in Europe and Asia are growing targets.

2018/4/6
阅读更多

DDoS’s Newest Minions: IoT Devices (Volume 1)

The latest evolution of cyber weapons is brought to you by the default passwords in Internet of Things (IoT) devices.

2016/10/8
阅读更多

From NSA Exploit to Widespread Ransomware: WannaCry Is on the Loose

The new EternalBlue NSA exploit is powering a wave of virulent ransomware sweeping across Europe.

2017/5/12
阅读更多

2021 APR Supplement: Of Sectors and Vectors

A detailed examination of application risk and cybersecurity attack chains, broken down by sector.

2021/6/23
阅读更多

Cyberattacks Targeting South Africa, January through June 2021

South Africa’s cyberattack landscape saw targeting of Scryba, PHP, and CVE-2017-9841 web vulnerabilities.

2021/9/11
阅读更多

Web Injection Threats: The Cost of Community Engagement on Your Site

Customer engagement drives web application design, but user-generated content brings inherent security challenges.

2016/7/22
阅读更多

RSA in a “Pre-Post-Quantum” Computing World

Quantum computing is coming. What should your strategy be today to deal with what’s on the horizon?

2017/8/1
阅读更多

The 2021 TLS Telemetry Report

Creating an encrypted HTTPS website depends on a lot more than simply throwing a digital certificate at it and hoping for the best. In fact, Transport Layer Security (TLS) and HTTPS misconfigurations are now so commonplace that in the 2021 OWASP Top 10, Cryptographic Failures now comes in second place.

2021/10/20
阅读更多

Sensor Intel Series: Top CVEs in November 2022

Learn which vulnerabilities attackers preferred in November.

2022/12/21
阅读更多

The Hunt for IoT: The Networks Building Death Star-Sized Botnets

With a growth rate of 1,473% in 2016, the hunt for vulnerable IoT devices rages on...

2017/5/10
阅读更多

How To Survive the Rash of Ransomware

Ransomware is ramping up, especially in the public sector. The key to stopping these attacks is to focus on the ransomware attack vectors.

2019/9/5
阅读更多

How Credential Stuffing Bots Bypass Defenses

Website logins are under constant assault, with attackers quickly modifying their bots to evade simplistic defenses.

2020/8/26
阅读更多

Cryptocurrency Hacks 2019

Attacks against exchanges, exit scams and nation-state threats mean that cryptocurrencies retain their Wild West character in 2019.

2019/9/11
阅读更多

FluBot’s Authors Employ Creative and Sophisticated Techniques to Achieve Their Goals in Version 5.0 and Beyond

A deconstruction of FluBot 5.0’s new communication protocol and other capabilities FluBot uses to hide, making it difficult for researchers and security solutions to detect.

2022/1/6
阅读更多

Will Losses from Cryptocurrency Exchange Hacks Hit a Billion Dollars In 2018?

Cryptocurrency exchanges and their supporting application systems are being attacked at an unprecedented level. As the value of cryptocurrency has climbed, so has the incentive to steal.

2018/10/18
阅读更多

Vulnerabilities, Exploits, and Malware Driving Attack Campaigns in June 2019

Similar to April and May, threat actors in June continued targeting the deserialization vulnerabilities found in Oracle WebLogic to mine cryptocurrency.

2019/7/31
阅读更多

What Happens to Encryption in a Post-Quantum Computing World?

As the possibility of quantum computing draws nearer, changes to today’s TLS key exchange algorithms will be required.

2017/11/7
阅读更多

BackSwap Defrauds Online Banking Customers Using Hidden Input Fields

BackSwap demonstrates unique behavior in its manipulation of user input fields and its handling of International Bank Account Numbers (IBANs).

2018/6/29
阅读更多

2020 APR, Vol. 1: APIs, Architecture, and Making Sense of the Moment

APIs have become critical for business online, but they are also leading to more security incidents, most of which should have been preventable.

2020/7/31
阅读更多

Ramnit’s Twist: A Disappearing Configuration

The Ramnit banking Trojan continues to evolve, this time with the intent of making the malware harder to detect.

2017/2/17
阅读更多

Regional Threat Perspectives, Fall 2019: Russia

The same countries that attacked the rest of the world also attacked systems in Russia, but from different networks and IP addresses.

2019/12/23
阅读更多

Explaining the Widespread log4j Vulnerability

The log4j security vulnerability is one of the most widespread cybersecurity vulnerabilities in recent years. Here's a non-technical explanation of it.

2021/12/12
阅读更多

Cyber Threats Targeting Europe, Winter 2019

European systems saw large volumes of attack traffic coming from in-region IP addresses attempting to conduct abusive port scanning.

2020/3/13
阅读更多

What Are The Spring4Shell Vulnerabilities?

Despite how they sound, Spring4Shell and the related vulnerabilities in the Spring Framework aren’t exactly like Log4Shell. Learn how they work and what you can do.

2022/4/1
阅读更多

Ready or Not, Cyberwarfare Is Here

By targeting critical infrastructure, cyberwarfare attackers can plunge a nation into chaos without ever firing a single shot.

2018/9/25
阅读更多

Know the Risks to Your Critical Apps and Defend Against Them

Critical apps are the ones that must never go down or be hacked. They are also the hardest to defend because they are often massive, ancient, and touch everything.

2018/4/10
阅读更多

Regional Threat Perspectives, Fall 2019: Asia

Attackers targeted applications and conducted credential stuffing attacks against systems in Asia during the fall of 2019.

2019/12/19
阅读更多

Post-Breach Analysis: Sophistication and Visibility

Analyzing a single attack in detail yields interesting findings about attacker sophistication, living off the land, and architectural risk.

2022/10/18
阅读更多

2024 Bad Bots Review

Learn the latest trends in bots and malicious automation so you can compare with attacks against your own organizations.

2024/3/14
阅读更多

Application Protection Report 2019, Episode 4: Access Attack Trends in 2018

The tactic that featured most prominently in U.S. data breaches in 2018 was access attacks, such as phishing or credential stuffing. We identified the changing patterns, and provided some tips on how to prevent them.

2019/6/25
阅读更多

Interview With the Experts: The Future of IoT Security Through the Eyes of F5 Threat Researchers

When it comes to IoT threats, we’re nowhere near being out of the woods yet; we’ve just barely entered the forest.

2017/10/19
阅读更多

2018 Application Protection Report

In this report, we demystify the complexities of apps, explore how and where they’re attacked, and provide practical steps to take now to start winning the app protection battle.

2018/7/25
阅读更多

Phishing for Information, Part 4: Beware of Data Leaking Out of Your Equipment

Organizations often overlook the many ways in which their own systems put useful information right into the hands of attackers building cyber scams.

2017/9/7
阅读更多

Vulnerabilities, Exploits, and Malware Driving Attack Campaigns in March 2019

In March, threat actors focused on targeting vulnerabilities released in the last few months. WordPress Easy SMTP Plugin Authentication Bypass vulnerability attacks had the most impact during that time frame.

2019/4/9
阅读更多

“CryptoSink” Campaign Deploys a New Miner Malware

Attackers continue to exploit old vulnerabilities, use new methods to kill competing crypto-miners, and survive removal by administrators.

2019/3/13
阅读更多

Sensor Intel Series: Top CVEs in August 2023

A few formerly popular CVEs fell in traffic in August, leaving an old router vuln to resume its normal position at the top. Plus seven new CVEs added to the list of signatures.

2023/9/25
阅读更多

Privacy and Surveillance: How Generation Z and Millennials See the Internet of Things

Over 700 survey respondents from different generations shared their views about the IoT and the tradeoffs between privacy and convenience.

2020/4/14
阅读更多

Apache Struts 2 Vulnerability (CVE-2018-11776) Exploited in CroniX Crypto-Mining Campaign

Attackers are exploiting new vulnerabilities almost as quickly as they're being discovered.

2018/9/4
阅读更多

Bleichenbacher Rears Its Head Again with the ROBOT Attack

Bleichenbacher attacks will likely continue to pop up until TLS 1.3 is fully adopted, which could take years.

