security: From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence

1 · Sujith Quintelier · May 23, 2026, 6:03 a.m.
Summary
This blog post discusses a multi-stage Linux intrusion that originated from an exposed F5 BIG-IP appliance and progressed to an internal Confluence server for credential theft and identity compromise. It highlights aspects of the attack, including Kerberos relay attempts and lateral movement, with mention of Microsoft Defender's detection capabilities.