1
00:00:13,840 --> 00:00:17,240
Welcome to the Decipher Podcast.
I'm Dennis Fisher. 

2
00:00:17,240 --> 00:00:20,200
I'm here with Lindsay O'Donnell 
Welch, and we're going to talk a

3
00:00:20,200 --> 00:00:25,120
little bit about this kind of 
crazy F5 story that emerged this

4
00:00:25,120 --> 00:00:29,000
week. 
Linds, you know, we've both been

5
00:00:29,000 --> 00:00:31,040
doing this a long time and we've
seen a lot of these kind of 

6
00:00:31,040 --> 00:00:35,040
incidents, you know, intrusions 
at tech companies have become 

7
00:00:35,040 --> 00:00:40,720
more and more common, especially
from, you know, well resourced, 

8
00:00:40,720 --> 00:00:44,120
state backed actors who are 
looking for sensitive 

9
00:00:44,120 --> 00:00:46,800
information, you know, product 
information, whatever they can 

10
00:00:46,800 --> 00:00:49,320
get their hands on. 
But this one seems to have a 

11
00:00:49,320 --> 00:00:52,000
whole bunch of different layers 
and different kind of 

12
00:00:52,760 --> 00:00:55,360
storylines. 
And it's only been about 24 

13
00:00:55,360 --> 00:00:58,720
hours as we're recording this 
since the news came out. 

14
00:01:00,160 --> 00:01:03,680
But as I was just reading the 
initial reports from F5 

15
00:01:03,680 --> 00:01:09,720
yesterday in the middle of the 
day, looking at it, we've both 

16
00:01:09,720 --> 00:01:13,320
read enough of these statements 
and public reports to kind of 

17
00:01:13,320 --> 00:01:16,360
read between the lines and you 
can see what they're saying and 

18
00:01:16,360 --> 00:01:21,200
what they're not saying. 
You know the the public 

19
00:01:21,200 --> 00:01:29,800
statements are that an unnamed 
government backed actor had long

20
00:01:29,800 --> 00:01:33,040
term is the phrase they used 
access to F5 networks. 

21
00:01:33,560 --> 00:01:36,080
Yep, long term persistent 
access. 

22
00:01:36,600 --> 00:01:39,680
Right, that's the, that's the 
absolute basics. 

23
00:01:39,680 --> 00:01:44,240
They all, they said that the 
attackers were able to get some 

24
00:01:44,240 --> 00:01:47,600
product information. 
They also had access to some 

25
00:01:47,600 --> 00:01:53,160
information about undisclosed 
vulnerabilities and some limited

26
00:01:53,160 --> 00:01:56,080
customer information and 
financial information, I 

27
00:01:56,080 --> 00:01:59,240
believe. 
So, you know, kind of a of grab 

28
00:01:59,240 --> 00:02:03,920
bag of really sensitive 
information, but there's a lot 

29
00:02:03,920 --> 00:02:06,600
that's unsaid in the the 
statement as well. 

30
00:02:06,600 --> 00:02:09,240
They don't say how long the 
attackers were in there. 

31
00:02:09,600 --> 00:02:12,720
They don't attribute this attack
to any, they don't even 

32
00:02:12,720 --> 00:02:17,480
attribute it to a country or 
anything like that. 

33
00:02:17,480 --> 00:02:19,760
It's just sort of the, the bare 
bones of it. 

34
00:02:20,040 --> 00:02:22,320
And then, you know, it kind of 
goes into the the customer 

35
00:02:22,320 --> 00:02:26,320
impact. 
But this is one of the more 

36
00:02:26,680 --> 00:02:30,560
thorny and potentially really 
damaging ones that I think we've

37
00:02:30,560 --> 00:02:33,040
seen in a while. 
Yeah. 

38
00:02:33,040 --> 00:02:37,360
And you know, just taking a step
back, looking at F5 big IP, as 

39
00:02:37,360 --> 00:02:40,680
soon as I saw that in the news, 
I was kind of like, OK, this is.

40
00:02:40,680 --> 00:02:43,840
And I was just telling you, this
is a product that has come up 

41
00:02:43,840 --> 00:02:47,320
like, you know, a handful of 
times every year because it's 

42
00:02:47,320 --> 00:02:52,040
such a popular type of appliance
that threat actors have been 

43
00:02:52,040 --> 00:02:55,360
targeting. 
And if you look at the, the 

44
00:02:55,360 --> 00:02:58,080
platform, the product itself, it
makes sense, right? 

45
00:02:58,080 --> 00:03:01,720
I mean, if there's, it's on the 
edge of the network, it, there's

46
00:03:01,760 --> 00:03:04,560
kind of, if you get a foothold 
into that, it's easy access to 

47
00:03:04,760 --> 00:03:08,960
then launch out lateral movement
or some of these other vectors. 

48
00:03:08,960 --> 00:03:14,080
But then also looking at F5 like
the customer base I'd imagine is

49
00:03:14,080 --> 00:03:16,320
pretty valuable as well. 
For threat. 

50
00:03:16,680 --> 00:03:22,720
As if they want to target that. 
So it's, you know, just the 

51
00:03:22,720 --> 00:03:26,760
reasons why, you know, the 
threat actors, especially nation

52
00:03:26,760 --> 00:03:28,600
state actors might be interested
in this. 

53
00:03:28,600 --> 00:03:30,440
I think is important to 
highlight here. 

