Tux Machines

Do you waddle the waddle?

Other Sites

Internet Society

What Happens When a Community Wires Itself: Lessons from Colville on the Power of Indigenous-Led Connectivity

When commercial Internet providers declined to serve the Colville Reservation in Washington, United States, the Confederated Tribes of the Colville Reservation decided to build their own network. By connecting tribal offices, schools, and community centers, they strengthened the infrastructure the community relies on daily. A recent study examines what changed after the network went live and offers evidence that connectivity can support local economic opportunity.

LinuxGizmos.com

nRF54LC10A SoC features Cortex-M33, RISC-V coprocessor, Bluetooth LE, Thread and Zigbee

Nordic Semiconductor has expanded its nRF54L Series with the nRF54LC10A, an entry-level multiprotocol SoC aimed at compact, cost-sensitive IoT devices. The chip integrates a 128MHz Arm Cortex-M33, a 128MHz RISC-V coprocessor, 1MB of non-volatile memory, 192KB of RAM, and a 2.4GHz radio supporting Bluetooth LE, Thread, Zigbee, Matter, and proprietary protocols.

Coin-sized Radxa rCore-Q8550 module features 48-TOPS NPU and PCIe Gen 4

Described by Radxa as its flagship edge AI module, the rCore-Q8550 targets robotics and machine vision with the Qualcomm Dragonwing QCS8550 platform and an optional Hexagon AI processor delivering up to 48 Dense INT8 TOPS. The 36 x 32mm module also supports up to 16GB of LPDDR5X, 128GB of UFS 3.1 storage, PCIe Gen 4, and six four-lane MIPI-CSI interfaces.

CompuLab i.MX952 Linux-capable module showcases 2.5GbE, Wi-Fi 6 and PCIe Gen 3

CompuLab has introduced the UCM-iMX952, a 28 x 40mm System-on-Module based on NXP’s i.MX952 processor. The module supports up to 16GB of LPDDR5 or LPDDR4X memory and 128GB of eMMC storage, along with PCIe Gen 3, 2.5GbE, Wi-Fi 6, Bluetooth 5.4, and multiple display and camera interfaces.

OpenMote turns a Wiimote-style remote into an ESP32-S3 Home Assistant controller

Hat & Hammer has launched a Crowd Supply campaign for OpenMote, a programmable universal remote built around an ESP32-S3-WROOM-1 module. The device supports infrared transmission and reception, Bluetooth LE, Wi-Fi, motion sensing, audio, haptic feedback, and Qwiic/STEMMA QT expansion, while also targeting smart-home and game-controller applications.

9to5Linux

Calibre 9.15 E-Book Manager Introduces “Create Your Own Adventure” Writing Game

Coming three weeks after Calibre 9.14, the Calibre 9.15 release introduces a new, optional AI feature called “Create your own adventure”, which lets you create interactive storytelling with an AI model managing the world you create. As with all AI features, this one isn’t enabled by default.

PipeWire 1.6.9 Improves Bluetooth, JACK, ALSA Plugin, Pulse Server, and More

Coming two months after PipeWire 1.6.8, the PipeWire 1.6.9 release improves JACK object callbacks to avoid reporting old removed objects, adds the node.network=true option to network sinks and sources so that pavucontrol and others don’t wake them up, and improves the FC and LFE volumes when upmixing is enabled.

HP Linux Imaging and Printing (HPLIP) 3.26.6 Drivers Add Support for More Printers

HPLIP 3.26.6 adds support for printers in the HP ScanJet Enterprise Flow series, including HP ScanJet Enterprise Flow N9000 sn1 and HP ScanJet Enterprise Flow 9000 s1, as well as printers in the HP ScanJet Pro series, such as the HP ScanJet Pro 4200 s1.

Ubuntu 26.10 “Stonking Stingray” Snapshot 4 Is Out for Public Testing with Linux 7.2

Development of Ubuntu 26.10 (codename Stonking Stingray) kicked off on April 30th, 2026, with the usual toolchain upload, based on the Ubuntu 26.04 LTS (Resolute Raccoon) release. Ubuntu 26.10 Snapshot 4 is running the latest and greatest Linux 7.2 kernel series.

schestowitz.com

Money is Not a Noble Goal

10cc – Art For Art’s Sake

Writing Books

Writing one isn’t the hard part (some use LLM slop)

Lowering Our Carbon Footprint and Planning to Visit the Court of Appeal

Application already in progress

Climate Change is Banging on Our Doors

What will we as individuals do about it?

32 Years With IRC

IRC was created 38+ years ago

Enjoying the Simplest Things

Long break between the last September 2026 match, then comes a really hard match in Anfield (October 2026)

Our 15th Year

Starting today

Sign of Life: Will Wikileaks Announce Turning 20 Next Month?

