Clicky

mobile btn
Thursday, August 27th, 2026

CISA issues emergency directive after identifying cyber threat targeting federal networks

© Shutterstock

The Cybersecurity and Infrastructure Security Agency (CISA) recently issued an emergency directive after identifying a significant cyber threat targeting federal networks utilizing certain F5 devices and software.

F5 disclosed that a nation-state threat actor had long-term persistent access to, and exfiltrated files from, the company’s BIG-IP development environment and engineering knowledge management platforms. The cyber threat actor exploited vulnerabilities in F5’s products to gain unauthorized access to embedded credentials and Application Programming Interface keys.

Under the directive, all agencies must apply the latest vendor-provided update for at-risk F5 virtual and physical devices and downloaded software.

“Despite the government shutdown and the lapse of the Cybersecurity Information Sharing Act of 2015, CISA remains steadfast in its commitment to protect our federal networks from nation-state adversaries,” CISA Acting Director Madhu Gottumukkala said. “The alarming ease with which these vulnerabilities can be exploited by malicious actors demands immediate and decisive action from all federal agencies. These same risks extend to any organization using this technology, potentially leading to a catastrophic compromise of critical information systems. We emphatically urge all entities to implement the actions outlined in this emergency directive without delay.”

CISA will assess and support agency adherence while federal civilian agencies implement the mandate and will provide additional resources if required.