Tux Machines

Do you waddle the waddle?

Other Sites

schestowitz.com

More Than a Decade Later She’s Still Appreciated

Susan of Tux Machines

Why Series (Long Form) Might Work Best

If it irritates your ‘opponent’, then you must be doing something right

E.ON (E.ON Next) Tried to Force or Trick Me Into Talking to a Chatbot, Not Staff of E.ON

They should know better than that; it insults the customers

Daniel Pocock is Picking on the Racists in the UK

Daniel Pocock is using the High Court now

‘Guilty’ of Opposing Violence Against Women

No actual verdict, just hypothetical

Pen and Paper

Old is not bad

The 200-Part Series on Microsofters’ SLAPP Censorship

t last! Today it’s done and I’ll move on to other topics.

The Media as Repeater of Lies From Slop Pushers

Not “slowing down” but failing

International Break

Tomorrow

When Bloggers Move to GNU/Linux

The word spreads

LinuxGizmos.com

Open-source flight controller pairs i.MX RT1176 with Pixhawk PAB compatibility

ARK Electronics recently showcased the ARKV6X-RT, an NDAA-compliant flight controller based on the FMUV6X-RT and Pixhawk Autopilot Bus open standards. The module uses an NXP i.MX RT1176 microcontroller and includes three synchronized IMUs, onboard FRAM, a secure element and PX4 Autopilot support.

Pocket-sized OpenWrt router offers dual-band Wi-Fi 5 and Gigabit Ethernet

GL.iNet has unveiled the Mango 2 (GL-MG1300), a compact travel router with dual-band Wi-Fi 5, Gigabit Ethernet and USB 3.0. The device supports WireGuard and OpenVPN, along with Ethernet, Wi-Fi repeater, USB tethering and USB cellular modem connections.

16-TOPS AI SBC with SATA 3.0 runs on octa-core Sophgo BM1688

Orange Pi has published hardware details for the OrangePi O1, a 90 × 70mm SBC based on the Sophgo BM1688 processor. It pairs eight Arm Cortex-A53 cores with a RISC-V C906 coprocessor and a 16-TOPS INT8 TPU, along with up to 16GB of LPDDR4/LPDDR4X memory.

9to5Linux

OBS Studio 33 Promises Support for Latest NVIDIA Broadcast SDKs, Beta Out Now

OBS Studio 33 promises support for the newest NVIDIA Broadcast SDKs for NVIDIA Audio Effects and Video Effects, a check for encoders being missing when loading a profile, hotkeys for controlling audio monitoring of a source, and NVENC (NVIDIA Encoder) support on AArch64 (ARM64).

Shelly 3.1.5 GUI Package Manager for Arch Linux Adds Atoll-Powered AUR Browser

Coming two weeks after Shelly 3.1.4, the Shelly 3.1.5 release introduces an optional Atoll-powered AUR browser to let you navigate a paginated package list from the Arch User Repository (AUR), sort packages by votes or popularity, view dependency information, and see information about installed or out-of-date dependencies.

COSMIC 1.9 Desktop Environment Released with COSMIC Viewer and COSMIC OSK

Coming about two weeks after COSMIC 1.8, the COSMIC 1.9 release introduces two new apps, namely COSMIC Viewer as an image viewer that supports a wide range of formats and features built-in editing capabilities, and COSMIC OSK as an on-screen keyboard that supports both touch and gamepad input.

Canonical Releases Mir 2.30 with wl_fixes Wayland Protocol Support

Highlights of Mir 2.30 include wl_fixes Wayland protocol support, a typed wrapper for wl_array, a run nest command for the workshop tooling, mandatory Rust support at build time alongside the newly packaged Rust-powered evdev input platform, and libxml++ 5.0 compatibility with a 2.6 fallback for older Linux distros.

Fwupd 2.1.8 Linux Firmware Updater Is Out Now with Support for More Devices

Coming almost two months after fwupd 2.1.7, the fwupd 2.1.8 release introduces support for ASUS GX5407, Elan PID 0CB6, FocalTech MOC fingerprint sensors, Lenovo ThinkPad Thunderbolt 4 Dock Gen 2 7000, MaxLinear MxL862xx, MediaTek MT9700 FCTE and MT9701 KSMU, Pixart PID 4F01, 4F02, 4F0D and 4F0E, and Rolling RW101 devices.

news

Microsoft Windows 11 Caches Exploitable Malware

posted by Roy Schestowitz on May 15, 2024

Fishtank PC builds

Reprinted with permission from Cybershow. Author: Helen Plews.

