A Linux rootkit is running inside F5 BIG-IP APM devices right now, injecting a PHP web shell directly into server memory while leaving every file on disk completely unchanged. What is unsettling is that the standard file integrity monitoring finds nothing, and The PHP scripts look clean. The web shell is not there, until it […] The post PoisonedRefresh is the F5 Rootkit Your File Scanner Won’t Find appeared first on CybelAngel .