Tux Machines

Do you waddle the waddle?

Other Sites

9to5Linux

GStreamer 1.26 Open-Source Multimedia Framework Released, Here’s What’s New

Coming a year after GStreamer 1.24, the GStreamer 1.26 release adds H.266 Versatile Video Coding (VVC) codec support, Low Complexity Enhancement Video Coding (LCEVC) support, H.264/H.265 extractor/inserter for closed captions, H.266 video and rotation tag support for Matroska, and JPEG XS image codec support.

First Look: Garuda Linux Introduces New COSMIC Edition

Garuda Linux is known for maintaining several editions with some of the most acclaimed desktop environments and window managers, including KDE Plasma, GNOME, Xfce, Cinnamon, Hyprland, Sway, i3, and others. It even offers a Garuda Nix Subsystem edition to let you easily try out NixOS.

Mesa 25.1 to Replace Nouveau Driver with Zink/NVK by Default for NVIDIA GPUs

Until now, the Mesa graphics stack defaulted to Nouveau as the open-source graphics driver for NVIDIA GPUs, but starting with the Mesa 25.1 series, the old OpenGL driver will be taking a backseat in favor of a combination of the Zink Gallium driver and the NVK open-source Vulkan graphics driver, both developed by Collabora.

KDE Plasma 6.3.3 Implements Battery Charge Threshold Support for More Devices

Coming two weeks after KDE Plasma 6.3.2, the KDE Plasma 6.3.3 release implements battery charge threshold support for more devices, improves the way colors are displayed on the screen when using the Night Light feature on Intel GPU machines, and adds a warning message when you disable power management.

IPFire Hardened Linux Firewall Distro Is Now Powered by Linux Kernel 6.12 LTS

The biggest change in the new IPFire release is the switch to the latest LTS (Long-Term Support) kernel branch, namely Linux 6.12 LTS, a major update from the Linux 6.6 LTS kernel series used until now, along with a new driver for Realtek 8812au chips, a set of firmware for Raspberry Pi SBCs, and U-Boot 2024.10.

LXQt 2.2 Desktop Promises Many Wayland Improvements, QTerminal Updates

LXQt 2.2 promises to further improve the Wayland session introduced in the LXQt 2.1 release and flagged as experimental. In LXQt 2.2, the Wayland session will still be experimental, but it will let you set the default compositor and the screen locker by distribution or system-wide.

Audacity 3.7.2 Improves the Linux AppImage Bundle for Ubuntu 22.04 LTS

Audacity 3.7.2 improves the AppImage bundle for Ubuntu 22.04 LTS (Jammy Jellyfish) systems fix an issue with the loading of the FFmpeg multimedia server, adds a new option to turn off automatic tempo detection, a new “get effects” button next to the ‘Upload Audio’ button, and introduces UUID instance support.

9to5Linux Weekly Roundup: March 9th, 2025

I want to thank everyone who sent us donations; your generosity is appreciated. I also want to thank all of you for your continued support by commenting, liking, sharing, and boosting the articles, following us on social media, and, last but not least, sending us feedback.

Internet Society

How the South Sudan Chapter Mobilized to Keep the Internet On

On 22 January 2025, the National Communications Authority of the Republic of South Sudan instructed Internet Service Providers (ISPs) across the country to begin blocking TikTok and Facebook for a minimum of 30 days, with the potential to extend this up to 90 days. The justification was to prevent the further distribution of graphic content related to ongoing violence in neighboring Sudan.

LinuxGizmos.com

Texas Instruments Introduces MSPM0C1104 as the Smallest Available Microcontroller

Texas Instruments has introduced the MSPM0C1104, which it describes as the world’s smallest microcontroller, expanding its MSPM0 MCU portfolio. Measuring only 1.38mm², this wafer chip-scale package MCU is 38% smaller than existing alternatives. It is designed for applications where board space is limited, such as medical wearables and personal electronics, while maintaining functionality.

Radxa CM3J with Built-in Wi-Fi 5 and Bluetooth 5.0 for Industrial Applications

The Radxa CM3J is an industrial-grade compute module built around the Rockchip RK3568J SoC. This compact module integrates a CPU, PMU, LPDDR4X, eMMC, and wireless connectivity options such as Wi-Fi 5 and Bluetooth 5.0 in a 55mm x 40mm form factor.

