From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence
Reported 22 May 2026 by otx · Severity: medium
A sophisticated multi-stage intrusion began with the compromise of an internet-facing F5 BIG-IP load balancer running an end-of-life version. The threat actor established SSH access to a Linux server using privileged credentials, then conducted extensive reconnaissance including