A critical vulnerability in F5’s BIG-IP Access Policy Manager (APM) is being exploited in the wild. The bug, allocated CVE-2025-53521, gives a remote attacker unauthenticated remote code execution (pre-auth RCE) powers. IOCs published by F5 today point to sophisticated attacks in which the threat group is disabling the SELinux
Read the full storyThe Stack
Interviews, insight, intelligence, and exclusive events for digital leaders.
All the latest
All the latest
"We’re seeing CISOs getting elevated in the business, taking on a larger scope and being exposed to increased liability."
Microsoft had "shifted at least $39 billion in U.S. profits to Puerto Rico, where... KPMG, had persuaded the territory’s government to give Microsoft a tax rate of nearly 0%."
"This tofu has beef with HashiCorp..." Core OpenTofu Contributor and Scalr Founder talks to The Stack at OSS Europe.
A CVSS 9.8, pre-auth RCE that lets an attacker execute arbitrary code without user interaction is wormable on systems where Message Queuing is enabled.
"Any enterprise or individual that is serving an HTTP-based workload to the Internet may be at risk from this attack"
"People often think theatre is very scary and confrontational. It can be at times. But it's not the way we do it and I think that's why it’s a very unique experience..."
Package includes Ollama, which lets you download a range of open source LLM model packages, bundling weights, configuration and data into a single portable file