Tux Machines

Do you waddle the waddle?

Other Sites

LinuxGizmos.com

Alp Lab Unveils E1M Platform with Multi-vendor Embedded Roadmap

According to the announcement, the E1M is designed around a common hardware and software foundation for edge AI systems. A consistent footprint and pinout allow developers to choose processing platforms based on performance, power, or cost without redesigning the carrier board, helping shorten development cycles and evaluate multiple silicon vendors.

ICORE-3576Q38 SoM packs RK3576 AI processor into a 38 mm module

The ICORE-3576Q38 family is available in three variants. The standard ICORE-3576Q38 targets commercial embedded systems, while the ICORE-3576JQ38 and ICORE-3576MQ38 are designed for industrial use. All three variants share the same interfaces and feature set, with differences limited to CPU frequency and operating temperature range.

9to5Linux

9to5Linux Weekly Roundup: December 21st, 2025

I would like to thank everyone who sent us donations; your generosity is greatly appreciated. I also want to thank all of you for your continued support by commenting, liking, sharing, and boosting the articles, following us on social media, and, last but not least, sending us feedback.

GnuCash 5.14 Open-Source Accounting Software Adds Support for US Bonds

Highlights of GnuCash 5.14 include support for US Bonds (usbonds) on the New Finance::Quote module to get prices for series E, EE, or I bonds, a new Postponed column to the Scheduled Transactions list for postponing scheduled transaction instances, and the removal of the Bulgarian Lev (BGN) currency as it’s replaced by EUR from January 1st, 2026.

Ventoy 1.1.10 Bootable USB Creator Released with Support for AerynOS

Highlights of Ventoy 1.1.10 include support for the AerynOS distributions, support for the musl libc environment for Ventoy2Disk.sh, improved boot support for the EXT4 file system, improved Wayland support for the LinuxGUI program, improved Windows boot support in F2 mode, and improved boot support with Kylin Server V11.

Darktable 5.4 Open-Source RAW Image Editor Improves Camera Support

Coming more than eight months after Darktable 5.2.1, the Darktable 5.4 release adds base support for new cameras, including Canon EOS R1, Canon EOS R5 Mark II, Canon PowerShot D10 (DNG), Canon PowerShot S100V, Canon PowerShot S2 IS (DNG), Fujifilm FinePix HS33EXR, and Fujifilm X-E5 (compressed).

news

Microsoft Windows 11 Caches Exploitable Malware

posted by Roy Schestowitz on May 15, 2024

Fishtank PC builds

Reprinted with permission from Cybershow. Author: Helen Plews.

Figure 1: Tom's Hardware: Fishtank PC builds.

Malware is often thought of as a human interaction with a digital device that causes an infection such as a virus or worm. We assume a human used bad authentication, or the human clicked the bad link, the human downloaded the malware…

So if we have anti-virus and anti-phish educational campaigns we should be well protected right? What about the technical side of cybersecurity, where the hardware, network equipment, end device or software vulnerability is the cause?

This article will examine a case where an operating system is able to automatically open and store a phishing email attachment, leading to potential compromise. In this case Windows 11 has been caching attachments locally to provide synchronisation across devices with the Outlook Application. In many cases, it has cached exploitable malware. This is a growing issue brought to light by Windows 11 users and anti-virus providers, instead of the makers at Microsoft.

Dropper Investigation

I am a life-long gamer and from experimentation over the years, I know I have the best rig, a customisable gaming PC. It’s very nice hardware it looks stunning with rainbow glowing fans and it sounds like a mini jet engine, rendering most graphics on Ultra with a graphics card which is at most 2 years old. The only issue I have had with it is in the operating system, which of course for a big gamer is Windows 11 due to its age. After just two weeks of operation I was alerted to a dropper located in my Windows Appdata folder, it was not dropping any further viruses yet as it had been caught by my expensive AV - which is why it sounds like a jet engine due to the large use of CPU!!

Was it a false positive? Well I ran the offline scan myself as my machine took 8x longer to boot. It behaved as if rebooting after a major update. There were no updates carried out, which made me suspect something amiss.

The virus location was not new to me, it is an appdata folder present in Windows 10 and Windows 11 for Windows mail in particular it processes mail syncing across devices; the full path is:

C:\Users\’Username’\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\SO\

Now I have had viruses popping up here before, in fact it has been an ongoing problem since I adopted the Windows 11 operating system (OS) in 2022 on the household laptops. Since then, both of my son’s laptops have alerted me to droppers and Trojans in the same Appdata folder. I initially assumed my children were not so good with their cybersecurity (being aged 5 and 9 that makes sense). Maybe they had clicked an email notification. Maybe they had downloaded some Trojan in the style of a game from a requested and shoddy gaming store all parents know about, stealthy and all whilst under supervision. That was until my brand new gaming rig got one.

