Day Lila

Cybersecurity · Friday, 25 September 2026

01 Briefing what happened

Attackers are using a flaw in F5's remote-login boxes. US agencies were given until Friday to fix it.

Cybersecurity 6 sources

F5 says attackers found and used a flaw in its BIG-IP APM boxes, which let staff log in to company networks from outside, and the US cyber agency ordered federal agencies to fix it by Friday.

14,700+

internet addresses that look like F5's remote-login box, counted by Shadowserver

Nobody has said how many of them are fixed. [1]

8

flaws in F5 products the US has listed as used in attacks since November 2021

Four of the eight were also used by ransomware gangs. [1]

48 of 50

of the biggest US companies are F5 customers, the company says

It serves more than 23,000 customers worldwide. [1]

The lead story — what happened

  • F5, a US company that sells equipment for running and guarding the traffic into company networks, said on Tuesday that attackers are using a flaw in one of its products. [1]
  • The product is BIG-IP APM, the part of the box that lets staff log in to their company's network from outside. [1]
  • The flaw lets an attacker run their own commands on the box from across the internet. [1]
  • It is a zero-day: attackers found it and used it before any fix was out. [1]
  • F5 has now released updates. Staff who cannot install them at once can add a blocking rule that F5's support team provides. [1]
  • Boxes that only accept logins checked by another service are not affected, F5 says. [1]
  • F5 told customers to look for a pattern in their logs: several failed logins, then odd commands, then the box's traffic program crashing. [1]
  • On the same day, CISA, the US government's cyber-defence agency, put the flaw on its list of holes known to be in use. [1]
  • CISA gave US federal agencies until Friday to fix it. [1]
  • Shadowserver, a non-profit that scans the internet, counts more than 14,700 internet addresses that look like this F5 product. [1]
  • It cannot tell how many of those are already fixed, or are decoys set up to watch attackers. [1]
  • F5 said in October 2025 that state-backed hackers had broken into its own systems in August 2025 and stolen BIG-IP code and details of unfixed flaws. [1]

Who is involved

  • F5

    a US company whose boxes sit at the edge of company networks and let staff log in from outside; it said the flaw is being used and shipped fixes

  • CISA

    the US government's cyber-defence agency; it listed the flaw as in use and set Friday as the deadline for federal agencies

  • Shadowserver

    a non-profit that scans the whole internet; it counted more than 14,700 boxes of this kind

How it unfolded

  1. Aug 2025 State-backed hackers break into F5 and take BIG-IP code and flaw details [1]
  2. Oct 2025 F5 tells the public about that break-in [1]
  3. Tuesday F5 says the new flaw is being used; CISA adds it to its list [1]
  4. Friday Deadline for US federal agencies to fix it [1]

Where this points

Watch whether F5 or CISA says who is behind these attacks, and whether Shadowserver's count of exposed boxes falls after Friday's deadline. [1]

What is pushing on the whole day

The bar and the word are our reading of how hard each one is pushing today. The arrow is where it is heading. The evidence is in the stories below.

Old holes still open High↑

TeamCity, a tool for building software, was fixed in July, and ransomware gangs are using the hole now. [2] The US has listed eight F5 flaws as used in attacks since 2021. [1]

Too few people to do the fixing Building→

An audit found one in three UK government cyber jobs empty or held by a temporary contractor. [4] A US congressman says many small towns cannot pay for the AI tools that find security holes. [5]

Hackers working for governments High↑

New Zealand's cyber agency says China is the most persistent government hacking it. [3] Groups with suspected links to Iran broke into 12 US water facilities this summer. [6] State-backed hackers stole F5's own code in 2025. [1]

The rest of the day

4 more stories on this beat.

Each with its own sources. None of these is a link to the story above.