54
00:03:31,320 --> 00:03:34,320
The other thing too is, you 
know, you mentioned this kind of

55
00:03:35,040 --> 00:03:39,920
high level bare bones that was 
released yesterday. 

56
00:03:40,480 --> 00:03:44,520
Since then, you know, there's 
been some news reports that have

57
00:03:44,520 --> 00:03:46,280
come out, I think from 
Bloomberg. 

58
00:03:46,280 --> 00:03:50,880
It was basically giving a little
bit more information into, you 

59
00:03:50,880 --> 00:03:54,920
know, what the scope and scale 
of this was, which, you know, it

60
00:03:54,920 --> 00:03:59,640
seems as though reports have 
linked the attack to China and 

61
00:03:59,640 --> 00:04:04,000
then also that threat actors 
have actually been inside F5 

62
00:04:04,040 --> 00:04:08,280
network for 12 months, about a 
year. 

63
00:04:08,280 --> 00:04:11,920
So just. 
That's a long time. 

64
00:04:12,520 --> 00:04:16,320
That's a long time, yeah. 
If you really think about it, a 

65
00:04:16,440 --> 00:04:21,160
year is of of access into your 
network. 

66
00:04:21,160 --> 00:04:24,080
Just think of all the things 
that happened and all the 

67
00:04:24,360 --> 00:04:26,280
potentials. 
It's just hard to even know the 

68
00:04:26,280 --> 00:04:29,160
true extent of this incident, 
you know? 

69
00:04:29,520 --> 00:04:34,920
It really is. 
I, I can't really recall any 

70
00:04:34,920 --> 00:04:39,480
publicly known incident where an
attacker was inside of an A 

71
00:04:40,520 --> 00:04:43,360
victim network for a year, 12 
months. 

72
00:04:43,800 --> 00:04:49,280
I mean, even going back to like 
the Aurora attacks that hit 

73
00:04:49,280 --> 00:04:51,720
Google and a whole bunch of 
other companies back in like 

74
00:04:51,720 --> 00:04:56,000
2010 or 11, whatever year that 
was, they had long term access, 

75
00:04:56,000 --> 00:04:57,760
but it wasn't anywhere close to 
that long. 

76
00:04:58,960 --> 00:05:03,080
You know, this is the kind of 
this sounds like, you know, 

77
00:05:03,160 --> 00:05:06,600
whether these whether this was 
opportunistic. 

78
00:05:06,920 --> 00:05:09,640
You know, the attackers had a 
bug that they were using against

79
00:05:09,640 --> 00:05:13,560
a bunch of potential targets and
happened to get lucky and hit F5

80
00:05:13,560 --> 00:05:16,760
with this. 
You know, with this, found a 

81
00:05:16,760 --> 00:05:20,440
vulnerable instance of whatever 
and got in there and then, you 

82
00:05:20,440 --> 00:05:22,720
know, may have sold that access 
to somebody or used it 

83
00:05:22,720 --> 00:05:25,640
themselves, who knows. 
Or whether this was a targeted 

84
00:05:25,640 --> 00:05:30,120
attack and they were 
specifically looking for, you 

85
00:05:30,120 --> 00:05:32,880
know, looking to get into F5's 
networks and then see what they 

86
00:05:32,880 --> 00:05:35,000
could get from there. 
Nobody knows. 

87
00:05:35,000 --> 00:05:40,000
But but the state back state 
backed actor targeted seems more

88
00:05:40,000 --> 00:05:45,720
likely. 
And there were a couple of sort 

89
00:05:45,720 --> 00:05:50,320
of weird things or odd phrasing 
in the F5 statement. 

90
00:05:51,080 --> 00:05:54,920
I'm just going to read like 1 
portion of it from the What We 

91
00:05:54,920 --> 00:05:58,000
Know section. 
And this came out on October 

92
00:05:58,000 --> 00:06:01,000
15th, which was the day 
everything became public. 

93
00:06:01,000 --> 00:06:04,800
So it says we have confirmed 
that the threat actor 

94
00:06:04,800 --> 00:06:07,680
exfiltrated files from our Big 
IP product development 

95
00:06:07,680 --> 00:06:11,080
environment in engineering 
knowledge management platforms. 

96
00:06:11,560 --> 00:06:15,040
These files contain some of our 
Big IP source code and 

97
00:06:15,040 --> 00:06:18,320
information about undisclosed 
vulnerabilities we were working 

98
00:06:18,320 --> 00:06:22,360
on in Big IP. 
OK, next sentence. 

99
00:06:22,400 --> 00:06:25,880
We have no knowledge of 
undisclosed critical or remote 

100
00:06:25,880 --> 00:06:30,760
code vulnerabilities and we are 
not aware of active exploitation

101
00:06:30,760 --> 00:06:33,400
of any undisclosed F5 
vulnerabilities. 

102
00:06:34,120 --> 00:06:39,120
So those two statements seem to 
contradict each other. 

103
00:06:40,160 --> 00:06:42,960
I'm not. 
The only way that I can sort of 

104
00:06:43,080 --> 00:06:52,360
make them agree is if the 
attackers had access to this 

105
00:06:52,480 --> 00:06:56,360
vulnerability database or 
whatever it was for X number of 

106
00:06:56,360 --> 00:07:00,360
months, and now all of those 
vulnerabilities have become 

107
00:07:00,360 --> 00:07:03,040
public. 
So everything that the attackers

108
00:07:03,040 --> 00:07:06,480
had access to is now public 
through other means. 

