Tux Machines

Do you waddle the waddle?

Other Sites

Internet Society

Advancing a Connected Future for Indigenous Communities

For Indigenous communities, meaningful connectivity can strengthen self-determination, expand access to education and economic opportunities, and help preserve languages, cultures, and knowledge. Yet many remain among the least connected communities in the world, often overlooked by traditional investment, infrastructure, and service models.

9to5Linux

Linux Mint Devs Change the Way Linux Kernels Are Tracked

Until now, Linux Mint users were able to manage kernels from within the Update Manager tool. When a new kernel was available, you could fire up Update Manager, go to the View menu, and select Linux kernels. There, you could choose which kernel you want to install or remove.

SparkyLinux 8.4 Released with Support for Linux Kernel 7.1, Debian 13.6 Base

Based on and fully compatible with the Debian 13.6 “Trixie” repositories, SparkyLinux 8.4 ships with Linux 6.12.101 LTS as the default kernel on the live system, as well as support for Linux 7.1.8 and 6.18.43 LTS kernels, Linux 6.18.39 LTS for ARM64 systems, and Linux 6.12.102 LTS for 32-bit systems.

Linux Mint 22.3 HWE ISOs Now Available for Download with Linux Kernel 7.0

In April 2026, the Linux Mint project announced that they have decided to adopt a longer development cycle for future Linux Mint releases, starting with the upcoming Linux Mint 23 release, planned for Christmas 2026, so that they can focus more on fixing bugs than shipping newer features.

9to5Linux Weekly Roundup: August 9th, 2026

I want to thank everyone who sent us donations; your generosity is greatly appreciated. I also want to thank all of you for your continued support by commenting, liking, sharing, and boosting the articles, following us on social media, and, last but not least, sending us feedback.

GNOME Disks Has Finally Been Ported to GTK4 and LibAdwaita – First Look

It took a few years, but GNOME Disks has been rebuilt from the ground up on GTK4 and LibAdwaita, moving away from the old GTK3/libhandy stack that was used until version 46. As one can expect, the GTK4/LibAdwaita port brings Disks in line with the rest of the standard GNOME apps, offering a modern user experience in 2026.

Ubuntu 24.04 LTS Users Get Linux 7.0 HWE Kernel Ahead of Ubuntu 24.04.5 LTS

Released in April 2024, Ubuntu 24.04 LTS is a long-term supported series that will receive software updates and security patches for at least 5 years, until June 2029, as well as regular point releases every six months. The next, and probably the last, Noble Numbat point release will be Ubuntu 24.04.5 LTS.

DebConf27 Debian Developers Conference to Be Held in Asahikawa, Japan

Asahikawa is a city in Hokkaido, the northernmost of Japan’s main islands, which is known for its volcanoes, natural hot springs (onsen), and ski areas. As tradition follows, the local organizers in Japan will start the conference activities with DebCamp with a focus on individual and teamwork towards improving the Debian distro.

CachyOS ISO Release for August 2026 Improves the Installer, Desktop Profiles

Still powered by the Linux 6.18 LTS kernel series, the CachyOS ISO snapshot for August 2026 ships with the latest KDE Plasma 6.7.4 desktop environment, which is accompanied by the KDE Frameworks 6.28 and KDE Gear 26.04.3 software suites, all compiled against Qt 6.11.1.

LinuxGizmos.com

Challenger+ RP2350 NB-IoT Enables LTE Cat NB2 and GNSS for Embedded IoT

ILABS is offering the Challenger+ RP2350 NB-IoT, a compact development board combining Raspberry Pi’s RP2350 microcontroller with STMicroelectronics’ ST87M01-1301 cellular module. The board targets low-power IoT applications requiring LTE Cat NB2 connectivity, GNSS positioning, and long battery life.

Radxa Broadens rCore Series with Snapdragon and Dragonwing AI SoMs

Radxa has revealed two Qualcomm-based system-on-modules aimed at edge AI, multimedia, robotics, and industrial applications. The new rCore-Q8280 uses the Snapdragon 8cx Gen 3 with 29+ TOPS of AI performance, while the smaller rCore-Q6490 is based on the Dragonwing QCS6490 and provides up to 12 Dense TOPS.

