Tux Machines

Do you waddle the waddle?

Other Sites

LinuxGizmos.com

x86 compute module features Intel Core Ultra 200V with up to 115 TOPS

The LattePanda Mu Ultra measures 60 x 69.6mm and uses an AMI UEFI BIOS stored on a 256Mbit SPI device. The module is available with either an Intel Core Ultra 5 226V or Core Ultra 7 256V processor, both featuring eight CPU cores and eight threads. The 226V operates at up to 4.5GHz and integrates an Intel Arc 130V GPU with seven Xe cores, together with an Intel AI Boost NPU rated at up to 40 TOPS. LattePanda lists up to 53 TOPS from the GPU and 97 TOPS of combined INT8 performance across the CPU, GPU, and NPU.

i.MX95 SMARC module offers LPDDR5, Wi-Fi 6 and PCIe Gen3

MYIR’s MYC-JMX95X is a SMARC 2.2 System-on-Module based on NXP’s i.MX95 processor. The module features six Cortex-A55 cores, Cortex-M7 and Cortex-M33 auxiliary cores, a 2-TOPS NPU, LPDDR5 memory, eMMC storage, Wi-Fi 6, Bluetooth 5.4, and a range of high-speed expansion interfaces.

ODROID-M1S goes Lite with 2GB RAM, NVMe and 4K video

The ODROID-M1S Lite is based on Rockchip’s RK3566 processor, which integrates four Arm Cortex-A55 cores operating at up to 1.8GHz, a Mali-G52 GPU with two execution engines, and an RKNN neural processing unit rated at up to 0.8 TOPS of INT8 performance.

Tor Project blog

New Release: Tor Browser 15.0.22

This version includes important security updates to Tor.

Tor VPN Beta: What we've learned building our own VPN for Android from scratch

And for years, we heard this again and again in our user research. People wanted a simple way to protect their entire device, which inspired the idea for Tor VPN back in 2021. We focused on Android first, where the need was greatest and where we could reach the most users in censored regions. We built Tor VPN Beta as a first version, with the expectation that we would learn from real-world use. And when we first launched Tor VPN Beta for Android in a limited release last fall, the primary use case quickly became much clearer: unblock the internet. This has shaped how we've prioritized development and user support in the time since the initial launch, and how we think about the product moving forward.

schestowitz.com

Made It to 4 Digits!

An uptime of 1000 days

Stevie Wonder in Manchester

Stevie Wonder coming here again

Quotas Are Not Common Sense

Quality matters

Long Ago (And Far Away)

Simple, but still brilliant, still one of my favourites.

Cheap But Unfit for Purpose and Unsafe

Appliances have gotten worse (less safe, less reliable), even branded goods from NIMA [1, 2] because people like “cheap” and companies are cheapening the production processes, materials, quality control

A Fishy Week

So far, so good

Enzo Has Started Better Than Pep

EnzoFC seems to be getting better over time

Linus Torvalds Again Complains That LLM Slop (That Nobody Audits) Overwhelms the Linux Kernel

could not help but notice the wordings of Torvalds, as uttered in writing this past Sunday. This is not the first time he expresses (apprehensively, his boss is the Linux Foundation, bribed by the slop industry) concerns about Linux slipping out of developers’ control only to become a bloated pig that few people understand.

Art, Not Slop

used to find it disturbing when some football clubs shared slop, especially in social control media, about their squad.

Always Pleased With Manchester Pets & Aquatics at Ardwick

had a very productive day today, especially all the “fish tank” stuff. At one point we discussed the options available to us, then I left home just in time to reach the pet store at 9AM (when it opens). I spent a long time looking at all the animals and could see the people who ran the shop really love animals. One was hugging the lizard while cleaning its cage; the lizard would not let go when he came to the fish section to help and advise me. They also checked things on a computer system to give me expert advice when I asked questions.

Internet Society

From Curiosity to Confidence: CodificaKids Builds Digital Trust in Rural Brazil

Walking home one afternoon through the streets of São José do Alegre, a quiet rural town in the Brazilian state of Minas Gerais, João heard a notification ping and pulled out his phone.

Community Snapshot—August

Around the world, our community works locally, regionally, and globally to keep the Internet a force for good: open, globally connected, secure, and trustworthy.