109
00:07:06,520 --> 00:07:10,360
You know, F5 has disclosed them 
and patched them or they've 

110
00:07:10,360 --> 00:07:14,360
become public in other ways, but
that that's not really the way 

111
00:07:14,360 --> 00:07:17,240
that it's worded. 
So it's a little difficult to 

112
00:07:17,240 --> 00:07:20,560
kind of parse all of that, but 
that that's the only way that I 

113
00:07:20,560 --> 00:07:25,520
can parse it that makes any real
sense to me. 

114
00:07:26,680 --> 00:07:30,440
Yeah, that wording was weird. 
I think it's probably like 

115
00:07:30,480 --> 00:07:35,880
legalese, you know, some sort of
lawyer speak that probably got 

116
00:07:35,880 --> 00:07:40,560
their their hands on that. 
To your point, though, I know 

117
00:07:40,560 --> 00:07:45,160
they did also, they pushed out a
security update and I guess it 

118
00:07:45,160 --> 00:07:49,720
was like pretty big and it 
included some high severity 

119
00:07:49,720 --> 00:07:55,280
flaws and then also some denial 
of service bugs that could be 

120
00:07:55,280 --> 00:07:58,600
remotely exploited without 
authentication. 

121
00:07:58,600 --> 00:08:03,840
But like what, what worries me 
too about this is, you know, 

122
00:08:04,600 --> 00:08:07,960
reading between the lines again.
I mean, if threat actors got 

123
00:08:08,000 --> 00:08:13,720
access to their source code, you
know, looking at actual 0 days 

124
00:08:13,720 --> 00:08:18,360
in the sense of, you know, the 
fact that threat actors now can 

125
00:08:18,360 --> 00:08:21,920
find their own bugs and 
vulnerabilities that even F5 

126
00:08:21,920 --> 00:08:24,720
doesn't know about. 
And F5 may have disclosed all 

127
00:08:24,720 --> 00:08:27,520
this. 
But it just makes me nervous 

128
00:08:27,520 --> 00:08:31,520
that they can, they'll be able 
to study, you know, these things

129
00:08:31,520 --> 00:08:36,200
and really be able to get to 
kind of those root issues and 

130
00:08:36,200 --> 00:08:38,840
those root weaknesses. 
And I don't think that's 

131
00:08:38,840 --> 00:08:41,600
something that, I mean, they 
mentioned pen testing or 

132
00:08:41,600 --> 00:08:46,120
whatever in the advisory, but 
like, I don't know if that was 

133
00:08:46,120 --> 00:08:50,640
something that F5 has, you know,
given me enough confidence in 

134
00:08:50,640 --> 00:08:53,280
how they have talked about. 
They've addressed that. 

135
00:08:54,480 --> 00:08:57,720
The other thing too that I, that
kind of came to mind was like, 

136
00:08:57,760 --> 00:09:02,320
yes, they push out patches, but 
like if threat actors are able 

137
00:09:02,320 --> 00:09:06,920
to have this level of access and
able to really study, you know, 

138
00:09:07,520 --> 00:09:10,960
this, you know, to this level 
like the source code and 

139
00:09:10,960 --> 00:09:15,160
everything. 
Like, you know, I'd imagine if 

140
00:09:15,160 --> 00:09:18,680
there was any sort of like 
incomplete patch or like, you 

141
00:09:18,680 --> 00:09:22,400
know, something like just the 
ability for them to really skirt

142
00:09:22,400 --> 00:09:26,960
around that and, you know, have 
that level of knowledge, it just

143
00:09:26,960 --> 00:09:29,560
makes me nervous about what's 
going on behind the scenes. 

144
00:09:30,360 --> 00:09:32,880
Yeah, there's a, there's a bunch
of different really concerning 

145
00:09:32,880 --> 00:09:34,800
things there. 
If they, they got the source 

146
00:09:34,800 --> 00:09:36,920
codes, there's all those 
problems that you mentioned. 

147
00:09:38,480 --> 00:09:42,840
They did publish a couple of, 
they said that they brought in 

148
00:09:42,840 --> 00:09:49,360
IO Active and NCC group to do, 
you know, kind of not the 

149
00:09:49,360 --> 00:09:52,560
incident response work that you 
know, I guess they also brought 

150
00:09:52,560 --> 00:09:54,640
in Mandiant and Crowdstrike. 
That's the kind of thing that 

151
00:09:54,640 --> 00:09:57,320
they were doing. 
I think NCC and IO Active 

152
00:09:57,320 --> 00:10:01,840
specifically were looking at the
code repositories and things 

153
00:10:01,840 --> 00:10:04,320
along those lines to see if 
there were any modifications. 

154
00:10:04,320 --> 00:10:09,160
I read the IO Active letter that
said, you know, in the scope of 

155
00:10:09,160 --> 00:10:11,920
the work that they looked at, 
they could, they didn't find any

156
00:10:11,920 --> 00:10:16,440
modifications to 2F5's code 
base. 

