Tux Machines

Do you waddle the waddle?

Other Sites

schestowitz.com

This Tank Is Not for Drinking

But birds don’t care

Casualty of Dead Media: The Climate

Bad for the planet

BBC on Stockpiling for Emergencies

This has become more mainstream

When I Was a Young Lad (24 Years Ago)

It was simple at the start

Focusing on Bigger Tasks

Focus needs time, not bells

Working in Law Firms for (Almost) Minimum Wage

Seems wrong

Reform UK Can be Shut Down (as a Business), But UK Government Enforcement Needed

Seriously

Health Before Optics

Dishwashing liquid

Covering Abuse and Lawfare Twice Per Day

The public must know, the law needs to be reformed

Feels Like Autumn, Even Winter

Change of plans

9to5Linux

Mozilla Firefox 157 Is Now Available for Download with Brand-New Design

Highlights of Firefox 157 include the brand-new design that we previewed in Firefox Nightly back in July. The new theme is called Nova and promises to make the popular open-source web browser feel cleaner, faster, adaptable, and warmer, according to Mozilla.

Flatpak 1.18.4 Linux App Sandboxing Framework Fixes Security Issues

Coming only a week after Flatpak 1.18.3, the Flatpak 1.18.4 release is here to address several security vulnerabilities, including CVE-2026-97024 to prevent privileged overwrite of arbitrary files with an empty file or a symlink to /run/host/monitor/resolv.conf when a malicious application is installed.

OpenShot 4.0.1 Video Editor Released with Timeline and Zoom Improvements

Coming almost a month after OpenShot 4.0, the OpenShot 4.0.1 release introduces official Snap support on Linux systems that use Ubuntu’s Snap package format via the Snap Store, and an updated Razor tool that now lets you preview the frame at a cut, snap to timeline targets, and remove unwanted footage while closing the gap.

Shotcut 26.9 Video Editor Improves the VA-API HEVC Hardware Encoder on Linux

Shotcut 26.9 is here almost two months after Shotcut 26.7 with new features like Automatic Ducking for audio, volume control, and an audio level meter/indicator for timeline track headers, and a new Adjustment Clip option in Timeline > Generate to create a dummy video clip to apply its filters to the composite of all video tracks below it.

9to5Linux Weekly Roundup: September 27th, 2026

I want to thank everyone who sent us donations; your generosity is greatly appreciated. I also want to thank all of you for your continued support by commenting, liking, sharing, and boosting the articles, following us on social media, and, last but not least, sending us feedback.

Budgie 10.10.3 Desktop Environment Introduces Free Placement of Desktop Icons

Coming more than six months after Budgie 10.10.2, the Budgie 10.10.3 release introduces the ability to place desktop icons wherever you want on the desktop, brings back the Keyboard Layout applet, adds the ability to choose the primary monitor, and improves the Labwc bridge integration to listen to budgie-daemon.

GNOME 50.5 Improves Multi-Monitor Support, HDR Support, and More

Coming one and a half months after GNOME 50.4, the GNOME 50.5 release improves the opening of windows created via the new-window action to appear on the correct workspace, improves keyboard navigation on the unlock dialog, improves switching of workspaces with direct scanout, and adds support for tracking magnifier mouse position without polling.

PeaZip 11.3 Archive Manager Improves ZPAQ Support, Adds New Themes

Coming two months after PeaZip 11.2, the PeaZip 11.3 release improves ZPAQ support with a new “Force typing password interactively” option, and a new option to automatically explore the output path with PeaZip after a task is completed, which also changes the behavior of internal drag-and-drop copy/move actions to explore the destination path.

LinuxGizmos.com

ESP32-S3 powers EWatch smartwatch with open drivers and DIY options

EWatch, developed by Ewan Wills, is a programmable ESP32-S3 smartwatch with a 1.69-inch color touchscreen, 350mAh battery, vibration feedback and USB-C connectivity. The platform is offered as a bare PCB, self-assembly kit or complete watch, following more than five years of development.

