Week in review: Linux rootkit deployed on F5 BIG-IP APM devices, Cisco FMC bugs exploited
What happened
Sophos identified a Linux rootkit on compromised F5 BIG-IP APM devices that conceals a web shell in memory rather than writing it to disk. This technique evades standard file-based detection methods on the access policy enforcement platform used by enterprises and government agencies.
Why it ranks #1
Sophos identified a Linux rootkit on compromised F5 BIG-IP APM devices that conceals a web shell in memory rather than writing it to disk, evading standard file-based detection methods on the access policy enforcement platform used by enterprises and government agencies.
Who should care
Identity and access teams, IT and platform operations, SOC and incident response teams
- Impact
- high
- Urgency
- near-term
- Confidence
- high
- Scope
- enterprise
- Status
- emerging