Expanding Open-Source Support for MediaTek’s Genio IoT Platforms with Collabora

MediaTek continues to strengthen upstream support for its Genio IoT platforms through its collaboration with Collabora. Following the initial efforts to integrate Genio EVKs into the open-source ecosystem, recent updates bring improvements to the Linux kernel, Debian-based images, and automated testing frameworks. These enhancements ensure broader compatibility and long-term support for developers working with Genio-based IoT solutions.

news

Microsoft Windows 11 Caches Exploitable Malware

posted by Roy Schestowitz on May 15, 2024

Fishtank PC builds

Reprinted with permission from Cybershow. Author: Helen Plews.

Figure 1: Tom's Hardware: Fishtank PC builds.

Malware is often thought of as a human interaction with a digital device that causes an infection such as a virus or worm. We assume a human used bad authentication, or the human clicked the bad link, the human downloaded the malware…

So if we have anti-virus and anti-phish educational campaigns we should be well protected right? What about the technical side of cybersecurity, where the hardware, network equipment, end device or software vulnerability is the cause?

This article will examine a case where an operating system is able to automatically open and store a phishing email attachment, leading to potential compromise. In this case Windows 11 has been caching attachments locally to provide synchronisation across devices with the Outlook Application. In many cases, it has cached exploitable malware. This is a growing issue brought to light by Windows 11 users and anti-virus providers, instead of the makers at Microsoft.

Dropper Investigation

I am a life-long gamer and from experimentation over the years, I know I have the best rig, a customisable gaming PC. It’s very nice hardware it looks stunning with rainbow glowing fans and it sounds like a mini jet engine, rendering most graphics on Ultra with a graphics card which is at most 2 years old. The only issue I have had with it is in the operating system, which of course for a big gamer is Windows 11 due to its age. After just two weeks of operation I was alerted to a dropper located in my Windows Appdata folder, it was not dropping any further viruses yet as it had been caught by my expensive AV - which is why it sounds like a jet engine due to the large use of CPU!!

Was it a false positive? Well I ran the offline scan myself as my machine took 8x longer to boot. It behaved as if rebooting after a major update. There were no updates carried out, which made me suspect something amiss.

The virus location was not new to me, it is an appdata folder present in Windows 10 and Windows 11 for Windows mail in particular it processes mail syncing across devices; the full path is:

C:\Users\’Username’\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\SO\

Now I have had viruses popping up here before, in fact it has been an ongoing problem since I adopted the Windows 11 operating system (OS) in 2022 on the household laptops. Since then, both of my son’s laptops have alerted me to droppers and Trojans in the same Appdata folder. I initially assumed my children were not so good with their cybersecurity (being aged 5 and 9 that makes sense). Maybe they had clicked an email notification. Maybe they had downloaded some Trojan in the style of a game from a requested and shoddy gaming store all parents know about, stealthy and all whilst under supervision. That was until my brand new gaming rig got one.

Examining the attack timeline of my gaming rig in detail showed that a phish had been ‘clicked’ from my Hotmail account which was logged in on my Outlook App, running in the background processes (not running in my taskbar) whilst I played some epic title the night before. This ‘click’ put an infected PDF invoice on my PC, and on boot the next day activated the dropper, slowing the machine right down - which gave me a clue.

Now let's be clear about how Microsoft works, as I understand it, and why this is a gripe serious enough to warrant its own blog post.

You must sign in online to a Microsoft account to access the PC at all times, then it creates session keys for all applications that come installed as standard with the OS. So, unless you take some drastic measures I will discuss in a moment, you will undoubtedly be running sessions of Windows apps in the background; Outlook, OneDrive, Teams, Xbox, Photos, Office, Store, the list is quite extensive.

Moving on, I look for the phish email I had. According to my AV "clicked on" log, I located the suspicious subject of the email. It was something akin to;

AMAZON ACCOUNT ###U$IIHknDBWON38383y4y29~~~

Now, you do not need to be a cybersecurity expert to tell that is a phish from the subject which was located using the now foreground Outlook app. And as expected, it was unread. It showed me that within a few minutes of receiving the unread email, the attached PDF invoice was added to the Windows Communication Appdata folder, which led to the dropper found by the offline scan.