9to5Linux

Calamares 3.4.3 Linux Graphical Installer Improves Disk Partitioning, Locale

Coming six months after Calamares 3.4.2, the Calamares 3.4.3 release is here to improve disk partitioning by adding support for the latest KPMcore release, improve the partition-needs-alignment behavior, and no longer accidentally mark /boot as the EFI boot partition, which could break with systemd-gpt-auto-generator.

KDE Gear 26.08.1 Is Out with More Improvements for Your Favorite KDE Apps

KDE Gear 26.08.1 is here to fix the orientation of an arrow within the plasmoid of the KDE Connect app, fix opening the room map from a talk in the Kongress companion application for conferences, and fix a crash in the Okular document viewer that occurred when saving documents.

OpenSSL 4.1 Promises Support for DTLS 1.3, IKEV2 KDF, and GREASE, Alpha Out Now

OpenSSL 4.1 promises support for the DTLS (Datagram Transport Layer Security) 1.3 protocol, support for the GREASE (Generate Random Extensions And Sustain Extensibility) mechanism to prevent extensibility failures in the TLS ecosystem, support for the IKEV2 KDF cryptographic mechanism, and initial support for the Elbrus2000 (e2k) architecture.

KDE Frameworks 6.30 Improves Baloo File Indexer, KWallet, and System Monitor

The monthly KDE Frameworks releases continue, and KDE Frameworks 6.30 is here to improve in-window dialogs in Kirigami-based apps to be better highlighted against the rest of the window content when using a dark theme and update Plasma System Monitor graphs to request “tabular numerals” for the legends when using a font that supports them, improving alignment.

NVIDIA 615 Linux Graphics Driver Improves Support for Vulkan-Native Games

The NVIDIA 615 graphics driver series introduces support for revision 2 of the VK_NV_low_latency Vulkan extension to enable out-of-the-box Proton support for NVIDIA Reflex in Vulkan-native games, support for cgroups-based memory partitioning, and support for the VK_EXT_cluster_acceleration_structure Vulkan extension.

MocaccinoOS 26.09 Adds x86-64-v3 Optimized Builds for Improved Performance

Still powered by the long-term supported Linux 6.18 LTS kernel series, namely Linux 6.18.50, MocaccinoOS 26.09 improves Intel CPU/platform support, including for Raptor Lake systems, improves ASUS ROG/Armoury hardware support for asusctl, and adds optional x86-64-v3 optimized builds for improved performance on supported modern CPUs.

KDE Plasma 6.7.5 Desktop Environment Is Out with Many Improvements and Fixes

Coming more than a month after KDE Plasma 6.7.4, the KDE Plasma 6.7.5 release is here to improve the way HDR content looks when using an ICC profile, improve the Spectacle utility to be faster at taking screenshots, and update Discover only to offer to open and install DEB packages on distros that natively support it.

GStreamer 1.28.7 Open-Source Multimedia Framework Adds Support for OpenCV 5

Coming about a month after GStreamer 1.28.6, the GStreamer 1.28.7 release is here to add support for building against OpenCV 5, add a missing API version suffix in the HIP support library filename, restore gap event sending in the MPEG-PS demuxer, and limit the number of remote sources being tracked in the rtprecv element.

news

Microsoft Windows 11 Caches Exploitable Malware

posted by Roy Schestowitz on May 15, 2024

Fishtank PC builds

Reprinted with permission from Cybershow. Author: Helen Plews.

Figure 1: Tom's Hardware: Fishtank PC builds.

Malware is often thought of as a human interaction with a digital device that causes an infection such as a virus or worm. We assume a human used bad authentication, or the human clicked the bad link, the human downloaded the malware…

So if we have anti-virus and anti-phish educational campaigns we should be well protected right? What about the technical side of cybersecurity, where the hardware, network equipment, end device or software vulnerability is the cause?

This article will examine a case where an operating system is able to automatically open and store a phishing email attachment, leading to potential compromise. In this case Windows 11 has been caching attachments locally to provide synchronisation across devices with the Outlook Application. In many cases, it has cached exploitable malware. This is a growing issue brought to light by Windows 11 users and anti-virus providers, instead of the makers at Microsoft.