157
00:10:16,760 --> 00:10:19,320
But that doesn't, as you said, 
Lance, it doesn't take into 

158
00:10:19,320 --> 00:10:22,480
account the fact that the 
attackers can now just look at 

159
00:10:22,480 --> 00:10:24,520
whatever they took. 
We don't know how much source 

160
00:10:24,520 --> 00:10:28,000
code they took or what it was, 
but yeah, they can just kind of 

161
00:10:28,000 --> 00:10:31,440
pour over that and get the lay 
of the land, see how see how 

162
00:10:31,440 --> 00:10:35,520
everything works. 
You know, it's, it's yeah, it's 

163
00:10:35,520 --> 00:10:38,600
really tough. 
Yeah, yeah, yeah. 

164
00:10:38,680 --> 00:10:42,920
The, and the other thing too I 
saw that was interesting was 

165
00:10:44,760 --> 00:10:49,960
the, there were some reports 
that were linking this intrusion

166
00:10:49,960 --> 00:10:55,240
to a separate recent report by 
Google, Google Mandiant, which 

167
00:10:56,000 --> 00:11:00,400
basically has some threat Intel 
parallels and talked about kind 

168
00:11:00,400 --> 00:11:04,120
of Chinese espionage groups that
were targeting, you know, tech 

169
00:11:04,120 --> 00:11:07,680
companies to grab their source 
code data and analyze it for 0 

170
00:11:07,680 --> 00:11:10,160
days. 
And you know, I'm sure you've 

171
00:11:10,320 --> 00:11:13,160
read that one, but it was the 
one that involved the malware, 

172
00:11:13,440 --> 00:11:18,520
the Brickstorm malware. 
So that was a, you know, another

173
00:11:18,520 --> 00:11:21,000
kind of interesting piece of 
this as well. 

174
00:11:22,400 --> 00:11:24,400
Just kind of. 
Looking at the parallels there. 

175
00:11:24,920 --> 00:11:28,800
I think, you know, if you, if 
you had to bet your mortgage on 

176
00:11:29,560 --> 00:11:32,720
who the attackers were, I think 
you, I think we'd both bet on a 

177
00:11:32,960 --> 00:11:38,480
China backed group. 
You know, I don't think that 

178
00:11:39,120 --> 00:11:41,960
Google has a name for them in 
that report that you mentioned. 

179
00:11:41,960 --> 00:11:47,560
It's one of the UNC groups, I 
believe one of the groups, not 

180
00:11:47,840 --> 00:11:50,640
University of North Carolina, 
but yeah. 

181
00:11:54,000 --> 00:11:56,840
But the, the link to the 
Brickstorm malware is 

182
00:11:56,840 --> 00:11:59,880
interesting too. 
They don't, there wasn't any 

183
00:12:01,120 --> 00:12:05,920
mention in the Mandy or excuse 
me, the F5 reports from this 

184
00:12:05,920 --> 00:12:08,560
week about any specific malware 
that they found in their 

185
00:12:08,560 --> 00:12:10,280
environment or anything like 
that. 

186
00:12:11,560 --> 00:12:13,640
Just judging by the way that 
these things have gone in the 

187
00:12:13,640 --> 00:12:18,800
past, I would expect some sort 
of public post mortem report 

188
00:12:18,880 --> 00:12:23,240
from either Mandy and or crowd 
strike on this. 

189
00:12:23,240 --> 00:12:26,480
You know, it'll, it'll be 
limited because of the way these

190
00:12:26,480 --> 00:12:28,400
things work and Ndas and all of 
that. 

191
00:12:28,400 --> 00:12:35,520
But if there's some new malware 
strain or some use of unknown 

192
00:12:35,520 --> 00:12:38,600
malware strain like Brickstorm, 
those are the kind of things 

193
00:12:38,600 --> 00:12:42,920
that usually get publicly 
reported in these cases. 

194
00:12:42,920 --> 00:12:47,160
And we haven't mentioned there's
also SISA put out an emergency 

195
00:12:47,160 --> 00:12:51,160
directive on Thursday or excuse 
me on Wednesday as well. 

196
00:12:51,560 --> 00:12:55,880
You know, with the the usual 
language of that, you know, 

197
00:12:55,880 --> 00:12:58,600
these things apply to all the 
federal civilian executive 

198
00:12:58,600 --> 00:13:02,280
branch agencies. 
So basically if you've got an 

199
00:13:02,320 --> 00:13:07,600
EF5-GO, look at it, see if it's 
vulnerable, if it is, you know, 

200
00:13:07,960 --> 00:13:09,640
pull it off the network, all of 
that kind of stuff. 

201
00:13:09,640 --> 00:13:12,720
And there's, there's usually a 
48 hour, 72 hour deadline for 

202
00:13:12,720 --> 00:13:15,160
these things. 
I didn't, I don't recall exactly

203
00:13:15,160 --> 00:13:18,760
what it is for this one, but 
that gives you a good idea of, 

204
00:13:19,280 --> 00:13:21,440
you know, obviously SISA knew 
about this long before it was 

205
00:13:21,440 --> 00:13:23,360
public. 
That's the way that these things

206
00:13:23,360 --> 00:13:26,640
are coordinated. 
So I assume that they've been 

207
00:13:27,280 --> 00:13:34,200
scrambling around on any other 
government networks as well, you

208
00:13:34,200 --> 00:13:38,400
know, the DoD and other networks
trying to get those in shape. 

209
00:13:38,520 --> 00:13:46,440
But at the same time, SISA is 
being systematically gutted. 

210
00:13:46,760 --> 00:13:53,880
So I don't really know how much 
manpower they have right now to 

211
00:13:55,280 --> 00:13:58,280
to get to do this, to respond to
something like this. 

