Unprivileged users could exploit AppArmor bugs to gain root access

2026-03-16T08:51:48Ze53a2135963733fadc7f0b1fbf596f20792aa7ad2fb47b92a7583f762354e57e
AVreconAppArmorCISACrackArmorGoogle ChromeInterpolKnown Exploited VulnerabilitiesLinux kernelOperation SynergiaPayload RansomwareSEO poisoningSocksEscortStorm-2561botnetcontainer escapecredential theftdata exfiltrationhealthcare breachphishingprivilege escalationransomware

What happened

Multiple high-impact security stories: Qualys researchers disclosed nine “CrackArmor” vulnerabilities in the Linux kernel AppArmor module (flaws dating back to 2017) that can let unprivileged users bypass protections, escalate to root, and weaken container isolation. Payload Ransomware claims to have exfiltrated ~110 GB from Royal Bahrain Hospital. Other notable incidents include a Starbucks employee portal phishing breach affecting 889 staff, a Storm-2561 campaign using SEO-poisoned fake Ivanti/Cisco/Fortinet VPN sites to harvest corporate credentials, and law enforcement disruptions: INTERP0

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
e53a2135963733fadc7f0b1fbf596f20792aa7ad2fb47b92a7583f762354e57e
Enrichment time
2026-03-16T08:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Unprivileged users could exploit AppArmor bugs to gain root access · Baitaphish