2017/12/27
阅读更多

Sensor Intel Series: Top CVEs in March 2024

TP-Link Archer AX21 Wifi Router targeting, plus a handful of new CVEs! See what mass scanning looks like in March 2024.

2024/4/30
阅读更多

2019 Application Protection Report

This is the full version of the 2019 Application Protection Report. It contains research and data from all of the 2019 volumes, updated with 2019 breach trends that paint a clearer picture of where application threats are heading.

2020/5/11
阅读更多

Attacker Tricks for Taking Over Risk-Based Multifactor Authentication

From spoofing device fingerprints to hijacking authenticated sessions, attackers use a range of techniques to bypass multifactor authentication.

2021/6/17
阅读更多

Default Passwords Are Not the Biggest Part of the IoT Botnet Problem

Providers and manufacturers could go a long way toward reducing the very real threat of IoT.

2017/6/6
阅读更多

2021 Application Protection Report: Of Ransom and Redemption

The 2021 version of F5’s continuing analysis of the application security threat landscape explores ransomware, payment card theft, and account takeover.

2021/5/18
阅读更多

NSA, CIA Leaks Provide a Roadmap to Stealthier, Faster, More Powerful Malware Like SambaCry and NotPetya

Recent NSA and CIA leaks exposed advanced new techniques for building automated malware factories that churn out threats like SambaCry and Petya/NotPetya, which deploy over untraceable networks.

2017/6/27
阅读更多

Vulnerabilities, Exploits, and Malware Driving Attack Campaigns in October 2019

Vulnerable web servers are the top target for threat actors, who continue to exploit known vulnerabilities with the goal of running commands remotely.

2019/11/26
阅读更多

The 2016 TLS Telemetry Report

In just four short years, encryption estimates have gone from almost non-existent (in the low single digits before 2013) to just over 50% by the end of 2016. How much of a victory is this?

2017/1/19
阅读更多

Application Protection Report 2019, Episode 2: 2018 Breach Trends

Analysis of public breach reports showed a relationship between business models and breach vectors, with injection and phishing the leading causes.

2019/4/8
阅读更多

Regional Threat Perspectives, Fall 2019: Middle East

IP addresses assigned in Russia launched significantly more attacks against Middle East systems than any other regions of the world.

2019/11/21
阅读更多

rTorrent Client Exploited In The Wild To Deploy Monero Crypto-Miner

A previously undisclosed misconfiguration vulnerability in the rTorrent client is being exploited in the wild to mine Monero.

2018/2/28
阅读更多

Cyber Threats Targeting Middle East, Winter 2019

Attackers used two top ASNs to broadly distribute IP addresses in an attempt to camouflage attack traffic targeting Middle Eastern systems.

2020/3/11
阅读更多

Top Attacks Against Service Providers 2017-2019

Three years of data shows DDoS attacks against service providers are growing while brute force and other authentication attacks are slowly waning.

2020/2/6
阅读更多

The Startup Security Challenge: Safe in the Cloud From Day One

How this cloud startup met its goals for security and availability right out of the gate by setting goals, doing a risk analysis, and examining tradeoffs.

2017/11/30
阅读更多

New Threat May Slip Through the KRACK in BYOD Policies

Combating this vulnerability might mean you have to force updates on employees’ personal devices or deny them access altogether.

2017/10/17
阅读更多

Abusing Googlebot Services to Deliver Crypto-Mining Malware

Seventeen years after the opportunity for abuse was made public, attackers are finding new ways to make use of this unpatched web crawler service.

2018/10/9
阅读更多

DDoS Against a Financial Service: Analysis of a Massive Attack

A detailed look at an 840-Gbps DDoS attack on a financial services provider and a deeper dive into attacking nodes.

2021/8/23
阅读更多

Gootkit Italian Campaign Overview

The Gootkit banking trojan is still active and protecting itself in Italy using a dedicated redirection defense.

2019/6/18
阅读更多

Application Protection Report 2019, Intro Episode: Why Application Security?

Find out why we care so much about application security, how applications have grown into the weird beasts that they are today, and how our work fits into the bigger picture of securing and running an application.

2019/7/22
阅读更多

Dyre Update: Moving to Edge and Windows 10 With Anti-Antivirus

Dyre malware requires little introduction as it has been the focus of many publications, and it is a well-known threat. One of the reasons for it being so infamous is the frequent changes the authors incorporate in...

2015/11/11
阅读更多

Regional Threat Perspectives, Fall 2019: Canada

The U.S. and Canada have 95% of top source traffic countries in common.

2019/12/2
阅读更多

Russia Attacks Global Network Infrastructure Through Vulnerabilities That Extend Far Beyond Their Targets

US-CERT TL18-106A alert underscores how insecure Internet systems really are and that ignoring the problem only increases the collateral damage.

2018/5/4
阅读更多

The 2017 TLS Telemetry Report

Privacy today isn’t just about staying away from prying eyes. The very act of communicating across the Internet with open, non-confidential protocols invites exposure to multiple threat types.

2018/4/23
阅读更多

De-icing IcedID: Decompression and Decryption Methods Explained in an IcedID Attack

We detail the steps for decrypting and decompressing IcedID webinject files, enabling researchers to analyze IcedID samples and pull out target and web injection files.

2019/9/4
阅读更多

Wirex Android DDoS Malware Adds UDP Flood

As quickly as attackers commandeer IoT devices to build more “thingbots,” they continue to evolve their attack types and functionality.

2017/9/1
阅读更多

Scanning for TP-Link Wifi Router Vulnerability Increases by 100%

The TP-Link Archer AX21 Wifi Router vulnerability CVE-2023-1389 experiences massive targeting along with a rather old critical RCE in PHPUnit.

2024/6/21
阅读更多

Is HEIST a Risk or a Threat?

HEIST is an example of how risk and threat are different, and why the distinction matters.

2016/8/12
阅读更多

Sensor Intel Series: Top CVEs in September 2023

We added another signature (for CVE-2020-0618) and we take a look at a cred stuffing attack from last month. One formerly prevalent CVE has disappeared entirely, and we investigate why that happened.

2023/10/18
阅读更多

The Good News About Breaches

Security breaches in the news serve as a good reminder to check and make sure you have a solid application protection strategy in place, starting with never trusting user input.

2017/10/4
阅读更多

New Python-Based Crypto-Miner Botnet Flying Under the Radar

A new Python-based botnet that mines Monero spreads via SSH and leverages Pastebin to publish new C&C server addresses.

2018/1/3
阅读更多

Fake Account Creation Bots – Part 4

The fourth and final part of a series investigating how automation is used to create fake accounts for fraud, disinformation, scams, and account takeover.

2023/12/8
阅读更多

Malware Targeting Bank Accounts Has a Swapping Pattern

F5 Labs analysts discovered a target pattern in the IBAN number formats as well as weekly changes to the script injection content. In May 2016, the F5 Security Operations Center (SOC) detected a generic form grabber and IBAN (International Bank...

2016/9/1
阅读更多

Sensor Intel Series: Top CVEs in June 2023

In terms of attacker interest, it was more about continuity than change in June, with many of the same old CVEs being targeted.

2023/7/21
阅读更多

BotPoke Scanner Switches IP

Our top talker changes up their infrastructure, and CVE-2023-1389 continues to hold the top spot.

2024/11/25
阅读更多

Strike Back at Silent Bob: Scan and Block Ports Used by Intel AMT

Is the Intel AMT vulnerability as bad as we all first thought? Either way, here are some suggestions for protecting yourself.

2017/5/16
阅读更多

Top Attacks Against Financial Services Organizations 2017–2019

Attackers are targeting financial services organizations with brute force, credential stuffing, and DoS attacks. See how you can mitigate the risks.

2020/4/27
阅读更多

Cyberthreats Targeting Canada, Winter 2019

The Canadian threat landscape was characterized by a large amount of attack traffic from in-county systems, which can be the most difficult to filter.

2020/4/3
阅读更多

Internet, We (Still) Have a Problem With Internationalized Domain Names

Even URLs that look legitimate can be fake, so train, train, train your users to verify links before they click.

