Capability does not equal resilience in the world of generative AI. 🧠🛡️ In a recent test, a 4-billion-parameter model scored a solid 80 on our security index, while its 2-billion-parameter sibling scored 1.28. As you scale your enterprise #AI initiatives, you can’t assume that high-performing models are secure by default. ➡️ Find out more: https://go.f5.net/jhw9ttpw
F5 Labs Threat Research
IT Services and IT Consulting
Seattle, WA 9,999 followers
We process application threat data into actionable intelligence, analyze & share information with the InfoSec community.
About us
Threat research. Security leadership. Decades of experience. We process app threat data from F5 and our partners into actionable intelligence, and analyze and share the Who, What, When, Why, How, & What’s Next of cyber attacks to benefit the security community.
- Website
-
https://www.f5.com/labs
External link for F5 Labs Threat Research
- Industry
- IT Services and IT Consulting
- Company size
- 1,001-5,000 employees
- Headquarters
- Seattle, WA
- Type
- Public Company
- Founded
- 2016
- Specialties
- InfoSec, Threat Intelligence, Application Security, IoT, Cybersecurity, threat research, application services, malware, phishing, credential stuffing, breaches, hackers, CISO, independent, application protection, ddos, tls, and magecart
Updates
-
Is your WordPress site at risk? In our latest analysis we highlight the wp2shell attack chain compromising #WordPress installations via CVE-2026-63030 and CVE-2026-60137. Plus, we dive into: ⚙️ How the vulnerabilities work 🔍 Observed exploit behaviors 🛠️ Patch recommendations 👉 View the full analysis: https://go.f5.net/7sk6mz9b
-
💻 A live video call used to be the gold standard for verifying identity. Not anymore. ICYMI: Generative #AI is enabling threat actors to bypass traditional security checks with cloned voices and deepfake visuals, launching flawless impersonation attacks on business leaders. As David Warburton, Director of F5 Labs Threat Research states, “We’ve officially crossed the threshold where a live video call is no longer proof of life. Threat actors are executing flawless, real-time corporate espionage and identity fraud directly over platforms like Zoom.” Learn more ➡️ https://go.f5.net/xrq3qn33 via Financial Times
-
🤖 ICYMI: Not all bots are bad, but malicious automation is now a serious business risk. For CISOs, bot activity is not just “noise” in web traffic. It can drive: 1️⃣ Credential stuffing 2️⃣ Fake account creation 3️⃣ Account takeover If your business depends on digital channels, malicious automation is not a side issue. It’s part of your threat model. Check out our research on bots and automation here: https://go.f5.net/k3py6t6v
-
Are your current security controls tuned to handle this week’s emerging threats? 🛡️ Threat actors don’t take time off, and neither should your threat intel. Our new Weekly Threat Bulletin is out, providing a concise roundup of the latest vulnerabilities, active exploits, and mitigation recommendations. 👉 View our bulletin: https://go.f5.net/w1c7ji8m
-
Could your AI model’s strength be its biggest vulnerability? 🤖🛡️ Taking a closer look at Morality Dilemma jailbreak, attackers are successfully bypassing standard guardrails by feeding #AI models corrupted ethical rules and asking them to “reason” through them. The paradox? Stronger models with superior instruction following capabilities are significantly more vulnerable to this tactic than weaker ones. Find out how this emerging threat vector works and what it means for prompt security. 🔗 https://go.f5.net/seqj0i9q
-
🚨 Our new #F5 Labs Weekly Threat Bulletin is live! Our latest intelligence roundup for August 26th covers everything you need to know to secure your apps and APIs this week, including updates on CVE-2026-32475, which affects the Elementor Pro #WordPress plugin. 👇 View our full list of active exploits. https://go.f5.net/nqx3k5ks
-
Did your #AI model’s security posture drop overnight? 📉 Since providers frequently deploy silent updates to backend system prompts and classifiers, a model’s resilience can shift dramatically post-deployment. We observed models losing between 29 to 55 security index points in just one month. Point-in-time security approval are no longer sufficient for AI. Learn why continuous assurance is critical and how our CASI leaderboard tracks these changes. 🔗 https://go.f5.net/6t7schrr
-
As the team continues to track CVE data, the composition of the top 10 has shifted with four CVEs leaving and four new entries taking their place. ↔️ Swipe below to see the new CVEs and view our analysis ➡️ https://go.f5.net/tonhu19n to see where they rank.
-
The top 4️⃣ models from this month’s CASI rankings came from the same #AI provider, #Anthropic. ⬇️