F5's sizable security breach last week underscored the need to shift to zero trust adoption.
The security firm revealed last week that it was subject to a state-sponsored attack on its networks. The breach is believed to have been orchestrated by Chinese-linked hackers who may have had access to F5’s network for at least a year.
Figures from Palo Alto Networks suggest that more than 600,000 F5 network security devices running its BIG-IP software are unpatched and potentially vulnerable. While the security nonprofit Shadowserver Foundation tracked more than 266,000 F5 BIG-IP instances that have been exposed online following the breach, according to BleepingComputer.
Following the Cisco bug exploited by a Russian espionage group earlier this year, security experts outlined that nation-state threat groups are getting smarter and more persistent – with zero trust adoption the only real way to shore up security.
“Traditional firewalls, VPN concentrators, and other network appliances with publicly exposed IP addresses remain prime targets,” Misha Kuperman, Zscaler’s chief reliability officer, told SDxCentral. “Organizations must act quickly and move to a modern zero trust architecture, one that assumes no implicit trust, verifies every connection, and enforces least-privileged access by design.”
So, what is zero trust, and how can it help?
Zero trust is a security framework that abandons the concept of trusted internal networks. Instead of assuming anything inside a corporate perimeter is safe, it requires continuous verification of every user, device, and connection before granting access to resources.
The approach, which applies regardless of a user’s location, aims to eliminate implicit trust, instead segmenting access to only what's necessary for each user or system.
“Organizations seeking to reduce their exposure to incidents like this should prioritize a combined zero trust and defense-in-depth approach,” Roman Arutyunov, co-founder and SVP of products at Xage Security, told SDxCentral. “Properly implemented, zero trust and defense-in-depth create layered defenses, minimize the blast radius of a breach and enable faster, more effective containment, even from sophisticated state-backed adversaries.”
Ironically, F5 does offer zero trust solutions like its distributed cloud services, which can be integrated with a zero-trust security model to secure access, identity verification, and application security.
Such an approach would help to prevent the kind of prolonged, undetected compromise that befell the cybersecurity vendor.
“Shifting away from single points of hack is critical to building resilience against advanced attacks like these,” Arutyunov said. “When security teams rely on a centralized security solution, if that solution is compromised, everything will be lost. Many organizations are now increasingly implementing ‘mesh’ architectures where many systems work together and protect each other, to eliminate that risk of a single point of hack.”
The industry shift toward zero trust architectures has seen related offerings from vendors sky-rocket of late.
Cisco’s zero trust capabilities, for example, were recently lauded by SE Labs, with Cisco Security executive Raj Chopra recently telling SDxCentral that the Cisco suite is going all-in on universal zero-trust network access (ZTNA).
Cloudflare, meanwhile, recently tapped an out-of-the-box zero trust capability from CrowdStrike to shore up networks. Cloudflare itself launched its own zero trust updates in August to combat the threat of shadow AI, or the unapproved use of AI tools and applications by employees without their organization's knowledge or IT oversight.
“Zero trust, powered by AI to fight AI, eliminates implicit trust, validating every user, device, and application before allowing communication,” Zscaler's Kuperman added. “In a zero trust everywhere environment, a large majority of the cyberattacks today will go away.”
Comments