2017/4/25
阅读更多

We Expected SSL Everywhere, and It’s Well on the Way

Malicious actors and eavesdroppers are forcing Internet communication into a single cryptographic protocol: SSL.

2016/8/2
阅读更多

Profile of a Hacker: The Real Sabu, Part 1 of 2

Notorious hacker of Anonymous and LulzSec fame is challenged by rival hacker, The Jester, to reveal his identity.

2017/4/18
阅读更多

If Your Security Question List Looks Like a Facebook Favorite List, Start Over Now

Seriously, how many colors are there? And how many of us share the same love of one of those limited choices?

2017/11/21
阅读更多

Cyber Threats Targeting Asia, Winter 2019

Asian systems saw a large amount of SMB attack traffic during this time period, mainly driven from in-region IP addresses.

2020/3/6
阅读更多

Drupalgeddon 2 Highlights the Need for AppSecOps

If you aren’t aware of Drupalgeddon 2, then you’ve either been living off the grid or don’t use the popular content management system (CMS).

2018/5/11
阅读更多

Trickbot Rapidly Expands its Targets in August, Shifting Focus to US Banks and Credit Card Companies

TrickBot kicked into high gear coming into August with the most targeted URLs since its launch. It released a new worm module, shifted its focus towards the US, and soared past the one thousand target URL mark in a single configuration.

2017/9/14
阅读更多

2023 Identity Threat Report: Executive Summary

Welcome to the fun-size version of our 2023 Identity Threat Report! If you only have 5 minutes to spare this is the place to start - and you can always download the full PDF for later.

2023/11/1
阅读更多

SambaCry: The Linux Sequel to WannaCry

With simple exploits plaguing Windows and Linux SMB week over week, do yourself a favor and patch for CVE-2017-7494 now to avoid having to do it in panic mode.

2017/5/26
阅读更多

Cyberthreats Targeting India, October through December 2020

India’s attack landscape saw focus on Port 5900 and the highest number of scans from the UK.

2021/2/11
阅读更多

Reaper: The Professional Bot Herder’s Thingbot

While Reaper might be considered an “object lesson” today, it should serve as a blistering warning that IoT security needs to be fixed now.

2017/10/26
阅读更多

Sensor Intel Series: Top CVEs in February 2023

One IoT vulnerability stops growing, and another one starts. See what attackers are up to this month.

2023/3/25
阅读更多

Thanks to Anonymous’ Latest Toolset, Anyone Can Play the DDoS Game

Anonymous commoditizes well-known DDoS attacks by making easy-to-use tools, available to even the most unsophisticated user.

2016/6/1
阅读更多

Mirai is Attacking Again, So We’re Outing its Hilarious, Explicit C&C Hostnames

With Mirai rearing its ugly head again, we’re revealing its C&C hostnames so organizations can update their denylists and protect themselves.

2018/1/4
阅读更多

New Jenkins Campaign Hides Malware, Kills Competing Crypto-Miners

Threat actors continue to find creative yet relatively unsophisticated ways to launch new campaigns to reap profits from crypto-mining operations.

2018/7/6
阅读更多

Attackers Use New, Sophisticated Ways to Install Cryptominers

How a Jenkins dynamic routing vulnerability becomes an attacker’s infection vector for installing and executing a cryptominer.

2019/10/1
阅读更多

Regional Threat Perspectives, Fall 2019: Latin America

Latin American systems received more attacks from IP addresses within the region that coincidentally did not attack anywhere else in the world.

2019/12/3
阅读更多

The DNS Attacks We’re Still Seeing

F5 threat intelligence reports attackers are still doing DNS water torture DDoS, DNS reflection DDoS, expired domain takeover, and using DNS requests for covert channels.

2018/12/4
阅读更多

Breaking Down the Door to Emergency Services through Cellular IoT Gateways

If configured incorrectly, cellular IoT gateways can give attackers access to critical infrastructure, threatening human life in ways only Hollywood has conceived.

2018/8/9
阅读更多

Scanning for CVE-2017-9841 Drops Precipitously

Last issue, we observed huge amounts of scanning for the rather old CVE-2017-9841, an RCE in PHPUnit. This time it’s fallen off nearly as sharply. We look into why!

2024/8/22
阅读更多

New Golang Malware is Spreading via Multiple Exploits to Mine Monero

A newcomer to the malware scene, Golang-based malware has been seen installing cryptominers specifically targeting Moreno cryptocurrency.

2019/7/2
阅读更多

Exploited Memcached Servers Lead to Record-Setting 1.3Tbps DDoS Attack

Memcached is just one of many application infrastructure systems that could launch the same types of attacks if they were also misconfigured.

2018/3/2
阅读更多

Red Team Tools Reveal Gaps in Vulnerability Management Practice

FireEye tools show attackers aren’t worried about your defenses.

2021/1/22
阅读更多

Sensor Intel Series: Top CVEs in July 2023

One old favorite CVE declined by more than half in July, and a new one (to us) was so heavily targeted it ended up ranked fifth out of 72.

2023/8/24
阅读更多

Sensor Intel Series: Top CVEs in March 2023

Some IoT vulnerabilities, some Microsoft Exchange vulnerabilities, but not too much going on in March.

2023/4/25
阅读更多

Continued Intense Scanning From One IP in Lithuania

Plus a few interesting changes in the CVEs we track, and some notes on just what kinds of malware stagers we see.

2024/10/21
阅读更多

The Hunt for IoT: Multi-Purpose Attack Thingbots Threaten Internet Stability and Human Life

Businesses, critical systems, infrastructure, and even human life are more threatened than ever as attackers target the Internet-connected “things” that run the modern world.

2018/10/24
阅读更多

URL Obfuscation—Still a Phisher’s Phriend

Cyber crooks use several common URL disguising techniques to trick users into thinking their sham sites are legitimate.

2017/8/29
阅读更多

Vulnerabilities, Exploits, and Malware Driving Attack Campaigns in September 2019

Threat actors shift focus away from cryptominers and back to remote code execution—this month with a new zero-day exploits.

2019/10/30
阅读更多

Phishing for Information, Part 1: How Phishers Bait Their Hooks With Information You Volunteer

In this five-part blog series, we look at how cyber scammers vacuum up information across the Internet to build profiles for phishing and other kinds of social engineering attacks.

2017/7/6
阅读更多

IoT Vulnerability Assessment of the Irish IP Address Space

Vulnerability assessment of IoT devices in Ireland detailing the biggest threats, most at-risk and highly exposed devices.

2020/11/17
阅读更多

A Single IP is Scanning Intensely, and Yields a List of Malware Loaders

Overall scanning for CVEs we track is down, but one specific scanner caught our attention. We dig into what it’s doing.

2024/9/19
阅读更多

Russian Attacks Against Singapore Spike During Trump-Kim Summit

Singapore saw a sharp rise in attacks targeting a variety of ports, from SIP clear-text (5060), Telnet, SQL, and host-to-host ports to those used for remote router management and proxy servers and caching.

2018/6/15
阅读更多

New Struts 2 Campaign Compiles Its Own C# Downloader, Leverages a User Profile Page as Its C&C Server

Attackers continue to find new and creative ways to carry out malicious crypto-mining operations, employing multiple exploits in a single campaign.

2018/6/23
阅读更多

Speed Over Security Still Prevalent in Spite of Substantial Risk for IoT Apps

Speed to market means IoT and mobile apps are being released with known vulnerabilities.

2017/3/3
阅读更多

Sensor Intel Series: Top CVEs in September 2022

Learn which CVEs are top of mind for attackers this autumn.

2022/10/24
阅读更多

Academic Research: Web Application Attacks

Personally identifiable information and user credentials are the primary nuggets attackers are after when they exploit known vulnerabilities in web applications.

2017/10/10
阅读更多

New Perl Botnet (Tuyul) Found with Possible Indonesian Attribution

Tuyul bot targets vulnerable PHPUnit systems to install an Internet Relay Chat (IRC) bot.

2020/3/3
阅读更多

Marcher Gets Close to Users by Targeting Mobile Banking, Android Apps, Social Media, and Email

Marcher targets focused on European, Australian, and Latin American banks, along with PayPal, eBay, Facebook, WhatsApp, Viber, Gmail, and Yahoo—all in the month of March.

