All updates
security: From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence
May 22, 2026
Microsoft describes a multi-stage Linux intrusion that started from an exposed F5 BIG-IP appliance and then pivoted to an internal Confluence server to steal credentials and compromise identity. The attack involved attempted Kerberos relay and lateral movement, and Microsoft Defender detected and blocked parts of the chain.
- Source: Microsoft Security Blog