It seemed that Outlook App was saving unread attachments to the appdata folder where the virus was located. Some of the located viruses over the past two years were found on multiple devices that used the same MS credentials which unless stated otherwise, auto sync application data. That is exactly what the

microsoft.windowscommunicationsapps_8wekyb3d8bbwe

folder is for. It contains both the application data for Windows apps like Outlook to run and sync as well as data obtained in the process. I synced between my children's laptops as my account was the administrator for the network, it kept them safer online. Or so I thought.

Vulnerability Research

So I start down the usual process of researching the vulnerability to find a permanent mitigation. I find nothing at first, no CVE, no reports. I do find some details on the MS community website like this one from "2020 Trojan Found and Deleted"… but it Returns (Trojan: HTML/Phish.AB!MSR) . It is here I see the same problem and I see a response from an expert.

“The trojan is an email attachment synced to your PC. Do you have some Hotmail or Microsoft email setup in an email client applications like Outlook?” - Independent Expert, MS Community, 2020

So I search all around this topic and I cannot find anything from Microsoft about this issue right away, but I do find many victims. Anti-Virus companies, affected users and experts alike are all drawing attention to this problem. Eventually, thanks to Reddit I find a similar experience from a commentor who managed to find the reported exploit listed by Microsoft. You can find many more threads on the issue on Reddit with a search.

“Looking into the report we have a "Exploit:O97M/CVE-2017-11882.AZA!MTB" match, which doesn't seem to be that ominous since it requires the file to be executed on a non-updated Office/WordPad, still it ain't something I'd like to find lying around because the app found it was a good thing to download it, without my consent.” - JVMTG, Reddit, 2023

It is a known software error marked as severe on their own security intelligence website, with 24 exploits under the O97M CVE. I’d like to say I have more details from Microsoft but I do not, instead they offer very little default cybersecurity steps, such as "remain up to date and don’t click a phish".

This does seem rather severe. It locally caches attachments from emails including those which have not been opened to the windowscommunicationsapps folder from the Outlook App. It will then auto sync the data in the folder to all devices using the same credentials in their Outlook App on their phones, laptops, desktops, anywhere the Outlook App runs.

The only step missing for a full compromise is that infected files are auto-run… a feature I feel sure Microsoft are working on at this exact moment!

Attacks are becoming more complex, in 2022 they were able to add the dropper, which very slowly downloaded a fairly rubbish Trojan, which was easily removed. Recently there were 74 password protected files and multiple Trojans appearing as game applications in the same appdata folder. These were located only weeks after a fresh OS install and could not be explained by known activities on the machine or entirely resolved by AV due to the encryption of the folders they were located in.

Impact

Take a moment to think about how many commercial users of the Outlook application have auto-sync enabled in daily use. All those using Office 365 who sync between devices on their smartphone, personal devices and company equipment, or amongst family member's tablets and laptops. You should be concerned. And then get mad as hell, because it seems Microsoft have created their own quite special service for propagating malware, one that's been ongoing since at least 2020.

I have wasted countless hours re-installing OS’s, searching files, reading reports and researching this issue to find my only salvation in Reddit. Reddit of all places! This looks like something Microsoft rather wanted to sweep under the rug.

If you sync with Outlook App between devices with the same MS account, you are vulnerable to this malware propagation. Microsoft insist users take advantage of auto-synced features across devices and use this as a clear marketing tool especially for commercial settings. It seems my trust in this feature was misplaced.

Mitigation And Loss of Trust

Some will say that this is "just a feature" of sync. I disagree because like so many Microsoft processes it feels out of control. It does not just synchonise expected user data. It inappropriately populates and copies undocumented files into system folders and, without any knowledge or intervention from the user, replicates them across devices.

The mitigation is you must live without synchronisation in Microsoft applications. So far it has worked 100%. Turning off sync across applications does work. This can be done during an OS install by refusing all sync options when prompted. You must also make sure it is off in the account settings for the user. This can be done from the settings panel when logged on to Windows. There are many guides available like this one from Process.st. Even with sync off, you can still access email and other services using the web applications, which will sync files and emails but will not store these to the local machine.

If like myself, you have lost trust in the applications themselves, removing windows apps entirely may be more fitting, this allows the folder

microsoft.windowscommunicationsapps_8wekyb3d8bbwe

to be deleted and does not appear, like a lurking background threat at a later date just in case you change your mind. My gaming rig has only one MS app remaining, Xbox and that is the way it will stay until the situation is openly discussed by MS and the vulnerability resolved. No more Appdata Phishes please.

