CVE Tools

Week in review: Linux rootkit deployed on F5 BIG-IP APM devices, Cisco FMC bugs exploited

Help Net SecurityBy Help Net Security

Reported exploitedF5 BIG-IP APMCisco FMC

Our summary

Security teams face a mix of active intrusions and emergency patches, highlighted by a new Linux rootkit discovered on compromised F5 BIG-IP APM devices that conceals its web shell in memory rather than on disk. Active exploitation continues for critical authentication bypass flaws in Cisco Secure Firewall Management Center, identified as CVE-2026-20079 and CVE-2026-20316.

Updates were also released to address newly exploited zero-day vulnerabilities in Google Chrome and N-able N-central, while researchers detailed an "MikroTrick" exploit chain targeting unauthenticated MikroTik RouterOS devices.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store