Unprivileged users could exploit AppArmor bugs to gain root access
2026-03-16T08:51:48Z•e53a2135963733fadc7f0b1fbf596f20792aa7ad2fb47b92a7583f762354e57e
AVreconAppArmorCISACrackArmorGoogle ChromeInterpolKnown Exploited VulnerabilitiesLinux kernelOperation SynergiaPayload RansomwareSEO poisoningSocksEscortStorm-2561botnetcontainer escapecredential theftdata exfiltrationhealthcare breachphishingprivilege escalationransomware
What happened
Multiple high-impact security stories: Qualys researchers disclosed nine “CrackArmor” vulnerabilities in the Linux kernel AppArmor module (flaws dating back to 2017) that can let unprivileged users bypass protections, escalate to root, and weaken container isolation. Payload Ransomware claims to have exfiltrated ~110 GB from Royal Bahrain Hospital. Other notable incidents include a Starbucks employee portal phishing breach affecting 889 staff, a Storm-2561 campaign using SEO-poisoned fake Ivanti/Cisco/Fortinet VPN sites to harvest corporate credentials, and law enforcement disruptions: INTERP0
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- e53a2135963733fadc7f0b1fbf596f20792aa7ad2fb47b92a7583f762354e57e
- Enrichment time
- 2026-03-16T08:51:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.