Examining the attack timeline of my gaming rig in detail showed that a phish had been ‘clicked’ from my Hotmail account which was logged in on my Outlook App, running in the background processes (not running in my taskbar) whilst I played some epic title the night before. This ‘click’ put an infected PDF invoice on my PC, and on boot the next day activated the dropper, slowing the machine right down - which gave me a clue.

Now let's be clear about how Microsoft works, as I understand it, and why this is a gripe serious enough to warrant its own blog post.

You must sign in online to a Microsoft account to access the PC at all times, then it creates session keys for all applications that come installed as standard with the OS. So, unless you take some drastic measures I will discuss in a moment, you will undoubtedly be running sessions of Windows apps in the background; Outlook, OneDrive, Teams, Xbox, Photos, Office, Store, the list is quite extensive.

Moving on, I look for the phish email I had. According to my AV "clicked on" log, I located the suspicious subject of the email. It was something akin to;

AMAZON ACCOUNT ###U$IIHknDBWON38383y4y29~~~

Now, you do not need to be a cybersecurity expert to tell that is a phish from the subject which was located using the now foreground Outlook app. And as expected, it was unread. It showed me that within a few minutes of receiving the unread email, the attached PDF invoice was added to the Windows Communication Appdata folder, which led to the dropper found by the offline scan.

It seemed that Outlook App was saving unread attachments to the appdata folder where the virus was located. Some of the located viruses over the past two years were found on multiple devices that used the same MS credentials which unless stated otherwise, auto sync application data. That is exactly what the

microsoft.windowscommunicationsapps_8wekyb3d8bbwe

folder is for. It contains both the application data for Windows apps like Outlook to run and sync as well as data obtained in the process. I synced between my children's laptops as my account was the administrator for the network, it kept them safer online. Or so I thought.

Vulnerability Research

So I start down the usual process of researching the vulnerability to find a permanent mitigation. I find nothing at first, no CVE, no reports. I do find some details on the MS community website like this one from "2020 Trojan Found and Deleted"… but it Returns (Trojan: HTML/Phish.AB!MSR) . It is here I see the same problem and I see a response from an expert.

“The trojan is an email attachment synced to your PC. Do you have some Hotmail or Microsoft email setup in an email client applications like Outlook?” - Independent Expert, MS Community, 2020

So I search all around this topic and I cannot find anything from Microsoft about this issue right away, but I do find many victims. Anti-Virus companies, affected users and experts alike are all drawing attention to this problem. Eventually, thanks to Reddit I find a similar experience from a commentor who managed to find the reported exploit listed by Microsoft. You can find many more threads on the issue on Reddit with a search.

“Looking into the report we have a "Exploit:O97M/CVE-2017-11882.AZA!MTB" match, which doesn't seem to be that ominous since it requires the file to be executed on a non-updated Office/WordPad, still it ain't something I'd like to find lying around because the app found it was a good thing to download it, without my consent.” - JVMTG, Reddit, 2023

It is a known software error marked as severe on their own security intelligence website, with 24 exploits under the O97M CVE. I’d like to say I have more details from Microsoft but I do not, instead they offer very little default cybersecurity steps, such as "remain up to date and don’t click a phish".

This does seem rather severe. It locally caches attachments from emails including those which have not been opened to the windowscommunicationsapps folder from the Outlook App. It will then auto sync the data in the folder to all devices using the same credentials in their Outlook App on their phones, laptops, desktops, anywhere the Outlook App runs.

The only step missing for a full compromise is that infected files are auto-run… a feature I feel sure Microsoft are working on at this exact moment!

Attacks are becoming more complex, in 2022 they were able to add the dropper, which very slowly downloaded a fairly rubbish Trojan, which was easily removed. Recently there were 74 password protected files and multiple Trojans appearing as game applications in the same appdata folder. These were located only weeks after a fresh OS install and could not be explained by known activities on the machine or entirely resolved by AV due to the encryption of the folders they were located in.

Impact

Take a moment to think about how many commercial users of the Outlook application have auto-sync enabled in daily use. All those using Office 365 who sync between devices on their smartphone, personal devices and company equipment, or amongst family member's tablets and laptops. You should be concerned. And then get mad as hell, because it seems Microsoft have created their own quite special service for propagating malware, one that's been ongoing since at least 2020.

I have wasted countless hours re-installing OS’s, searching files, reading reports and researching this issue to find my only salvation in Reddit. Reddit of all places! This looks like something Microsoft rather wanted to sweep under the rug.

If you sync with Outlook App between devices with the same MS account, you are vulnerable to this malware propagation. Microsoft insist users take advantage of auto-synced features across devices and use this as a clear marketing tool especially for commercial settings. It seems my trust in this feature was misplaced.