  1. 02

    Ransomware gangs now use a TeamCity hole

    CISA, the US cyber-defence agency, said on Wednesday that ransomware gangs are now using a flaw in TeamCity. [2] TeamCity is software that developers use to build, test and ship their code, and its maker JetBrains says more than 30,000 teams use it. [2] JetBrains fixed the flaw on 25 July. It lets a stranger skip the login and run commands on the server. [2] CISA first listed it as used in attacks on 5 August. [2] Shadowserver now counts just over 160 unfixed servers, down from about 700. [2]

    Shadowserver's count of TeamCity servers still open to the July flaw. The second bar is just over 160.

    Why it matters — A build server holds stored passwords and the code a company sends to its customers, so a gang inside it can reach much further. [2] The owners of the last 160 servers have had the fix for two months.

  2. 03

    UK civil service swaps orders for a helper

    Breandan Knowlton-Hung, the UK civil service's deputy security chief, spoke at a London conference on 23 September. [4] He said a 2025 review by the National Audit Office, which checks UK government spending, found no proper plan behind the 2022 cyber strategy. [4] It also found one in three cyber jobs empty or filled by temporary contractors. [4] The UK government then built a service that scans thousands of public bodies for weaknesses anyone online can see, and tells the right team. [4] He said the median time to fix those weaknesses fell from about 50 days to 8. [4]

    How long UK public bodies took to fix weaknesses visible from the internet, before and after a central team began finding them.

    Why it matters — The UK government is about 465 separate bodies, each with its own budget and computers. [4] Those bodies fixed things faster when someone else did the finding, and he said nobody ordered those fixes. [4]

  3. 04

    New Zealand names China as its top state hacker

    New Zealand's National Cyber Security Centre, part of the country's intelligence services, published its yearly threat report on Thursday. [3] It said China is the most persistent and capable government hacking in New Zealand, and also named Russia, Iran and North Korea. [3] Of 369 incidents that might matter to the whole country, in the year to June 2026, 86 had suspected links to government-backed groups. [3] Targets included government agencies, health and education bodies, and firms that run other companies' computers. [3] China's government has routinely denied such claims. [3]

    Why it matters — Firms that run other companies' computers were among the targets, and one break-in there can reach every customer they serve. The agency says these spies often set up their access months or years before they use it. [3]

  4. 05

    US bill would give small utilities free AI tools

    Josh Gottheimer, a Democrat in the US House of Representatives, has introduced the AI Cyber Defense Act with two Republican and two Democratic co-sponsors. [5] It would set up a CISA test programme giving operators of vital services, such as water plants, free use of advanced AI to find and fix holes. [5] It would allow $100 million from 2027 to 2031, but the US Congress would still have to hand over the money. [5] Small, rural, public and non-profit operators would go first. [5] This summer, groups with suspected links to Iran broke into 12 US water facilities. [6]

    Why it matters — Gottheimer said many local communities cannot pay for the AI tools that find holes before attackers do. [5] A separate White House test in Texas relies on companies offering help for free, with no real budget behind it. [5]

02 Lesson why it matters

A fix gets done when doing it is easier than leaving it

When the UK civil service found weaknesses for its teams instead of ordering fixes, the median fix fell from 50 days to 8.

The twist

An order does not install anything. The UK civil service cut its fix time from 50 days to 8 by doing the finding and the telling for its teams, not by writing a stricter rule.

The picture

Median days UK public bodies took to fix a weakness visible from the internet, before and after the central service began.

How it works

  1. A maker finds a hole and ships a fix
  2. A warning or an order says who should install it
  3. Each owner weighs the work: staff, money, time offline
  4. Where the work is easy, the fix goes in within days
  5. Where it is hard, the machine stays open for months

The same force, elsewhere today

Where this chain is also running, in today's other stories.

  • The TeamCity hole

    The fix has been out since July and most owners installed it, but about 160 servers are still open, and ransomware gangs are using them.

  • The UK civil service

    Fixes went in about six times faster once a central team found each weakness and sent it to the team that owned it.

