Back to the feed

~/article/hackers-deploy-linux-rootkit-on-f5-big-ip-apm-devices-hiding-web-shell-i-1rq6ta
infoSource: Help Net Security

Hackers deploy Linux rootkit on F5 BIG-IP APM devices, hiding web shell in memory

A rootkit found on hacked F5 BIG-IP APM devices skips the usual step of writing a web shell to disk, hiding it in memory instead, according to Sophos. F5 BIG-IP APM provides access policy enforcement to secure access to apps, APIs, and data. It’s primarily used by enterprises, financial institutions, government agencies, and public sector organizations. “The implant delivers a familiar outcome…

Read at the source

Summary written for cymesh.dev. The full article lives at Help Net Security.

~/cymesh.net

Certificates expire quietly

cymesh.net watches your TLS and SSL certificates and warns you before one lapses.

monitorsTLS/SSL expiry, chain and hostnamealertsemail, ahead of the expiry datescopenon-intrusive, read-only checks

Related

~/related/hackers-deploy-linux-rootkit-on-f5-big-ip-apm-devices-hiding-web-shell-i-1rq6ta