Dropper Investigation

I am a life-long gamer and from experimentation over the years, I know I have the best rig, a customisable gaming PC. It’s very nice hardware it looks stunning with rainbow glowing fans and it sounds like a mini jet engine, rendering most graphics on Ultra with a graphics card which is at most 2 years old. The only issue I have had with it is in the operating system, which of course for a big gamer is Windows 11 due to its age. After just two weeks of operation I was alerted to a dropper located in my Windows Appdata folder, it was not dropping any further viruses yet as it had been caught by my expensive AV - which is why it sounds like a jet engine due to the large use of CPU!!

Was it a false positive? Well I ran the offline scan myself as my machine took 8x longer to boot. It behaved as if rebooting after a major update. There were no updates carried out, which made me suspect something amiss.

The virus location was not new to me, it is an appdata folder present in Windows 10 and Windows 11 for Windows mail in particular it processes mail syncing across devices; the full path is:

C:\Users\’Username’\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\SO\

Now I have had viruses popping up here before, in fact it has been an ongoing problem since I adopted the Windows 11 operating system (OS) in 2022 on the household laptops. Since then, both of my son’s laptops have alerted me to droppers and Trojans in the same Appdata folder. I initially assumed my children were not so good with their cybersecurity (being aged 5 and 9 that makes sense). Maybe they had clicked an email notification. Maybe they had downloaded some Trojan in the style of a game from a requested and shoddy gaming store all parents know about, stealthy and all whilst under supervision. That was until my brand new gaming rig got one.

Examining the attack timeline of my gaming rig in detail showed that a phish had been ‘clicked’ from my Hotmail account which was logged in on my Outlook App, running in the background processes (not running in my taskbar) whilst I played some epic title the night before. This ‘click’ put an infected PDF invoice on my PC, and on boot the next day activated the dropper, slowing the machine right down - which gave me a clue.

Now let's be clear about how Microsoft works, as I understand it, and why this is a gripe serious enough to warrant its own blog post.

You must sign in online to a Microsoft account to access the PC at all times, then it creates session keys for all applications that come installed as standard with the OS. So, unless you take some drastic measures I will discuss in a moment, you will undoubtedly be running sessions of Windows apps in the background; Outlook, OneDrive, Teams, Xbox, Photos, Office, Store, the list is quite extensive.

Moving on, I look for the phish email I had. According to my AV "clicked on" log, I located the suspicious subject of the email. It was something akin to;

AMAZON ACCOUNT ###U$IIHknDBWON38383y4y29~~~

Now, you do not need to be a cybersecurity expert to tell that is a phish from the subject which was located using the now foreground Outlook app. And as expected, it was unread. It showed me that within a few minutes of receiving the unread email, the attached PDF invoice was added to the Windows Communication Appdata folder, which led to the dropper found by the offline scan.

It seemed that Outlook App was saving unread attachments to the appdata folder where the virus was located. Some of the located viruses over the past two years were found on multiple devices that used the same MS credentials which unless stated otherwise, auto sync application data. That is exactly what the

microsoft.windowscommunicationsapps_8wekyb3d8bbwe

folder is for. It contains both the application data for Windows apps like Outlook to run and sync as well as data obtained in the process. I synced between my children's laptops as my account was the administrator for the network, it kept them safer online. Or so I thought.

Vulnerability Research

So I start down the usual process of researching the vulnerability to find a permanent mitigation. I find nothing at first, no CVE, no reports. I do find some details on the MS community website like this one from "2020 Trojan Found and Deleted"… but it Returns (Trojan: HTML/Phish.AB!MSR) . It is here I see the same problem and I see a response from an expert.

“The trojan is an email attachment synced to your PC. Do you have some Hotmail or Microsoft email setup in an email client applications like Outlook?” - Independent Expert, MS Community, 2020

So I search all around this topic and I cannot find anything from Microsoft about this issue right away, but I do find many victims. Anti-Virus companies, affected users and experts alike are all drawing attention to this problem. Eventually, thanks to Reddit I find a similar experience from a commentor who managed to find the reported exploit listed by Microsoft. You can find many more threads on the issue on Reddit with a search.

