A critical vulnerability in F5’s BIG-IP Access Policy Manager (APM) is being exploited in the wild. The bug, allocated CVE-2025-53521, gives a remote attacker unauthenticated remote code execution (pre-auth RCE) powers. IOCs published by F5 today point to sophisticated attacks in which the threat group is disabling the SELinux
Read the full storyThe Stack
Interviews, insight, intelligence, and exclusive events for digital leaders.
All the latest
All the latest
On tough decisions, fixing the “broken middle rung”, wearing two hats at work, experiences modernising Oracle's IT estate and having an "unconventional" background as a CIO...
"There is a lot of anxiety about the Broadcom-VMware acquisition around pricing, support and other issues"
"Industry has gotten good at identifying vulnerabilities in the supply chain; SBOMs and so on [but not at] at insidious backdoors and logic issues that are built into software, and update mechanisms that could cause implants..."
"We’ve learned a lot over the years about how to give founders and innovators space to build independent identities and cultures within Microsoft"
MicroCloud can scale from three servers to around 50-node clusters and it is lightweight enough, claims Canonical, to run on a developer laptop.
Altman was "not consistently candid in his communications with the board, hindering its ability to exercise its responsibilities. The board no longer has confidence in his ability to continue leading OpenAI.”
The group "register their own MFA tokens [and] add a federated identity provider to the victim’s SSO tenant and activate automatic account linking..."
"The significance of code quality goes beyond mere functionality—it reflects the development team's culture and, by extension, the potential for scalability and synergy generation..."
"That’s definitely the hottest topic right now in tech for us across the bank,”