Mitigation And Loss of Trust

Some will say that this is "just a feature" of sync. I disagree because like so many Microsoft processes it feels out of control. It does not just synchonise expected user data. It inappropriately populates and copies undocumented files into system folders and, without any knowledge or intervention from the user, replicates them across devices.

The mitigation is you must live without synchronisation in Microsoft applications. So far it has worked 100%. Turning off sync across applications does work. This can be done during an OS install by refusing all sync options when prompted. You must also make sure it is off in the account settings for the user. This can be done from the settings panel when logged on to Windows. There are many guides available like this one from Process.st. Even with sync off, you can still access email and other services using the web applications, which will sync files and emails but will not store these to the local machine.

If like myself, you have lost trust in the applications themselves, removing windows apps entirely may be more fitting, this allows the folder

microsoft.windowscommunicationsapps_8wekyb3d8bbwe

to be deleted and does not appear, like a lurking background threat at a later date just in case you change your mind. My gaming rig has only one MS app remaining, Xbox and that is the way it will stay until the situation is openly discussed by MS and the vulnerability resolved. No more Appdata Phishes please.

In summary, no amount of phishing training will prevent a bad design in the operating system. Caching malware infected attachments to system folders and replicating them is bad design in my opinion. In this case, the operating system has been phished, not the human.

Other Recent Tux Machines' Posts

In the Name of Love [original]
The Web is filled with hate and vitriol
Calm Week Ahead, Looking Forward to 2026 [original]
This year this site added over 10,000 new pages
XBox is Dead, What Next? [original]
The future of gaming looks increasingly bright for "Linux", not "Windows"
Parrot OS Switches to KDE Plasma Desktop
Yet another distro is making the move to the KDE Plasma desktop
Darktable 5.4 Open-Source RAW Image Editor Improves Camera Support
Darktable 5.4 open-source RAW image editor is now available for download with support for new cameras, new noise profiles, and bug fixes.
Ventoy 1.1.10 Bootable USB Creator Released with Support for AerynOS
Ventoy 1.1.10 open-source bootable USB solution is now available for download with support for AerynOS and other improvements.
New Beta of Linux Mint
Linux Mint 22.3 “Zena”
Georgia: GNU/Linux Rises to Record High [original]
like in Russia
GNU/Linux Climbs to All-Time High in Saudi Arabia [original]
Microsoft is measured at 13.8% there this month, based on Web usage
Tux Machines Works With Web Browsers From 30 Years Ago [original]
Also, oldweb.today seems not to be working today
 