ESP32 Bit Pirate 1.7 Gains LoRa, Meshtastic, and Browser-Based BPIO2 Control

ESP32 Bit Pirate has released version 1.7 of its ESP32-S3-based hardware debugging platform, adding LoRa support for SX1262 transceivers, a Meshtastic analysis shell, a new BPIO2 USB adapter, and support for additional boards. The open-source project continues to expand its browser-based tools for hardware debugging, programming, and experimentation.

news

Microsoft Windows 11 Caches Exploitable Malware

posted by Roy Schestowitz on May 15, 2024

Fishtank PC builds

Reprinted with permission from Cybershow. Author: Helen Plews.

Figure 1: Tom's Hardware: Fishtank PC builds.

Malware is often thought of as a human interaction with a digital device that causes an infection such as a virus or worm. We assume a human used bad authentication, or the human clicked the bad link, the human downloaded the malware…

So if we have anti-virus and anti-phish educational campaigns we should be well protected right? What about the technical side of cybersecurity, where the hardware, network equipment, end device or software vulnerability is the cause?

This article will examine a case where an operating system is able to automatically open and store a phishing email attachment, leading to potential compromise. In this case Windows 11 has been caching attachments locally to provide synchronisation across devices with the Outlook Application. In many cases, it has cached exploitable malware. This is a growing issue brought to light by Windows 11 users and anti-virus providers, instead of the makers at Microsoft.

Dropper Investigation

I am a life-long gamer and from experimentation over the years, I know I have the best rig, a customisable gaming PC. It’s very nice hardware it looks stunning with rainbow glowing fans and it sounds like a mini jet engine, rendering most graphics on Ultra with a graphics card which is at most 2 years old. The only issue I have had with it is in the operating system, which of course for a big gamer is Windows 11 due to its age. After just two weeks of operation I was alerted to a dropper located in my Windows Appdata folder, it was not dropping any further viruses yet as it had been caught by my expensive AV - which is why it sounds like a jet engine due to the large use of CPU!!

Was it a false positive? Well I ran the offline scan myself as my machine took 8x longer to boot. It behaved as if rebooting after a major update. There were no updates carried out, which made me suspect something amiss.

The virus location was not new to me, it is an appdata folder present in Windows 10 and Windows 11 for Windows mail in particular it processes mail syncing across devices; the full path is:

C:\Users\’Username’\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\SO\

Now I have had viruses popping up here before, in fact it has been an ongoing problem since I adopted the Windows 11 operating system (OS) in 2022 on the household laptops. Since then, both of my son’s laptops have alerted me to droppers and Trojans in the same Appdata folder. I initially assumed my children were not so good with their cybersecurity (being aged 5 and 9 that makes sense). Maybe they had clicked an email notification. Maybe they had downloaded some Trojan in the style of a game from a requested and shoddy gaming store all parents know about, stealthy and all whilst under supervision. That was until my brand new gaming rig got one.

Examining the attack timeline of my gaming rig in detail showed that a phish had been ‘clicked’ from my Hotmail account which was logged in on my Outlook App, running in the background processes (not running in my taskbar) whilst I played some epic title the night before. This ‘click’ put an infected PDF invoice on my PC, and on boot the next day activated the dropper, slowing the machine right down - which gave me a clue.

Now let's be clear about how Microsoft works, as I understand it, and why this is a gripe serious enough to warrant its own blog post.

You must sign in online to a Microsoft account to access the PC at all times, then it creates session keys for all applications that come installed as standard with the OS. So, unless you take some drastic measures I will discuss in a moment, you will undoubtedly be running sessions of Windows apps in the background; Outlook, OneDrive, Teams, Xbox, Photos, Office, Store, the list is quite extensive.

Moving on, I look for the phish email I had. According to my AV "clicked on" log, I located the suspicious subject of the email. It was something akin to;

AMAZON ACCOUNT ###U$IIHknDBWON38383y4y29~~~

Now, you do not need to be a cybersecurity expert to tell that is a phish from the subject which was located using the now foreground Outlook app. And as expected, it was unread. It showed me that within a few minutes of receiving the unread email, the attached PDF invoice was added to the Windows Communication Appdata folder, which led to the dropper found by the offline scan.