  • The US bill for small utilities

    A small town cannot pay for the AI tools that find holes, so the bill would hand them over free, with small and rural operators first.

  • The F5 flaw

    F5 gave a short-term blocking rule to staff who cannot install the full update straight away.

Where you've seen this

Car recalls

the maker pays for the repair, but it only happens if the owner books a garage visit

Phone updates

a phone that installs updates overnight on its own gets fixed; one that asks first often waits

Flu jabs at work

a jab offered at your desk takes less effort than one you must book, so more people take it

The catch

Making a fix easy only helps with machines someone knows about. The UK service sees only weaknesses visible from outside, and Shadowserver cannot tell a fixed F5 box from an unfixed one.

And the whole of it

Behind each unfixed server there is a person with a queue of other jobs, often with nobody to share them. Most people know the feeling from a phone update they keep putting off.

03 Truth what's really going on

What is really going on

JetBrains fixed its TeamCity hole in July, and ransomware gangs are now using the servers whose owners have not installed the fix. F5 has shipped a fix too, but nobody knows how many of the 14,700 F5 boxes online have it. The UK civil service got its fixes in about six times faster once a central team found each weakness and told the team that owned it.

Who gains

  • Whoever is using the F5 flaw — Every remote-login box not yet updated can be reached from across the internet, and more than 14,700 are visible. [1]
  • Ransomware gangs — An unfixed TeamCity server holds stored passwords and the code a company ships, so one break-in reaches further. [2]
  • UK government departments — A central service now finds weaknesses and tells the right team, and the median fix time fell from about 50 days to 8. [4]
  • Small and rural US utilities, if the bill passes — They would get first call on free AI tools to find holes in their own systems. [5]

Who pays

  • Staff running F5 remote-login boxes — They must install the update or add a blocking rule, then read their logs for signs of a break-in. [1]
  • Companies with the last 160 unfixed TeamCity servers — They are now the pool ransomware gangs pick from. [2]
  • Health, education and IT service bodies in New Zealand — They were among the targets of state-linked hacking in the year to June 2026. [3]
  • Small towns with one IT person — Many cannot pay for the AI tools that find holes, and water facilities were among this summer's targets. [5][6]

What nobody knows yet

Open questions from across today’s stories — ours included.

  • 01

    How many of the 14,700 F5 boxes on the internet are already fixed.

    Shadowserver can see the boxes but not whether they are updated, and some may be decoys. [1]

  • 02

    Who is using the F5 flaw, and against whom.

    F5 said the flaw has been used but did not name an attacker or a victim. [1]

  • 03

    Whether the new F5 flaw is one of those stolen from F5 in 2025.

    F5 said state-backed hackers took details of unfixed flaws in August 2025. Nobody has said whether this is one of them. [1]

  • 04

    Which organisations the ransomware gangs have hit through TeamCity.

    CISA flagged ransomware use but has shared no information about the attacks. [2]

  • 05

    Who owns the roughly 160 TeamCity servers still unfixed.

    Shadowserver counts servers from the outside and does not publish owners. [2]

  • 06

    Which New Zealand organisations the 86 state-linked incidents hit.

    The report gives counts and sectors, not names. [3]

  • 07

    Whether the $100 million for small utilities will ever be paid.

    The bill only allows the money. The US Congress would still have to vote to spend it, and CISA's funding has been cut. [5]

  • 08

    Whether the UK's faster fixes reach harder problems.

    The 50-to-8-day figure covers only weaknesses visible from the internet, and the talk did not say whether the audit's one-in-three empty cyber jobs has changed. [4]

04 Hope carry this

The UK civil service cut the median time to fix weaknesses anyone on the internet can see from about 50 days to 8, after a central team began finding them and telling the right people.

Also true today

  • The number of TeamCity build servers still open to a known flaw fell from about 700 to just over 160 as owners installed the July fix.
  • F5 released fixes for its remote-login boxes, plus a temporary blocking rule for anyone who cannot install them straight away.

Across the beats