Tag

Cve 2025 53521

All articles tagged with #cve 2025 53521

In-Memory Linux Rootkit Targets F5 BIG-IP APM After CVE-2025-53521 Exploit
technology1 month ago

In-Memory Linux Rootkit Targets F5 BIG-IP APM After CVE-2025-53521 Exploit

Sophos describes a second-stage Linux rootkit that targets F5 BIG-IP APM after CVE-2025-53521, hooking the Apache/PHP stack to load a memory-resident web shell, with an installer that corrupts SELinux and persists across upgrades; the malware hides strings with RC4, intercepts __libc_start_main, and creates a local UNIX socket for an interactive Bash shell, avoiding disk writes and using targeted PHP3 scripts to evade alerts, while ShadowServer notes hundreds of exposed endpoints.

F5 BIG-IP APM Flaw Upgraded to Active RCE Risk, Urgency to Patch
technology6 months ago

F5 BIG-IP APM Flaw Upgraded to Active RCE Risk, Urgency to Patch

F5 Networks reclassified the BIG-IP APM vulnerability CVE-2025-53521 from a DoS issue to a critical remote code execution flaw, with attackers exploiting unpatched systems to deploy webshells. CISA has ordered federal agencies to patch, and F5 issued mitigations and indicators of compromise as online exposure of BIG-IP instances remains high. Patch now and review disks, logs, and terminal history for signs of intrusion.