@Squid_Sec: LIVE: SquidSec Threat Feed update. Hackers are breaching F5 BIG-IP APM devices and dropping a Linux rootkit with a file…
Summary
Hackers are exploiting vulnerabilities in F5 BIG-IP APM devices to deploy a Linux rootkit with a fileless web shell, as reported in the SquidSec Threat Feed.
View Cached Full Text
Cached at: 09/09/26, 01:54 PM
LIVE: SquidSec Threat Feed update. Hackers are breaching F5 BIG-IP APM devices and dropping a Linux rootkit with a fileless web shell. HIGH severity. https://t.co/jtjHGtMckl
SquidSec Threat Feed
Source: https://squidhacker.com/brief/ SQUID SEC
Cybersecurity research, penetration testing tradecraft, and agentic recon — by SquidSec.
🇺🇸 U.S. Veteran Owned
Explore
SquidSec Network
© 2026 SQUID SECCleveland, OH · High-signal security content
Similar Articles
@kl_secservices: Attackers don't need fancy tricks to breach schools: stolen accounts, Potato privesc, then PsExec to move around. Outda…
Attackers are breaching schools using simple methods like stolen accounts and outdated systems, with ransomware groups DragonForce and LockBit 3 targeting private schools for payments. A report analyzes incidents in Brazil and provides recommendations for protection.
Linux Compromises, Broken Embargoes, and the Shrinking Patch Window
A report on three serious Linux local privilege escalation vulnerabilities discovered in May 2026, highlighting breakdowns in the disclosure model and implications for production environments.
Deadbugz: Currently Active MCP Supply-Chain Campaign
Pillar Security researchers detail Deadbugz, an active supply-chain campaign that distributes a malicious MCP server through GitHub pull requests, gating credential-stealing instructions behind three benign tool calls.
CVE-2026-25089: FortiSandbox unauthenticated command injection added to CISA KEV
Fortinet FortiSandbox contains a critical unauthenticated OS command injection vulnerability (CVE-2026-25089) actively exploited in the wild, added to CISA's Known Exploited Vulnerabilities catalog on July 16, 2026.
@n0tduck1e: [from a fellow researcher] Quick look at #Tengu (Mirai-based Linux/IoT botnet, late July). Abuses hardware watchdog so …
A researcher shares a quick analysis of Tengu, a Mirai-based Linux/IoT botnet that abuses a hardware watchdog to survive process termination, spreads via Telnet, and includes nastier self-defense than classic Mirai.