Incidents at security vendors
Which disclosed incidents in the log happened at companies that sell security products? 2 entries at 2 vendors, newest first, with the vendor's category from the directory.
How to read this list. An entry records what the company disclosed, sourced to its filing. Being listed says nothing about the quality of the company’s products, and the log assigns no blame to anyone and draws no link between an incident and any person’s work.
Vendor names link to the company’s one record on cisotribune.com, which lists what it sells. A company counts as a vendor when its name or ticker matches a published directory record. No vendor pays to be listed or left out. Directory data as of September 27, 2026.
- F5 discloses nation-state access to BIG-IP source code and vulnerability dataDisclosed October 15, 2025
- Vendor
- F5Public (NASDAQ: FFIV) · Seattle, United States
- Category
- WAF and WAAPApplication security
- Filing
- 8-K Item 1.05 · FFIV
- Microsoft discloses nation-state access to senior leadership email accountsDisclosed January 19, 2024
- Vendor
- MicrosoftPublic (NASDAQ: MSFT) · Redmond, United States
- Category
- EDR and XDREndpoint security
- Filing
- 8-K Item 1.05 · MSFT
The full log, with every sector and form item, is on the incident log.