“Looking into the report we have a "Exploit:O97M/CVE-2017-11882.AZA!MTB" match, which doesn't seem to be that ominous since it requires the file to be executed on a non-updated Office/WordPad, still it ain't something I'd like to find lying around because the app found it was a good thing to download it, without my consent.” - JVMTG, Reddit, 2023

It is a known software error marked as severe on their own security intelligence website, with 24 exploits under the O97M CVE. I’d like to say I have more details from Microsoft but I do not, instead they offer very little default cybersecurity steps, such as "remain up to date and don’t click a phish".

This does seem rather severe. It locally caches attachments from emails including those which have not been opened to the windowscommunicationsapps folder from the Outlook App. It will then auto sync the data in the folder to all devices using the same credentials in their Outlook App on their phones, laptops, desktops, anywhere the Outlook App runs.

The only step missing for a full compromise is that infected files are auto-run… a feature I feel sure Microsoft are working on at this exact moment!

Attacks are becoming more complex, in 2022 they were able to add the dropper, which very slowly downloaded a fairly rubbish Trojan, which was easily removed. Recently there were 74 password protected files and multiple Trojans appearing as game applications in the same appdata folder. These were located only weeks after a fresh OS install and could not be explained by known activities on the machine or entirely resolved by AV due to the encryption of the folders they were located in.

Impact

Take a moment to think about how many commercial users of the Outlook application have auto-sync enabled in daily use. All those using Office 365 who sync between devices on their smartphone, personal devices and company equipment, or amongst family member's tablets and laptops. You should be concerned. And then get mad as hell, because it seems Microsoft have created their own quite special service for propagating malware, one that's been ongoing since at least 2020.

I have wasted countless hours re-installing OS’s, searching files, reading reports and researching this issue to find my only salvation in Reddit. Reddit of all places! This looks like something Microsoft rather wanted to sweep under the rug.

If you sync with Outlook App between devices with the same MS account, you are vulnerable to this malware propagation. Microsoft insist users take advantage of auto-synced features across devices and use this as a clear marketing tool especially for commercial settings. It seems my trust in this feature was misplaced.

Mitigation And Loss of Trust

Some will say that this is "just a feature" of sync. I disagree because like so many Microsoft processes it feels out of control. It does not just synchonise expected user data. It inappropriately populates and copies undocumented files into system folders and, without any knowledge or intervention from the user, replicates them across devices.

The mitigation is you must live without synchronisation in Microsoft applications. So far it has worked 100%. Turning off sync across applications does work. This can be done during an OS install by refusing all sync options when prompted. You must also make sure it is off in the account settings for the user. This can be done from the settings panel when logged on to Windows. There are many guides available like this one from Process.st. Even with sync off, you can still access email and other services using the web applications, which will sync files and emails but will not store these to the local machine.

If like myself, you have lost trust in the applications themselves, removing windows apps entirely may be more fitting, this allows the folder

microsoft.windowscommunicationsapps_8wekyb3d8bbwe

to be deleted and does not appear, like a lurking background threat at a later date just in case you change your mind. My gaming rig has only one MS app remaining, Xbox and that is the way it will stay until the situation is openly discussed by MS and the vulnerability resolved. No more Appdata Phishes please.

In summary, no amount of phishing training will prevent a bad design in the operating system. Caching malware infected attachments to system folders and replicating them is bad design in my opinion. In this case, the operating system has been phished, not the human.

Other Recent Tux Machines' Posts

Ubuntu 26.10 reveals new official wallpaper, mascot art
The official wallpaper for the upcoming Ubuntu 26.10 ‘Stonking Stringray’ release has been revealed
KDE Frameworks 6.30 Improves Baloo File Indexer, KWallet, and System Monitor
KDE Frameworks 6.30 open-source software suite is out now with improved support for Kirigami-based apps, Plasma System Monitor, Baloo file indexer, KWallet app, and more.
today's leftovers
BSD, GNU/Linux, and more
Red Hat's Latest Firehose of Slop (Plagiarism) Hype and Marketeering
really awful
Ubisoft Does Not Like GNU/Linux, Blocks Users (Despite Full Compatibility)
DRM lovers wants rootkits
Asahi Linux takes on Apple M3, minus a few creature comforts
The Asahi Linux gang has announced support for Apple's M3 silicon
KDE, Plasma, Gwenview Replacement, and Harmonicon Weekly Update
KDE news picks
Good News! CERN is Migrating Over 2,200 Control Systems to Debian 13
The migration would move accelerator control computers out of the Red Hat ecosystem
 
