Tux Machines

Do you waddle the waddle?

Other Sites

LinuxGizmos.com

Sfera Labs ships Strato Pi Plus with quad RS-485 and CAN FD

Sfera Labs has begun shipping the Strato Pi Plus, a DIN-rail industrial edge server based on the Raspberry Pi 4B or Raspberry Pi 5. The system adds a 10–50 V DC power supply, up to four isolated RS-485 interfaces, CAN FD connectivity, and an independent RP2354 microcontroller.

Raspberry Pi launches 10-inch Touch Display 2 with 1200 × 1920 resolution

Raspberry Pi has introduced a 10-inch version of its Touch Display 2, expanding the display family beyond the existing 5-inch and 7-inch models. The new panel provides a 1200 × 1920 resolution, ten-point capacitive touch, and compatibility with the Raspberry Pi 5 and supported Compute Module platforms.

Tor Project blog

New Release: Tails 7.10

The standard shutdown procedure is a bit slower, but better prevents data loss.

New Release: Tor Browser 15.0.19

This version includes important security updates to Firefox.

9to5Linux

Tails 7.10 Anonymous Linux OS Introduces New Shutdown Procedure

Coming a month after Tails 7.9, which only updated to Tor Browser 15.0.16 and some firmware packages, the Tails 7.10 release is a bigger one, introducing a new shutdown procedure, the one from the GNOME desktop environment, which is slower but better prevents data loss. The previous, faster emergency shutdown can still be used.

Mozilla Firefox 154 Enters Public Beta Testing, Here’s What to Expect

Firefox 154 promises support for clearing and updating cached favicons when performing a hard reload on a page, a “Manage AI” quick action in the address bar that opens the AI section of Settings, and the ability to highlight selected text in PDFs like in normal web pages.

COSMIC 1.4 Desktop Environment Introduces New Default Sound Theme

Coming only a week after COSMIC 1.3, which introduced the highly anticipated Frosted Glass effect, the COSMIC 1.4 release is here to introduce a new default sound theme, improve screen edge pointer accuracy with fractional scaling, improve NetworkManager support, and add xdg-desktop-portal-cosmic as a system service.

Raspberry Pi Launches 10-Inch Raspberry Pi Touch Display 2 at $80

Raspberry Pi Touch Display 2 is a multi-touch portrait display for Raspberry Pi single-board computers. It is designed to be used for all sorts of interactive projects, such as tablets, entertainment systems, home automation dashboards, robotics interfaces, gaming systems, and information dashboards.

New Steam Client Update Improves NVIDIA GPU Hardware Acceleration on Linux

For Linux gamers, the July 21st, 2026, Steam Client update fixes a steamwebhelper crash that occurred when hardware acceleration is enabled on NVIDIA GPUs and fixes a crash that occurred when manually starting a game recording.

OBS Studio 32.2 Released with New Filter to Compose SDR into HDR

Coming more than four months after OBS Studio 32.1, the OBS Studio 32.2 release is here to introduce a new filter to compose SDR into HDR, dynamic bitrate support for multitrack video, missing file support for filters, support for plugins to set custom icons for new source types, and support for copy-paste functions for the frontend API.

Mozilla Thunderbird 153 Is Out with Various New Features and Many Fixes

Highlights of Mozilla Thunderbird 153 include support for unified folders to display account color indicator with account name tooltip, support for opening OAuth login for mail accounts in the default web browser, support for using Thundermail services without installing an add-on, and support for OAuth responses to verify issuer fields and reject missing required issuers.

Canonical Launches the Enterprise Store for Ubuntu Pro Users

Part of Ubuntu Pro, the Enterprise Store is an on-premises edge proxy that sits between Canonical’s software stores and your devices, allowing you to install and update software without requiring direct outbound access from every machine.