Figure 1: Tom's Hardware: Fishtank PC builds.

Malware is often thought of as a human interaction with a digital device that causes an infection such as a virus or worm. We assume a human used bad authentication, or the human clicked the bad link, the human downloaded the malware…

So if we have anti-virus and anti-phish educational campaigns we should be well protected right? What about the technical side of cybersecurity, where the hardware, network equipment, end device or software vulnerability is the cause?

This article will examine a case where an operating system is able to automatically open and store a phishing email attachment, leading to potential compromise. In this case Windows 11 has been caching attachments locally to provide synchronisation across devices with the Outlook Application. In many cases, it has cached exploitable malware. This is a growing issue brought to light by Windows 11 users and anti-virus providers, instead of the makers at Microsoft.

Dropper Investigation

I am a life-long gamer and from experimentation over the years, I know I have the best rig, a customisable gaming PC. It’s very nice hardware it looks stunning with rainbow glowing fans and it sounds like a mini jet engine, rendering most graphics on Ultra with a graphics card which is at most 2 years old. The only issue I have had with it is in the operating system, which of course for a big gamer is Windows 11 due to its age. After just two weeks of operation I was alerted to a dropper located in my Windows Appdata folder, it was not dropping any further viruses yet as it had been caught by my expensive AV - which is why it sounds like a jet engine due to the large use of CPU!!

Was it a false positive? Well I ran the offline scan myself as my machine took 8x longer to boot. It behaved as if rebooting after a major update. There were no updates carried out, which made me suspect something amiss.

The virus location was not new to me, it is an appdata folder present in Windows 10 and Windows 11 for Windows mail in particular it processes mail syncing across devices; the full path is:

C:\Users\’Username’\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\SO\

Now I have had viruses popping up here before, in fact it has been an ongoing problem since I adopted the Windows 11 operating system (OS) in 2022 on the household laptops. Since then, both of my son’s laptops have alerted me to droppers and Trojans in the same Appdata folder. I initially assumed my children were not so good with their cybersecurity (being aged 5 and 9 that makes sense). Maybe they had clicked an email notification. Maybe they had downloaded some Trojan in the style of a game from a requested and shoddy gaming store all parents know about, stealthy and all whilst under supervision. That was until my brand new gaming rig got one.

Examining the attack timeline of my gaming rig in detail showed that a phish had been ‘clicked’ from my Hotmail account which was logged in on my Outlook App, running in the background processes (not running in my taskbar) whilst I played some epic title the night before. This ‘click’ put an infected PDF invoice on my PC, and on boot the next day activated the dropper, slowing the machine right down - which gave me a clue.

Now let's be clear about how Microsoft works, as I understand it, and why this is a gripe serious enough to warrant its own blog post.

You must sign in online to a Microsoft account to access the PC at all times, then it creates session keys for all applications that come installed as standard with the OS. So, unless you take some drastic measures I will discuss in a moment, you will undoubtedly be running sessions of Windows apps in the background; Outlook, OneDrive, Teams, Xbox, Photos, Office, Store, the list is quite extensive.

Moving on, I look for the phish email I had. According to my AV "clicked on" log, I located the suspicious subject of the email. It was something akin to;

AMAZON ACCOUNT ###U$IIHknDBWON38383y4y29~~~

Now, you do not need to be a cybersecurity expert to tell that is a phish from the subject which was located using the now foreground Outlook app. And as expected, it was unread. It showed me that within a few minutes of receiving the unread email, the attached PDF invoice was added to the Windows Communication Appdata folder, which led to the dropper found by the offline scan.

It seemed that Outlook App was saving unread attachments to the appdata folder where the virus was located. Some of the located viruses over the past two years were found on multiple devices that used the same MS credentials which unless stated otherwise, auto sync application data. That is exactly what the

microsoft.windowscommunicationsapps_8wekyb3d8bbwe

folder is for. It contains both the application data for Windows apps like Outlook to run and sync as well as data obtained in the process. I synced between my children's laptops as my account was the administrator for the network, it kept them safer online. Or so I thought.

Vulnerability Research

So I start down the usual process of researching the vulnerability to find a permanent mitigation. I find nothing at first, no CVE, no reports. I do find some details on the MS community website like this one from "2020 Trojan Found and Deleted"… but it Returns (Trojan: HTML/Phish.AB!MSR) . It is here I see the same problem and I see a response from an expert.

