F5 Labs threat research
In-depth threat research, global vulnerability analyses, and actionable security intelligence uncovered by F5 Labs researchers.
Featured Blog Posts
Threat research Blog posts
(353)
Analysis of a Large-Scale DDoS Attack Against a Payment Processing Platform | F5 Labs
The two-wave attack reached a peak of 1.8 Tbps. ... Several phases of the attack unfolded in high-intensity waves, employing multiple DDoS techniques and achieving traffic volumes previously unseen...

Weekly Threat Bulletin – July 1st, 2026 | F5 Labs
These are the top threats you should know about this week. ... Threat intelligence firm Defused observed automated attacks originating from Tor, which leverage the WebDialer SSRF to install a rogue...

Weekly Threat Bulletin – June 3rd, 2026 | F5 Labs
These are the top threats you should know about this week. ... Microsoft responded with a blog post on uncoordinated vulnerability disclosure, asserting that none of the flaws were reported through...

Weekly Threat Bulletin – June 17th, 2026 | F5 Labs
These are the top threats you should know about this week. ... This flaw, discovered by security researcher NightmareEclipse, leverages an interaction between the Windows Recovery Environment (WinR...

Topic Bridge | F5 Labs
CASI leaderboard shifts, and two incidents where AI was handed the keys. ... The most instructive reading this month lies in the widening distance between two properties that have long been treated...

Weekly Threat Bulletin – May 27th, 2026 | F5 Labs
These are the top threats you should know about this week. ... Attackers are actively exploiting two Microsoft Defender vulnerabilities, CVE-2026-41091 and CVE-2026-45498, which Microsoft has ackno...

The Small Model Cliff | F5 Labs
May's CASI run added 12 new models, including eight Qwen3.5 variants from 0.8B to 397B parameters and two new Gemma 4 entries. ... The two smallest Qwen3.5 variants had a CASI Score of under CASI 2...

GeoServer Targeting on the Rise | F5 Labs
This article highlights the top 10 CVEs, their activity levels, and their potential impact on organizations. ... By examining long-term trends and recent activity, this report aims to inform securi...

Looking at the SmarterMail API Vulnerability CVE-2026-24423 | F5 Labs
The F5 Labs Sensor Intel Series provides an in-depth analysis of the most significant vulnerabilities and their exploitation trends. ... This article highlights the top 10 CVEs, their activity leve...

2024 DDoS Attack Trends | F5 Labs
The OWASP Top 10 has not called out denial of service (DoS) attacks as a top threat to web applications for over twenty years. ... By combining analysis of the DoS incidents encountered by the F5 D...

Fake Account Creation Bots – Part 1 | F5 Labs
Part one of a series investigating how automation is used to create fake accounts for fraud, disinformation, scams, and account takeover. ... Much of the activity on the internet is automated, and ...

When AI Gets Bullied: How Agentic Attacks Are Replaying Human Social Engineering | F5 Labs
December closed out 2025 with a clear signal that AI risk, capability, and governance are evolving faster than ever. ... Updated CASI and ARS leaderboards showed a notable shift at the top, with GP...

Fake Account Creation Bots – Part 3: 8 Ways to Identify Fake Bot Accounts | F5 Labs
Part three of a series investigating how automation is used to create fake accounts for fraud, disinformation, scams, and account takeover. ... In Part One of this series, we introduced fake accoun...

Adversarial Poetry and the Efficacy of AI Guardrails | F5 Labs
We investigate the rise of adversarial poetry in AI security. ... Understand how metaphor-based exploits circumvent guardrails and the defenses we need for LLMs moving forward. ... By Lee Ennis (ad...

Weekly Threat Bulletin – September 9th, 2026 | F5 Labs
These are the top threats you should know about this week. ... N-able has released N-central 2026.3 Hotfix 4 to address a maximum-severity remote code execution (RCE) vulnerability, tracked as CVE-...

Weekly Threat Bulletin – February 18th, 2026 | F5 Labs
These are the top threats you should know about this week. ... CISA has mandated U.S. federal agencies to secure their systems against a critical Microsoft Configuration Manager vulnerability, CVE-...

Weekly Threat Bulletin – February 25th, 2026 | F5 Labs
These are the top threats you should know about this week. ... On February 17, 2026, the open-source, AI-powered coding assistant Cline CLI experienced a supply chain attack where version 2.3.0 was...

Weekly Threat Bulletin – March 18th, 2026 | F5 Labs
These are the top threats you should know about this week. ... Google has issued an emergency Chrome update to address two zero-day vulnerabilities, CVE-2026-3909 and CVE-2026-3910, which are activ...