It seemed that Outlook App was saving unread attachments to the appdata folder where the virus was located. Some of the located viruses over the past two years were found on multiple devices that used the same MS credentials which unless stated otherwise, auto sync application data. That is exactly what the

microsoft.windowscommunicationsapps_8wekyb3d8bbwe

folder is for. It contains both the application data for Windows apps like Outlook to run and sync as well as data obtained in the process. I synced between my children's laptops as my account was the administrator for the network, it kept them safer online. Or so I thought.

Vulnerability Research

So I start down the usual process of researching the vulnerability to find a permanent mitigation. I find nothing at first, no CVE, no reports. I do find some details on the MS community website like this one from "2020 Trojan Found and Deleted"… but it Returns (Trojan: HTML/Phish.AB!MSR) . It is here I see the same problem and I see a response from an expert.

“The trojan is an email attachment synced to your PC. Do you have some Hotmail or Microsoft email setup in an email client applications like Outlook?” - Independent Expert, MS Community, 2020

So I search all around this topic and I cannot find anything from Microsoft about this issue right away, but I do find many victims. Anti-Virus companies, affected users and experts alike are all drawing attention to this problem. Eventually, thanks to Reddit I find a similar experience from a commentor who managed to find the reported exploit listed by Microsoft. You can find many more threads on the issue on Reddit with a search.

“Looking into the report we have a "Exploit:O97M/CVE-2017-11882.AZA!MTB" match, which doesn't seem to be that ominous since it requires the file to be executed on a non-updated Office/WordPad, still it ain't something I'd like to find lying around because the app found it was a good thing to download it, without my consent.” - JVMTG, Reddit, 2023

It is a known software error marked as severe on their own security intelligence website, with 24 exploits under the O97M CVE. I’d like to say I have more details from Microsoft but I do not, instead they offer very little default cybersecurity steps, such as "remain up to date and don’t click a phish".

This does seem rather severe. It locally caches attachments from emails including those which have not been opened to the windowscommunicationsapps folder from the Outlook App. It will then auto sync the data in the folder to all devices using the same credentials in their Outlook App on their phones, laptops, desktops, anywhere the Outlook App runs.

The only step missing for a full compromise is that infected files are auto-run… a feature I feel sure Microsoft are working on at this exact moment!

Attacks are becoming more complex, in 2022 they were able to add the dropper, which very slowly downloaded a fairly rubbish Trojan, which was easily removed. Recently there were 74 password protected files and multiple Trojans appearing as game applications in the same appdata folder. These were located only weeks after a fresh OS install and could not be explained by known activities on the machine or entirely resolved by AV due to the encryption of the folders they were located in.

Impact

Take a moment to think about how many commercial users of the Outlook application have auto-sync enabled in daily use. All those using Office 365 who sync between devices on their smartphone, personal devices and company equipment, or amongst family member's tablets and laptops. You should be concerned. And then get mad as hell, because it seems Microsoft have created their own quite special service for propagating malware, one that's been ongoing since at least 2020.

I have wasted countless hours re-installing OS’s, searching files, reading reports and researching this issue to find my only salvation in Reddit. Reddit of all places! This looks like something Microsoft rather wanted to sweep under the rug.

If you sync with Outlook App between devices with the same MS account, you are vulnerable to this malware propagation. Microsoft insist users take advantage of auto-synced features across devices and use this as a clear marketing tool especially for commercial settings. It seems my trust in this feature was misplaced.

Mitigation And Loss of Trust

Some will say that this is "just a feature" of sync. I disagree because like so many Microsoft processes it feels out of control. It does not just synchonise expected user data. It inappropriately populates and copies undocumented files into system folders and, without any knowledge or intervention from the user, replicates them across devices.

The mitigation is you must live without synchronisation in Microsoft applications. So far it has worked 100%. Turning off sync across applications does work. This can be done during an OS install by refusing all sync options when prompted. You must also make sure it is off in the account settings for the user. This can be done from the settings panel when logged on to Windows. There are many guides available like this one from Process.st. Even with sync off, you can still access email and other services using the web applications, which will sync files and emails but will not store these to the local machine.