VirtualBox 7.2.14 Released with Initial Support for Linux Kernel 7.2

VirtualBox 7.2.14 comes three weeks after VirtualBox 7.2.12, a small update that only fixed a kernel panic for Linux hosts, various NASM build issues for Linux guests and hosts, and added DX11 performance improvements and fixes for Windows guests.

news

Microsoft Windows 11 Caches Exploitable Malware

posted by Roy Schestowitz on May 15, 2024

Fishtank PC builds

Reprinted with permission from Cybershow. Author: Helen Plews.

Figure 1: Tom's Hardware: Fishtank PC builds.

Malware is often thought of as a human interaction with a digital device that causes an infection such as a virus or worm. We assume a human used bad authentication, or the human clicked the bad link, the human downloaded the malware…

So if we have anti-virus and anti-phish educational campaigns we should be well protected right? What about the technical side of cybersecurity, where the hardware, network equipment, end device or software vulnerability is the cause?

This article will examine a case where an operating system is able to automatically open and store a phishing email attachment, leading to potential compromise. In this case Windows 11 has been caching attachments locally to provide synchronisation across devices with the Outlook Application. In many cases, it has cached exploitable malware. This is a growing issue brought to light by Windows 11 users and anti-virus providers, instead of the makers at Microsoft.

Dropper Investigation

I am a life-long gamer and from experimentation over the years, I know I have the best rig, a customisable gaming PC. It’s very nice hardware it looks stunning with rainbow glowing fans and it sounds like a mini jet engine, rendering most graphics on Ultra with a graphics card which is at most 2 years old. The only issue I have had with it is in the operating system, which of course for a big gamer is Windows 11 due to its age. After just two weeks of operation I was alerted to a dropper located in my Windows Appdata folder, it was not dropping any further viruses yet as it had been caught by my expensive AV - which is why it sounds like a jet engine due to the large use of CPU!!

Was it a false positive? Well I ran the offline scan myself as my machine took 8x longer to boot. It behaved as if rebooting after a major update. There were no updates carried out, which made me suspect something amiss.

The virus location was not new to me, it is an appdata folder present in Windows 10 and Windows 11 for Windows mail in particular it processes mail syncing across devices; the full path is:

C:\Users\’Username’\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\SO\

Now I have had viruses popping up here before, in fact it has been an ongoing problem since I adopted the Windows 11 operating system (OS) in 2022 on the household laptops. Since then, both of my son’s laptops have alerted me to droppers and Trojans in the same Appdata folder. I initially assumed my children were not so good with their cybersecurity (being aged 5 and 9 that makes sense). Maybe they had clicked an email notification. Maybe they had downloaded some Trojan in the style of a game from a requested and shoddy gaming store all parents know about, stealthy and all whilst under supervision. That was until my brand new gaming rig got one.

Examining the attack timeline of my gaming rig in detail showed that a phish had been ‘clicked’ from my Hotmail account which was logged in on my Outlook App, running in the background processes (not running in my taskbar) whilst I played some epic title the night before. This ‘click’ put an infected PDF invoice on my PC, and on boot the next day activated the dropper, slowing the machine right down - which gave me a clue.

Now let's be clear about how Microsoft works, as I understand it, and why this is a gripe serious enough to warrant its own blog post.

You must sign in online to a Microsoft account to access the PC at all times, then it creates session keys for all applications that come installed as standard with the OS. So, unless you take some drastic measures I will discuss in a moment, you will undoubtedly be running sessions of Windows apps in the background; Outlook, OneDrive, Teams, Xbox, Photos, Office, Store, the list is quite extensive.

Moving on, I look for the phish email I had. According to my AV "clicked on" log, I located the suspicious subject of the email. It was something akin to;

AMAZON ACCOUNT ###U$IIHknDBWON38383y4y29~~~

Now, you do not need to be a cybersecurity expert to tell that is a phish from the subject which was located using the now foreground Outlook app. And as expected, it was unread. It showed me that within a few minutes of receiving the unread email, the attached PDF invoice was added to the Windows Communication Appdata folder, which led to the dropper found by the offline scan.