2017/4/7
阅读更多

2019 TLS Telemetry Report Summary

The Summary of the 2019 F5 Labs TLS Telemetry Report expands the scope of our research to bring deeper insights into encryption on the web, including ciphers, SSL/TLS versions, and digital certificates.

2020/2/27
阅读更多

DNS Is Still the Achilles’ Heel of the Internet

Since the Internet can’t survive without DNS, let’s make our best effort to defend it.

2017/3/10
阅读更多

Russian Hackers, Face to Face

An undercover interview of two infamous Russian hackers speak volumes about skills, passion, and motivation of some of the world’s most dangerous cybercriminals.

2017/6/21
阅读更多

Sensor Intel Series: Top CVEs in January 2023

One vulnerability took all the headlines in January, and, well, it probably won’t shock you.

2023/2/25
阅读更多

The Hunt for IoT: The Opportunity and Impact of Hacked IoT

We’re still thinking of Internet of Things devices as low risk when reality tells us exactly the opposite.

2019/7/15
阅读更多

Regional Threat Perspectives: Canada

Europe was Canada’s primary source of attack traffic targeting VoIP systems and web applications.

2019/5/28
阅读更多

rTorrent Vulnerability Leveraged in Campaign Spoofing RIAA and NYU User-Agents?

The same rTorrent XML-RPC function configuration error that was targeted to mine Monero in February was also targeted in January in a campaign apparently spoofing user-agents for RIAA and NYU.

2018/3/8
阅读更多

Why Managing Low-Severity Vulnerabilities Can’t Be Just a Pipe Dream

Putting off fixing low-severity vulnerabilities can have high-impact effects.

2017/3/3
阅读更多

Application Protection Report 2019, Episode 1: PHP Reconnaissance

Analysis of sensor data from 2018 revealed a big focus on PHP generally, and specifically a large, unsophisticated reconnaissance campaign looking for unsecured databases with PHP front ends.

2019/3/25
阅读更多

Dridex Botnet 220 Campaign: Targeting UK Financials With Webinjects

Like many other financial Trojans, the notorious Dridex malware keeps evolving and strengthening its presence.

2016/2/25
阅读更多

Regional Threat Perspectives: United States

Attackers using IP addresses in Vietnam, China, and Russia focused on attacking applications over Samba, SSH, and HTTP.

2019/5/2
阅读更多

Is the Cloud Safe? Part 2: Breach Highlights for the Past 3 Years

A deep dive into a wide variety of cloud-related security data breaches, both maliciously caused and accidental.

2019/12/30
阅读更多

Are You Ready to Handle 100+ Gbps DDoS Attacks—the New Normal?

DDoS attacks have been common since the late 2000s, but average attack peaks have increased to 100+ Gbps.

2016/6/13
阅读更多

Old Protocols, New Exploits: LDAP Unwittingly Serves DDoS Amplification Attacks

A new DDoS attack vector that leverages LDAP for reflection-amplification attacks is seeing increased usage.

2016/11/15
阅读更多

Mirai “COVID” Variant Disregards Stay-at-Home Orders

New Mirai variant references the COVID-19 pandemic with a filename change and two targets: Huawei routers and TeamSpeak.

2020/4/24
阅读更多

Joining Forces With Criminals, Deviants, and Spies to Defend Privacy

Organizations need to provide clear and specific guidance to employees who travel across national borders when it comes to giving up passwords and surrendering devices.

2017/10/12
阅读更多

Gafgyt Targeting Huawei and Asus Routers and Killing Off Rival IoT Botnets

IoT botnet Gafgyt targets popular routers through RCE vulnerabilities, and even removes competing malware.

2019/12/26
阅读更多

Introducing the Sensor Intel Series: Top CVEs Jan-Jun 2022

Learn which CVEs attackers scanned for most in the first half of 2022.

2022/8/9
阅读更多

Cyberattacks at Banks and Financial Services Organizations, and a Look at Open Banking

A review of 2018-2020 cyberattacks at brokerages, investment funds, payment processors, and financial services organizations as well as API security incidents and open banking.

2021/6/2
阅读更多

Building DDoS Botnets with TP-Link and Netgear Routers

Threat actors double down with their botnet building efforts. Vulnerable Netgear routers join exploitable TP-Link and other IoT devices, expanding attacker DDoS capabilities.

2024/5/22
阅读更多

How Three Low-Risk Vulnerabilities Become One High

It’s easy to brush off low-risk vulnerabilities as trivial—until they’re combined to create a deep-impact attack.

2017/2/13
阅读更多

Tinba Malware: Domain Generation Algorithm Means New, Improved, and Persistent

Tinba, also known as "Tinybanker", "Zusy" and "HµNT€R$", is a banking Trojan.

2014/10/15
阅读更多

DDoS Attack Trends for 2020

Denial-of-service attacks are increasing and becoming more complex. We look at how attackers are attempting to bring down services around the world.

2021/5/8
阅读更多

perlb0t: Still in the Wild with UDP Flood DDoS Attacks

Despite being around since 2005, perlb0t is still being used against unpatched servers.

2014/7/24
阅读更多

Snooping on Tor from Your Load Balancer

An F5 Labs researcher snoops on Tor exit node traffic from a load balancer. What he finds will shock you. SHOCK YOU.

2018/7/3
阅读更多

Profile of a Hacker: The Real Sabu, Part 2 of 2

New information sheds light on Sabu’s activities following the revelation of his identity.

2017/5/2
阅读更多

Tricky Trickbot Runs Campaigns Without Redirection

Known for redirection attacks, recent Trickbot banking trojan campaigns use server-side injection and target fewer victims.

2019/9/17
阅读更多

Little Trickbot Growing Up: New Campaign

Recently there have been several reports of a financial malware named TrickBot; this malware's code looks similar to Dyre.

2016/11/7
阅读更多

Thingbots and Reapers and Cryptominers—Oh, My! F5 Labs’ First Year in Review

F5 Labs covered a multitude of threats, vulnerabilities, botnets, attackers, and attacks in 2017. Here are just some of the highlights you might have missed.

2018/1/25
阅读更多

Why Cloud Sprawl Is a Security Risk

Cloud sprawl isn’t just a budget sinkhole; it’s quickly becoming a security blind spot and potential attack vector for data theft.

2017/5/18
阅读更多

Scanning For Credentials, and BotPoke Changes IPs Again

Nearly 50% of observed traffic is looking for accidentally exposed data.

2024/12/9
阅读更多

Panda Malware Broadens Targets to Cryptocurrency Exchanges and Social Media

Panda malware is back in full force with three currently active campaigns that extend its targets beyond banking to new industries and organizations worldwide.

2018/5/9
阅读更多

Genesis Marketplace, a Digital Fingerprint Darknet Store

Insights into Genesis Marketplace, a black market trading in digital identity.

2020/11/19
阅读更多

How I Hacked the Microsoft Outlook Android App and Found CVE-2019-1105

It looked like a simple XSS in the Outlook Android app, but the app developers couldn’t reproduce it so they didn’t fix it. Then things got interesting. Here’s the story of how I discovered CVE-2019-1105.

2019/6/21
阅读更多

The Hunt for IoT: So Easy To Compromise, Children Are Doing It

This episode in The Hunt for IoT Volume 6 series focuses on the threat actors building IoT botnets, how easy IoT devices are to exploit, recent thingbot discoveries, and the status of Mirai infections worldwide.

2019/8/5
阅读更多

Sensor Intel Series: Top CVEs in December 2023

We add 6 CVEs to our list and do a brief roundup of some stats from 2023.

2024/1/24
阅读更多

Spaceballs Security: The Top Attacked Usernames and Passwords

Expect a breach If you have basic, vendor default SSH credentials active on any system.

2018/12/20
阅读更多

Doxing, DoS, and Defacement: Today’s Mainstream Hacktivism Tools

Readily available hacking tools provide new ways for civil disobedience groups to antagonize their targets anonymously.

2017/4/12
阅读更多

The Credential Crisis: It’s Really Happening

With billions of data records compromised, it’s time to reconsider whether passwords are our best means for authenticating users.

