Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit | HappeningNow.news

Cybersecurity · 3 views

Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit

A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk. [...]

Source Summary Published 12h 26m ago Brief Under 1 min brief
Story intelligence
Coverage Single outlet Single-outlet story
Views 3 Community interest
Brief read Under 1 min brief 66 words

Summary

A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk. The malware shows signs of being a second-stage payload that was likely deployed after exploiting CVE-2025-53521, a critical remote code execution (RCE) flaw that F5 Networks reclassified from a DoS problem in March.

Read original at Bleepingcomputer

Coverage Context

Part of APM coverage 3 tracked stories

More from Cybersecurity

Continue reading recent Cybersecurity coverage

Support HappeningNow

Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.

Support HappeningNow

Report an issue with this page