Attackers are exploiting RCE vulnerability in BIG-IP APM systems (CVE-2025-53521)
A critical unauthenticated remote code execution vulnerability (CVE-2025-53521) in F5’s BIG-IP Access Policy Manager (APM) solution is under active exploitation, the US Cybersecurity and Infrastructure Security Agency warned on Friday.
CISA added the flaw to its Known Exploited Vulnerabilities catalog after F5 update...
The strongest version of this narrative highlights a sophisticated, state-sponsored cyber campaign exploiting a critical vulnerability in widely used enterprise infrastructure. The reclassification of CVE-2025-53521 from a denial-of-service flaw to an RCE underscores the dynamic nature of threat intelligence and the challenges of initial assessments. The involvement of a Chinese-linked actor, prolonged network access, and potential deployment of backdoors like Brickstorm align with patterns of e...
