A critical vulnerability in F5’s BIG-IP Access Policy Manager (APM) is being exploited in the wild. The bug, allocated CVE-2025-53521, gives a remote attacker unauthenticated remote code execution (pre-auth RCE) powers. IOCs published by F5 today point to sophisticated attacks in which the threat group is disabling the SELinux
Read the full storyThe Stack
Interviews, insight, intelligence, and exclusive events for digital leaders.
All the latest
All the latest
New grant funding will support maintainers being buried in AI-generated bug report slop.
All the joy of physical-presence vulnerabilities but remotely, and many cheap, single-port IP-KVMs are wide open, says Eclypsium.
China's retail-and-cloud giant says it has a secure multi-agent platform for "real-world enterprise workloads", which is good for… editing documents.
Hackers "enumerated and accessed objects within S3 buckets, terminated production EC2 and RDS instances, and decrypted application keys."
"It is simply wrong that taxpayers are covering the costs for Fujitsu’s sins" says committee chair.
Google is offering $30 million to help Europeans master AI to offset future AI-driven job losses, while calling for more permissive AI regulation. At the Future of Work Forum in Latvia, Google execs announced a new project and corresponding funding to help Europeans meet the AI era. Google's