logo

Mitigating New Vulnerabilities with owLSM

ID: a2ac6a8a-bf59-5042-a202-46093a4c19f8

STIX ID: report--a2ac6a8a-bf59-5042-a202-46093a4c19f8

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
55/100

Date Published: 2026-07-13

Date Updated: 2026-07-15

...
...

This blog-style technical post demonstrates exploiting the CrackArmor AppArmor vulnerabilities to allow an unprivileged user to remove AppArmor profiles and shows how the open-source owLSM agent can detect the relevant write events and immediately prevent exploitation by applying a Sigma-like rule that blocks non-root writes to /sys/kernel/security/apparmor and kills the SUID process; the article includes an example event JSON, the rule text, and guidance on using owLSM as an interim mitigation when patches are not yet available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.