212
00:13:58,680 --> 00:14:02,560
You know, it's one thing to put 
out these EDS and, you know, 

213
00:14:02,680 --> 00:14:06,120
public advisories, but it's, 
it's another thing like one of 

214
00:14:06,120 --> 00:14:09,400
their functions is to go and 
help agencies respond to things 

215
00:14:09,400 --> 00:14:12,640
like this. 
I don't know who's left to do 

216
00:14:12,640 --> 00:14:15,160
that, you know? 
Yeah. 

217
00:14:15,160 --> 00:14:18,120
And I don't even know who at 
other agencies themselves would 

218
00:14:18,120 --> 00:14:20,280
be leading the charge on this. 
Great point. 

219
00:14:20,680 --> 00:14:25,880
If they're if they're there as 
well, I know you know, that's, 

220
00:14:26,280 --> 00:14:29,320
that's definitely a good big 
picture thing to be thinking 

221
00:14:29,320 --> 00:14:31,800
about right now. 
I I thought they saw that they 

222
00:14:32,080 --> 00:14:35,160
had given them till like 
Halloween, which I thought was. 

223
00:14:35,320 --> 00:14:38,480
Oh, OK, Long, yeah. 
Now that you're talking about 

224
00:14:38,480 --> 00:14:40,520
this, it actually makes sense 
because they're probably trying 

225
00:14:40,520 --> 00:14:44,960
to like, just like with the 
limited resources and manpower 

226
00:14:44,960 --> 00:14:46,800
that they have in place now, 
it's like. 

227
00:14:47,160 --> 00:14:49,640
Yeah, there's probably like 4 
people that have to go around 

228
00:14:49,640 --> 00:14:53,840
and do all this for every 
civilian agency. 

229
00:14:54,560 --> 00:14:57,120
Yeah, I mean, that's a whole 
other story. 

230
00:14:57,120 --> 00:15:00,400
But it's, it's connected in 
that, you know, it's a limited 

231
00:15:00,920 --> 00:15:04,160
pool of resources to do this 
stuff, you know? 

232
00:15:04,320 --> 00:15:07,720
Right. 
But well, the you know, that 

233
00:15:07,720 --> 00:15:10,560
brings to mind though the 
timeline here is interesting 

234
00:15:10,560 --> 00:15:12,520
too. 
And the reason I bring that up 

235
00:15:12,520 --> 00:15:15,920
is because I, I don't, I'd 
imagine there's been some behind

236
00:15:15,920 --> 00:15:19,600
the scenes like preparation from
a government perspective, if the

237
00:15:19,760 --> 00:15:23,120
government is known about this. 
And it has because as you 

238
00:15:23,120 --> 00:15:29,240
mentioned, they became, they F5 
said they learned of this in 

239
00:15:29,360 --> 00:15:34,880
August, August 8th or something.
And but they only, you know, had

240
00:15:34,880 --> 00:15:39,520
the public SEC filing disclosed 
this past week. 

241
00:15:40,080 --> 00:15:44,160
But part of that is because the 
that you were mentioning the DOJ

242
00:15:44,160 --> 00:15:48,600
gave them an extension. 
So behind the scenes, you know, 

243
00:15:48,600 --> 00:15:52,800
there has been some coordination
that's not leaving federal 

244
00:15:52,880 --> 00:15:56,400
agencies scrambling during a 
government shutdown. 

245
00:15:57,480 --> 00:16:01,880
Yeah, it which if you go and 
read the SEC filing from F5, 

246
00:16:02,200 --> 00:16:07,080
which is linked to in our story,
you can see that DOJ, as you 

247
00:16:07,080 --> 00:16:09,960
mentioned, I think it's 
September 12th is the date if I 

248
00:16:09,960 --> 00:16:15,480
recall correctly, that DOJ said,
yes, you can delay this 

249
00:16:16,040 --> 00:16:19,400
basically out of the in the 
interest of national security 

250
00:16:19,800 --> 00:16:23,600
because F5's products are 
everywhere, you know, including 

251
00:16:23,600 --> 00:16:26,120
government agencies, as we 
mentioned, but they're in a ton 

252
00:16:26,120 --> 00:16:31,000
of enterprises and cloud 
providers and everywhere else. 

253
00:16:31,680 --> 00:16:40,240
So it's one of those situations 
where it you know, there the 

254
00:16:40,240 --> 00:16:43,480
longest running argument in the 
security community about when to

255
00:16:43,480 --> 00:16:45,960
disclose bugs and how to 
disclose them and all that kind 

256
00:16:45,960 --> 00:16:48,880
of shit. 
But in these kind of cases, you 

257
00:16:48,880 --> 00:16:54,520
look at it completely legitimate
request on F fives part and to 

258
00:16:54,520 --> 00:17:00,400
my mind completely legitimate 
answer from DOJ saying yes, in 

259
00:17:00,400 --> 00:17:05,599
this case we should delay this 
so that everybody who can has a 

260
00:17:05,599 --> 00:17:09,720
chance to go in, you know, make 
whatever changes they can in the

261
00:17:09,720 --> 00:17:11,599
interim. 
Right. 

262
00:17:11,920 --> 00:17:14,280
Yeah, that's that's a good 
point. 

