Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit

MediumBleepingComputer · Bill Toulas·

A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk. [...]

We summarise and link; this source is not one we hold a licence to reproduce. Everything below is what NexaPulse adds: the vulnerabilities involved, whether they are being exploited, who is named, and who else covered it.

At a glance

Severity
Mediumfrom category and source signals; no CVSS referenced
Exploitation
No vulnerabilities referenced
Vulnerabilities
None referenced
Vendors & products
F5, Linux
Threat actors & malware
None named
Industries
Not industry-specific
Coverage
1 outlet· first seen 2026-09-08 20:08 UTC
Priority
41/100Source tier, category, exploitation and corroboration. Not a risk score for your environment.

Coverage

One outlet has carried this so far.

  1. BleepingComputerEstablished SourceFirst reported

    2026-09-08 20:08 UTC

Related stories