Tux Machines

Do you waddle the waddle?

Other Sites

9to5Linux

Ubuntu Summit for Ubuntu 26.10 Takes Place on November 12-13, 2026

The Ubuntu Summit 26.10 event will take place next month, November 12-13, 2026. Ubuntu Summit is Ubuntu’s biggest event of the year, where developers and users gather together to discuss the features of the next major version of Ubuntu, attend various workshops, and see presentations of all kinds of products.

OpenVPN 2.7.8 Released with Security and Bug Fixes, Various Improvements

Coming a month after OpenVPN 2.7.7, the OpenVPN 2.7.8 release makes certificate validation stricter regarding NULL bytes in strings, which might break existing installations if such certificates exist and OpenSSL builds are used, and updates the OpenSSL builds to use the last field when handling certificates with duplicate fields.

NVIDIA 615.78.08 Linux Graphics Driver Improves Support for The Last of Us Part II

Coming a month after NVIDIA 615.71.09, which was the first release in the NVIDIA 615 series, the NVIDIA 615.78.08 update enables the NVreg_UseKernelSuspendNotifiers=1 option by default, and adds support for revision 3 of the VK_NV_low_latency2 Vulkan extension to improve latency and stutter with vkd3d-proton, particularly when Frame Generation is enabled.

Multiple Security Issues Patched in XOrg Server 21.1.25 and Xwayland 24.1.14

The fixes include CVE-2026-88812, an XKB SetGeometry TextDoodad double free that can lead to heap corruption, potentially enabling arbitrary code execution or denial of service (crash), and CVE-2026-93515, a present extension cross-window notify use-after-free that can lead to denial of service (crash) or potentially information disclosure.

Debian 14 “Forky” Artwork Proposals Are Now Open for Submission

This is the moment for aspiring artists and designers who want to display their work in front of millions of Debian users to submit their best artwork for the upcoming Debian 14 (codename Forky – continuing the “Toy Story” naming) operating system series, due for release in mid-2027.

Canonical Beefs Up Security for Ubuntu 26.10 with Slimmed-Down GRUB, Linux 7.3

Ubuntu 26.10 (codename Stonking Stingray) is scheduled for release next week, on October 15th, 2026, with the latest and greatest GNOME 51 “A Coruña” desktop environment, the unreleased Linux 7.3 kernel series (yes, Ubuntu 26.10 will ship with an RC (Release Candidate) kernel), OpenSSL 4.0, OpenSSH 10.5, and Rust-based core utilities.

Raspberry Pi OS Updated with Battery and Squeekboard Dock Widgets

Based on the latest Debian 13 “Trixie” operating system series and powered by Linux kernel 6.18.50 LTS, the new Raspberry Pi OS release ships with battery and squeekboard widgets for the new dock, support for automounting encrypted drives, Control Centre debug code, and new, better-quality Raspberry Pi menu icons.

Debian Trixie-Based Raspberry Pi Desktop Is Now Available for PC and Mac

The wait is finally over, and you can download an updated Raspberry Pi Desktop ISO image that you can install on your x86_64 (not ARM) laptop or desktop computer, or on a 64-bit Mac. The latest Raspberry Pi Desktop release is based on Debian 13 “Trixie,” and it’s powered by the long-term supported Linux 6.12 LTS kernel series.

GNOME 52 “Terengganu” Desktop Environment Is Scheduled for March 17th, 2027

With GNOME 51 “A Coruña” being released last month and slowly making its way into the stable software repositories of popular GNU/Linux distributions, such as openSUSE Tumbleweed, Fedora Linux, Ubuntu, and Arch Linux, the GNOME devs have started work on the GNOME 52 release.

LinuxGizmos.com

IBASE IB966 3.5-inch SBC with Panther Lake and up to 180 TOPS

IBASE has announced the IB966, a 3.5-inch SBC based on Intel Core Ultra Series 3 “Panther Lake” processors, with up to 180 TOPS of aggregate AI performance, 128GB of DDR5-7200 memory, dual 2.5GbE and three M.2 slots.

Raspberry Pi 5 cluster runs Qwen3-30B-A3B at 15 tokens/s on CPU

Hellomatik has published a study and a modified distributed-llama implementation for running the Qwen3-30B-A3B language model across four Raspberry Pi 5 boards. Using only the boards’ Arm Cortex-A76 CPUs, the cluster reached a reported decode throughput of 15.143 tokens per second, without GPU or NPU acceleration or CPU overclocking.

schestowitz.com

Lazy Panda Pan Asian Surviving OK

Lazy Panda still open

Litigation Update

t is a matter of public record (as of today) that another Order was issued. It was issued by the joint head of the media and communications list at the UK’s High Court. As is already known to the opposing party, we’re not unrepresented in the case because of Legal Aid and pro bono advice from a “leading specialist in defamation, privacy, and data protection law.”