ESP-Mosaico centers dual-core RISC-V ESP32-S31 around a 2.16-inch square AMOLED

The Espressif ESP-Mosaico is an expandable smart-interaction development kit based on the ESP32-S31 microcontroller. The compact device integrates a 2.16-inch square touch display, audio hardware, motion and magnetic sensors, NAND storage, haptic feedback and dual expansion interfaces for HMI, edge voice and multimedia applications.

news

Microsoft Windows 11 Caches Exploitable Malware

posted by Roy Schestowitz on May 15, 2024

Fishtank PC builds

Reprinted with permission from Cybershow. Author: Helen Plews.

Figure 1: Tom's Hardware: Fishtank PC builds.

Malware is often thought of as a human interaction with a digital device that causes an infection such as a virus or worm. We assume a human used bad authentication, or the human clicked the bad link, the human downloaded the malware…

So if we have anti-virus and anti-phish educational campaigns we should be well protected right? What about the technical side of cybersecurity, where the hardware, network equipment, end device or software vulnerability is the cause?

This article will examine a case where an operating system is able to automatically open and store a phishing email attachment, leading to potential compromise. In this case Windows 11 has been caching attachments locally to provide synchronisation across devices with the Outlook Application. In many cases, it has cached exploitable malware. This is a growing issue brought to light by Windows 11 users and anti-virus providers, instead of the makers at Microsoft.

Dropper Investigation

I am a life-long gamer and from experimentation over the years, I know I have the best rig, a customisable gaming PC. It’s very nice hardware it looks stunning with rainbow glowing fans and it sounds like a mini jet engine, rendering most graphics on Ultra with a graphics card which is at most 2 years old. The only issue I have had with it is in the operating system, which of course for a big gamer is Windows 11 due to its age. After just two weeks of operation I was alerted to a dropper located in my Windows Appdata folder, it was not dropping any further viruses yet as it had been caught by my expensive AV - which is why it sounds like a jet engine due to the large use of CPU!!

Was it a false positive? Well I ran the offline scan myself as my machine took 8x longer to boot. It behaved as if rebooting after a major update. There were no updates carried out, which made me suspect something amiss.

The virus location was not new to me, it is an appdata folder present in Windows 10 and Windows 11 for Windows mail in particular it processes mail syncing across devices; the full path is:

C:\Users\’Username’\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\SO\

Now I have had viruses popping up here before, in fact it has been an ongoing problem since I adopted the Windows 11 operating system (OS) in 2022 on the household laptops. Since then, both of my son’s laptops have alerted me to droppers and Trojans in the same Appdata folder. I initially assumed my children were not so good with their cybersecurity (being aged 5 and 9 that makes sense). Maybe they had clicked an email notification. Maybe they had downloaded some Trojan in the style of a game from a requested and shoddy gaming store all parents know about, stealthy and all whilst under supervision. That was until my brand new gaming rig got one.

Examining the attack timeline of my gaming rig in detail showed that a phish had been ‘clicked’ from my Hotmail account which was logged in on my Outlook App, running in the background processes (not running in my taskbar) whilst I played some epic title the night before. This ‘click’ put an infected PDF invoice on my PC, and on boot the next day activated the dropper, slowing the machine right down - which gave me a clue.

Now let's be clear about how Microsoft works, as I understand it, and why this is a gripe serious enough to warrant its own blog post.

You must sign in online to a Microsoft account to access the PC at all times, then it creates session keys for all applications that come installed as standard with the OS. So, unless you take some drastic measures I will discuss in a moment, you will undoubtedly be running sessions of Windows apps in the background; Outlook, OneDrive, Teams, Xbox, Photos, Office, Store, the list is quite extensive.

