Security News > 2021 > March > Researchers Raise Alarm for F5 BIG-IP Malware Attacks
The urgency to patch gaping security holes in F5 Networks BIG-IP and BIG-IQ products escalated over the weekend after researchers spotted malicious in-the-wild attack activity.
Malware hunters at U.K.-based NCC Group are raising the alarm for mass scanning and "Multiple exploitation attempts" with exploits targeting critical security flaws in the F5 enterprise networking infrastructure products.
Are considered high-priority fixes because of the risk of exposure to authentication bypass and remote code execution attacks.
Less than a week after the release of the patches, proof-of-concept code started circulating and, over the last weekend, NCC Group's researchers said its honeypot infrastructure was being hit with exploitation attempts.
The most useful endpoint for an attacker is the tm/util/bash endpoint, which allows an user to execute commands on the underlying server with root privileges.
As part of the F5 patches, a command injection vulnerability was also patched in the tm/access/bundle-install-tasks REST endpoint - which could be used as an alternative way to execute arbitrary commands once authentication has been bypassed.
News URL
Related news
- Researchers Warn of Ongoing Attacks Exploiting Critical Zimbra Postjournal Flaw (source)
- Crypto-apocalypse soon? Chinese researchers find a potential quantum attack on classical encryption (source)
- Researchers Uncover Hijack Loader Malware Using Stolen Code-Signing Certificates (source)
- Astaroth Banking Malware Resurfaces in Brazil via Spear-Phishing Attack (source)
- VEILDrive Attack Exploits Microsoft Services to Evade Detection and Distribute Malware (source)
- Iranian Hackers Use "Dream Job" Lures to Deploy SnailResin Malware in Aerospace Attacks (source)
- Iranian Hackers Deploy WezRat Malware in Attacks Targeting Israeli Organizations (source)