Sunbathing One Last Time

Gettint cold, sun low

Solicitors Regulation Authority (SRA) and Conflicts of Interest

Hard to pretend it ain’t happening

Envy is a Terrible Motivator

“Up” is elusive

Motion to Put “Reform UK” Out of Business Still in Progress (CR-2026-007405)

Will Reform UK disband this year, then reappear in a new shell?

Brett Wilson LLP v Schestowitz

They are hijacking Americans’ cases, using American money

How We Won the Battle for the Birds

If it’s legal, then it’s legal

Lighting and Moods

Underappreciated factor

Biodiversity and Happiness

Heal the world

news

Microsoft Windows 11 Caches Exploitable Malware

posted by Roy Schestowitz on May 15, 2024

Fishtank PC builds

Reprinted with permission from Cybershow. Author: Helen Plews.

Figure 1: Tom's Hardware: Fishtank PC builds.

Malware is often thought of as a human interaction with a digital device that causes an infection such as a virus or worm. We assume a human used bad authentication, or the human clicked the bad link, the human downloaded the malware…

So if we have anti-virus and anti-phish educational campaigns we should be well protected right? What about the technical side of cybersecurity, where the hardware, network equipment, end device or software vulnerability is the cause?

This article will examine a case where an operating system is able to automatically open and store a phishing email attachment, leading to potential compromise. In this case Windows 11 has been caching attachments locally to provide synchronisation across devices with the Outlook Application. In many cases, it has cached exploitable malware. This is a growing issue brought to light by Windows 11 users and anti-virus providers, instead of the makers at Microsoft.

Dropper Investigation

I am a life-long gamer and from experimentation over the years, I know I have the best rig, a customisable gaming PC. It’s very nice hardware it looks stunning with rainbow glowing fans and it sounds like a mini jet engine, rendering most graphics on Ultra with a graphics card which is at most 2 years old. The only issue I have had with it is in the operating system, which of course for a big gamer is Windows 11 due to its age. After just two weeks of operation I was alerted to a dropper located in my Windows Appdata folder, it was not dropping any further viruses yet as it had been caught by my expensive AV - which is why it sounds like a jet engine due to the large use of CPU!!

Was it a false positive? Well I ran the offline scan myself as my machine took 8x longer to boot. It behaved as if rebooting after a major update. There were no updates carried out, which made me suspect something amiss.

The virus location was not new to me, it is an appdata folder present in Windows 10 and Windows 11 for Windows mail in particular it processes mail syncing across devices; the full path is:

C:\Users\’Username’\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\SO\

Now I have had viruses popping up here before, in fact it has been an ongoing problem since I adopted the Windows 11 operating system (OS) in 2022 on the household laptops. Since then, both of my son’s laptops have alerted me to droppers and Trojans in the same Appdata folder. I initially assumed my children were not so good with their cybersecurity (being aged 5 and 9 that makes sense). Maybe they had clicked an email notification. Maybe they had downloaded some Trojan in the style of a game from a requested and shoddy gaming store all parents know about, stealthy and all whilst under supervision. That was until my brand new gaming rig got one.

Examining the attack timeline of my gaming rig in detail showed that a phish had been ‘clicked’ from my Hotmail account which was logged in on my Outlook App, running in the background processes (not running in my taskbar) whilst I played some epic title the night before. This ‘click’ put an infected PDF invoice on my PC, and on boot the next day activated the dropper, slowing the machine right down - which gave me a clue.

Now let's be clear about how Microsoft works, as I understand it, and why this is a gripe serious enough to warrant its own blog post.

You must sign in online to a Microsoft account to access the PC at all times, then it creates session keys for all applications that come installed as standard with the OS. So, unless you take some drastic measures I will discuss in a moment, you will undoubtedly be running sessions of Windows apps in the background; Outlook, OneDrive, Teams, Xbox, Photos, Office, Store, the list is quite extensive.

Moving on, I look for the phish email I had. According to my AV "clicked on" log, I located the suspicious subject of the email. It was something akin to;

AMAZON ACCOUNT ###U$IIHknDBWON38383y4y29~~~

Now, you do not need to be a cybersecurity expert to tell that is a phish from the subject which was located using the now foreground Outlook app. And as expected, it was unread. It showed me that within a few minutes of receiving the unread email, the attached PDF invoice was added to the Windows Communication Appdata folder, which led to the dropper found by the offline scan.