Calamares 3.4.3 Linux Graphical Installer Improves Disk Partitioning, Locale
Calamares 3.4.3 open-source universal graphical installer for GNU/Linux distributions is now available for download with improvements to disk partitioning, locale, and Wayland support.
KDE Gear 26.08.1 Is Out with More Improvements for Your Favorite KDE Apps
KDE Gear 26.08.1 is now available as the first maintenance update to the latest KDE Gear 26.08 open-source software suite series with fixes for various KDE applications.
Red Hat Still Morbidly Obsessed With Promotion of Slop Plagiarism
the bubble act
Android Leftovers
Google Maps finally added features that make it worth using on Android Auto
Arch Linux is not hard to install, by the way
Have you ever wondered why Arch Linux users can’t stop mentioning that they use Arch
These obscure Linux utilities solve problems you didn’t know you had
Firefox, GIMP, and LibreOffice are the obvious, popular apps that you'll see everyone recommend for your Linux system
Best Free and Open Source Software, howtos and Installations
We recommend the best free and open source alternatives
Fedora Asahi Remix – Fedora Linux for Apple Silicon Macs
Fedora Asahi Remix is a Fedora-based Linux distribution designed specifically for Apple Silicon Macs
Tame Firefox UI ergonomics with a non-default Mozilla theme
Every few weeks, Mozilla releases a new version of Firefox
Today in Techrights
Some of the latest articles
Latest From LWN (Outside Paywall) and Latest GAFAM Layoffs
assorted picks
OpenSSL 4.1 Promises Support for DTLS 1.3, IKEV2 KDF, and GREASE, Alpha Out Now
OpenSSL 4.1 is now available for public testing with an alpha version adding support for DTLS 1.3, IKEV2 KDF, and GREASE, as well as other improvements.
NVIDIA 615 Linux Graphics Driver Improves Support for Vulkan-Native Games
NVIDIA 615.71.09 graphics driver is now available for download with improved support for Vulkan-native games, improved support for NVIDIA Smooth Motion, and Wayland fixes.
Free, Libre, and Open Source Software Leftovers
FOSS and more
Web Browsers/Web Servers: Server Side Rendering, Ladybird, and Firefox
mostly Firefox
Programming Leftovers
Development picks
GNU/Linux and BSD Leftovers
related picks, mixed
Kubernetes v1.37 and KYAML in View
some KYAML stuff and more
FreeCORE, OpenBSD, and FreeBSD 14.5
BSD leftovers
Canonical/Ubuntu: Qualcomm Dragonwing, Stonking Stingray, and WSL Lies From a Microsoft Site Still Circulating
Ubuntu stories
Events and Educational Highlights: RustConf, LibreOffice Conference, and More
half a dozen picks today
Security Leftovers
Security patches and more
Almost 1000 New Holes in Microsoft's Stuff, But 'Linux' Foundation Presents Microsoft as 'Secure' and Security Expert
bad news for LF
today's howtos
Instructionals/Technical picks
Games: Preservation Program, Wanderburg, Deadzoned, and More
gaming related news
Linux Devices, Open Hardware, and Modding Projects
hardware picks
Android Leftovers
10 Android settings I always keep disabled
These 10 Linux commands showed me how much better life is off Windows
When I first switched to Linux from Windows, I was intimidated by the terminal
5 popular Arch distros ranked by how much babysitting they need
Arch Linux has a reputation for being an operating system you build for yourself rather than one that comes built for you
GNOME 51 Release Candidate is Available for Testing
GNOME 51, the Linux desktop expected to be default in Ubuntu 26.10 and Fedora Workstation 45
Best Free and Open Source Software, and many more
We recommend the best free and open source alternatives
Pulsar OS – Linux distribution with a macOS-style workflow
Pulsar OS is a desktop Linux distribution designed to reproduce the workflow and familiarity of other operating systems while retaining the flexibility of Linux
KDE Plasma 6.7.5 Desktop Environment Is Out with Many Improvements and Fixes