In summary, no amount of phishing training will prevent a bad design in the operating system. Caching malware infected attachments to system folders and replicating them is bad design in my opinion. In this case, the operating system has been phished, not the human.

Other Recent Tux Machines' Posts

IPFire Hardened Linux Firewall Distro Is Now Powered by Linux Kernel 6.12 LTS
IPFire 2.29 Core Update 192 open-source hardened Linux firewall has been released today, and it’s now available for download, with Linux kernel 6.12 LTS and other interesting changes.
LXQt 2.2 Desktop Promises Many Wayland Improvements, QTerminal Updates
The developers of the lightweight LXQt desktop environment have showcased some of the major changes coming to the LXQt 2.2 release, which is due in mid-April.
KDE Plasma 6.3.3 Implements Battery Charge Threshold Support for More Devices
The KDE Project released today KDE Plasma 6.3.3 as the third maintenance update to the latest KDE Plasma 6.3 desktop environment series to address more of those pesky issues and also add some enhancements.
First Look: Garuda Linux Introduces New COSMIC Edition
After releasing Garuda Linux “Broadwing”, the development team behind this Arch Linux-based distribution announced that they’re working on a new edition featuring the up-and-coming COSMIC desktop environment.
New WINE and Games News
mostly games
Clonezilla 3.2.1 Drops i686 Support, Moves to Linux Kernel 6.12
Clonezilla Live 3.2.1 brings Linux kernel 6.12, partclone 0.3.33
Linux From Scratch 12.3 Version 12.3
LFS and more
"Linux" Being Blamed for Typosquatting
Fear, Uncertainty, Doubt, as usual
Audacity 3.7.2 Improves the Linux AppImage Bundle for Ubuntu 22.04 LTS
Audacity 3.7.2 open-source digital audio editor and recording software is now available for download with improvements for Linux and various bug fixes.
 