It seemed that Outlook App was saving unread attachments to the appdata folder where the virus was located. Some of the located viruses over the past two years were found on multiple devices that used the same MS credentials which unless stated otherwise, auto sync application data. That is exactly what the

microsoft.windowscommunicationsapps_8wekyb3d8bbwe

folder is for. It contains both the application data for Windows apps like Outlook to run and sync as well as data obtained in the process. I synced between my children's laptops as my account was the administrator for the network, it kept them safer online. Or so I thought.

Vulnerability Research

So I start down the usual process of researching the vulnerability to find a permanent mitigation. I find nothing at first, no CVE, no reports. I do find some details on the MS community website like this one from "2020 Trojan Found and Deleted"… but it Returns (Trojan: HTML/Phish.AB!MSR) . It is here I see the same problem and I see a response from an expert.

“The trojan is an email attachment synced to your PC. Do you have some Hotmail or Microsoft email setup in an email client applications like Outlook?” - Independent Expert, MS Community, 2020

So I search all around this topic and I cannot find anything from Microsoft about this issue right away, but I do find many victims. Anti-Virus companies, affected users and experts alike are all drawing attention to this problem. Eventually, thanks to Reddit I find a similar experience from a commentor who managed to find the reported exploit listed by Microsoft. You can find many more threads on the issue on Reddit with a search.

“Looking into the report we have a "Exploit:O97M/CVE-2017-11882.AZA!MTB" match, which doesn't seem to be that ominous since it requires the file to be executed on a non-updated Office/WordPad, still it ain't something I'd like to find lying around because the app found it was a good thing to download it, without my consent.” - JVMTG, Reddit, 2023

It is a known software error marked as severe on their own security intelligence website, with 24 exploits under the O97M CVE. I’d like to say I have more details from Microsoft but I do not, instead they offer very little default cybersecurity steps, such as "remain up to date and don’t click a phish".

This does seem rather severe. It locally caches attachments from emails including those which have not been opened to the windowscommunicationsapps folder from the Outlook App. It will then auto sync the data in the folder to all devices using the same credentials in their Outlook App on their phones, laptops, desktops, anywhere the Outlook App runs.

The only step missing for a full compromise is that infected files are auto-run… a feature I feel sure Microsoft are working on at this exact moment!

Attacks are becoming more complex, in 2022 they were able to add the dropper, which very slowly downloaded a fairly rubbish Trojan, which was easily removed. Recently there were 74 password protected files and multiple Trojans appearing as game applications in the same appdata folder. These were located only weeks after a fresh OS install and could not be explained by known activities on the machine or entirely resolved by AV due to the encryption of the folders they were located in.

Impact

Take a moment to think about how many commercial users of the Outlook application have auto-sync enabled in daily use. All those using Office 365 who sync between devices on their smartphone, personal devices and company equipment, or amongst family member's tablets and laptops. You should be concerned. And then get mad as hell, because it seems Microsoft have created their own quite special service for propagating malware, one that's been ongoing since at least 2020.

I have wasted countless hours re-installing OS’s, searching files, reading reports and researching this issue to find my only salvation in Reddit. Reddit of all places! This looks like something Microsoft rather wanted to sweep under the rug.

If you sync with Outlook App between devices with the same MS account, you are vulnerable to this malware propagation. Microsoft insist users take advantage of auto-synced features across devices and use this as a clear marketing tool especially for commercial settings. It seems my trust in this feature was misplaced.

Mitigation And Loss of Trust

Some will say that this is "just a feature" of sync. I disagree because like so many Microsoft processes it feels out of control. It does not just synchonise expected user data. It inappropriately populates and copies undocumented files into system folders and, without any knowledge or intervention from the user, replicates them across devices.

The mitigation is you must live without synchronisation in Microsoft applications. So far it has worked 100%. Turning off sync across applications does work. This can be done during an OS install by refusing all sync options when prompted. You must also make sure it is off in the account settings for the user. This can be done from the settings panel when logged on to Windows. There are many guides available like this one from Process.st. Even with sync off, you can still access email and other services using the web applications, which will sync files and emails but will not store these to the local machine.