Moving on, I look for the phish email I had. According to my AV "clicked on" log, I located the suspicious subject of the email. It was something akin to;

AMAZON ACCOUNT ###U$IIHknDBWON38383y4y29~~~

Now, you do not need to be a cybersecurity expert to tell that is a phish from the subject which was located using the now foreground Outlook app. And as expected, it was unread. It showed me that within a few minutes of receiving the unread email, the attached PDF invoice was added to the Windows Communication Appdata folder, which led to the dropper found by the offline scan.

It seemed that Outlook App was saving unread attachments to the appdata folder where the virus was located. Some of the located viruses over the past two years were found on multiple devices that used the same MS credentials which unless stated otherwise, auto sync application data. That is exactly what the

microsoft.windowscommunicationsapps_8wekyb3d8bbwe

folder is for. It contains both the application data for Windows apps like Outlook to run and sync as well as data obtained in the process. I synced between my children's laptops as my account was the administrator for the network, it kept them safer online. Or so I thought.

Vulnerability Research

So I start down the usual process of researching the vulnerability to find a permanent mitigation. I find nothing at first, no CVE, no reports. I do find some details on the MS community website like this one from "2020 Trojan Found and Deleted"… but it Returns (Trojan: HTML/Phish.AB!MSR) . It is here I see the same problem and I see a response from an expert.

“The trojan is an email attachment synced to your PC. Do you have some Hotmail or Microsoft email setup in an email client applications like Outlook?” - Independent Expert, MS Community, 2020

So I search all around this topic and I cannot find anything from Microsoft about this issue right away, but I do find many victims. Anti-Virus companies, affected users and experts alike are all drawing attention to this problem. Eventually, thanks to Reddit I find a similar experience from a commentor who managed to find the reported exploit listed by Microsoft. You can find many more threads on the issue on Reddit with a search.

“Looking into the report we have a "Exploit:O97M/CVE-2017-11882.AZA!MTB" match, which doesn't seem to be that ominous since it requires the file to be executed on a non-updated Office/WordPad, still it ain't something I'd like to find lying around because the app found it was a good thing to download it, without my consent.” - JVMTG, Reddit, 2023

It is a known software error marked as severe on their own security intelligence website, with 24 exploits under the O97M CVE. I’d like to say I have more details from Microsoft but I do not, instead they offer very little default cybersecurity steps, such as "remain up to date and don’t click a phish".

This does seem rather severe. It locally caches attachments from emails including those which have not been opened to the windowscommunicationsapps folder from the Outlook App. It will then auto sync the data in the folder to all devices using the same credentials in their Outlook App on their phones, laptops, desktops, anywhere the Outlook App runs.

The only step missing for a full compromise is that infected files are auto-run… a feature I feel sure Microsoft are working on at this exact moment!

Attacks are becoming more complex, in 2022 they were able to add the dropper, which very slowly downloaded a fairly rubbish Trojan, which was easily removed. Recently there were 74 password protected files and multiple Trojans appearing as game applications in the same appdata folder. These were located only weeks after a fresh OS install and could not be explained by known activities on the machine or entirely resolved by AV due to the encryption of the folders they were located in.

Impact

Take a moment to think about how many commercial users of the Outlook application have auto-sync enabled in daily use. All those using Office 365 who sync between devices on their smartphone, personal devices and company equipment, or amongst family member's tablets and laptops. You should be concerned. And then get mad as hell, because it seems Microsoft have created their own quite special service for propagating malware, one that's been ongoing since at least 2020.

I have wasted countless hours re-installing OS’s, searching files, reading reports and researching this issue to find my only salvation in Reddit. Reddit of all places! This looks like something Microsoft rather wanted to sweep under the rug.

If you sync with Outlook App between devices with the same MS account, you are vulnerable to this malware propagation. Microsoft insist users take advantage of auto-synced features across devices and use this as a clear marketing tool especially for commercial settings. It seems my trust in this feature was misplaced.

