<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[🐧 F5 and Confluence Multi-Stage Linux Intrusion]]></title><description><![CDATA[<p><img
      src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f427.png?v=28325c671da"
      class="not-responsive emoji emoji-android emoji--penguin"
      style="height: 23px; width: auto; vertical-align: middle;"
      title="🐧"
      alt="🐧"
    /> F5 and Confluence Multi-Stage Linux Intrusion</p><p><img
      src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f4dd.png?v=28325c671da"
      class="not-responsive emoji emoji-android emoji--memo"
      style="height: 23px; width: auto; vertical-align: middle;"
      title="📝"
      alt="📝"
    /> Threat actors compromised an internet-f...</p><p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://www.microsoft.com/en-us/security/blog/2026/05/22/from-edge-appliance-to-enterprise-compromise-multi-stage-linux-intrusion-via-f5-and-confluence/" title="From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence | Microsoft Security Blog">
<img src="https://www.microsoft.com/en-us/security/blog/wp-content/uploads/2026/04/MS_Actional-Insights_Access.png" class="card-img-top not-responsive" style="max-height: 15rem;" alt="Link Preview Image" />
</a>



<div class="card-body">
<h5 class="card-title">
<a href="https://www.microsoft.com/en-us/security/blog/2026/05/22/from-edge-appliance-to-enterprise-compromise-multi-stage-linux-intrusion-via-f5-and-confluence/">
From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence | Microsoft Security Blog
</a>
</h5>
<p class="card-text line-clamp-3">A multi-stage attack on Linux devices began with an exposed F5 BIG-IP edge appliance and pivoted to an internal Confluence server for credential theft and identity compromise. Learn how the threat actor attempted Kerberos relay and lateral movement, and how Microsoft Defender detected, blocked, and unraveled the attack.</p>
</div>
<a href="https://www.microsoft.com/en-us/security/blog/2026/05/22/from-edge-appliance-to-enterprise-compromise-multi-stage-linux-intrusion-via-f5-and-confluence/" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://www.microsoft.com/favicon.ico" alt="favicon" class="not-responsive overflow-hiddden" style="max-width: 21px; max-height: 21px;" />



<p class="d-inline-block text-truncate mb-0">Microsoft Security Blog <span class="text-secondary">(www.microsoft.com)</span></p>
</a>
</div></p><p><img
      src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f4f0.png?v=28325c671da"
      class="not-responsive emoji emoji-android emoji--newspaper"
      style="height: 23px; width: auto; vertical-align: middle;"
      title="📰"
      alt="📰"
    /> Microsoft Security Blog</p><p><a href="https://infosec.exchange/tags/AppSec" rel="tag">#<span>AppSec</span></a> <a href="https://infosec.exchange/tags/InfoSec" rel="tag">#<span>InfoSec</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/8d8cc12f-328d-48e0-8d55-aefe745d7917/f5-and-confluence-multi-stage-linux-intrusion</link><generator>RSS for Node</generator><lastBuildDate>Mon, 25 May 2026 08:01:05 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/8d8cc12f-328d-48e0-8d55-aefe745d7917.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 23 May 2026 10:00:58 GMT</pubDate><ttl>60</ttl></channel></rss>