A critical vulnerability in F5’s BIG-IP Access Policy Manager (APM) is being exploited in the wild. The bug, allocated CVE-2025-53521, gives a remote attacker unauthenticated remote code execution (pre-auth RCE) powers. IOCs published by F5 today point to sophisticated attacks in which the threat group is disabling the SELinux
Read the full storyThe Stack
Interviews, insight, intelligence, and exclusive events for digital leaders.
All the latest
All the latest
"We have also seen devices... getting the implant successfully installed through an as of yet undetermined mechanism."
HMG's Chief Commercial Officer wrote to the data software firm to raise concerns, which it rejects.
"Because of the interconnected nature of our supply chain, the ramifications of a single incident in these underserved less cyber mature pockets can have devastating downstream impact..."
"As consumers we all need to look at that consumption and usage data as our baseline... and then design and deliver more efficient digital systems and services"
"We're deep into the large body of work of automating manual controls and processes, consolidating fragmented tech platforms and upgrading our data architecture"
"The risk of identity theft never stops. Cyber criminals are sophisticated and innovative... firms must raise their standards."
Enterprises running – or looking to run – SAP HANA in the cloud have got an improved proposition from AWS, with AWS Systems Manager for SAP generally available (GA) this week and offering new capabilities to operate, manage, and backup SAP applications on AWS more efficiently. AWS Systems Manager for SAP is