Mitigation And Loss of Trust

Some will say that this is "just a feature" of sync. I disagree because like so many Microsoft processes it feels out of control. It does not just synchonise expected user data. It inappropriately populates and copies undocumented files into system folders and, without any knowledge or intervention from the user, replicates them across devices.

The mitigation is you must live without synchronisation in Microsoft applications. So far it has worked 100%. Turning off sync across applications does work. This can be done during an OS install by refusing all sync options when prompted. You must also make sure it is off in the account settings for the user. This can be done from the settings panel when logged on to Windows. There are many guides available like this one from Process.st. Even with sync off, you can still access email and other services using the web applications, which will sync files and emails but will not store these to the local machine.

If like myself, you have lost trust in the applications themselves, removing windows apps entirely may be more fitting, this allows the folder

microsoft.windowscommunicationsapps_8wekyb3d8bbwe

to be deleted and does not appear, like a lurking background threat at a later date just in case you change your mind. My gaming rig has only one MS app remaining, Xbox and that is the way it will stay until the situation is openly discussed by MS and the vulnerability resolved. No more Appdata Phishes please.

In summary, no amount of phishing training will prevent a bad design in the operating system. Caching malware infected attachments to system folders and replicating them is bad design in my opinion. In this case, the operating system has been phished, not the human. █

Other Recent Tux Machines' Posts

Software Freedom / Digital Sovereignty Pursuits: FOSS Force and El País
2 examples of it
Qualcomm Snapdragon X2
Qualcomm Announces Snapdragon X2 Linux Developer Preview
Budgie 10.10.3 Desktop Environment Introduces Free Placement of Desktop Icons
Budgie 10.10.3 is now available as the third maintenance update to the Wayland-only Budgie 10.10 desktop environment series with various improvements, new features, and the usual bug fixes.
Project rebrand: Nura
From now on this project is known as Nura
VLC 3.0.24 Released with APV and Atrac3/Atrac9 Decoding, FFmpeg 8.1 Support
VLC 3.0.24 open-source media player is now available for download with an APV decoder, Atrac3/Atrac9 decoding, FFmpeg 8.1 support, support for CEA-708 closed captions in MP4, and more.
This Week in Plasma: Akademy Special
Welcome to a new issue of This Week in Plasma
 