KDE Plasma 6.7.5 is now available as the fifth maintenance update to the KDE Plasma 6.7 desktop environment series with more improvements and bug fixes.
ODROID-M1S goes Lite with 2GB RAM, NVMe and 4K video
The standard ODROID-M1S supports Android 11, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS
i.MX95 SMARC module offers LPDDR5, Wi-Fi 6 and PCIe Gen3
Software support is based on Linux and Yocto
Europe at Almost 7% GNU/Linux (Desktop/Laptop Share) [original]
World's largest economies leave Windows behind
Today in Techrights
Some of the latest articles
MocaccinoOS 26.09 Adds x86-64-v3 Optimized Builds for Improved Performance
MocaccinoOS 26.09 distribution is now available for download with optional x86-64-v3 optimized builds for improved performance on supported modern CPUs, improved Intel CPU/platform support, and other changes.
Thomas Günther Moving to GNU/Linux, OpenSUSE Talks About GAFAM-Sponsored Work
a couple more picks
Audiocasts/Shows: This Week in Linux, Rubenerd Show, and Late Night Linux
3 new episodes
Debian: Development Report by Colin Watson, Freexian, New Debian Developers and Maintainers
Debian news
Free, Libre, and Open Source Software Leftovers
GNU and more
LibreOffice Highlights/Spotlights Tulio Macedo, The Document Foundation Collaborates With GNU/Linux Hardware Vendor
LibreOffice picks
Content Management Systems (CMS): WordPress Aims for Quantity, TCMS 16.4 is Out
CMS news
FreeBSD 14.5-RELEASE and NetBSD 9.5, NetBSD Google Summer of Code
BSD leftovers
Next Ubuntu, RISC-V, and Bugs
Canonical/Ubuntu news
Open Hardware/Modding: Raspberry Pi, Buildroot 2026.08, and More
Linux devices and more
Graphics: Mesa and Lossless Scaling Frame Gen for Linux
Graphics stories
Consoles/Emulation: ScummVM, RPCS3, PlayStation 5 Linux Project
3 picks for today
Games: GTA, Oldies, Chess, and More
gaming on GNU/Linux and more
Fedora-based Bazzite Linux 44, Red Hat Flaunting Slop, and More
Red Hat and IBM
Security Leftovers
Security related picks
Programming Leftovers
Development news/views
Benchmarks for Games Shows GNU/Linux Performs Better Than Windows
2 picks about this
Applications: Albert and CoolerControl
GNU/Linux software news
today's howtos
Instructionals/Technical picks
Linux 7.3-rc2
Another Sunday afternoon, another -rc
Open Hardware/Modding: Weekly GNU-like Mobile Linux Update, Adafruit, and Raspberry Pi
hardware picks
Servers: Podman, Hosting in Europe, and Troubleshooting Tip
Podman and more
Android Leftovers
Goodbye Chrome — Firefox finally became the Android browser I always wanted
I finally found a Linux music player that feels better than Spotify's desktop app
I like to test out different music/media players on Linux every so often
I dual-booted Linux for a year, then deleted Windows and never thought about it again
I knew I wanted to give Linux a try
YuzukiNeko – A Linux-capable Allwinner F101 RISC-V SBC with Raspberry Pi Pico form factor
YuzukiHD has made another open-source hardware Linux SBC
Best Free and Open Source Software
This is free and open source software
A Clanker Pitted Fedora Against Windows 11. Fedora Won, Mostly
PhoneBuff's automated test found Windows 11 ahead only at launching Cyberpunk 2077
Project Final Report: Adding Debug Adapter Protocol Support to GJS
How to debug a GJS application in Zed using DAP support
Stable kernels: Linux 7.2.4, Linux 6.18.50, and Linux 6.12.109
I'm announcing the release of the 7.2.4 kernel
Microsoft Crisis in the US [original]
in US laptops and desktops, according to Cloudflare, GNU/Linux is now measured at about 20%
Today in Techrights
Some of the latest articles
GStreamer 1.28.7 Open-Source Multimedia Framework Adds Support for OpenCV 5
GStreamer 1.28.7 open-source multimedia framework is now available for download with support for building against OpenCV 5, missing API version suffix in HIP support library filename, and other changes.