It seemed that Outlook App was saving unread attachments to the appdata folder where the virus was located. Some of the located viruses over the past two years were found on multiple devices that used the same MS credentials which unless stated otherwise, auto sync application data. That is exactly what the

microsoft.windowscommunicationsapps_8wekyb3d8bbwe

folder is for. It contains both the application data for Windows apps like Outlook to run and sync as well as data obtained in the process. I synced between my children's laptops as my account was the administrator for the network, it kept them safer online. Or so I thought.

Vulnerability Research

So I start down the usual process of researching the vulnerability to find a permanent mitigation. I find nothing at first, no CVE, no reports. I do find some details on the MS community website like this one from "2020 Trojan Found and Deleted"… but it Returns (Trojan: HTML/Phish.AB!MSR) . It is here I see the same problem and I see a response from an expert.

“The trojan is an email attachment synced to your PC. Do you have some Hotmail or Microsoft email setup in an email client applications like Outlook?” - Independent Expert, MS Community, 2020

So I search all around this topic and I cannot find anything from Microsoft about this issue right away, but I do find many victims. Anti-Virus companies, affected users and experts alike are all drawing attention to this problem. Eventually, thanks to Reddit I find a similar experience from a commentor who managed to find the reported exploit listed by Microsoft. You can find many more threads on the issue on Reddit with a search.

“Looking into the report we have a "Exploit:O97M/CVE-2017-11882.AZA!MTB" match, which doesn't seem to be that ominous since it requires the file to be executed on a non-updated Office/WordPad, still it ain't something I'd like to find lying around because the app found it was a good thing to download it, without my consent.” - JVMTG, Reddit, 2023

It is a known software error marked as severe on their own security intelligence website, with 24 exploits under the O97M CVE. I’d like to say I have more details from Microsoft but I do not, instead they offer very little default cybersecurity steps, such as "remain up to date and don’t click a phish".

This does seem rather severe. It locally caches attachments from emails including those which have not been opened to the windowscommunicationsapps folder from the Outlook App. It will then auto sync the data in the folder to all devices using the same credentials in their Outlook App on their phones, laptops, desktops, anywhere the Outlook App runs.

The only step missing for a full compromise is that infected files are auto-run… a feature I feel sure Microsoft are working on at this exact moment!

Attacks are becoming more complex, in 2022 they were able to add the dropper, which very slowly downloaded a fairly rubbish Trojan, which was easily removed. Recently there were 74 password protected files and multiple Trojans appearing as game applications in the same appdata folder. These were located only weeks after a fresh OS install and could not be explained by known activities on the machine or entirely resolved by AV due to the encryption of the folders they were located in.

Impact

Take a moment to think about how many commercial users of the Outlook application have auto-sync enabled in daily use. All those using Office 365 who sync between devices on their smartphone, personal devices and company equipment, or amongst family member's tablets and laptops. You should be concerned. And then get mad as hell, because it seems Microsoft have created their own quite special service for propagating malware, one that's been ongoing since at least 2020.

I have wasted countless hours re-installing OS’s, searching files, reading reports and researching this issue to find my only salvation in Reddit. Reddit of all places! This looks like something Microsoft rather wanted to sweep under the rug.

If you sync with Outlook App between devices with the same MS account, you are vulnerable to this malware propagation. Microsoft insist users take advantage of auto-synced features across devices and use this as a clear marketing tool especially for commercial settings. It seems my trust in this feature was misplaced.

Mitigation And Loss of Trust

Some will say that this is "just a feature" of sync. I disagree because like so many Microsoft processes it feels out of control. It does not just synchonise expected user data. It inappropriately populates and copies undocumented files into system folders and, without any knowledge or intervention from the user, replicates them across devices.

The mitigation is you must live without synchronisation in Microsoft applications. So far it has worked 100%. Turning off sync across applications does work. This can be done during an OS install by refusing all sync options when prompted. You must also make sure it is off in the account settings for the user. This can be done from the settings panel when logged on to Windows. There are many guides available like this one from Process.st. Even with sync off, you can still access email and other services using the web applications, which will sync files and emails but will not store these to the local machine.

