Wire · technology
Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
◆ Sectors
◆ Source
◆ Verified
Fusion42 · 9 September 2026 · Fusion42 review
A Linux rootkit targeting F5 BIG-IP APM devices exploits a critical remote code execution vulnerability (CVE-2025-53521) to inject a fileless PHP web shell into memory, avoiding disk detection and achieving persistence across device upgrades. The rootkit enables stealthy on-demand server-side code execution and local backdoor access without exposing a network port.
This Wire brief sits within Fusion42's coverage of Cybersecurity.
◆ ◆ The Wire takeaway
Your BIG-IP APM deployments are at risk of stealthy rootkit infection that evades disk-based detection and persists across upgrades. Patch CVE-2025-53521 immediately and audit for in-memory hijacks to prevent attackers from gaining undetected server control.
◆ Coverage
1 source · 8 Sep 2026
◆ Related on Wire
◆ Topics