A critical vulnerability in F5’s BIG-IP Access Policy Manager (APM) is being exploited in the wild. The bug, allocated CVE-2025-53521, gives a remote attacker unauthenticated remote code execution (pre-auth RCE) powers. IOCs published by F5 today point to sophisticated attacks in which the threat group is disabling the SELinux
Read the full storyThe Stack
Interviews, insight, intelligence, and exclusive events for digital leaders.
All the latest
All the latest
"Scanning for one type of content, for instance, opens the door for bulk surveillance" says Apple's user privacy chief.
The EU has proposed a new Cyber Resilience Act. The lack of industry dialogue has the open-source sector worry that the act will stifle development.
His "knowledge of software security appears to exceed that of most governments"
Renowned IT research institute Georgia Tech has been fined for discriminating against non US citizens in its job fairs
A study out of Germany has highlighted shortcomings in the CVSS system and the way security vulnerabilities are assessed and scored
The little-known hacking technique of subdomain hijacking is threatening thousands of sites and their visitors despite efforts to eradicate
HPE says it is bullish on edge computing and cloud as its compute and storage businesses are down slightly
Arm is adding additional layers to its CPU designs with CSS, a platform that will ease the burden on chipmakers to handle external functions