If like myself, you have lost trust in the applications themselves, removing windows apps entirely may be more fitting, this allows the folder

microsoft.windowscommunicationsapps_8wekyb3d8bbwe

to be deleted and does not appear, like a lurking background threat at a later date just in case you change your mind. My gaming rig has only one MS app remaining, Xbox and that is the way it will stay until the situation is openly discussed by MS and the vulnerability resolved. No more Appdata Phishes please.

In summary, no amount of phishing training will prevent a bad design in the operating system. Caching malware infected attachments to system folders and replicating them is bad design in my opinion. In this case, the operating system has been phished, not the human.

Other Recent Tux Machines' Posts

Mozilla Thunderbird 153 Is Out with Various New Features and Many Fixes
Mozilla Thunderbird 153 open-source email client is now available for download with new features, improvements, and numerous bug fixes. Here’s what’s new!
OBS Studio 32.2 Released with New Filter to Compose SDR into HDR
OBS Studio 32.2 open-source video recording and live streaming software is now available for download with a new filter to compose SDR into HDR, dynamic bitrate support for multitrack video, and more.
When and how did the world's dental clinics start to offer Botox? [original]
If this is real or not, as I am not sure (hard to believe), it needs to be scrutinised
COSMIC 1.4 Desktop Environment Introduces New Default Sound Theme
COSMIC 1.4 desktop environment is now available with improvements to COSMIC Settings, COSMIC Panel, COSMIC Monitor, COSMIC Launcher, COSMIC Files, COSMIC Applets, COSMIC Workspaces, and more.
VirtualBox 7.2.14 Released with Initial Support for Linux Kernel 7.2
VirtualBox 7.2.14 open-source virtualization software is now available for download with initial support for Linux kernel 7.2, better support for updated RHEL 9.8 and 9.9 kernels, and more.
IPFire 2.29 Core Update 203 Firewall Distro Replaces Unbound with Knot Resolver
IPFire 2.29 Core Update 203 hardened Linux firewall distro is now available for download with Knot Resolver, 6 GHz Wi-Fi band support, and other changes.
 
