BT
Privacy ToolboxJournalProjectsResumeBookmarks
Feed
Privacy Toolbox
Journal
Projects
Resume
Bookmarks
Intel
CIPHER
Threat Actors
Privacy Threats
Dashboard
CVEs
Tags
Intel
CIPHERThreat ActorsPrivacy ThreatsDashboardCVEsTags

Intel

  • Feed
  • Threat Actors
  • Privacy Threats
  • Dashboard
  • Privacy Toolbox
  • CVEs

Personal

  • Journal
  • Projects

Resources

  • Subscribe
  • Bookmarks
  • Developers
  • Tags
Cybersecurity News & Analysis
github
defconxt
•
© 2026
•
blacktemple.net
  1. Feed
  2. /Critical Linux AppArmor Flaws Enable Root Escalation, Payload Ransomware Hits Bahrain Healthcare

Critical Linux AppArmor Flaws Enable Root Escalation, Payload Ransomware Hits Bahrain Healthcare

March 16, 2026Nation-State & APT2 min readhigh

Originally reported by Security Affairs

#linux#privilege-escalation#apparmor#ransomware#healthcare#payload#malware-research#container-security
Share

TL;DR

Qualys disclosed nine critical AppArmor vulnerabilities allowing unprivileged users to gain root access on Linux systems. Meanwhile, Payload ransomware claimed responsibility for breaching Royal Bahrain Hospital and stealing 110 GB of sensitive data.

Why high?

Nine critical privilege escalation vulnerabilities in AppArmor affecting Linux systems since 2017, combined with active ransomware targeting critical healthcare infrastructure.

Critical AppArmor Vulnerabilities Enable Linux Privilege Escalation

Qualys researchers disclosed nine vulnerabilities in the Linux kernel's AppArmor security module, collectively designated as "CrackArmor." The flaws have persisted since 2017 and allow unprivileged users to bypass AppArmor protections, escalate privileges to root level, and compromise container isolation mechanisms.

AppArmor serves as a mandatory access control framework designed to restrict program capabilities and prevent unauthorized system access. The discovery of these long-standing vulnerabilities represents a significant security gap in Linux distributions relying on AppArmor for system hardening.

The vulnerabilities particularly impact containerized environments where AppArmor provides critical isolation boundaries between containers and the host system. Successful exploitation could enable attackers to break out of container sandboxes and gain full system control.

Payload Ransomware Targets Bahrain Healthcare Infrastructure

The Payload ransomware group claimed responsibility for breaching Royal Bahrain Hospital (RBH), a prominent healthcare facility in Bahrain. The threat actors allegedly exfiltrated 110 GB of sensitive data before adding the hospital to their Tor-based data leak site.

The ransomware operators published proof-of-breach materials on their leak site, following the established double-extortion model where threat actors both encrypt systems and threaten to release stolen data. Healthcare organizations remain high-value targets for ransomware groups due to their critical operational requirements and sensitive patient data.

This incident highlights the continued targeting of healthcare infrastructure by ransomware operators, particularly in regions where cybersecurity resources may be limited.

Nation-State Malware Research Highlights

Security Affairs released their 88th malware newsletter roundup, featuring several notable research developments. Key highlights include analysis of Coruna, described as a nation-state iOS exploit kit, demonstrating advanced persistent threat capabilities targeting mobile platforms.

Additional research covered BoryptGrab stealer campaigns targeting Windows users through deceptive GitHub pages, and ClipXDaemon, an autonomous clipboard hijacker delivered via Bincrypter-based loaders. The newsletter also highlighted A0Backdoor research, indicating continued evolution in backdoor malware capabilities.

These research findings underscore the diverse threat landscape spanning mobile platforms, desktop systems, and advanced persistent threat toolkits.

Sources

  • https://securityaffairs.com/189487/hacking/unprivileged-users-could-exploit-apparmor-bugs-to-gain-root-access.html
  • https://securityaffairs.com/189467/cyber-crime/payload-ransomware-claims-the-hack-of-royal-bahrain-hospital.html
  • https://securityaffairs.com/189459/breaking-news/security-affairs-malware-newsletter-round-88.html

Originally reported by Security Affairs

Tags

#linux#privilege-escalation#apparmor#ransomware#healthcare#payload#malware-research#container-security

Threat Actors

🏴Royal

Related Intelligence

  • Weekly Roundup: INTERPOL Dismantles 45K Malicious IPs, AppArmor Flaws Hit 12.6M Linux Systems

    highMar 14, 2026
  • CISA Adds Chrome Exploits to KEV, SocksEscort Botnet Disrupted, Ransomware Responder Charged

    criticalMar 14, 2026
  • APT Threat Roundup: AI-Assisted Malware, Healthcare Ransomware, and Cryptojacking Campaigns

    highFeb 24, 2026

Related Knowledge

  • Threat Intelligence Deep Training

    reference
  • MITRE ATT&CK / D3FEND Deep Reference

    reference
  • CIPHER Training: Emerging Threats Deep Dive (2025-2026)

    reference

Explore

  • Dashboard
  • Privacy Threats
  • Threat Actors
← Back to the feed

Previous Article

← FBI Seeks Victims of Steam Malware Distribution Campaign

Next Article

Companies House Web Vulnerability Exposes Corporate Data of Millions →