Search in TuxMachines.org [original]
A day later
qBittorrent 5.2.4 Open-Source BitTorrent Client Released with WebUI Improvements
qBittorrent 5.2.4 open-source BitTorrent client is now available for download with various bug fixes and improvements, especially for the web-based user interface.
Git 2.56 Adds New Options for Cleaning Up Branches and Resolving Conflicts
Git 2.56 open-source distributed version control system is now available for download with new features, new options, and performance improvements.
Links Between UK and Ireland Severed [original]
incident at the network level
GNU/Linux Leftovers
Wireshark, Ubuntu, and more
Web and Education Leftovers
FOSS and more
gengetopt 2.23.1 is out and GNU turns 43
GNU news
Programming Leftovers
Development picks
Lazy Reading and OpenBSD News
BSD Leftovers
KDE: Interview with Michael Tunnell about KDE’s 30th birthday and Oxygen at Akademy 2026
KDE news
New Steam Games Playable on the Steam Deck, AnyPS5, and VR Streaming on Linux
gaming picks for today
today's howtos
Instructionals/Technical
Kernel: OpenBSD (VMs), Slop, and CVE-2026-55074
3 picks
Linux 7.3-rc5
just the same old, same old.
Mozilla Firefox 157 Is Now Available for Download with Brand-New Design
Mozilla Firefox 157 open-source web browser is now available for download with the brand-new Nova design, HDR improvements, improved audio/video synchronization, and more.
Flatpak 1.18.4 Linux App Sandboxing Framework Fixes Security Issues
Flatpak 1.18.4 Linux application sandboxing and distribution framework is now available for download with various security fixes for the stable Flatpak 1.18 series.
ESP32-S3 and RISC-V ESP32-S31 Projects
Open Hardware picks
Android Leftovers
De-Googling Android isn't about losing features—it's about gaining control
Scheduled Maintenance on Host System Completed [original]
There is no further risk of timeouts
Linux: Linux terminal upgrade, No sudo and modern Linux file manager
I never disliked working in the Linux terminal
Introducing Toolpak
GNOME OS does something similar: There is a “developer” system extension that overlays the toolchain used for building the OS on top of the user-facing OS image
I spent a year on Linux Mint, but I'll never use it again for these reasons
Linux Mint has a reputation for being the friendly face of Linux and the perfect first step
Give Linux Mint a dramatic makeover with this theme pack
The refrain goes that ‘Linux Mint looks dated’
Try Immutable Mode with openSUSE Leap 16.1 RC
openSUSE Leap 16.1 has entered the Release Candidate phase
Today, we are celebrating sixteen years of LibreOffice’s independence and commitment to supporting free software, open standards and digital sovereignty
Sixteen years on, LibreOffice has been independent for longer than OpenOffice.org ever was under Sun Microsystems
Best Free and Open Source Software
Only free and open source software is eligible for inclusion here
matrixOS – Gentoo-Based Immutable Distribution with Atomic Upgrades
matrixOS is a Gentoo-based distribution which combines Gentoo’s flexibility with an immutable base system and atomic updates
Review: ReactOS 0.4.16
I try out new versions of ReactOS every few years to see how the project is coming along
Today in Techrights
Some of the latest articles
OpenShot 4.0.1 Video Editor Released with Timeline and Zoom Improvements
OpenShot 4.0.1 open-source video editor is now available for download with timeline and zoom improvements, updated Razor tool, faster keyframe and color editing, and more.
Shotcut 26.9 Video Editor Improves the VA-API HEVC Hardware Encoder on Linux
Shotcut 26.9 open-source video editor is now available for download with Automatic Ducking for audio, volume control and audio level meter/indicator for timeline track headers, and more.
9to5Linux Weekly Roundup: September 27th, 2026
The 311th installment of the 9to5Linux Weekly Roundup is here for the week ending September 27th, 2026.
I nuked my openSUSE OS to test Snapper, and it survived what should have been fatal
Whenever someone asks me why I use openSUSE
Searching Tux Machines Summaries [original]
At one point we hope to have unified search
Klassic brings the KDE 3 desktop experience from 2002 to KDE Plasma 6
As a newcomer to the Linux scene, I didn't have the pleasure of using it back in the 2000s
I replaced Fedora’s slow software manager with these 3 better alternatives
Fedora is easily one of the best Linux distributions out there
What Happened in 2023 [original]
We are writing a series about it this weekend
I tried Fedora Everything, now I have a Linux desktop without any bloat
If you want to cut the bloat and have more control over which apps are installed on your Linux PC
