Hackers now exploit critical F5 BIG-IP flaw in attacks, patch now

2026-03-30T13:23:31Z8bf934c8de00ac4ce6a265cb1138841d9922af5ff726bb890785ea149fc8b04f
Europa.euEuropean CommissionF5 BIG-IPFortinet FortiClient EMSGitHubHandalaInfinity StealerPyPI compromiseShinyHuntersSmart SliderTelnyxWordPressactive exploitationcloud compromisecredential theftcriticaldata breachdeveloper-targeting malware spread via fake alerts','Windows 11email compromisefile readmacOSmalwareremote code executionsupply-chainwebshell

What happened

BleepingComputer roundup: multiple high-impact incidents and active exploitations. F5 reclassified a BIG‑IP APM bug from DoS to a critical remote code execution vulnerability and warns attackers are exploiting it to install webshells on unpatched devices. A separate critical Fortinet FortiClient EMS vulnerability is also being exploited in the wild. The European Commission (Europa.eu) and an EU Amazon cloud account suffered breaches (claims by ShinyHunters and other activity), and the FBI Director’s personal email was compromised by an Iran‑linked actor. Additional notable incidents include a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
8bf934c8de00ac4ce6a265cb1138841d9922af5ff726bb890785ea149fc8b04f
Enrichment time
2026-03-30T13:23:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.