“The trojan is an email attachment synced to your PC. Do you have some Hotmail or Microsoft email setup in an email client applications like Outlook?” - Independent Expert, MS Community, 2020

So I search all around this topic and I cannot find anything from Microsoft about this issue right away, but I do find many victims. Anti-Virus companies, affected users and experts alike are all drawing attention to this problem. Eventually, thanks to Reddit I find a similar experience from a commentor who managed to find the reported exploit listed by Microsoft. You can find many more threads on the issue on Reddit with a search.

“Looking into the report we have a "Exploit:O97M/CVE-2017-11882.AZA!MTB" match, which doesn't seem to be that ominous since it requires the file to be executed on a non-updated Office/WordPad, still it ain't something I'd like to find lying around because the app found it was a good thing to download it, without my consent.” - JVMTG, Reddit, 2023

It is a known software error marked as severe on their own security intelligence website, with 24 exploits under the O97M CVE. I’d like to say I have more details from Microsoft but I do not, instead they offer very little default cybersecurity steps, such as "remain up to date and don’t click a phish".

This does seem rather severe. It locally caches attachments from emails including those which have not been opened to the windowscommunicationsapps folder from the Outlook App. It will then auto sync the data in the folder to all devices using the same credentials in their Outlook App on their phones, laptops, desktops, anywhere the Outlook App runs.

The only step missing for a full compromise is that infected files are auto-run… a feature I feel sure Microsoft are working on at this exact moment!

Attacks are becoming more complex, in 2022 they were able to add the dropper, which very slowly downloaded a fairly rubbish Trojan, which was easily removed. Recently there were 74 password protected files and multiple Trojans appearing as game applications in the same appdata folder. These were located only weeks after a fresh OS install and could not be explained by known activities on the machine or entirely resolved by AV due to the encryption of the folders they were located in.

Impact

Take a moment to think about how many commercial users of the Outlook application have auto-sync enabled in daily use. All those using Office 365 who sync between devices on their smartphone, personal devices and company equipment, or amongst family member's tablets and laptops. You should be concerned. And then get mad as hell, because it seems Microsoft have created their own quite special service for propagating malware, one that's been ongoing since at least 2020.

I have wasted countless hours re-installing OS’s, searching files, reading reports and researching this issue to find my only salvation in Reddit. Reddit of all places! This looks like something Microsoft rather wanted to sweep under the rug.

If you sync with Outlook App between devices with the same MS account, you are vulnerable to this malware propagation. Microsoft insist users take advantage of auto-synced features across devices and use this as a clear marketing tool especially for commercial settings. It seems my trust in this feature was misplaced.

Mitigation And Loss of Trust

Some will say that this is "just a feature" of sync. I disagree because like so many Microsoft processes it feels out of control. It does not just synchonise expected user data. It inappropriately populates and copies undocumented files into system folders and, without any knowledge or intervention from the user, replicates them across devices.

The mitigation is you must live without synchronisation in Microsoft applications. So far it has worked 100%. Turning off sync across applications does work. This can be done during an OS install by refusing all sync options when prompted. You must also make sure it is off in the account settings for the user. This can be done from the settings panel when logged on to Windows. There are many guides available like this one from Process.st. Even with sync off, you can still access email and other services using the web applications, which will sync files and emails but will not store these to the local machine.

If like myself, you have lost trust in the applications themselves, removing windows apps entirely may be more fitting, this allows the folder

microsoft.windowscommunicationsapps_8wekyb3d8bbwe

to be deleted and does not appear, like a lurking background threat at a later date just in case you change your mind. My gaming rig has only one MS app remaining, Xbox and that is the way it will stay until the situation is openly discussed by MS and the vulnerability resolved. No more Appdata Phishes please.

In summary, no amount of phishing training will prevent a bad design in the operating system. Caching malware infected attachments to system folders and replicating them is bad design in my opinion. In this case, the operating system has been phished, not the human. █

Other Recent Tux Machines' Posts

The Netherlands joins Europe's gradual migration from Windows to Linux on government PCs
Something very interesting is happening over in Europe in the world of FOSS
Fedora Linux 45 Beta Released with Linux 7.2, GNOME 51, and KDE Plasma 6.7
Fedora Linux 45 distribution is now available for public beta testing powered by Linux kernel 7.2 and featuring the GNOME 51 desktop environment. Here’s what to expect from the final release.
Emacs Chat, Using Emacs, and Org mode
Emacs stories
Qualcomm Snapdragon X2
Qualcomm Announces Snapdragon X2 Linux Developer Preview
F-Droid 2.0: A New Chapter for Android Freedom
After more than a year of hard work, we are thrilled to announce the launch of F-Droid 2.0
 
