security1 publisher
Implant on CVE-2025-53521 BIG-IP APM boxes persists through F5 upgrade images
SophosLabs pulled apart a second-stage Linux payload that hooks Apache's module loader and keeps its PHP web shell in memory only, and the installer behind it writes itself into BIG-IP upgrade images, so a version bump does not evict it.
Publishers:nakedsecurity.sophos.com
Reality
- Evidence72
- Adoption40
- Hype gap+10
- Incentives58