If like myself, you have lost trust in the applications themselves, removing windows apps entirely may be more fitting, this allows the folder

microsoft.windowscommunicationsapps_8wekyb3d8bbwe

to be deleted and does not appear, like a lurking background threat at a later date just in case you change your mind. My gaming rig has only one MS app remaining, Xbox and that is the way it will stay until the situation is openly discussed by MS and the vulnerability resolved. No more Appdata Phishes please.

In summary, no amount of phishing training will prevent a bad design in the operating system. Caching malware infected attachments to system folders and replicating them is bad design in my opinion. In this case, the operating system has been phished, not the human.

Other Recent Tux Machines' Posts

Four Weeks After the Hearing at the High Court [original]
Garrett's lawyer and barrister only spent a few years in this occupation
Resisting Misogyny [original]
We stand with (and for) equality, justice, and freedom
Linux Mint 22.3 HWE ISOs Now Available for Download with Linux Kernel 7.0
Linux Mint 22.3 HWE ISO images are now available for download powered by the Linux 7.0 kernel series from Ubuntu 24.04.5 LTS.
Linux Mint Devs Change the Way Linux Kernels Are Tracked
The Linux Mint developers have re-implemented kernel management within the System Administration tool and are changing how kernels are being tracked.
Clownflare Says 7.6% of Web Traffic in the United Kingdom Comes From GNU/Linux [original]
GNU/Linux rose to 8% and we can see the difference because "Linux" is widely heard of
GNU/Linux Market Share Quickly Catching Up With Vista 11 [original]
If this data is more or less accurate, it's time for panic at Microsoft
 