2017/12/14
阅读更多

When Information Security is a Matter of Public Safety

Seven steps for improving the security of critical infrastructure systems—and protecting the public from unnecessary risk.

2018/3/22
阅读更多

From DDoS to Server Ransomware: Apache Struts 2 – CVE-2017-5638 Campaign

A common infection vector used by botnet creators is scanning the Internet for web vulnerabilities to exploit for malware or back doors. The advantage of hitting servers over personal consumer devices is the ability to leverage powerful hardware that is...

2017/3/27
阅读更多

How to Identify and Stop Scrapers

Fighting sophisticated scrapers requires advanced detection methods. Discover the techniques needed to identify and manage these hidden threats outlined in our investigation.

2024/9/5
阅读更多

How I Designed an Open Source HTTPS Checker

F5 Labs summer intern describes her experiences building a Python-based HTTPS scanning library for security research and release as an open source tool.

2020/8/18
阅读更多

Sensor Intel Series: Top CVEs in May 2023

Relative stability in attacker activity this past month serves to highlight the ongoing importance of Exchange Server vulnerabilities and poorly-secured IoT devices to attackers.

2023/6/16
阅读更多

Fake Account Creation Bots – Part 2

Part two of a series investigating how automation is used to create fake accounts for fraud, disinformation, scams, and account takeover.

2023/10/12
阅读更多

DARPA Proves Automated Systems Can Detect, Patch Software Flaws at Machine Speed

According to DARPA, it takes an average of 312 days for security pros to discover software vulnerabilities such as viruses, malware, and other attacks. In hacker time, that’s a virtual eternity in which bad actors can wreak havoc.

2016/10/23
阅读更多

Slave Malware Analysis: Evolving From IBAN Swaps to Persistent Webinjects

Slave is financial malware written in Visual Basic. Since 2015 it has evolved from relatively simple IBAN swapping.

2015/6/24
阅读更多

Regional Threat Perspectives, Fall 2019: United States

U.S. systems were heavily targeted by IP addresses in Russia, Moldova, and France that launched credential stuffing attacks on VNC port 5900 beginning in June 2019.

2019/11/25
阅读更多

The Email that Could Steal Your Life Savings and Leave You Homeless

Real estate scams are big business for attackers. Be on the lookout for this one, which can leave home buyers destitute if not caught in time.

2018/2/8
阅读更多

F5 Labs Investigates MaliBot

We found a novel malware strain that is targeting financial sites in Italy and Spain... so far.

2022/6/15
阅读更多

Collusion Fraud: The Art of Gaming the System with Complicity

How platform business models are at an increased risk of fraud when two or more separate parties collude.

2021/4/14
阅读更多

“Cry ‘Havoc’ and Let Loose the Thingbots of War!”

Gray hats might have good intentions launching their “vigilante” botnets, but are they really helping us win the war against Death Star-sized thingbots?

2017/8/17
阅读更多

Echobot Malware Now up to 71 Exploits, Targeting SCADA

A Mirai variant named Echobot appeared mid-2019. Echobot has been seen expanding its arsenal to 71 exploits, targeting SCADA systems and IoT devices.

2019/12/18
阅读更多

Lessons Learned From a Decade of Data Breaches

F5 Labs researched 433 breach cases spanning 12 years, 37 industries, and 27 countries to discover patterns in the initial attacks that lead to the breach.

2017/12/7
阅读更多

The Rising IoT Threat to the Agriculture Industry and the Global Food Supply

Precision agriculture leveraging IoT and API technology is both a great boon and a huge cybersecurity risk.

2020/9/15
阅读更多

2019 Phishing and Fraud Report

In our 2019 edition of the Phishing and Fraud Report, we look at the latest methods and trends attackers are using to exploit the most vulnerable part of your defensive posture: your users.

2019/10/24
阅读更多

Qbot Banking Trojan Still Up to Its Old Tricks

The Qbot banking trojan is back, targeting American banks with dedicated campaigns followed by stealth and evasion techniques.

2020/6/11
阅读更多

Denial of Service Vulnerabilities Discovered in HTTP/2

SETTINGS frame abuse and Slow POST attacks in HTTP/2 can lead to CPU and memory exhaustion.

2019/4/29
阅读更多

Threat Actors Rapidly Adopt New ThinkPHP RCE Exploit to Spread IoT Malware and Deploy Remote Shells

Threat actors wasted no time jumping on this new exploit to launch new campaigns for reconnaissance, uploading back doors, and deploying variants of the Mirai botnet.

2018/12/19
阅读更多

Zealot: New Apache Struts Campaign Uses EternalBlue and EternalSynergy to Mine Monero on Internal Networks

New Apache Struts campaign, Zealot, targets vulnerabilities in Windows, Linux, and the DotNetNuke CMS, then leverages leaked NSA exploits to move laterally through internal networks and mine Monero.

2017/12/15
阅读更多

Fight Credential Stuffing by Taking a New Approach to Authorization

How a token-based authorization model can help organizations dramatically reduce credential stuffing attacks.

2017/5/31
阅读更多

Cyber Threats Targeting Russia, Winter 2019

The Russian threat landscape is unique from other regions of the world in that it had the most unique attacking IP addresses.

2020/3/17
阅读更多

Is the Cloud Safe? Part 3: How to Make it Safe

Now that we’ve explored cloud security failures, we’re going to explain defensive strategies laid out by deployment model.

2020/1/7
阅读更多

Cloudbleed: What We Know and What You Should Do

Definitive steps individuals and organizations can take today to deal with the impact of Cloudbleed.

2017/2/24
阅读更多

The Evolving CVE Landscape

Plus, the 7 Weirdest CVEs (You won’t believe number 6!)

2023/2/28
阅读更多

Regional Threat Perspectives: Australia

Attackers using IP addresses in China, the United States, and the Netherlands focus on attacking applications over SSH, SMB and HTTP.

2019/4/24
阅读更多

IoT Threats: A First Step Into a Much Larger World of Mayhem

So far, we’ve seen IoT DDoS attacks on a Death Star scale. What's next for those of us that may be caught in the blast?

2017/1/17
阅读更多

Security’s “Rule Zero” Violated Again With Zero-Day Apache Struts 2 Exploit

If you’re running Apache Struts 2 and the vulnerable component, stop reading and update now.

2017/3/9
阅读更多

Application Protection Report 2019, Episode 5: API Breaches and the Visibility Problem

API use has grown tremendously as applications grow more decentralized. Some large apps have hundreds of APIs, and mobile apps depend on them completely.

2019/8/13
阅读更多

A Spectre of Meltdowns Could be in Store for 2018, Including Fileless Malware Attacks and More Costly Bots

Every week another bug, vulnerability, or exploit is released - we need a multi-layered security strategy (beyond our standard patch “spin cycles”) to deal with threats like Spectre and Meltdown.

2018/1/10
阅读更多

Application Protection Report 2019, Episode 3: Web Injection Attacks Get Meaner

Web injection represents an even greater risk than it did previously, thanks to the growth of third-party content and increasingly complex attack surfaces.

2019/5/16
阅读更多

Phishing for Information, Part 2: How Attackers Collect Data About Your Employees

The personal and job-related information that employees often innocently post on various websites makes it easy for phishers to pull off their scams.

2017/7/20
阅读更多

Vulnerabilities, Exploits, and Malware Driving Attack Campaigns in February 2019

Continuing the trend from January, threat actor activity in February focused heavily on exploiting a ThinkPHP remote code execution vulnerability.

2019/3/12
阅读更多

Ramnit Returns to its Banking Roots, Just in Time for Italian Tax Season

Ramnit’s latest configuration targets Europe leading up to tax season, focusing on Italian banks and international online advertisers.

2019/4/23
阅读更多

Bots Cheat to Win

How automated fraudsters tried to ruin a restaurant’s promotional contest.

2024/2/5
阅读更多

Vulnerabilities, Exploits, and Malware Driving Attack Campaigns in January 2019

January threat actor activity focused heavily on exploiting a ThinkPHP remote code execution vulnerability and infecting vulnerable Oracle WebLogic systems with a Mirai variant.

