Attackers are exploiting RCE vulnerability in BIG-IP APM systems (CVE-2025-53521)
2026-03-28T14:51:50Z•2983ad8eabb3ff47a39da3ac030435a65d5c3d6e0135d46f67f540c7a24c3aa3
Aqua SecurityBPFDoor detectionCISA Known Exploited VulnerabilitiesF5 BIG-IP APMLangflowPyPI backdoorRCERed MenshenRedLine infostealerTails 7.6TeamPCPTelnyxTor bridgesTrivycredential exposuredata breachsecrets sprawlsupply chain compromise
What happened
Multiple high-risk security incidents and research updates were reported: an unauthenticated critical RCE (CVE-2025-53521) in F5 BIG-IP APM is under active exploitation and added to CISA’s Known Exploited Vulnerabilities catalog; TeamPCP attackers backdoored the Telnyx PyPI package to deliver malware; CISA also added CVE-2026-33017 (Langflow code injection) and CVE-2026-33634 (malicious code in Trivy) to the KEV catalog after rapid exploitation. Additional items include a data breach at AFC Ajax, GitGuardian’s report on widespread secret/credential exposure, OpenAI’s safety bug bounty, Tails 7
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- 2983ad8eabb3ff47a39da3ac030435a65d5c3d6e0135d46f67f540c7a24c3aa3
- Enrichment time
- 2026-03-28T14:51:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.