Security Updates
Timely advisories and news regarding threats, vulnerabilities, and service-related infrastructure updates.
1
Critical
1
High
1
Medium
2
Info
Critical Patch Available: Linux Kernel Privilege Escalation (CVE-2026-3147)
A critical privilege escalation vulnerability affecting Linux kernel versions 5.14 through 6.10 has been disclosed. HawkData has begun rolling out patched kernels to all managed Ubuntu Pro hosts via Livepatch. No client action is required — affected systems will be patched automatically during the current maintenance window. Clients with non-managed hosts should apply the update immediately.
Ransomware Campaign Targeting Backup Repositories
Threat intelligence indicates an active ransomware campaign specifically targeting exposed backup management consoles. HawkData has verified that all managed backup repositories are air-gapped and not externally accessible. We recommend all clients review external-facing services and report any newly exposed ports to our SOC.
Infrastructure Upgrade: Wazuh SIEM Correlation Engine v4.9
The Wazuh correlation engine backing all managed SIEM deployments has been upgraded to v4.9, adding 40+ new detection rules mapped to MITRE ATT&CK techniques. No downtime occurred during the rolling upgrade. Clients may notice enhanced alerting detail in their next monthly security report.
Phishing Wave Impersonating HawkData Support
A phishing campaign using spoofed HawkData support email addresses has been reported. Legitimate HawkData communications will never ask for passwords or MFA codes. If you receive a suspicious message, forward it to your account manager and delete it. Do not click any links.
Scheduled Maintenance: Firewall Rule Update Window
A scheduled maintenance window for firewall rule updates will occur on Saturday, August 16 from 02:00–04:00 local time. Brief intermittent connectivity to managed VPN endpoints may occur. All services will automatically recover; no client action is required.
New Resource: Secure Remote Work Best Practices Guide
A new client training video covering secure remote work practices has been published to the Client Resources page. Topics include MFA setup, secure Wi-Fi configuration, and recognizing social engineering attempts.