OBS Studio 33 Promises Support for Latest NVIDIA Broadcast SDKs, Beta Out Now
OBS Studio 33 entered public beta testing today with support for newest NVIDIA Broadcast SDKs for NVIDIA Audio Effects and Video Effects, a check for encoders being missing when loading a profile, and more.
The Dutch Fall in Love With GNU/Linux [original]
ClownFlare says about 10%, statCounter says about 13% on desktop/laptop
Shelly 3.1.5 GUI Package Manager for Arch Linux Adds Atoll-Powered AUR Browser
Shelly 3.1.5 graphical package manager for Arch Linux distributions is now available for download with Atoll-powered AUR browser, a build-and-install command, and native tools for maintaining your own package repositories.
GNU/Linux and BSD Leftovers
primarily GNU/Linux
Release or Availability of F-Droid 2.0, 5 Android Data Recovery Tools to Consider When Important Files Go Missing
Android picks
Raspberry Pi and ZimaBoard 2 Review
Hardware stories
Security and Microsoft TCO
bugs and incidents
Free, Libre, and Open Source Software & Standards Leftovers
FOSS and more
Programming leftovers
Development picks
Fuzzers in "AI" Clothing Clogging Up CVE Queues, a Burden for Distros
4 picks
Fedora and Red Hat Leftovers, About Half of It Selling Slop Plagiarism, Not Linux
sad, but true...
LibreOffice Conference 2026 Videos and The BSD Now Podcast
new shows or talks
today's howtos
Instructionals/Technical articles
KDE Akademy 2026 Report and Rebellion Over Slop (LLM Junk) in KDE
KDE picks
Desktop Environments (DE)/Window Managers (WM): COSMIC in System76, Xlibre in Peppermint, and WIMP
3 stories
Games: CONTROL Resonant, Faugus Launcher, Quake Champions, and More
mostly from Liam Dawe
The Kernel Report 2026 edition and Linux OOM on the desktop
Linux picks
'Linux' Foundation Promotes (for Money) Slop Plagiarism, Fake Currencies, and Scams, Calling Sloppy Bots "Agentic"
4 picks today
Susan Linton Also Played a Role at DistroWatch [original]
DistroWatch is still going strong
Android Leftovers
Samsung starts rolling out Android 17, One UI 9 to Galaxy S26 in the US following delay
The Fairphone (Gen. 6+): Loved by critics. Plus more
A month in, and the conversation around the Fairphone (Gen. 6+) is only getting louder
I automated my entire Linux desktop with 4 bash scripts—and reclaimed hours every week
The more you get into using Linux, the more likely you are to start using the Terminal for various tasks
5 free Linux distros I wish had premium versions – and why I’d pay for them
Why would I want to pay for something I can get for free? I've got plenty of reasons
I gave up on Windows and Linux for an OS that gives me the best of both worlds
Let me preface this with the fact that I love Linux
Free and Open Source Software
This is free and open source software
MollyOS – Debian-Based Linux Distribution for Children
MollyOS is a Debian-based Linux distribution designed for children and families
Bouncy Ball 3D and Taking KDE to the Pyramids
During this year's Akademy, while celebrating KDE's 30th birthday
Ubuntu is Tightening its Kernel SRU Cycle to Two Weeks, and Clankers Are to Blame
Ubuntu users will get kernel security fixes faster thanks to this
Finishing a Series About SLAPP Censorship Against Tux Machines [original]
Part 200 (the last) will be more technical
Today in Techrights
Some of the latest articles
today's leftovers
4 picks
Distributions and Operating Systems: Pixar, Distrobox, and EasyOS
3 stories
Games: Boiling Steam, Steam Deck, GamingOnLinux, and More
many stories
Canonical is Propping Up Slop (Hype), Even in Ubuntu
Ubuntu leftovers
Free Software Events and Education
4 more stories
C++ and Qt Leftovers
mostly Qt
Net, Web, and CMS Worries
WWW related picks
PgBouncer 1.26.0 and More PostgreSQL Coverage
PostgreSQL leftovers
GNU Project, FSF / Software Freedom, and More
activist centric
Linux Devices, Open Hardware, and Android
gadgets and hardware news
WordPress 7.1.2 Release, Patches ‘Click2Shell’ Vulnerability
new from WordPress
Programming Leftovers
Development picks
Security Leftovers
Security picks
Fedora and Red Hat: OpenJDK, ROS2, Lots About Slop, and Flatpak
IBM related stuff
today's howtos
Instructionals/Technical posts
Linux and AMD: Radeon RX 5700 XT for Games and RDNA 5 Support for GDDR7
