Linux Rootkit Exploits F5 BIG-IP APM & Cisco FMC Vulnerabilities
This week’s cybersecurity developments highlight critical vulnerabilities, emerging threats, and industry responses across multiple platforms.
A Linux-based rootkit was discovered on compromised F5 BIG-IP APM systems, bypassing traditional detection methods by storing a web shell in memory rather than on disk. This technique, identified by Sophos, allows attackers to maintain persistence without leaving conventional forensic traces.
F5 BIG-IP APM is widely used by enterprises, financial institutions, and government agencies to enforce access policies for applications, APIs, and data. The rootkit’s deployment underscores the growing sophistication of attacks against critical infrastructure.
Cisco FMC vulnerabilities (CVE-2026-20079 and CVE-2026-20316) were actively exploited by both nation-state groups and ransomware operators. These flaws, related to improper input validation and authentication bypasses, enabled unauthorized access to network management systems. The exploits highlight the risks of outdated software in security-critical environments.
Other notable developments include the discovery of a zero-day in Google Chrome (CVE-2026-87491), which was patched in version 153.0.8010.36 and later. The flaw allowed remote code execution through a maliciously crafted webpage, emphasizing the need for timely software updates.
Additionally, attackers leveraged a file transfer vulnerability in ScreenConnect Remote Access Support to distribute malware, prompting ConnectWise to advise disabling file transfers until a fix is available. A critical zero-day in N-able’s N-central platform (CVE-2026-86218) was exploited in the wild, enabling pre-authenticated remote code execution. The vulnerability, which affects managed service providers, was addressed through an emergency hotfix.
Similarly, MikroTik RouterOS devices were targeted via a coordinated exploit chain (MikroTrick), which combined six vulnerabilities to grant full control without authentication. The Mathspace breach exposed data from over a million students and parents after attackers exploited an unpatched Metabase vulnerability. The incident, linked to a self-hosted Metabase installation, highlights the risks of delayed patch management.
Meanwhile, a phishing campaign used Microsoft OAuth and Teams infrastructure to deliver fake login pages entirely within victims’ browsers, bypassing traditional detection mechanisms. Ransomware groups are increasingly automating attack workflows with AI agents, according to Google Threat Intelligence Group.
In the financial sector, a Singaporean individual pleaded guilty to a $245 million cryptocurrency heist, using stolen digital wallets to fund a lavish lifestyle. The case underscores the financial incentives driving cybercrime and the challenges of tracing illicit transactions.
Open-source initiatives like AI-Infra-Guard, developed by Tencent’s Zhuque Lab, aim to enhance AI system security by scanning for vulnerabilities and evaluating model resilience. Similarly, the OPAQUE project introduced a standard to lock AI model weights to approved hardware, addressing risks associated with model theft and unauthorized deployment.
Enterprise security teams face mounting challenges as AI adoption accelerates. A Proofpoint report reveals that CISOs are struggling to manage AI governance without proportional resource increases. Meanwhile, Microsoft’s Project Zenith enables large AI models to run locally on developer PCs, reducing reliance on cloud infrastructure.
The week also saw updates to open-source tools, including Jellyfin 12.0, which includes security fixes for file access restrictions, and BleachBit 6.0.4, which addresses secure wiping issues on Windows. AWS completed a multi-year rebuild of its routing control plane without service disruptions, demonstrating resilience in critical infrastructure.
As threat actors refine their techniques, organizations must prioritize proactive defense strategies, including continuous monitoring, timely patching, and adaptive security frameworks. The convergence of AI, zero-day exploits, and sophisticated attack chains demands a heightened focus on resilience and innovation in cybersecurity practices.