If like myself, you have lost trust in the applications themselves, removing windows apps entirely may be more fitting, this allows the folder

microsoft.windowscommunicationsapps_8wekyb3d8bbwe

to be deleted and does not appear, like a lurking background threat at a later date just in case you change your mind. My gaming rig has only one MS app remaining, Xbox and that is the way it will stay until the situation is openly discussed by MS and the vulnerability resolved. No more Appdata Phishes please.

In summary, no amount of phishing training will prevent a bad design in the operating system. Caching malware infected attachments to system folders and replicating them is bad design in my opinion. In this case, the operating system has been phished, not the human. █

Other Recent Tux Machines' Posts

Americans Connected to Microsoft versus Webhost of GNU/Linux News Sites [original]
It has been 4 months since we celebrated this site's anniversary in Seaham (England)
Cloudflare Radar Reckons GNU/Linux Gained About 2-3% This Past Year in China [original]
Will China see the share of GNU/Linux exceeding 10% by year's end?
Debian 14 “Forky” Artwork Proposals Are Now Open for Submission
The Debian Project officially open the artwork contest for the upcoming Debian 14 “Forky” operating system series, calling for all talented artists and designers to create a beautiful desktop look and feel.
 
Forget Linux Mint, this is the Windows alternative you need
I’ve found Zorin OS to be an ideal replacement. It’s built on Linux but offers a Windows-like interface
I tested the top 10 popular Linux distros, here's how I'd rank them
I’ve been using Linux for over a decade now, and during that time I’ve tested dozens of distros — both popular and obscure options
The 4 big Windows gaffes that convinced me to try Linux Mint
Linux Mint never asked me for anything but a working computer
Free and Open Source Software, and Benchmark
This is free and open source software
Vinix is Not a Linux Distro, But it Can Run Games, Docker, and QEMU
The project has been around since 2021, runs its own kernel, and is written in V
Gentoo infrastructure sponsors wanted!
Gentoo Linux is made possible by many community donations and sponsors, together with the enthusiastic work of our developers
Today in Techrights
Some of the latest articles
Ubuntu Summit for Ubuntu 26.10 Takes Place on November 12-13, 2026
Ubuntu Summit 26.10 will take place on November 12-13, 2026, for the upcoming Ubuntu 26.10 (Stonking Stingray) release, due out on October 15th.
"Decay of FOSS" [original]
the state of things in Ardour
15 Years [original]
The first time I met Rianne we actually chatted a little about Wikileaks and how Julian Assange was treated by the courts in the UK
Latest on Court Battles [original]
Crossposted from schestowitz.com
Free, Libre Software and Sharing Leftovers
FOSS and more
Linux and BSD Leftovers
mostly the former
GNU/Linux Desktop/Laptop: Google's Betrayal and 25 Years of Predictions
a pair of stories
Document Foundation on Community Member and LibreOffice
a pair of new blog posts
A Power Case for a FOSS Phone and More on Mobile Systems/Mobile Applications
Mobile stuff
Mozilla: Firefox Tooling, GNOME Theme, WebDriver Newsletter, and More
Firefox mostly
Programming Leftovers
Development news
Games: Bloodborne, Doom and Super Mario Bros, Steam, and More
gaming related picks
Audiocasts/Shows: Linux Plumbers Conference and More
videos and sound
Applications: Hylki, Auto-CPUFreq, OpenSearch
some software picks
today's howtos
Instructionals/Technical picks
Fossy Camp KDE, Akademy, and More KDE/Qt News
KDE news
GNOME: Global Menu and Icon for Haystack
a pair of updates
Scrcpy 5.0 Released
Scrcpy 5.0 news
Security, FUD, and Microsoft TCO
incidents and more
Red Hat: Lightwell, OpenShift, Slop, and More
mostly redhat.com
Open Hardware/Modding: Raspberry Pi, Arduino, and More
Hardware picks
OpenVPN 2.7.8 Released with Security and Bug Fixes, Various Improvements
OpenVPN 2.7.8 is now available for download as the eighth maintenance update to the OpenVPN 2.7 series with bug and security fixes, as well as a couple of user-visible changes.
NVIDIA 615.78.08 Linux Graphics Driver Improves Support for The Last of Us Part II
NVIDIA 615.78.08 Linux is now available for download with various fixes for bugs and issues to improve gaming, Wayland support, and the overall performance of the graphics driver.
Multiple Security Issues Patched in XOrg Server 21.1.25 and Xwayland 24.1.14
XOrg Server 21.1.25 and Xwayland 24.1.14 have been released today to address several security vulnerabilities that could lead to heap corruption, denial of service, or potentially information disclosure.
