Feed›Vulnerability›Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit...
VulnerabilityBleeping Computer
9.8 — CRITICAL

Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit

📅 8 September 2026 at 20:08 UTC📰 Bleeping ComputerView original source ↗
Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit

A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

Hackers have breached F5 BIG-IP APM devices to deploy a Linux rootkit, allowing for the interception of PHP file loading and injection of a fileless web shell into memory, potentially leading to remote code execution and elevated privileges.

⚙️Technical Details
💥Impact Assessment
Severity: Critical
Who Is at Risk
Organizations with F5 BIG-IP APM environments, particularly those using Apache on these systems
🛡️Recommended Actions
1Investigate unusual POST requests to targeted .php3 endpoints and PHP responses combining HTTP 201 with a text/css content type
2Monitor Apache workers reading /proc/self/maps, changing libphp memory protections, creating /run/bigtlog.pipe, or launching /bin/bash
3Implement additional security measures, such as enabling SELinux configurations and using secure credentials
📦Affected Products
F5 Big-Ip Access Policy ManagerF5 Big-IP Access Policy Manager
🔐NVD Verified DataVERIFIED
CVE-2025-53521 ↗CVSS 9.8 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-121
Affected Products (CPE)
F5 Big-Ip Access Policy Manager

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer ↗
← Back to feed