263
00:17:14,280 --> 00:17:17,800
And the other thing about 
timeline that stuck out to me, 

264
00:17:17,800 --> 00:17:21,839
at least when I saw that report 
of that, you know, the threat 

265
00:17:21,839 --> 00:17:26,359
actors had had access to the 
environment for a year 

266
00:17:26,359 --> 00:17:31,520
essentially is, you know what, 
what was the tip off in August 

267
00:17:31,520 --> 00:17:35,360
that eventually led to them 
discovering this? 

268
00:17:35,360 --> 00:17:39,040
I mean, was it an external 
company or like did they figure 

269
00:17:39,040 --> 00:17:41,520
it out themselves? 
And I don't know, like I feel 

270
00:17:41,520 --> 00:17:46,040
like a year like there's granted
it's Chinese threat actors, like

271
00:17:46,040 --> 00:17:49,440
they're pretty stealthy, I would
say. 

272
00:17:49,520 --> 00:17:53,000
Professional had a lot. 
With like, you know, the malware

273
00:17:53,000 --> 00:17:56,320
and IO CS that Mandy and has 
disclosed over time. 

274
00:17:56,320 --> 00:17:59,640
But like there's kind of, you 
know, there's there's always 

275
00:17:59,640 --> 00:18:02,760
bread crumbs, like there's 
always clues that point to these

276
00:18:02,760 --> 00:18:06,760
types of intrusions. 
Like, yeah, yeah, it's 12 

277
00:18:06,760 --> 00:18:08,680
months. 
Like that just always is. 

278
00:18:08,800 --> 00:18:14,640
That's just crazy to me. 
It is and it's, you know, my 

279
00:18:15,360 --> 00:18:20,280
sort of educated guess, but not,
you know, specifically to this 

280
00:18:20,280 --> 00:18:26,120
is in a lot of cases what 
happens is there's a separate 

281
00:18:26,120 --> 00:18:29,080
incident that seems completely 
unconnected. 

282
00:18:29,600 --> 00:18:35,920
And after the details of that 
become public, either an 

283
00:18:35,920 --> 00:18:39,600
internal team or an external 
team goes and looks for 

284
00:18:40,040 --> 00:18:43,360
indications of something 
similar, whether it was the 

285
00:18:44,040 --> 00:18:48,280
exploitation of a specific bug 
or the use of specific malware 

286
00:18:48,280 --> 00:18:51,120
like like Brickstorm. 
You know, somebody might have 

287
00:18:51,120 --> 00:18:56,040
picked up that hunting guide and
gone and looked and, you know, 

288
00:18:56,280 --> 00:18:59,400
whether it was an internal team 
at F5 or somebody external was 

289
00:18:59,400 --> 00:19:04,080
like, oh shit, this looks like 
we might have an issue here. 

290
00:19:04,080 --> 00:19:08,280
And then they sort of work back 
from there and you know, see 

291
00:19:08,280 --> 00:19:10,200
where the attackers had access 
in it. 

292
00:19:10,200 --> 00:19:13,040
But, you know, that's, that's 
one scenario that could be a 

293
00:19:13,040 --> 00:19:16,000
bunch of others. 
But in a lot of cases, that's 

294
00:19:16,000 --> 00:19:20,760
what you see with especially any
kind of widespread 

295
00:19:20,760 --> 00:19:22,960
vulnerability. 
You know, if it's some kind of 

296
00:19:22,960 --> 00:19:29,480
like really widespread Windows 
bug or, you know, anything like 

297
00:19:29,480 --> 00:19:32,920
that. 
And once one incident or 

298
00:19:32,920 --> 00:19:35,480
intrusion becomes public, then 
everybody else starts looking 

299
00:19:35,480 --> 00:19:39,080
around for that. 
They're like, oh God, yeah, you 

300
00:19:39,080 --> 00:19:43,120
know, so I don't know. 
But that that's the most likely 

301
00:19:43,120 --> 00:19:46,400
scenario I can think of. 
Yeah, I think you're right. 

302
00:19:46,400 --> 00:19:50,320
That's how a lot of those types 
of like discoveries are made. 

303
00:19:51,720 --> 00:19:54,360
Yeah, I think. 
And the other thing too is like,

304
00:19:54,360 --> 00:19:56,760
you know, there's a couple of 
things that we still don't know 

305
00:19:56,760 --> 00:19:59,160
at this point. 
Initial access is one of them. 

306
00:19:59,840 --> 00:20:02,360
And so, you know, a lot of 
there's a couple of other pieces

307
00:20:02,360 --> 00:20:06,000
as well. 
But it it'll be, you know, 

308
00:20:06,000 --> 00:20:09,960
interesting to see like how 
moving forward, if we see more 

309
00:20:09,960 --> 00:20:13,840
of these, you know, facts or, 
you know. 

310
00:20:14,480 --> 00:20:18,200
Findings come out through, you 
know, a Mandiant disclosure or 

311
00:20:18,200 --> 00:20:22,800
something like that or how you 
know how F5 is going to kind of 

312
00:20:22,800 --> 00:20:26,160
move forward in terms of 
revealing information about 

313
00:20:26,160 --> 00:20:28,200
this. 
Yeah, I would assume they're 

314
00:20:28,200 --> 00:20:33,880
going to continue to update what
they can, you know in legally 

315
00:20:33,880 --> 00:20:37,160
and and you know with the other 
constraints that they're going 

316
00:20:37,160 --> 00:20:40,640
to have. 
But you know, in terms of the, 

317
00:20:40,920 --> 00:20:45,200
the customer impacted, as you 
said, Lance, they, they released

318
00:20:45,200 --> 00:20:50,200
all these patches yesterday and 
you know, essentially said go 

319
00:20:50,320 --> 00:20:54,800
update, which is, you know, all 
the guidance there kind of is 

320
00:20:54,800 --> 00:20:58,040
right now. 
And they're, oh, we should 

321
00:20:58,040 --> 00:21:01,320
mention we, we didn't, it's my 
fault we didn't mention this. 

