CuraSec

tag: F5-Big-Ip · 2 items

2026-09-09 · BleepingComputer · source ↗ #f5-big-ip#rootkit#fileless-malware
  • Engineer — Act: Active breach campaign targeting F5 BIG-IP APM appliances — a common enterprise edge device. Audit your BIG-IP APM fleet for indicators of compromise: look for anomalous PHP interpreter activity, unexpected in-memory web shell behavior, and verify firmware/software versions against F5’s latest advisories.
  • SOC/IR — Act: The fileless, memory-resident web shell evades file-based detection, so standard endpoint scans will miss it. Hunt for anomalous PHP file-load interception and unusual outbound connections from F5 BIG-IP APM processes; if your org runs BIG-IP APM, treat as assume-breach and initiate a memory forensics sweep.
  • Leader — Plan: Active compromise campaign against widely-deployed F5 BIG-IP APM appliances — confirm with your network/infra team whether your org runs these devices, verify that monitoring and patching processes are in place, and be prepared to brief leadership if exposure is confirmed.
2026-09-09 · The Hacker News · source ↗ #f5-big-ip#web-shell#memory-injection
  • Engineer — Act: F5 BIG-IP APM is a widely-deployed enterprise edge appliance and the malware is linked to confirmed break-ins; disk-based file integrity checks won’t detect this web shell, so audit BIG-IP APM instances using network-based IOCs and memory forensics from the Sophos September 7 analysis.
  • SOC/IR — Act: Active exploitation of an edge appliance combined with a memory-resident web shell means EDR and file-scan detections will miss it; assume-breach posture applies — hunt using any network or request-pattern IOCs from the Sophos report and flag all BIG-IP APM devices for manual inspection.
  • Leader — Act: If your organization runs F5 BIG-IP APM, direct the security team to perform a compromise assessment this week — the memory-evasion technique means standard monitoring may have already missed a breach on this access gateway.