vulnerabilities
A critical vulnerability in F5’s BIG-IP Access Policy Manager (APM) is being exploited in the wild. The bug, allocated CVE-2025-53521, gives a remote attacker unauthenticated remote code execution (pre-auth RCE) powers. IOCs published by F5 today point to sophisticated attacks in which the threat group is disabling the SELinux
Ubuntu: "Our recommendation is that you apply both userspace mitigations and Linux kernel security updates"
Security
|
Feb 07, 2026
Dutch NCSC warns on the same day that Ivanti EPMM "abuse has taken place much more broadly than previously known - assume compromise"