2019/2/21
阅读更多

Ransomware: How It Has Evolved to Be Faster, Stealthier, and Strike Harder

Ransomware now includes data leakage, stealth, attack delay, anti-security, and ransomware as a service. CI Security’s John-Luke Peck shares his thoughts.

2020/10/15
阅读更多

Vulnerabilities, Exploits, and Malware Driving Attack Campaigns in November 2019

New campaign activity for remote code execution (RCE) vulnerabilities disclosed this year picked up in the month of November.

2019/12/24
阅读更多

Vulnerabilities, Exploits, and Malware Driving Attack Campaigns in August 2019

August 2019 was slowest month on record F5 researchers have seen in new threat activity. But while active exploitation slowed, new reconnaissance campaigns grew.

2019/9/24
阅读更多

Fake Account Creation Bots – Part 1

Part one of a series investigating how automation is used to create fake accounts for fraud, disinformation, scams, and account takeover.

2023/9/8
阅读更多

Dridex is Watching You

And we're watching Dridex. Here's the latest in this malware's evolution.

2016/6/17
阅读更多

Shellshock: Malicious Bash, Obfuscated perlb0t, Echo Probes, and More

Shellshock can take advantage of HTTP headers as well as other mechanisms to enable unauthorized access to Bash.

2014/10/10
阅读更多

API Authentication Incidents: 2020 APR, Vol. 2

Broken API authentication is leading to avoidable security incidents and unusual impacts. Learn what you can do to control the risk.

2020/9/1
阅读更多

Regional Threat Perspectives, Fall 2019: Europe

Europe saw more in-region attack traffic—the hardest kind to filter out—than any of the 8 regions of the world we analyzed.

2019/12/17
阅读更多

Phishing: The Secret of Its Success and What You Can Do to Stop It

Learn about the tricks attackers use to dupe unsuspecting users and how you can help protect them—and your organization.

2017/11/16
阅读更多

Sensor Intel Series: Top CVEs in October 2023

Despite an overall downward trend, an old favorite comes back into play.

2023/11/27
阅读更多

Email Compromise with Credential Stuffing Attack Tools

How cybercriminals use credential stuffing attack tools OpenBullet and MailRanger to bypass CAPTCHA, compromise mailboxes, and reset passwords.

2021/4/22
阅读更多

Vulnerabilities, Exploits, and Malware Driving Attack Campaigns in May 2019

Similar to April, threat actors in May continued targeting the deserialization vulnerabilities found in Oracle WebLogic to mine cryptocurrency.

2019/6/27
阅读更多

Three Ways to Hack the U.S. Election

There are three primary avenues to hack a U.S. election: voter registration, voting machines, and the voters themselves. We’ll dig into each and see which offers the most bang for the buck.

2019/10/22
阅读更多

2019 Application Protection Report Podcast Series

In this companion podcast, the 2019 F5 Labs Application Protection Report researchers examine how both apps and threats are changing, and what security practitioners can do to stay ahead of these changes.

2019/10/22
阅读更多

Sensor Intel Series: Top CVEs in December 2022

See which vulnerabilities caught attackers’ eyes in December 2022.

2023/1/23
阅读更多

Sensor Intel Series: Top CVEs in January 2024

More IoT Targeting, plus a bunch of new CVEs! See what attackers went after in January 2024.

2024/2/20
阅读更多

Holiday Phishing Trends For 2021

As Christmas quickly approaches, seasonal phishing trends once again show that attackers are taking advantage of increased online shopping. Fraudsters doubled their efforts in November attacking ecommerce giants such as Amazon. The real attacker focus, however, was cryptocurrency with fraudulent sites attempting to steal crypto-exchange credentials.

2021/12/17
阅读更多

JWT: A How Not to Guide

JWT brings performance to identity assertion and is being widely adopted, but it’s also garnering the attention of cybercriminals.

2020/9/23
阅读更多

Organizations Seek Help Fighting App-Focused DDoS Attacks Even as Total DDoS Attack Rates Stay Flat

While DDoS attack rates hold, tensions rise for organizations trying to mitigate app-targeted attack that can be easily launched by script kiddies.

2018/9/14
阅读更多

Yasuo-Bot: Flexible, Customized, Fraudulent Content

Standard mobile banking trojans post their own fraudulent content over banking applications. Yasuo-Bot goes further.

2015/12/14
阅读更多

Denial-Of-Service and Password Login Attacks Top Reported Security Incidents, 2018-2020

Three years of reported security incidents shows continued growth in denial-of-service and password login attacks such as brute force and credential stuffing.

2021/3/23
阅读更多

How The IcedID Banking Trojan Exploits Pandemic

TA551 (AKA Shathak) deploys the IcedID banking trojan using COVID-19 in Microsoft Word documents containing a malicious macro that drops an installer.

2021/3/4
阅读更多

Cyberthreats Targeting Australia, Winter 2019

The Australian threat landscape closely mirrored the threats we observed in Asia, with an added focus on NetBIOS port 139.

2020/4/2
阅读更多

2023 DDoS Attack Trends

We analyzed the last three years of DDoS data, and found attackers shifting to more complex approaches, and shifting up the stack.

2023/2/21
阅读更多

Kazakhstan Attempts to MITM Its Citizens

Kazakhstan is now asking its citizens to install digital certificates so that it can decrypt all online communications. Their methods, however, may leave the population vulnerable to cyber attacks for many years to come.

2019/8/1
阅读更多

Cyber Attacks Spike in Finland Before Trump-Putin Meeting

Cyber attackers seem to follow President Trump to every important international meeting, but Russia was not the main source of cyber attacks during the recent Trump-Putin meeting, China was.

2018/7/19
阅读更多

Dridex Update: Moving to US Financials with VNC

Ongoing campaign analysis has revealed that Dridex malware's latest focus has strongly shifted in recent months to US banks.

2016/4/26
阅读更多

New Campaign Targeting Apache Struts 2, WebLogic Deploys Malware Using VBScript

With the vast availability of new exploits and the competition for victims’ resources, the multi-exploit trend continues to be popular among attackers.

2018/6/21
阅读更多

Trickbot Expands Global Targets Beyond Banks and Payment Processors to CRMs

TrickBot shows no signs of slowing down as new targets are added and command and control servers hide within web hosting providers’ networks.

2017/6/15
阅读更多

Application Protection Research Series—Summary 2nd Edition

This is the quick espresso-style rundown on the 2018 threat landscape. This summary boils down the trends in the application threats, as well as our recommendations for managing application risk as it evolves.

2019/11/5
阅读更多

DanaBot’s New Tactics and Targets Arrive in Time for Peak Phishing and Fraud Season

DanaBot makes a strong resurgence at the end of 2019, using new tactics and techniques and expanding beyond its traditional banking targets.

2019/12/9
阅读更多

Gozi Banking Trojan Pivots Towards Italian Banks in February and March

Gozi authors, who targeted banks in Canada, France, and the US in January 2019, shifted their targets to Italian banks in February 2019.

2019/4/30
阅读更多

How Cyber Attacks Changed During the Pandemic

Cybersecurity attacks surged during the pandemic, with large jumps in DDoS and password login attacks against online retailers and APIs.

2020/10/6
阅读更多

Trickbot Now Targeting German Banking Group Sparkassen-Finanzgruppe

TrickBot, the latest arrival to the banking malware scene and successor to the infamous Dyre botnet, is in constant flux.

2016/12/1
阅读更多

Phishing for Information, Part 3: How Attackers Gather Data About Your Organization

The Internet is full of information about your company that’s easily accessible to anyone and particularly useful to attackers.

2017/8/22
阅读更多

Webinject Crafting Goes Professional: Gozi Sharing Tinba Webinjects

Webinject crafting is a separate profession now. Hackers write webinjects and sell them to fraudsters, who use them to weaponize Trojans.

2016/5/26
阅读更多

Cyberattacks at Banks and Financial Services Organizations

A look at cybersecurity incidents at banks, credit unions, insurance companies, government-sponsored financial institutions, and stock exchanges.

