VYPR
breachPublished Sep 13, 2026· 1 source

Linux Rootkit Targets F5 BIG-IP APM, Cisco FMC Exploited, and Other Security News

A Linux rootkit is infecting F5 BIG-IP APM devices, while Cisco FMC vulnerabilities are actively exploited by nation-state and ransomware actors, alongside other significant security developments.

Security researchers have uncovered a sophisticated Linux rootkit targeting F5 BIG-IP Access Policy Manager (APM) devices, capable of deploying fileless PHP web shells directly into server memory. This allows attackers to maintain persistent access and potentially exfiltrate sensitive data from compromised appliances.

Simultaneously, critical vulnerabilities within Cisco Secure Firewall Management Center (FMC) software are being actively exploited by both nation-state actors and ransomware groups. The vulnerabilities, identified as CVE-2026-20079 and CVE-2026-20316, allow for authentication bypass and could lead to unauthorized access and control over network security devices.

Beyond these significant threats, the past week has seen a flurry of other security news. Microsoft's September Patch Tuesday delivered a record number of patches, including fixes for two zero-day vulnerabilities that were already being exploited in the wild. This highlights the ongoing challenge of zero-day exploitation and the need for rapid patching.

In the realm of AI security, Tencent's Zhuque Lab has released AI-Infra-Guard, an open-source security scanner designed to identify risks in AI systems. This tool aims to help organizations secure their AI deployments by checking for known vulnerabilities and assessing risk across various categories.

Separately, researchers have detailed a "zero-click" worm for WeChat, dubbed "WeWorm," which can spread through voice calls without any user interaction, posing a significant threat to user accounts on both iOS and Android devices. This discovery underscores the evolving nature of mobile malware and the potential for novel attack vectors.

Additionally, a file transfer flaw in ConnectWise ScreenConnect has been exploited by attackers to spread malware, prompting recommendations to disable file transfers until a fix is available. N-able also released an emergency hotfix for a critical remote code execution vulnerability (CVE-2026-86218) in its N-central RMM solution, which had been exploited in the wild.

Finally, the week's news also touched upon broader security trends, including the need for updated zero trust principles for AI agents, the evolving tactics of ransomware negotiators, and the growing concern over AI accelerating cyberattacks to machine speed, potentially outpacing human defenses.

Synthesized by Vypr AI