F5 BIG-IP Zero-Day Exploited, Plus Critical cPanel, Ubuntu, Chrome, and Next.js Flaws
Attackers are exploiting an F5 BIG-IP APM zero-day. cPanel patched a flaw giving any hosting account root, and a public exploit targets unpatched Ubuntu container hosts. A China-nexus actor is chaining Chrome and Windows zero-days, and Next.js fixed a 9.5 CVSS code execution bug.