:

F5 BIG-IP APM DEVICES TARGETED BY LINUX ROOTKIT

DEV DESK1 MIN READ
TUE, SEP 8, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Attackers have breached F5 BIG-IP APM devices to deploy a Linux rootkit capable of injecting malicious code directly into memory. The attack bypasses disk-based detection by intercepting PHP file loading.

The rootkit targets F5 BIG-IP Application Performance Monitoring (APM) systems, exploiting them as entry points for infrastructure compromise. Rather than writing malicious files to disk—where security tools typically detect them—the rootkit operates as a fileless attack, injecting a web shell directly into system memory. This technique allows attackers to maintain persistent access while evading traditional endpoint detection systems. The PHP file interception capability enables the rootkit to modify application behavior at runtime, potentially granting unauthorized access or enabling data exfiltration. F5 BIG-IP devices are widely deployed in enterprise networks for load balancing and application security, making them high-value targets. Organizations running vulnerable APM instances should review access logs and apply available security patches. The breach underscores the growing threat posed by fileless malware techniques that exploit legitimate system processes to avoid detection.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Cisco's President Jeetu Patel joined executives from OpenAI, Anthropic, and others in signing an open letter warning that AI-enabled cyberattacks will likely become more widespread and sophisticated. The same AI capabilities that boost productivity can be weaponized by malicious actors.

1H AGOAI Desk

Anthropic has warned users about unauthorized token theft after discovering hackers accessing Claude accounts. The breach prompted the AI company to alert subscribers about potential account compromises.

1H AGOAI Desk

The EU Cyber Resilience Act's vulnerability reporting requirements take effect September 11, requiring software vendors to disclose actively exploited flaws within 24 hours. Vendors must now prove exactly what shipped and when vulnerabilities were discovered.

2H AGOIndustry Desk

A large-scale fraud operation dubbed DoppelCart uses over 119,000 domains to operate counterfeit e-commerce sites designed to steal payment card details from unsuspecting customers.

2H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.