F5 released out-of-band patches for two critical NGINX vulnerabilities that can lead to remote code execution or denial-of-service on non-default setups. The updates also fix high-severity configuration injection issues in NGINX Gateway Fabric against a backdrop of frequent real-world targeting of F5 products.

F5 separately disclosed that state-backed intruders compromised its environment in August 2025 and exfiltrated undisclosed BIG-IP vulnerabilities together with source code.
Over the past several years the U.S. Cybersecurity and Infrastructure Security Agency has listed seven F5 flaws as actively exploited, four of them in ransomware incidents.
Security teams should prioritize these patches immediately given F5's track record of exploitation by ransomware and nation-state actors, especially on systems where ASLR may not fully mitigate the risk.
Tap a lens to see what this story means for you.
Reader-supported · Daily Brief
Daily brief at 7 AM ET. Top tech stories, every morning. Sourced and fact-checked.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
Apple has introduced iOS modifications in Brazil that open authorized alternative marketplaces and external payment tools under a CADE agreement while adding Notarization plus child-safety rules. The steps target newly created malware, fraud, and privacy hazards on the platform Apple still calls the most secure mobile option locally.
Attackers injected backdoors into three ShapedPlugin premium WordPress plugins on May 21, 2026, using the official update system to steal credentials and install hidden fake WooCommerce plugins on customer sites.
Senators Markey and Blumenthal have demanded that NHTSA examine Tesla's FSD safety claims after a Reuters report exposed flawed crash comparisons. The scrutiny extends to Europe, where regulators are now reviewing similarly optimistic projections before granting broader approval.