2021/5/25
阅读更多

Gozi Adds Evasion Techniques to its Growing Bag of Tricks

Gozi “banking” trojan continues to shift its targets beyond banking as it employs client-side and server-side evasion techniques via time-tested web injection.

2019/1/29
阅读更多

Virtual Kidnapping: The Latest in an Endless Stream of Scams

The virtual kidnapping scam is on the rise because of the excessive amount of personal information people volunteer on social media.

2017/3/30
阅读更多

How Quantum Computing Will Change Browser Encryption

Safeguarding TLS against attack in the quantum computing age will require changes to today’s TLS key exchange algorithms.

2017/7/13
阅读更多

Fighting Back Against Phishing and Fraud—Part 2

How certificate transparency can help you spot fraudulently registered TLS certificates that exploit your domain or brand name.

2019/1/31
阅读更多

2018 Phishing and Fraud Report: Attacks Peak During the Holidays

Phishing attack? Absolutely. Success? Likely. Risk of incident? High. Breach costs? About $6.5 million.

2018/11/8
阅读更多

Using F5 Labs Application Threat Intelligence

As security professionals, we often feel like we’re fighting a losing battle when it comes to cyber security.

2017/1/26
阅读更多

Is the Cloud Safe? Part 1: Models and Misadventures

Cloud security breaches happen, but how prevalent and dangerous are they? More than you might think.

2019/12/11
阅读更多

Bots Target Retailers for Black Friday Bargains

Did automation targeting retail companies rise towards Black Friday 2022?

2023/11/17
阅读更多

Huge Increase in Scanning for CVE-2017-9841 With Large Variability in Scanning Infrastructure

The rather old CVE-2017-9841, an RCE in PHPUnit, suddenly jumps to the top of our list, with an increase of nearly 400% since last month. We dig into the scanning infrastructure.

2024/7/25
阅读更多

2021 Credential Stuffing Report

Credential stuffing is a multifaceted and enduring risk to organizations of all types and sizes. This report is a comprehensive examination of the entire life cycle of stolen credentials—from their theft, to their resale, and their repeated use in credential stuffing attacks.

2021/2/9
阅读更多

Industry Breakdowns for the 2018 Application Protection Report

While app usage and breach costs differ by industry, most organizations, in the face of growing app dependence, still struggle with who owns responsibility for protecting them.

2018/8/30
阅读更多

Trickbot Focuses on Wealth Management Services from its Dyre Core

As TrickBot evolves, we examine version 24, which heavily targets Nordic financial institutions, and we take a close look at the Dyre–TrickBot connection.

2017/7/27
阅读更多

Sensor Intel Series: Top CVEs in July 2022

Learn which CVEs attackers scanned for the most in July 2022, and how it compares with the rest of the year.

2022/8/22
阅读更多

Friendly Reminder: App Security in the Cloud Is Your Responsibility

Nearly 200,000 servers are still vulnerable to Heartbleed—and the organizations who own them might surprise you.

2017/2/2
阅读更多

H1 2023 Bad Bots Review

Bot traffic for the first half of 2023 was fairly typical, some rapid change in a few industries notwithstanding. Learn who got hit hard and who got off easy.

2023/8/15
阅读更多

Are Gen Z-ers More Security Savvy Online than Millennials?

An F5 Labs survey of Gen Z-ers revealed they are not much more security savvy online than Millennials.

2020/2/13
阅读更多

Mirai: The IoT Bot that Took Down Krebs and Launched a Tbps Attack on OVH

The Mirai botnet has infected hundreds of thousands of Internet of Things (IoT) devices, specifically security cameras, by using vendor default passwords for Telnet access.

2016/10/6
阅读更多

Cyberthreats Targeting the United States, Winter 2019

The attack landscape targeting US systems was characterized by a large amount of traffic directed at web applications and web app databases.

2020/3/27
阅读更多

BlackGuard Infostealer Malware: Dissecting the State of Exfiltrated Data

Your data is at risk. Are you equipped to combat the risks posed by BlackGuard?

2022/8/15
阅读更多

XMRig Miner Now Targeting Oracle WebLogic and Jenkins Servers to Mine Monero

The same drop zone server used last week to mine Monero on compromised Jenkins automation servers is now being used in a new Monero mining campaign targeting Oracle Web Logic servers.

2018/2/21
阅读更多

Recent Cyberattacks: 2020 Application Protection Report, Vol. 3

Cyberattacks in Q3 2020 targeted WordPress and other content management systems, IoT devices, and the State of Israel.

2020/12/16
阅读更多

2024 DDoS Attack Trends

Unveiling the rise of Hacktivism in a tense global climate.

2024/7/16
阅读更多

Regional Threat Perspectives: Europe

Attackers are using IP addresses in the Netherlands, United States, and China to target systems in Europe over SIP, Microsoft SMB, and SSH.

2019/4/17
阅读更多

Vulnerabilities, Exploits, and Malware Driving Attack Campaigns in April 2019

In April, threat actors focused on targeting vulnerabilities that had the highest impact: this month it was a recently released deserialization vulnerability in Oracle WebLogic Server.

2019/5/14
阅读更多

2023 Identity Threat Report: The Unpatchables

We are excited to announce a new report covering threats to digital identities. This report goes into detail on credential stuffing, phishing, and multifactor authentication bypass techniques.

2023/11/1
阅读更多

Reviewing Recent API Security Incidents

Application programming interfaces (APIs) are a growing attack surface, offering predators unprecedented access to large data stores. As serverless, mobile, and online platforms grow, API attacks will surely rise.

2018/11/27
阅读更多

The Hunt for IoT: The Growth and Evolution of Thingbots Ensures Chaos

IoT attacks show no signs of decreasing while infected IoT devices go un-remediated, and discovery of new thingbots is at a decade-long high.

2018/3/13
阅读更多

Good Bots, Bad Bots, and What You Can Do About Both

Not all bots are bad, but for those that are, you need a multi-pronged strategy for keeping them off your network.

2019/3/1
阅读更多

The State of the State of Application Exploits in Security Incidents

The title of this report is not a typo. “The State of the State of Application Exploits in Security Incidents” is a meta-analysis of several prominent industry reports, each of which covers the state of application security.

2021/7/20
阅读更多

VBKlip Banking Trojan Goes Man-in-the-Browser

VBKlip has evolved significantly from searching for IBAN data in copy-paste functionality to MITB techniques.

2015/4/30
阅读更多

Academic Research: A Survey of Email Attacks

Email has become such an ordinary part of our daily lives that we can forget how vulnerable it is.

2017/10/31
阅读更多

Credential Stuffing Tools and Techniques, Part 1

We dig into the credential stuffing attack tool OpenBullet and look at configuring combolists, proxies, parse tokens, and check blocks for launching attacks.

2021/4/7
阅读更多

DanaBot November Campaigns Target European Banks and Email Providers

First detected in May 2018, DanaBot is a fraud trojan that has since shifted its targets from banks in Australia to banks in Europe, as well as global email providers such as Google, Microsoft and Yahoo for the holiday phishing season.

2018/12/17
阅读更多

Beware of Attackers Stealing Your Computing Power for their Cryptomining Operations

As the black-market price for stolen data declines, attackers turn to cryptojacking schemes to maximize their profits—all at your expense.

2018/2/15
阅读更多

2022 Application Protection Report: In Expectation of Exfiltration

Learn how the threat landscape evolved in 2021 so you can tune your defenses to suit.

2022/2/15
阅读更多

How a Sneaker Bot Earned $2M Profit from One Shoe Drop

Explore a highly automated attack against a sneaker manufacturer and learn how resellers optimize their bots for success, and profit!

2023/6/6
阅读更多

Leveraging Government Transparency to Find Vulnerable Cellular Gateways

A simple search of public records confirms the astounding number of potentially vulnerable cellular gateways in use in many cities’ emergency services vehicles.

2018/9/18
阅读更多

Rental Scams Are Pervasive, Even Years After the Housing Recession

Rental scams are getting more sophisticated and are making it harder for legitimate landlords and renters to find each other.

2018/7/26
阅读更多

Webinject Analysis: Newsidran.com

Webinject attacks modify webpages to allow fraudsters to collect credentials, or act more directly against user accounts.