Free and Open Source Software
This is free and open source software
Planet KDE: Legal obligations vs social contracts
My post about responsibility for bug reports on old software versions the other day stirred up quite some discussion
Mourning Dan Williams
I have just received the shocking news that Dan Williams, a longtime, high-profile kernel developer
Free, Libre, and Open Source Software Leftovers
Education, The Document Foundation (TDF), and more
GNU/Linux and BSD Leftovers
mostly GNU/Linux
Emulation: LWN Looks at Kitty and PlayStation 3 Emulator Improves GNU/Linux Support
a pair of stories
I've used Linux for 30 years, and this free security suite does it all - almost perfectly
Linux may be the most secure OS available
Kiwi TCMS 16.2, Broken Links, and WordPress 7.1 Beta 3
Content Management Systems (CMS) picks
Red Hat Leftovers and IBM's Demise
redhat.com and more
Open Hardware/Modding; Raspberry Pi, Arduino, and More
devices and more
Web, HTML, Thunderbird, and Firefox
WWW related picks
Programming Leftovers
Development picks
Ubuntu Changes, Canonical Upselling
Canonical and Ubuntu leftovers
CVE-2026-8933: Canonical's Snaps System Has Problems
some news links
Security Leftovers
Security picks
KDE Eco and Kaidan 0.16.0
KDE news
Applications for GNU/Linux: VPN. IPAM, Sniffnet, and More
software leftovers
today's howtos
Instructionals/Technical posts
Peter Hutterer on Latest libei Work
Peter Hutterer's latest blog posts
Linux Kernel and Graphics Work
Linux bugs and more
LWN on Kernel
4 new article outside paywall
Games: 60 FPS NES Emulator On ESP32, IVOR, Proton-CachyOS, and More
mostly GamingOnLinux
LibreOffice 26.8 RC1 is available for testing
LibreOffice 26.8 will be released as final at the end of August, 2026
Free and Open Source Software, and Benchmark
I’ll put the Beelink mini PC through its paces from a Linux perspective
Plex's Open Source Alternative Jellyfin is Having a Leadership Crisis
The departures come just months after the project flagged burnout as a growing risk
Tails 7.10 Anonymous Linux OS Introduces New Shutdown Procedure
Tails 7.10 anonymous Linux distribution is now available for download with the Celluloid media player, a new shutdown procedure, and other changes.
Android Leftovers
Samsung & Google’s first Android XR glasses have 9-hour battery life
Only one new Galaxy foldable supports Linux Terminal, and not everywhere
Linux Terminal support means you can run full-blown Linux apps like GIMP, LibreOffice, and Firefox on your phone
100+ Shells [original]
Shells are an interesting companion which does not require much maintenance
Free and Open Source Software, howtos and Installations
This is free and open source software
Fairphone 6 with /e/OS 4.0 - Results, results, results
The options are many. GrapheneOS, LineageOS, /e/OS, and then some
Raspberry Pi and Raspberry Pi OS
This arrangement allows the controller to detect an unresponsive Raspberry Pi and initiate a recovery without relying on software running under Raspberry Pi OS
New to Linux? This 10-day checklist will help you settle in nice and easy
I wish I had followed this 10-day plan when I started using Linux 30 years ago
Today in Techrights
Some of the latest articles
GNOME can look like Windows – and Flashback can do it without extensions
We built it and installed it, and it works
Security Leftovers
Security picks
Education and Free, Libre, and Open Source Software
FOSS and sharing
Web Browsers/Web Servers/Feed Readers Leftovers
WWW and more
Mozilla Firefox 153 ESR Is Now Available for Download, Here’s What’s New
Mozilla Firefox 153 ESR open-source web browser is now available for download as the new Extended Support Release series with various new features and enhancements.
GNU/Linux Leftovers
GNU/Linux related news
IBM's Red Hat Rebranding as Slop Company (Still)
latest from developers.redhat.com
OpenBSD, NetBSD, FreeBSD, and BSDCan
BSD leftovers
Games: Denuvo, Godot, and More
Games related picks
RISC-V, Linux, Open Source Vacuum, and More
devices and more
Audiocasts/Shows: Linux Matters and Fedora's Plug
a couple of new episodes
Linux 7.2 Benchmarks and Linux is Being Overtaken by LLM Slop After 'Linux' Foundation Got Paid to Participate in the Hype
kernel picks
"Ubuntu Certified" and Canonical Breaking Things in Ubuntu for No Good Reason
Canonical spoiling Ubuntu some more
Programming Leftovers
mostly R
today's howtos
Instructionals/Technical picks
Mozilla Firefox 154 Enters Public Beta Testing, Here’s What to Expect
Firefox 154 open-source web browser is now available for public beta testing with a new “Manage AI” quick action in the address bar, support for clearing cached favicons, and more.
Some Changes to GNOME Security Tracking
I have been managing GNOME security issue tracking since November 2020.