322
00:21:01,320 --> 00:21:05,400
But another thing that F5 
disclosed yesterday is that they

323
00:21:05,400 --> 00:21:11,560
rotated a bunch of their code 
signing certificates and keys as

324
00:21:11,680 --> 00:21:14,800
a result of this. 
They didn't say specifically 

325
00:21:14,800 --> 00:21:21,920
what, but they did say that they
listed a few big IP and other 

326
00:21:21,920 --> 00:21:27,560
products and said if you haven't
updated, you know, as a result 

327
00:21:27,560 --> 00:21:29,920
of this key and certificate 
rotation, some of these updates 

328
00:21:29,920 --> 00:21:32,960
might not take because, you 
know, if you haven't gotten 

329
00:21:32,960 --> 00:21:36,400
there yet. 
So that sounds like another sort

330
00:21:36,400 --> 00:21:41,240
of artifact of this whole thing,
you know, but that's, you know, 

331
00:21:41,240 --> 00:21:43,840
it's just one other piece of it 
that's there's nothing customers

332
00:21:43,840 --> 00:21:46,840
can do about that, but just more
kind of fallout. 

333
00:21:47,320 --> 00:21:49,920
Yeah, more fallout, yeah. 
I know, yeah. 

334
00:21:49,960 --> 00:21:52,520
Like we need more of that. 
Yeah, no, we don't. 

335
00:21:53,880 --> 00:21:57,120
But yeah, it it does seem like 
this is going to be one of those

336
00:21:57,120 --> 00:22:00,440
that we're going to be hearing 
bits as bits and pieces about 

337
00:22:00,440 --> 00:22:04,240
for the next few days and weeks.
I would imagine, you know, 

338
00:22:04,320 --> 00:22:07,480
something else will come along 
and grab everybody's attention 

339
00:22:08,160 --> 00:22:11,360
and then, you know, four weeks 
from now we'll see an update and

340
00:22:11,360 --> 00:22:13,520
be like, Oh yeah, yeah, I 
remember that. 

341
00:22:14,000 --> 00:22:18,960
That was like 3 incidents ago. 
Looking at you like Avanti. 

342
00:22:19,000 --> 00:22:24,320
Sonicwall somebody. 
Yeah, I I saw her friend Matt 

343
00:22:24,320 --> 00:22:27,520
Johansson yesterday, You know, 
somewhere, I don't know if it 

344
00:22:27,520 --> 00:22:31,040
was Twitter or wherever was 
saying, you know, everybody has 

345
00:22:31,040 --> 00:22:34,200
breached fatigue at this point. 
And it's just kind of one of 

346
00:22:34,200 --> 00:22:40,160
those it professional hazards in
this industry where you're like,

347
00:22:40,200 --> 00:22:43,800
OK, another thing, another 
thing, another thing. 

348
00:22:43,800 --> 00:22:46,760
And it's hard to sometimes stop 
and take a look and be like, 

349
00:22:46,760 --> 00:22:49,360
well, hold on. 
One of these things is not like 

350
00:22:49,360 --> 00:22:51,880
the other. 
This is a big, this isn't just 

351
00:22:52,320 --> 00:22:55,200
an attacker got in and stole 
some, you know, financial 

352
00:22:55,200 --> 00:22:58,600
records from a manufacturer. 
This is a big thing. 

353
00:22:58,600 --> 00:23:02,600
So it we do sometimes, you know,
your eyes glaze over at some 

354
00:23:02,600 --> 00:23:05,280
point, you're like, OK, here we 
go again. 

355
00:23:05,280 --> 00:23:09,320
But yeah, this is, I think this 
is a a little different than 

356
00:23:09,320 --> 00:23:10,800
most of the other ones we 
usually see. 

357
00:23:11,480 --> 00:23:15,080
Yeah, I think that's that is a 
really interesting topic. 

358
00:23:15,080 --> 00:23:17,440
We should do another podcast on 
sometime though. 

359
00:23:17,440 --> 00:23:20,400
It's just like the level of 
breach fatigue and like the 

360
00:23:20,400 --> 00:23:23,880
issues with communication and 
the security industry about 

361
00:23:23,880 --> 00:23:28,960
like, you know, how high, how 
much of A priority one thing is 

362
00:23:28,960 --> 00:23:32,880
versus another. 
Because it is like, and you 

363
00:23:32,880 --> 00:23:36,480
know, I think the the news 
honestly has has a big role and 

364
00:23:36,480 --> 00:23:39,960
responsibility in this is 
there's just so many headlines 

365
00:23:39,960 --> 00:23:43,440
over and over about, you know, 
there was this actively 

366
00:23:43,440 --> 00:23:46,000
exploited vulnerability, There 
was this zero day. 