Latest From Red Hat
From redhat.com only
Linux Leftovers
mostly Linux
Programming Leftovers
Development links
Security Leftovers
Security links for today
today's howtos
Instructionals/Technical leftovers
Sparky Semi-Rolling 2025.03 Brings Linux Kernel 6.12 LTS
Debian-based Sparky semi-rolling 2025.03 update is out now featuring Linux kernel...
Debian 13 to Offer KDE Plasma 6.3.5 Desktop Environment
Debian 13 "Trixie" plans to feature KDE Plasma 6.3.5, Frameworks 6.12
FSF launches pre-bid phase for silent memorabilia auction
The Free Software Foundation (FSF) has published the memorabilia items for bidding in the silent auction on the LibrePlanet wiki
Free and Open Source Software, howtos and Installations
This is free and open source software
Prolong Laptop Battery Life in Linux by Limiting Charging Levels
Prolong your laptop's battery life in long run by limiting the charging to 80%
What's the best tiling window manager for a Linux beginner?
If you're looking to up your Linux desktop game, a tiling window manager might be what you're looking for
Games: Triple-i, Oblin Party, and More
9 new articles from GamingOnLinux
ExTiX 25.3 KDE Plasma and the Ubuntu Desktop together with Waydroid ('Waydroid lets you launch a complete Android system on Linux with GAPPS') :: Build 250305
ExTiX 25.3 KDE Plasma System 64 bit is based on Debian and Ubuntu 24.04.2 LTS Noble Numbat
Today in Techrights
Some of the latest articles
GStreamer 1.26 Open-Source Multimedia Framework Released, Here’s What’s New
The GStreamer project released GStreamer 1.26 today as the latest stable version for this open-source multimedia framework that introduces numerous new features and enhancements.
Free, Libre, and Open Source Software Leftovers
more FOSS news
Events: SCaLE and Postgres Extensions Day 2025
SCaLE-related picks
Education With FOSS and Standards
FOSS- and Education-centric News
Security Patches and Leftovers
Security links
GNU/Linux Leftovers and Other Operating Systems
mostly Linux
Linux Kernel Space: Networking and Problems With Rust Code Entering Where Developers Cannot Understand It
kernel picks
Mozilla Screwing Up Third-Party Developers Again
add-on breakage
Programming Leftovers
Development news and analysis
Linux Devices and Open Hardware
SDVs, GNU/Linux on Android, and more
Debian: Gunnar Wolf Gets PhD, Collabora Update, Joachim Breitner Dives Deep
Debian stories and updates
today's howtos
Instructionals/Technical links, a handful
Mesa 25.1 to Replace Nouveau Driver with Zink/NVK by Default for NVIDIA GPUs
Collabora informs today on some of the major changes coming to the major Mesa 25.1 open-source graphics stack for NVIDIA GPU users in terms of the default graphics driver.
Audiocasts/Shows: Late Night Linux, Linux User Space, and Destination Linux
3 new episodes
FreeBSD 13.5 Released
FreeBSD 13.5 is out
today's leftovers
3 for now
Security Leftovers and Windows TCO
mostly incidents
Fedora and Red Hat Leftovers
mostly redhat.com
today's howtos
Instructionals/Technical posts
Android Leftovers
Google is working on external display tools for Android 16
March’s Steam Client Update Brings Remote Demo Installation
March's Steam Client update brings remote demo management
Fedora Linux 43 to Feature RPM 6
Fedora Linux 43 may ship with RPM 6
The NixOS Foundation Board Announced
Change is always a big step, but we believe this one is for the better
Free and Open Source Software
Only free and open source software is eligible for inclusion here
Radxa CM3J with Built-in Wi-Fi 5 and Bluetooth 5.0 for Industrial Applications
It operates within a temperature range of -40°C to 85°C. Software support includes Debian and Android
Expanding Open-Source Support for MediaTek’s Genio IoT Platforms with Collabora
The first major results of this collaboration have been integrated into the Linux 6.14 kernel
Games: Control Ultimate Edition, Fallout with DOOM, and More
Latest 9 from GamingOnLinux
Today in Techrights
Some of the latest articles
Kali laid bare: the most famous Linux hacking distro of all time
Talking to the people behind Kali Linux
Navidrome 0.55 Music Server & Streamer Brings Major Overhaul
Navidrome 0.55 music server & streamer released with enhancements to file management
Garuda Linux “Broadwing” Released with New Mokka Edition, New Welcome App
Garuda Linux “Broadwing” is out today as the latest snapshot of this Arch Linux-based distro that promises to deliver a powerful, beautiful, and user-centric Linux desktop experience.
Free and Open Source Software, howtos and Installations
This is free and open source software
Zenned – Arch-based desktop Linux distribution
Zenned is a Linux-based and open source Arch distribution
Ubuntu vs. Debian: 7 key differences help determine which distro is right for you
Ubuntu is based on Debian, but they're not the same
I tried Nitrux OS - see how I handled this security-focused Linux beast
This review first appeared in issue 354 of PC Pro.
Free, Libre, and Open Source Software Leftovers
a few more FOSS links
Programming/Development and Arduino Hacking
some coder-centric links
GNU/Linux and BSD Leftovers
today's leftovers
Audiocasts/Shows: LINUX Unplugged, Invidious, and Linux Link Tech Show
Some new videos/shows
Dash to Panel GNOME Extension Gets Big Update
A big update to the perennially popular GNOME Shell extension Dash to Panel is rolling out, including new settings to go from Dash to Panel to dock mode
Best Free and Open Source Software, howtos and Installations
This is free and open source software written in Python
Review: Solus 4.7
Solus is an independently developed, rolling release distribution which uses the eopkg package manager
Devices, Open Hardware, and Mobile Systems
the hardware and gadgets side
today's howtos
Instructionals/Technical posts
This Week in KDE Apps: LSP Support in KDevelop, systemDGenie rewrite and big UI changes in Dolphin
Every week we cover as much as possible of what's happening in the world of KDE apps
Improving Debian packaging in Kate
The other day, I noted that the emacs integration with debputy stopped working
today's leftovers
retro and more
Programming Leftovers
Development picks
Linux 6.14-rc6
Linus has released 6.14-rc6 for testing. ""This release remains on track, nothing special to report"".
Today in Techrights
Some of the latest articles
9to5Linux Weekly Roundup: March 9th, 2025
The 230th installment of the 9to5Linux Weekly Roundup is here for the week ending on March 9th, 2025.