Canonical Launches the Enterprise Store for Ubuntu Pro Users
Ubuntu maker Canonical announced today the general availability of Enterprise Store as a new way to manage software behind firewalls and in air-gapped environments.
GNU/Linux Exceeds 5% in Ireland, According to Irish Company [original]
Ireland is in a good position to exceed 10% "market share" for GNU/Linux
Mozilla and Firefox Derivatives: Waterfox 6.6.17, Browser 15.0.19, Native Containers in Firefox 153
Firefox and relatives
Games: GameStream, Game Theory, RPG 'GRAFT', and More
gaming picks
Server: Istio 1.30.3, Istio 1.29.6, and 10ZiG
3 more picks
Recent Videos and Shows About GNU/Linux
via Invidious
100% of Red Hat's Blog Posts Yesterday Are "Quantum" and Slop (to Help IBM Fool the Shareholders With Vapourware)
latest 4
Arch Linux: Reviving a 15-year-old netbook with Arch Linux Collabora Releases First 64-Bit Arm Arch Linux Packages
pair of Arch Linux articles
Programming Leftovers
Development picks
A Tux Machines Anniversary This Coming Saturday [original]
This current site is very simple and light
GNU/Linux at 7% in the UK, Glimmer of Hype and Hope for Rain [original]
nobody mentions the latest data from statCounter
Raspberry Pi Launches 10-Inch Raspberry Pi Touch Display 2 at $80
A new Raspberry Pi Touch Display 2 model is now available with a 10-inch display and an $80 USD price tag, compatible with Raspberry Pi 5 and Raspberry Pi 5 CM SBCs.
SLAPP Reform in the UK [original]
We've meanwhile seen politicians who want to crack down on SLAPPs appointed to the new cabinet
Android Leftovers
Gboard rolling out M3 Expressive redesign of shortcuts on Android
I finally tried an Atomic Linux desktop—and I'm no longer afraid to break my system
I have broken Linux desktops in all the usual ways
Blur my Shell adding Blur Support for GNOME Menus & OSD Popups
Blur my Shell, the popular extension that adds blur effect to GNOME shell, is finally adding blur support for pop-up menus
Free and Open Source Software, and Benchmark
This is free and open source software
KDE for Enterprise Needs a Strong PIM Infrastructure
This post has been long overdue, but let’s say I’ve been busy and the reason will be obvious in this short piece
Fedora Xfce or Xubuntu: Which is the best Linux desktop?
Xfce is a Linux desktop environment that is great at giving old machines new life
This Android 17 setting logs suspicious activity on your phone for troubleshooting - turn it on ASAP
When something suspicious happens on your phone, it helps to have the means to track down what occurred
GNU/Linux in Angola: Over 3% Now, It Used to be Zero [original]
Angola is one of Africa's largest nations
Today in Techrights
Some of the latest articles
New Steam Client Update Improves NVIDIA GPU Hardware Acceleration on Linux
Valve released a new stable Steam Client update that promises to improve hardware acceleration for NVIDIA GPUs and game recording on Linux systems.
Trace Labs OSINT VM 2026.05: Rebuilt on Debian
We at the Trace Labs OSINT VM team are happy to announce the release of the Trace Labs OSINT VM 2026.05!
OPNsense 26.7 released
26.7, nicknamed "Xenial Xenops"
Games: GNOME, Steam, and More
gaming picks
Linux 7.2-rc4
typo though
In China, GNU/Linux Has Risen to Highest Levels Since 2023 [original]
Windows used to be 100% there, now it is 40%
Remembering Kevin Keegan [original]
Keegan played and was famous before I was born
Free, Libre, and Open Source Software Leftovers
FOSS picks
Programming Leftovers
Development news
GNU/Linux Leftovers
leftovers for today
WP2Shell Threatens WordPress Installations
WP2Shell news
The Case for Sponsoring openSUSE and Google (GSoC) Work on openSUSE
3 picks for today
Open Hardware/Modding: Arduino, ESP32, and More
hardware picks
Red Hat Promotes Slop (While Fedora/Flathub Bans It)
Latest from redhat.com
FreeBSD Leftovers
some FreeBSD picks
today's howtos
Instructionals/Technical picks
Audiocasts/Shows: LINUX Unplugged, Late Night Linux, and More
4 new episodes
Security Leftovers
Security picks for today
Birthday Preparations [original]
flowers and balloons are being prepared already
GNU/Linux Usage Estimate Continues to Grow [original]
Now it is 7.7%
Android Leftovers
Google releases Android 17 QPR2 Beta 1 for Pixel
GNU Planet: Help us reach our goal by Friday and get an anti-surveillance cover
Our fundraiser ends this Friday, July 24. If you are not a member yet, or know someone who isn't
Free and Open Source Software
This is free and open source software
AntherOS – Pop!_OS-based Linux distribution
AntherOS is a Pop!_OS-based Linux distribution designed for gaming and everyday desktop use
Today in Techrights
Some of the latest articles
Games: Rogue Eclipse, PUROMA, Faugus Launcher, and More
latest from GamingOnLinux