367
00:23:46,000 --> 00:23:50,720
But like what actually separates
something like this type of 

368
00:23:50,720 --> 00:23:55,160
incident from something from, 
you know, that we saw even 

369
00:23:55,320 --> 00:23:58,800
earlier this week, we saw the 
Oracle extortion attacks, like 

370
00:23:58,800 --> 00:24:02,280
continual fallout from that. 
So like looking at two different

371
00:24:02,280 --> 00:24:05,640
incidents, like what the impact 
is for customers, how long term 

372
00:24:05,640 --> 00:24:08,600
is this going to be in terms of 
the effect? 

373
00:24:09,520 --> 00:24:14,080
You know, all these questions, I
think, you know, it's there's 

374
00:24:14,080 --> 00:24:18,160
just a lot of a lot of different
pieces that go into it. 

375
00:24:18,680 --> 00:24:20,840
Yeah. 
I mean, we, we both know people 

376
00:24:20,840 --> 00:24:24,520
that do incident response and 
all of that kind of stuff. 

377
00:24:24,520 --> 00:24:29,760
And those people do often have 
that kind of like 1000 yard 

378
00:24:29,760 --> 00:24:31,920
stare where they've seen so many
things. 

379
00:24:31,920 --> 00:24:35,760
There's, you know, they're 
immune to those the same way 

380
00:24:35,760 --> 00:24:39,120
that, you know, like EMTs have a
certain look where they're like 

381
00:24:39,280 --> 00:24:40,920
they've seen everything at some 
point. 

382
00:24:41,840 --> 00:24:46,840
But if you're a customer or, you
know, an internal security team,

383
00:24:47,680 --> 00:24:51,240
you have to treat every one of 
these things as its own, you 

384
00:24:51,240 --> 00:24:55,720
know, discreet animal and be 
like, OK, let's go and look at 

385
00:24:55,720 --> 00:24:59,600
this on its own. 
And you can't, you can't afford 

386
00:24:59,600 --> 00:25:03,080
to let that fatigue really pile 
up on you, because then you 

387
00:25:03,080 --> 00:25:05,600
can't really do the job that 
you're supposed to be doing, you

388
00:25:05,600 --> 00:25:07,960
know? 
Yeah, that's true. 

389
00:25:08,160 --> 00:25:11,120
Makes like really difficult it. 
Does yeah. 

390
00:25:12,200 --> 00:25:16,720
And also even looking at the the
advisory to like just the the F5

391
00:25:16,720 --> 00:25:20,760
advisory, for instance, like, 
you know, using these same types

392
00:25:20,760 --> 00:25:24,680
of languages like long term 
persistent access, like I know 

393
00:25:24,680 --> 00:25:26,760
this is never going to happen. 
I know this is just me being 

394
00:25:26,760 --> 00:25:29,080
optimistic, but like if you're 
telling your customers that it 

395
00:25:29,080 --> 00:25:31,800
was 12 months, just come out and
say, say it was 12 months. 

396
00:25:31,800 --> 00:25:34,120
Like we're going to find that 
anyway. 

397
00:25:34,840 --> 00:25:36,440
Yeah. 
Yeah. 

398
00:25:36,520 --> 00:25:40,600
It's it's just like being able 
to better communicate so that we

399
00:25:40,600 --> 00:25:43,160
can really fully understand the 
impact of some of these things. 

400
00:25:43,680 --> 00:25:46,840
Yeah, there are those coded 
phrases. 

401
00:25:46,840 --> 00:25:51,160
It's, you know, long term 
persistent is something that you

402
00:25:51,160 --> 00:25:53,560
would look at. 
OK, That's, you know, people 

403
00:25:53,560 --> 00:25:56,840
generally won't put long term in
a statement unless they 

404
00:25:56,840 --> 00:26:00,680
absolutely have to. 
You know, they'll usually say 

405
00:26:01,760 --> 00:26:07,160
limited or, you know, whatever 
it is, they'll they'll use some 

406
00:26:07,160 --> 00:26:11,920
parameters to make it sound 
squishier than it than it really

407
00:26:11,920 --> 00:26:14,360
is. 
And, you know, obviously this 

408
00:26:14,360 --> 00:26:16,160
doesn't sound squishy at all. 
It sounds terrible. 

409
00:26:16,560 --> 00:26:20,920
So when I first saw that, I was 
like, yeah, this is, you know, 

410
00:26:20,920 --> 00:26:22,680
that's one of the phrases you 
kind of stop on. 

411
00:26:24,600 --> 00:26:29,480
So, yeah, it's again, I, I think
we're, we have certainly not 

412
00:26:29,480 --> 00:26:32,760
seen the the end of the 
disclosures for this so. 

413
00:26:33,120 --> 00:26:34,560
No, definitely not. 
Yeah. 

414
00:26:36,160 --> 00:26:39,720
All right. 
Well, we'll be definitely 

415
00:26:39,960 --> 00:26:42,480
updating the piece that we wrote
on this, and I have a feeling 

416
00:26:42,480 --> 00:26:44,600
we'll be mentioning this on 
future podcasts as well. 

417
00:26:44,600 --> 00:26:49,240
So yeah, stay tuned. 
Yeah. 

418
00:26:49,960 --> 00:26:50,920
All right. 
All right. 

419
00:26:50,920 --> 00:26:52,120
Thanks, Lynns. 
Good to see you. 

420
00:26:52,800 --> 00:26:53,480
Thanks. 
Bye. 

421
00:26:53,720 --> 00:26:53,920
Bye.