GNU/Linux Leftovers
GNOME, GNU/Linux, and more
Free, Libre, and Open Source Software and Standards Leftovers
FOSS and more
Programming Leftovers
Development related picks
Hardware and Retro: ZuluSCSI, Raspberry Pi, and More
hardware picks
Debian’s git transition and UCS (Univention Corporate Server) 5.2-4 released (based on Debian)
Debian news
Grml - new stable release 2025.12 available
code-named ‘Postwurfsendung’
Today in Techrights
Some of the latest articles
9to5Linux Weekly Roundup: December 21st, 2025
The 271st installment of the 9to5Linux Weekly Roundup is here for the week ending on December 21st, 2025.
GnuCash 5.14 Open-Source Accounting Software Adds Support for US Bonds
GnuCash 5.14 has been released today as the latest stable version of this open-source, free, and cross-platform double-entry accounting software for GNU/Linux, macOS, and Windows systems.
MPV 0.41 Open-Source Video Player Released with Improved Wayland Support
MPV 0.41, an open-source and free media player that supports a wide range of media file formats, is now available for download with new features and improvements.
GNU/Linux and BSD Leftovers
mostly GNU/Linux, as usual
Educational and GNOME Events
3 new ones
Programming Leftovers
Development centric news
KDE: KDE PIM Sprint 2025 in Paris and Why KMyMoney Lacks Old Binaries
KDE news
Web Servers and Chromium/Chrome Issues
WWW related links
Open Hardware/Modding and Mobile: Arduino, Raspberry Pi, and More
hardware oriented news
GNU/Linux On a Floppy Disk and Azulle Access Arm is a Fanless Linux PC Stick
2 new stories
Applications: jdSystemMonitor, Introducing Open Forms, and Release of GDB 17.1
Software leftovers
today's howtos
many howtos
Graphics Stack: Big GPUs, FPS Boosts, NVIDIA, and RDNA
Graphics news
Over Half A Million Windows Users Are Switching To Linux
Microsoft's loss is Linux's gain
Games: Steam Deck, Necesse, and More
gaming picks
Debian: Immutable Debian, MiniDebConf, EasyOS 7.1, and Sparky 2025.12
Debian news
Android Leftovers
I dug out my old Android tablet, and it replaced 3 expensive gadgets
MIT and Apache 2.0 Lead Open Source Licensing in 2025
According to the Open Source Initiative
Immich 2.4 Released With Command Palette and UI Refinements
Immich 2.4, a self-hosted photo and video management platform
Incus 6.20 Container & Virtual Machine Manager Released
Incus 6.20 delivers new clustering, storage, and VM enhancements
The 10 best Ubuntu default wallpapers of all time, ranked
Canonical has given cute animal-themed codenames to Ubuntu releases since the earliest versions of the operating system
Sparky 2025.12 Special Editions
There are new iso images of Sparky 2025.12
Free and Open Source Software
This is free and open source software
ICORE-3576Q38 SoM packs RK3576 AI processor into a 38 mm module
Software support includes Android 14, Linux distributions, Buildroot, and RT-Linux configurations, according to T-Firefly’s wiki
This Week in Plasma: ambient light sensor support
This week many KDE contributors wound down their activities in preparation for some well-deserved rest
Alp Lab Unveils E1M Platform with Multi-vendor Embedded Roadmap
The SDK supports bare-metal, RTOS, and Linux-based systems
Today in Techrights
Some of the latest articles
Security Leftovers
Security related picks
Free, Libre, and Open Source Software and Programming Leftovers
FOSS and coding
today's leftovers
mostly GNU/Linux stuff
Operating Systems: GNU/Linux Distributions, FreeBSD, Tumbleweed, Red Hat Going Astray ("AI" Nonsense)
OS news
Open Hardware/Modding: Homelab, Raspberry Pi, and More
Hardware leftovers
Ubuntu 26.04 LTS to arrive in April with Linux 6.20 kernel
Plans for the next LTS
Kdenlive 25.12.0 added New Welcome Dialog & Widget Docking System
The 25.12.0 version of Kdenlive video editor is finally available to download
Docker Licensing / Legal: Enterprise-Grade Hardened Image Now "Apache License 2.0"
Licence changes
GNOME Foundation Update and Roundup of This Week in GNOME
GNOME news
Reflecting on a Good Year [original]
2025 was a good year for us overall because we probably hit a record high for number of new pages and we were generally happy
Distributions and Operating Systems: BSD, GNU/Linux, HaikuOS and More
today's leftovers
Free, Libre, and Open Source Software, Sharing, Also Standards
FOSS and more
Programming Leftovers
Development related picks
Games: SteamOS, Game Engines, and Godot
gaming themed posts
Red Hat and Fedora Leftovers
mostly redhat.com
Mozilla: Politics and Firefox Nightly
latest from Mozilla
The FreeBSD Foundation Taking Stock of 2025
several new posts
today's howtos
some more stories for today, howtos for now
Kodi 22 “Piers” Preview Shows FFmpeg 8 Upgrade and New Format Support
Kodi 22 “Piers” is taking shape with FFmpeg 8, HEIC support
Firefox and Mozilla Commit Suicide With Slop
really bad
Fwupd 2.0.19 Released With New CRC Tools and udev Support
Fwupd 2.0.19 introduces new CRC calculation tools
Copying the Competition [original]
not a great idea
OpenZFS 2.4 Extends Linux Kernel Support to 6.18 and Supports FreeBSD 14–16
OpenZFS 2.4 extends Linux kernel compatibility up to 6.18 while supporting FreeBSD 14, 15, and 16
Android Leftovers
Your Pixel just got a major update. Here’s how to download Android 16 QPR3 Beta 1 right now
Debian Gets Its Own PPA-Like System as Debusine Repositories Launch
Debian introduces Debusine repositories
Mageia 10 Development Update: Planning and Key Highlights
On December 1st, the Mageia development team met to discuss the progress of Mageia 10
pearOS is a Linux that falls rather close to the Apple tree
Revived distro returns on Arch with KDE Plasma, global menus
We can't advocate for freedom without your help
It's getting harder to live in freedom and it shouldn't have to be
Free and Open Source Software
This is free and open source software
How I assembled my own Plasma desktop
I also want to use Linux on this box, through virtualization
Today in Techrights
Some of the latest articles
Proprietary Software, Qt, and Systemd on Linux
not so free after all
Security Leftovers
Security picks for today
GNU/Linux Leftovers
3 more stories
Open Hardware, Retro, Modding, and Linux
Hardware picks
PostgreSQL: pg_llm_helper 0.1.0 and tds_fdw
PostgreSQL news
'$100 Steam Machine' with Bazzite (GNU/Linux) and More Gaming News
Games in the news
LibreOffice 25.8.4 Released, Czech translation of LibreOffice Draw Guide 25.8
LibreOffice 25.8.4 released, more news from the project
Denmark Begins its Exit from Microsoft — and This is Just the Beginning
The move is part of a government-wide effort to reduce dependency on Abusive Monopolist Microsoft software
Armbian Team Launches New Official Imager for Flashing Armbian OS
The Armbian team has launched a new official imager that simplifies flashing Armbian OS on single-board computers across macOS