PoisonedRefresh embeds memory-only shells in F5 BIG-IP
Security researchers have detailed a stealthy Linux implant, dubbed PoisonedRefresh, that backdoors compromised F5 BIG-IP Access Policy Manager systems by injecting PHP web shells directly into server memory while leaving legitimate files on disk unchanged. The malware has been associated with exploitation of CVE-2025-53521, a critical unauthenticated remote code execution vulnerability in BIG-IP…
We haven't written up this one. Arabian Post has the full story — the link below goes straight to it.