AMD picks
NVIDIA 595.104.02 Linux Graphics Driver Is Out Now with Better Wayland Support
NVIDIA 595.104.02 Linux is now available for download with various fixes for bugs and crashes to improve the stability and reliability of the graphics driver.
Android Leftovers
I can't leave Android because of these 8 hidden features
COSMIC 1.9 Desktop Environment Released with COSMIC Viewer and COSMIC OSK
COSMIC 1.9 desktop environment is now available with the COSMIC Viewer image viewer app and COSMIC OSK on-screen keyboard app. Here’s what’s new!
I found a firewall GUI for KDE Plasma that’s way better than the default – and it’s free
If you use KDE Plasma on Fedora, you should consider switching to this firewall GUI
The newest ESP32 can actually run Linux, and it's getting uncomfortably close to a Raspberry Pi
It's a pretty standard set of features for a Linux single-board computer
Every distro should steal these 3 easy setup features from MX Linux
MX Linux is one of the most popular distros, and while its Debian base is attractive
Dolphin Emulator 2609 Released with Android NetPlay
Dolphin, the free open-source GameCube and Wii emulator, released new 2609 version today after 3 months of development
Best Free and Open Source Software
We recommend the best free and open source alternatives
NagisinnraLinux – lightweight Debian-based Linux distribution
NagisinnraLinux is a lightweight desktop Linux distribution based on Debian Stable and using the Xfce desktop environment
KDE Plasma 6.8 Desktop Environment Is Now Available for Public Beta Testing
KDE Plasma 6.8 desktop environment is now available for public beta testing with various new features, improvements, and bug fixes. Here’s what’s new!
Canonical Releases Mir 2.30 with wl_fixes Wayland Protocol Support
Mir 2.30 compositor is now available for download with wl_fixes Wayland protocol support, a typed wrapper for wl_array, a new command for the workshop tooling, and other changes.
Fwupd 2.1.8 Linux Firmware Updater Is Out Now with Support for More Devices
Fwupd 2.1.8 Linux firmware updater is now available for download with support for ASUS GX5407, Elan PID 0CB6, and other devices. Here’s what’s new!
Your Linux PC is talking behind your back — here’s how to listen in
The moment your Linux PC powers on
Stop chasing trendy Linux distros: pick one based on these 5 real problems instead
With so many Linux distros out there, how do you know you're using the right one
How Pixar Stopped Worrying And Learned To Love Linux
That path led Linux, and by 2001
I switched Ubuntu's desktop to Cinnamon for speed, but the real upgrade was how I work
System requirements for Ubuntu have risen a lot over the years
KeePassXC 2.8 Promises Auto-Type on Wayland and Qt 6 Port, Beta Out Now
KeePassXC 2.8 open-source password manager is now available for public beta testing with Auto-Type support on Wayland, quick unlock on Linux, and a long-anticipated Qt 6 port.
PPA Updated with Krita 6.0.4 / Krita 5.3.4 for Ubuntu 26.04 | 24.04
For those who want to install the most recent Krita 6.0.4 (or Krita 5.3.4) in native
Debian-Based SparkyLinux 2026.09 “Tiamat” Introduces Sparky Labwc Edition
SparkyLinux 2026.09 is now available for download with Linux kernel 7.2, Sparky Labwc edition, and the latest Debian “Forky” Testing updates.
Best Free and Open Source Software
Here are our recommended free and open source alternatives
KDE and AI, and you, and me
So I accidentally triggered an online shitstorm in the process of trying to craft a set of more restrictive LLM usage guidelines for KDE
RakuOS – hybrid atomic Fedora-based distribution
This is free and open source software
Linux PataOS – Debian-based distribution for engineering and design
Linux PataOS is a desktop Linux distribution based on Debian and built around the Cinnamon desktop environment
KDE Sets Ambitious Goals for 2026 and Beyond
KDE Connect reveals the goals for the Linux desktop darling, with one of those goals long overdue
Distro With an Expiry Date? Gravity Linux is a New Distro for Apple Silicon
Its first alpha targets the M4 Mac mini and runs on a Fedora base
The GNOME LLM Policy That I Want
KDE is on the news because of a controversial proposal to define an official “AI” (LLM) policy (archived link)
