news.mlab.sh
Back to the feed
vulnerability

Someone's attacking a critical 0-day RCE in F5 BIG-IP APM

CriticalCVSS 9.8
Summary

A zero-day vulnerability has been discovered in F5 BIG-IP Application Performance Manager (APM), allowing attackers to remotely execute code. This vulnerability is being actively exploited, and Microsoft has released a patch to address the issue. The attack is being carried out by Russian actors posing as Signal support.

A critical zero-day vulnerability is impacting F5 BIG-IP Application Performance Manager (APM). Attackers are exploiting this vulnerability to remotely execute code, bypassing standard security measures. Microsoft has released a patch to address the issue, but affected systems are currently vulnerable. Initial reports suggest that Russian actors are leveraging this vulnerability to conduct phishing attacks, impersonating Signal support to gain user credentials. The vulnerability is being actively exploited in the wild, highlighting the ongoing threat landscape for organizations utilizing F5 BIG-IP APM.

Read the full article at The Register