Hackers Deploy Linux Rootkit on F5 BIG-IP APM Devices
A Linux rootkit targets F5 BIG-IP APM devices by injecting fileless web shells into memory through PHP file loading interception, complicating detection.
Tag
12 results in the archive.
A Linux rootkit targets F5 BIG-IP APM devices by injecting fileless web shells into memory through PHP file loading interception, complicating detection.
MikroTik released a patch for an SSH authentication bypass vulnerability currently exploited to create unauthorized accounts on devices.
A Linux backdoor named 'Ted' has been found in trojanized HAProxy builds at South Korean organizations, intercepting and modifying web traffic while requiring prior code execution on the host.
Cisco released a patch for a critical vulnerability in Silicon One-based Nexus 9000 switches that allows unauthenticated remote code execution as root, identified as CVE-2026-20212 with a 9.8 CVSS score.
The China-linked Fire Ant group has compromised Cisco IOS XR routers, TACACS servers, and Linux hosts to steal credentials and disable security logs, targeting critical network infrastructure.
Evooo1Bot is a new Mirai-based Linux botnet targeting internet-facing routers to convert them into SOCKS5 traffic relay nodes, expanding attack surfaces.
Cisco alerts on a high-severity denial-of-service vulnerability in Secure Firewall ASA and Threat Defense VPN software actively exploited to crash devices, threatening enterprise network stability.
Cisco released patches for 12 critical vulnerabilities in Catalyst SD-WAN and IOS XE software impacting devices in all configurations.
Arista released a patch for a critical command injection zero-day vulnerability currently exploited in on-premises VeloCloud Orchestrator deployments, affecting enterprise network management.
A critical DHCPv6 stack overflow vulnerability in OpenWrt's default network service odhcpd allows unauthenticated remote root code execution.
SonicWall disclosed two critical zero-day vulnerabilities in SMA1000 devices being exploited in active attacks, highlighting urgent risk to enterprise network security.
Russian state-sponsored hackers from FSB Center 16 are exploiting poorly configured routers in critical infrastructure worldwide, heightening operational risks.