Latest From LWN (Outside Paywall) and Fake Jobs at Microsoft (LinkedIn)
half a dozen stories
Today in Techrights
Some of the latest articles
More Celebrations Ahead [original]
We expect nothing bumpy ahead, just more of the usual GNU/Linux links and lots more Microsoft layoffs
Wireshark 4.6.9 Updates Protocol and Capture File Support, Fixes More Bugs
Wireshark 4.6.9 open-source network protocol analyzer is now available for download with updated protocol and capture file support, as well as various bug and security fixes.
GNU/Linux Leftovers
Kube, SUSE, and Arch
Free, Libre, and Open Source Software Leftovers
FOSS and more
Audiocasts/Shows: LF "SOSS", "Kodsnack", and "Wonders of Web Weaving"
3 new shows
OpenSearch Uses 'Linux' Foundation for Slopwashing Its Image
Linux Foundation spam
VLC 3.0.24 Released with APV and Atrac3/Atrac9 Decoding, FFmpeg 8.1 Support
VLC 3.0.24 open-source media player is now available for download with an APV decoder, Atrac3/Atrac9 decoding, FFmpeg 8.1 support, support for CEA-708 closed captions in MP4, and more.
KDE Grapples With LLM Slop Problems, Bobby 51 Comes to GNOME
KDE and GNOME picks
Game Reviews and Ubisoft's Ban of GNU/Linux Users
gaming news
Canonical/Ubuntu: Snaps (OpenShot), Wiki Disposal, and Long-Term 15-Year Support Version of the Zephyr RTOS
3 stories
Web Browsers/Web Servers: Waterfox, Tor, Chromium, Firefox, and "Real" HTML
WWW related leftovers
Programming Leftovers
Development and flaws
Security Leftovers
Security and Microsoft TCO
Open Hardware/Modding: CODESYS, ESP32, Pi, and More
hardware leftovers
Red Hat: Valkey, Apache Kafka, Slop, and More
mostly from redhat.com
Applications: 88emu, VMware 1.0.1, Obscura, and Easy Effects for Linux
4 picks for today
Instructionals/Technical Posts for Today
aka today's howtos
CISA Issues Warnings Over Very Old (Previous Years) Bugs in Linux
borderline FUD
LLM Slop is Ruining Projects Dealing With Sony Consoles
several reports
Raspberry Pi Pushing Digital Restrictions (DRM) Schemes
3 picks
Games: JSAUX, Microsoft XBox Layoffs, and More
Microsoft and more
Microsoft Goes Through 'Death Spiral' of Shutdowns and Closures, Mass Layoffs Every Month [original]
This company is metastasising, first via GitHub, then LLM slop
NetBSD 10.2 released and more BSD news
BSD leftovers
NTFS-3G 2026.9.18 NTFS Driver for Linux Released with Security and Bug Fixes
NTFS-3G 2026.9.18 driver for handling NTFS partitions on Linux-based operating systems is now available for download with various security and bug fixes.
Tux Machines Moved to the UK Three Years Ago [original]
Men arrested in the US were trying to take of offline
Android Leftovers
Samsung Studio is a solid video editor, but this open source Android alternative is better
Fooyin 0.13.0 Released with Global Hotkeys, CD Playback & Ripping
Fooyin, the popular Foobar2000 alternative music player for Linux, released new 0.13.0 version today
Linux has a price, it's just not money
That's the whole business model of enterprise Linux outfits like Red Hat
7 vintage Linux features I want back – and why they still matter
If you've been around Linux long enough
My top 4 Omarchy alternatives for Linux users looking for a change
Whether you're interested in Arch Linux, Hyprland
I outgrew Ubuntu for a reason—immutable distros are the better first choice
Ubuntu got me through a decade of Linux use
GNU/Linux Rises to About 15% in Israel, Based on Clownflare Statistics [original]
increase in GNU/Linux usage (or user-agents that identify as such) in Israel
Best Free and Open Source Software
Only free and open source software is eligible for inclusion here
UmbraOS – NixOS-based distribution for cybersecurity learning
UmbraOS is a NixOS-based distribution aimed at people learning and experimenting with cybersecurity
NeOS – snapshot-based Arch Linux distribution
NeOS (Next Evolution Operating System) is an Arch Linux-based desktop distribution designed to combine Arch’s rolling software base with a more controlled update process
PeppermintOS Is Moving From Xorg to XLibre to Avoid Wayland
The lightweight distro will ship the XLibre display server in its upcoming Debian and Devuan ISO refreshes
Today in Techrights
Some of the latest articles