Red Hat Layoffs in October 2026 [original]
Journalists MIA
Still Surrounded by the Animal Kingdom [original]
They get along OK
GNU/Linux Growing in France [original]
Months ago the French government mandated a gradual migration to GNU/Linux
Android Leftovers
Android 17 October update rolling out with three Pixel fixes
Linux was almost called Freax, and someone renamed it without asking Linus
Even if you've never used it, there's a good chance you've heard of Linux
3 quick Linux tools that protect your PC from bad updates and hackers
Linux gives you plenty of control, but it also expects you to look after your own system
An Appeal [original]
We need to put an end to abuse in Free software communities; one way to get there is to illuminate of shine light on culprits
Free and Open Source Software, howtos and Installations
This is free and open source software
I tried 3 Linux distros inside Windows for free to see which felt most familiar
I can see pretty clearly that Linux can handle my regular workload and workflow without too much compromise
GNU/Linux Rose to About 5% in Brazil [original]
This is a bipartisan matter
Tobi Xu – Debian Sid-based Linux distribution
Tobi Xu is a Debian-based Linux distribution aimed at scientists, engineers, artists, and other creative users
Eslapion – lightweight SliTaz-derived Linux distribution
Eslapion is a lightweight Linux distribution derived from SliTaz
OpenSSH 10.6 released
Notable changes in this release include enabling the hybrid post-quantum ssh-mldsa44-ed25519 signature algorithm
Games: Steam Frame, SteamOS 0.4.4 Beta for Steam Frame, I Am Plague, and More
gaming picks from GamingOnLinux
Today in Techrights
Some of the latest articles
Canonical Beefs Up Security for Ubuntu 26.10 with Slimmed-Down GRUB, Linux 7.3
Ubuntu 26.10 will introduce new security features like a signed, slimmed down GRUB bootloader, TPM-backed encryption on machines without a hardware root of trust, and hardware-token VPN sign-in in NetworkManager.
Is 'free' costing us freedom?
The free in FOSS has always been freedom, and it was never about cost. Richard Stallman made this very clear and has been saying this for years.
Security, FUD, and Proprietary Omissions
leftovers for bugs
Free, Libre, and Open Source Software and Digital Sovereignty Leftovers
FOSS news
Education/Events: FOSDEM 2027 and DjangoCPH 2026
events regarding FOSS
Programming Leftovers
Development leftovers for today
GNU/Linux and BSD Leftovers
GNU/Linux mostly
Ubuntu-Based FunOS 26.10 Reaches Beta, Canonical Sells Hype and Misleading Buzzwords
3 picks
Red Hat: Ansible, Slop, and Paid Endorsements
redhat.com picks
Applications: Podman Alternatives, Docker Tips, and Picard 3.0
software picks
3 howtos
Instructionals/Technical picks
Games: Steam Frame, Heir of the Dog, Geometry Rift: Apocalypse, and More
gaming leftovers
Linux 7.3-rc6
Next week might look a bit different
Raspberry Pi OS Updated with Battery and Squeekboard Dock Widgets
Raspberry Pi OS 2026-10-06 is now available for download with battery and squeekboard dock widgets, Control Centre improvements, and Linux kernel 6.18.50 LTS.
Debian Trixie-Based Raspberry Pi Desktop Is Now Available for PC and Mac
Raspberry Pi Desktop for PC and Mac has been updated to the latest Debian 13 “Trixie” operating system series and comes with all the new features from Raspberry Pi OS.
GNOME 52 “Terengganu” Desktop Environment Is Scheduled for March 17th, 2027
The development cycle of the upcoming GNOME 52 “Terengganu” desktop environment kicks off with a draft release schedule and a final release set for March 17th, 2027.
Android Leftovers
Your old Android phone is a better Home Assistant dashboard than any cheap tablet
Why Linux power users love the features that hold it back
Linux is an operating system that encourages you to explore and tinker
My 5 favorite Linux distros for security – and how they protect your privacy
If security is a top priority, you should consider one of these five Linux distributions
These 5 distros are replacing Red Hat Enterprise Linux in the professional world
I have spent a substantial part of my professional career working with RHEL
Free and Open Source Software
This is free and open source software
3 Years and 13 Years [original]
The community can host a party again (like earlier this year)
FreeLinX – independent Linux distribution with NetBSD userland
FreeLinX is an independent Linux distribution built around the Linux kernel, a NetBSD-derived userland
Self-Hosting Lessons From Libera Chat [original]
Hosting one's own IRC network is the only rational way to go
Today in Techrights
Some of the latest articles