Back to Intel

Intel Node

From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence

criticalapt2026-05-22T16:53:39+00:00source excerpt
apttradecraftdetectionwindowslinuxcloudidentitynetwork

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

A multi-stage attack on Linux devices began with an exposed F5 BIG-IP edge appliance and pivoted to an internal Confluence server for credential theft and identity compromise. Learn how the threat actor attempted Kerberos relay and lateral movement, and how Microsoft Defender detected, blocked, and unraveled the attack. The post From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence appeared first on Microsoft Security Blog .

In this article Attack chain overview Initial access: Exploiting edge appliances Discovery and reconnaissance Lateral movement and identity compromise Mitigation and protection guidance Microsoft Defender XDR detections Advanced hunting Indicators of compromise (IOC) MITRE ATT&CK techniques observed References Learn more A growing trend in modern intrusions is the compromise of internet-facing edge appliances such as firewalls and VPN gateways. Systems traditionally deployed as security boundaries are increasingly becoming initial access points due to the continued discovery and exploitation of critical vulnerabilities.

Because these devices are externally exposed, lightly monitored, and highly trusted inside enterprise environments, compromise can provide a durable foothold with limited visibility.

Read Original Source