A critical vulnerability in F5’s BIG-IP Access Policy Manager (APM) is being exploited in the wild. The bug, allocated CVE-2025-53521, gives a remote attacker unauthenticated remote code execution (pre-auth RCE) powers. IOCs published by F5 today point to sophisticated attacks in which the threat group is disabling the SELinux
Read the full storyThe Stack
Interviews, insight, intelligence, and exclusive events for digital leaders.
All the latest
All the latest
Comcast says that it lost the data of roughly 35.9 million people as the result of data breach related to a Citrix software error
"SLAs are becoming differentiators and, in many cases, the ultimate decider in purchasing decisions..."
Google has settled with a number of US states over a lawsuit regarding its handling of Android apps and pricing. The total fee will tally out at $700m
The US department of justice has busted up a prolific ransomware as a service ring that targeted hundreds of companies
Vulnerabilities are turning into actively exploited flaws at a rapid pace, often within the same day. This according to research from security vendor Qualys.
The NSA has posted a new set of cybersecurity guidelines for government agencies
Attacker "disrupted… business operations by encrypting some IT systems, and stole data from the company"
Attackers had access to certain corporate systems “for some period of time before discovery”