2015/12/12
阅读更多

BrickerBot: Do “Good Intentions” Justify the Means—or Deliver Meaningful Results?

Most security researchers have good intentions, but ethics must play a central role in the decisions they make.

2017/12/28
阅读更多

2020 Phishing and Fraud Report

In our 2020 edition of the Phishing and Fraud Report, we focus on how cybercriminals build and host phishing sites, the tactics they use to avoid detection, and how they’ve capitalized this year on the COVID-19 pandemic.

2020/11/11
阅读更多

Cyberattacks Targeting Latin America, January through March 2021

Latin America’s cyberattack landscape saw continued focus on port 5900 and the targeting of common web vulnerabilities.

2021/4/28
阅读更多

Panda Malware: It’s Not Just About Cryptocurrencies Anymore

Panda malware is back with a March 2019 campaign that targets U.S. companies, and moves from cryptocurrencies to targeting web giants.

2019/4/25
阅读更多

Sensor Intel Series: Top CVEs in October 2022

We spotted a new Microsoft Exchange zero day and more security infrastructure vulns, as well as all of the usual suspects, in this month’s installment on vulnerability targeting.

2022/11/21
阅读更多

Regional Threat Perspectives, Fall 2019: Australia

Attackers probed Australian applications for vulnerabilities on the most commonly used ports, and credential stuffing attacks were prevalent.

2019/12/12
阅读更多

Sensor Intel Series: Top CVEs in November 2023

We add two IoT CVEs and discuss the other sorts of traffic we see regularly.

2023/12/19
阅读更多

Fake Account Creation Bots – Part 3: 8 Ways to Identify Fake Bot Accounts

Part three of a series investigating how automation is used to create fake accounts for fraud, disinformation, scams, and account takeover.

2023/11/7
阅读更多

Phishing for Information, Part 5: How Attackers Pull It All Together, and How You Can Fight Back

Stop feeding attackers every piece of the puzzle they need to pull off their scams.

2017/9/28
阅读更多

2018 Application Protection Report Podcast Series

In this companion podcast, the researchers who created the F5 Labs Application Protection Report discuss their findings, and share the details and backstories that helped shape the final report.

2019/7/16
阅读更多

Windows IIS 6.0 CVE-2017-7269 is Targeted Again to Mine Electroneum

Attacks are back to targeting a Windows IIS vulnerability first disclosed a year ago to mine Electroneum.

2018/4/12
阅读更多

What Are Scrapers and Why Should You Care?

Data miners and scraper bots are everywhere, feeding AI LLMs and more, and many of them are NOT harmless.

2024/8/2
阅读更多

Cybersecurity Threats to the COVID-19 Vaccine

A detailed look at the cybersecurity threats to the COVID-19 vaccine rollout pipeline

2021/2/1
阅读更多

Vulnerabilities, Exploits, and Malware Driving Attack Campaigns in July 2019

In July, vulnerable web servers continued to be the target of threat actors attempting to install cryptominers.

2019/8/28
阅读更多

Fighting Back Against Phishing and Fraud—Part 1

Using existing protocols and tools to begin building a robust phishing and fraud mitigation strategy.

2019/1/17
阅读更多

How Global Cyberthreats Changed Over 2021

Scans continue against remote logins like VNC, RDP, and SSH, as well as MySQL and Elasticsearch. And what’s going on in Malaysia and Lithuania?

2021/12/1
阅读更多

Trickbot Gets Trickier by Adding an Encryption Layer

Trickbot authors gain precious time to defraud unsuspecting victims by adding an encryption layer that slows down the malware investigation process.

2018/9/6
阅读更多

Ramnit Goes on a Holiday Shopping Spree, Targeting Retailers and Banks

Ramnit’s latest twist includes targeting the most widely used web services during the holidays: online retailers, entertainment, banking, food delivery, and shipping sites.

2018/1/15
阅读更多

2022 Application Protection Report: DDoS Attack Trends

Distributed denial-of-service attacks soared in complexity and size during 2021. While the overall number of DDoS attacks declined marginally compared with 2020, the F5 Silverline team saw the largest attack in 2021 peak at nearly 1.4 Tbps, 5.5 times larger than the largest attack in 2020.

2022/3/16
阅读更多

Dyre In-Depth: Server-Side Webinjects, I2P Evasion, and Sophisticated Encryption

Dyre is one of the most sophisticated banking malware agents in the wild.

2015/4/12
阅读更多

Weekly Threat Bulletin – January 21st, 2026

These are the top threats you should know about this week.

2026/1/21
阅读更多

Weekly Threat Bulletin – January 28th, 2026

These are the top threats you should know about this week.

2026/1/28
阅读更多

Weekly Threat Bulletin – February 4th, 2026

These are the top threats you should know about this week.

2026/2/3
阅读更多

Weekly Threat Bulletin – February 11th, 2026

These are the top threats you should know about this week.

2026/2/10
阅读更多

Weekly Threat Bulletin – February 18th, 2026

These are the top threats you should know about this week.

2026/2/17
阅读更多

Weekly Threat Bulletin – February 25th, 2026

These are the top threats you should know about this week.

2026/2/25
阅读更多

Weekly Threat Bulletin – March 4th, 2026

These are the top threats you should know about this week.

2026/3/3
阅读更多

Weekly Threat Bulletin – March 11th, 2026

These are the top threats you should know about this week.

2026/3/11
阅读更多

Weekly Threat Bulletin – March 18th, 2026

These are the top threats you should know about this week.

2026/3/18
阅读更多

Weekly Threat Bulletin – March 25th, 2026

These are the top threats you should know about this week.

2026/3/25
阅读更多

Weekly Threat Bulletin – April 1st, 2026

These are the top threats you should know about this week.

2026/4/1
阅读更多

Weekly Threat Bulletin – April 8th, 2026

These are the top threats you should know about this week.

2026/4/8
阅读更多

Weekly Threat Bulletin – April 15th, 2026

These are the top threats you should know about this week.

2026/4/15
阅读更多

Weekly Threat Bulletin – April 22nd, 2026

These are the top threats you should know about this week.

2026/4/22
阅读更多

Weekly Threat Bulletin – April 29th, 2026

These are the top threats you should know about this week.

2026/4/29
阅读更多

Weekly Threat Bulletin – May 6th, 2026

These are the top threats you should know about this week.

2026/5/6
阅读更多

Weekly Threat Bulletin – May 13th, 2026

These are the top threats you should know about this week.

2026/5/13
阅读更多

Weekly Threat Bulletin – May 20th, 2026

These are the top threats you should know about this week.

2026/5/20
阅读更多

Weekly Threat Bulletin – May 27th, 2026

These are the top threats you should know about this week.

2026/5/27
阅读更多

Weekly Threat Bulletin – June 3rd, 2026

These are the top threats you should know about this week.

2026/6/3
阅读更多

Weekly Threat Bulletin – June 10th, 2026

These are the top threats you should know about this week.

2026/6/10
阅读更多

Weekly Threat Bulletin – June 17th, 2026

These are the top threats you should know about this week.

2026/6/17
阅读更多

Weekly Threat Bulletin – June 24th, 2026

These are the top threats you should know about this week.

2026/6/24
阅读更多

Weekly Threat Bulletin – July 1st, 2026

These are the top threats you should know about this week.

2026/7/1
阅读更多

Weekly Threat Bulletin – July 8th, 2026

These are the top threats you should know about this week.

2026/7/8
阅读更多

Weekly Threat Bulletin – July 15th, 2026

These are the top threats you should know about this week.

2026/7/15
阅读更多

Weekly Threat Bulletin – July 22nd, 2026

These are the top threats you should know about this week.

2026/7/22
阅读更多

Weekly Threat Bulletin – July 29th, 2026

These are the top threats you should know about this week.

2026/7/29
阅读更多

Weekly Threat Bulletin – August 5th, 2026

These are the top threats you should know about this week.

2026/8/5
阅读更多

Weekly Threat Bulletin – August 12th, 2026

These are the top threats you should know about this week.

2026/8/12
阅读更多