Free, Libre, and Open Source Software Leftovers
FOSS picks
GNU/Linux Leftovers
PS5 and more
Programming Leftovers
Development links
Open Hardware/Modding: Reverse-engineering, ESP32, and More
Hardware stories
today's howtos
Instructionals/Technical picks
Valnet's howtogeek on Tiny Core Linux and "switching to Linux"
to stories
The Netherlands joins Europe's gradual migration from Windows to Linux on government PCs
Something very interesting is happening over in Europe in the world of FOSS
Susan Linton Also Played a Role at DistroWatch [original]
DistroWatch is still going strong
Games: Oldies, Proton Experimental, SteamOS 3.9.2 Beta, and More
mostly from GamingOnLinux
Best Free and Open Source Software
Only free and open source software is eligible for inclusion here
Linux Has Too Many Distributions – And Most New Ones Don’t Need to Exist
One of Linux’s greatest strengths is choice. It is also one of its easiest excuses
Era, the new Rust-based calendar for GNOME, is now in beta
Era is a new Rust-based calendar app for GNOME that describes itself as “beautiful and performant
Fastfetch 2.69.0 Released with GIF and APNG Animated Logo Support
Fastfetch, the popular tool for fetching system information and displaying in command-line interface (CLI)
Merlot – lightweight Linux distribution for running Windows applications
Merlot is a lightweight Linux distribution
Caelaris Linux – Arch-Based Distribution for Desktop and Gaming
Caelaris Linux is an Arch-based distribution designed to provide a ready-to-use system for desktop computing
AlmaLinux’s New Beefed-Up Hardware and Software Certification
The AlmaLinux booth at All Things Open 2023 conference in Raleigh, North Carolina
Today in Techrights
Some of the latest articles
Microsoft Windows is Collapsing in Singapore and Nearby Indonesia [original]
Windows is no longer "leader" at all, not even in desktops/laptops
GNU/Linux Reaches All-Time High of 6% (According to statCounter) or 7.3% (Clownflare) in Indonesia [original]
Indonesia's latest data suggests GNU/Linux is growing among Indonesian computer users
GNU/Linux Leftovers
misc. GNU/Linux picks
Free, Libre, and Open Source Software Leftovers
FOSS leftovers
Standards and Web Clients
Mozilla and more
NetBSD Leftovers
2 stories
Protesilaos Stavrou on Emacs and Free Software
a pair of posts
SPECviewperf 15.0.1 Linux Edition, Mike Blumenkrantz Explains Recent Graphics Work
a pair of articles
Slop in Linux and Slop About Linux Graphics
slopfest
Games: GamingOnLinux Stories, ‘World of Warcraft: Forever’, and Star Trek in BASIC
gaming news
Red Hat / Fedora / IBM / Clones
mostly Red Hat
Canonical/Ubuntu: Alan Pope Propping Up Microsoft's Mono, Ubuntu 26.10 Delay, and Ubuntu in Slop Surveillance
Ubuntu leftovers
Open Hardware/Modding: ESP32, OpenWrt, Pi Pico, and More
Hardware picks
Programming Leftovers
Development related picks
Events: 2026 Git Contributors' Summit and HomelabFest Coming
2 events
Security Leftovers
Security picks and more
The GNOME LLM Policy That I Want
KDE is on the news because of a controversial proposal to define an official “AI” (LLM) policy (archived link)
GNOME 50.5 Improves Multi-Monitor Support, HDR Support, and More
GNOME 50.5 is now available as the fifth update to the latest GNOME 50 desktop environment series with various bug fixes, updated translations, and other improvements.
PeaZip 11.3 Archive Manager Improves ZPAQ Support, Adds New Themes
PeaZip 11.3 open-source archive manager is now available for download with improved ZPAQ support, new themes, new keyboard shortcut, improved handling of invalid filenames, and more.
Android Leftovers
Android 17 QPR2 Beta 6 is rolling out: unexpected reboots and kernel crash fixes lead the way
5 niche Linux distros that deserve way more attention
There are hundreds, if not more, Linux distros out there, but not all of them get the same amount of attention
Free and Open Source Software, howtos and Installations
This is free and open source software
PH4NTXM – Debian-Based Cybersecurity and Privacy Distribution
PH4NTXM is a Debian-based live Linux distribution designed specifically for cybersecurity
KDE and AI, and you, and me
So I accidentally triggered an online shitstorm in the process of trying to craft a set of more restrictive LLM usage guidelines for KDE
Dedoimedo: Laptop and battery pending charge issue
If you have a Linux machine and you experience intermittent charging not-charging "issue" in normal everyday situations
Stable kernels: Linux 7.2.8, and Linux 6.18.54
I'm announcing the release of the 7.2.8 kernel
End of Support for Mageia 9
At Mageia, we have reached a significant milestone with the release of Mageia 10 on 30 June 2026
Today in Techrights
Some of the latest articles