Android Leftovers
I finally stopped missing Android notifications by changing one hidden setting
How I turned my old Fire Tablet into a portable Linux terminal
Transforming an old Fire Tablet into a Linux Terminal is a fun weekend project for modding and home lab enthusiasts
I finally switched Linux desktops, and COSMIC is the one to blame
Ever since my first experience with Arch Linux last year, my preference when it comes to Linux desktops has been KDE
If I were starting over with Linux, here's why I'd choose Fedora
For most of my computing life, Debian and Ubuntu have been my go-to Linux distros
Sparky 8.4
There is the fourth update of Sparky 8 – 8.4 available to download
Free and Open Source Software
This is free and open source software
Zyphor OS – Linux distribution
Zyphor OS is a Debian and Kali-based Linux distribution focused on simplicity, performance, and learning
Today in Techrights
Some of the latest articles
Thank You, Rianne [original]
Saying thank you to people we love isn't hard if (or when) we truly love them
SparkyLinux 8.4 Released with Support for Linux Kernel 7.1, Debian 13.6 Base
SparkyLinux 8.4 distribution is now available for download with support for Linux kernel 7.1 and Debian 13.6 “Trixie” base. Here’s what’s new!
Paul Buetow's Uptime Records [original]
Keeping computers live for a long time depends on a good power grid and other factors too, not just sysadmin skills
Clownflare Sees a Lot of GNU/Linux in China, Unlike statCounter [original]
Clownflare data sets are vastly bigger
Singapore: GNU/Linux Reaches 9% This Month [original]
There are many other countries that show a similar upward trend
Reproducible Builds in July 2026 and Critical Linux SCTP Flaw
security leftovers
GNU/Linux and BSD Leftovers
mostly GNU/Linux, some games, and more
Applications: FIGlet, Calibre, Bottles, and Weather
some software leftovers
Free Software, Education, and Standards
Free, Libre, and Open Source Software and more
Programming Leftovers
Development related views and news
Content Management Systems (CMS) / Static Site Generators (SSG) and "Enjoying Multiple Blog Platforms"
CMS and more
Linux Devices and Open Hardware/Modding: Raspberry Pi, ESP32, and More
hardware picks
today's howtos
4 only for today
FreeBSD 14.5-BETA1 Now Available
The first beta build of the 14.5-RELEASE release cycle is now available
Linux 7.2-rc7
I can't say that I'm exactly thrilled about the size of this all
Jasem's Ekosphere: KStars 3.8.4 Released
KStars v3.8.4 is released on 2026.08.09
9to5Linux Weekly Roundup: August 9th, 2026
The 304th installment of the 9to5Linux Weekly Roundup is here for the week ending August 9th, 2026.
I finally found the Linux distro I'd recommend to almost anyone
Dabbling with different Linux distributions is a fun hobby and something I've been doing for a while
Linux finally gave me back the joy of tinkering that Windows killed
The good news is, Linux has no signs of getting boring any time soon
I tried 5 Linux distros in a week to find one that "just works"
I spent time with five of the most popular desktop Linux distros: Zorin OS, Linux Mint, Fedora KDE, EndeavourOS, and Ubuntu
Free and Open Source Software
This is free and open source software
Review: Battle of the Children of Void
Over the past few years the number of distributions based on Void has risen quickly
Stable kernels: Linux 7.1.8, Linux 6.18.44, Linux 6.12.103, and Linux 6.6.151
I'm announcing the release of the 7.1.8 kernel
Blogs Are the Future, RSS (or Atom) Feeds Are "The Plumbing" [original]
why RSS feeds are so good
GNOME Disks Has Finally Been Ported to GTK4 and LibAdwaita – First Look
The GNOME Disks utility has finally been ported to GTK4 and LibAdwaita for a modern user experience, along with plenty of new features and enhancements.
GNU/Linux in Argentina: Doubling in Two Years [original]
adoption of GNU/Linux seems to have doubled in Argentina
GNU/Linux Measured at 8.95% on Desktops and Laptops [original]
So the estimates are being "corrected" upwards, not downwards
Ubuntu 24.04 LTS Users Get Linux 7.0 HWE Kernel Ahead of Ubuntu 24.04.5 LTS
Ubuntu 24.04 LTS (Noble Numbat) users are now receiving the Linux 7.0 kernel upgrade from Ubuntu 26.04 LTS (Resolute Raccoon) ahead of the Ubuntu 24.04.5 LTS point release.
Today in Techrights
Some of the latest articles
DebConf27 Debian Developers Conference to Be Held in Asahikawa, Japan
The DebConf27 Debian conference will be held from September 5th to September 11th, 2027, in Asahikawa, Hokkaido, Japan. Here’s how to attend and what you need to know.
CachyOS ISO Release for August 2026 Improves the Installer, Desktop Profiles
The CachyOS ISO snapshot for August 2026 is now available for download with Linux 6.18 LTS and Linux 7.1 kernels, 1KDE Plasma 6.7.4, an improved installer, and more.
GNU/Linux and BSD Leftovers
mostly GNU/Linux
Web Browsers and Feed Readers: Orion, Opera, and RSS Still Powerful
WWW and browsing, syndicating
Games: Steam, SteamOS, and More
gaming leftovers
today's howtos
Instructionals/Technical and CLI stuff
Audiocasts/Shows: Going Linux and Linux Saloon
2 new episodes
Wine 11.15 Released
The Wine 11.15 development release is out for the Windows to Linux compatibility layer to help run more applications and games
Fedora Promotes Slop, GNU/Linux On Mobile, and Who Should Pay For Source Code Availability?
4 recent picks
Programming Leftovers
Development picks
Less Personal Blogging Here [original]
We'll try to keep this site focused only on BSD and GNU/Linux
2026 Is Not the Year of the GNU/Linux Desktop (or Laptop) [original]
What changed isn't the readiness of GNU/Linux for the world but the world's readiness for Free software
Android Leftovers
I rely on these Android Auto safety features way more than the new speedometer
Free and Open Source Software
This is free and open source software
Planet KDE: About time…
Another missing Oxygen icon, this time KTimer
Upgrading the Static Site Generator (SSG) [original]
We actually implemented those months ago, but they need testing before being deployed to the live systems
Free Software is on the Ballot in Clacton [original]
a lot of media attention is devoted to Clacton's politics this month
Data Points on GNU/Linux Growth [original]
real traffic more than doubled in recent years
The Company Emptied His Lab. They Called Him a Thief. He Cost Them a Million Dollars.
They picked his birthday to tear up the agreement. For the next two years, he decided to take his revenge alone.
Today in Techrights
Some of the latest articles