Security news

Latest security news

4 of 1,256 storiesF5Clear all

Yesterday · Tue, 15 Sept 2026

  1. Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers

    Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an automated effort aimed at internet-exposed Vite development servers that's designed to steal cloud credentials, configurations from Amazon Web Services (AWS) and Microsoft Azure instances, and infrastructure state files, per F5 Labs. The

    The Hacker NewsMicrosoft, AWS, F5

Wed, 9 Sept 2026

  1. F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

    Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three appliances' own PHP scripts, the malware adds the web shell to the copy held in memory, so a check of the file on disk can come back clean. Those three scripts are

    The Hacker NewsF5, Sophos, Apache

Tue, 8 Sept 2026

  1. Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit

    A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk.

    BleepingComputerF5, Linux

Thu, 3 Sept 2026

  1. F5 security advisory (AV26-878)

    Serial Number: AV26-878 Date: September 3, 2026 As of September 2, 2026, F5 is affected by vulnerabilities in the following products: BIG-IP (all modules) Prior to 17.1.3.4 Prior to 17.5.1.8 Prior to 21.0.0.3 Prior to 21.1.0.1 BIG-IQ Prior to 8.4.2.1 NGINX Gateway Fabric Prior to 2.6.8 NGINX Ingress Controller Prior to 2026-lts-r5 Prior to 5.6.0 NGINX JavaScript 9.9 Prior to 1.0.1 APM Clients Prior to 7.2.6 BIG-IP APM Multiple versions The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. K000162872: Out-of-band Security Notification (September 2, 2026)

    Canadian Centre for Cyber SecurityF5, Nginx

About this news

1,256
Stories
35
Added in the last 24 hours
18
Critical in the last 7 days
4
Reported by several outlets