‘Proof of life’

I Would Simply Not Assert That I Have Reputation If I Were a Potty-mouth Who Cannot Get Even a Single ‘Like’ in 2+ Hours

Cursing all day long like a drunkard

When Your Identity Becomes “Politics”

They say it’s politics, then the debate ends

news

Microsoft Windows 11 Caches Exploitable Malware

posted by Roy Schestowitz on May 15, 2024

Fishtank PC builds

Reprinted with permission from Cybershow. Author: Helen Plews.

Figure 1: Tom's Hardware: Fishtank PC builds.

Malware is often thought of as a human interaction with a digital device that causes an infection such as a virus or worm. We assume a human used bad authentication, or the human clicked the bad link, the human downloaded the malware…

So if we have anti-virus and anti-phish educational campaigns we should be well protected right? What about the technical side of cybersecurity, where the hardware, network equipment, end device or software vulnerability is the cause?

This article will examine a case where an operating system is able to automatically open and store a phishing email attachment, leading to potential compromise. In this case Windows 11 has been caching attachments locally to provide synchronisation across devices with the Outlook Application. In many cases, it has cached exploitable malware. This is a growing issue brought to light by Windows 11 users and anti-virus providers, instead of the makers at Microsoft.

Dropper Investigation

I am a life-long gamer and from experimentation over the years, I know I have the best rig, a customisable gaming PC. It’s very nice hardware it looks stunning with rainbow glowing fans and it sounds like a mini jet engine, rendering most graphics on Ultra with a graphics card which is at most 2 years old. The only issue I have had with it is in the operating system, which of course for a big gamer is Windows 11 due to its age. After just two weeks of operation I was alerted to a dropper located in my Windows Appdata folder, it was not dropping any further viruses yet as it had been caught by my expensive AV - which is why it sounds like a jet engine due to the large use of CPU!!

Was it a false positive? Well I ran the offline scan myself as my machine took 8x longer to boot. It behaved as if rebooting after a major update. There were no updates carried out, which made me suspect something amiss.

The virus location was not new to me, it is an appdata folder present in Windows 10 and Windows 11 for Windows mail in particular it processes mail syncing across devices; the full path is:

C:\Users\’Username’\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\SO\

Now I have had viruses popping up here before, in fact it has been an ongoing problem since I adopted the Windows 11 operating system (OS) in 2022 on the household laptops. Since then, both of my son’s laptops have alerted me to droppers and Trojans in the same Appdata folder. I initially assumed my children were not so good with their cybersecurity (being aged 5 and 9 that makes sense). Maybe they had clicked an email notification. Maybe they had downloaded some Trojan in the style of a game from a requested and shoddy gaming store all parents know about, stealthy and all whilst under supervision. That was until my brand new gaming rig got one.

Examining the attack timeline of my gaming rig in detail showed that a phish had been ‘clicked’ from my Hotmail account which was logged in on my Outlook App, running in the background processes (not running in my taskbar) whilst I played some epic title the night before. This ‘click’ put an infected PDF invoice on my PC, and on boot the next day activated the dropper, slowing the machine right down - which gave me a clue.

Now let's be clear about how Microsoft works, as I understand it, and why this is a gripe serious enough to warrant its own blog post.

You must sign in online to a Microsoft account to access the PC at all times, then it creates session keys for all applications that come installed as standard with the OS. So, unless you take some drastic measures I will discuss in a moment, you will undoubtedly be running sessions of Windows apps in the background; Outlook, OneDrive, Teams, Xbox, Photos, Office, Store, the list is quite extensive.

Moving on, I look for the phish email I had. According to my AV "clicked on" log, I located the suspicious subject of the email. It was something akin to;

AMAZON ACCOUNT ###U$IIHknDBWON38383y4y29~~~

Now, you do not need to be a cybersecurity expert to tell that is a phish from the subject which was located using the now foreground Outlook app. And as expected, it was unread. It showed me that within a few minutes of receiving the unread email, the attached PDF invoice was added to the Windows Communication Appdata folder, which led to the dropper found by the offline scan.

It seemed that Outlook App was saving unread attachments to the appdata folder where the virus was located. Some of the located viruses over the past two years were found on multiple devices that used the same MS credentials which unless stated otherwise, auto sync application data. That is exactly what the

microsoft.windowscommunicationsapps_8wekyb3d8bbwe

folder is for. It contains both the application data for Windows apps like Outlook to run and sync as well as data obtained in the process. I synced between my children's laptops as my account was the administrator for the network, it kept them safer online. Or so I thought.

Vulnerability Research

So I start down the usual process of researching the vulnerability to find a permanent mitigation. I find nothing at first, no CVE, no reports. I do find some details on the MS community website like this one from "2020 Trojan Found and Deleted"… but it Returns (Trojan: HTML/Phish.AB!MSR) . It is here I see the same problem and I see a response from an expert.

“The trojan is an email attachment synced to your PC. Do you have some Hotmail or Microsoft email setup in an email client applications like Outlook?” - Independent Expert, MS Community, 2020

So I search all around this topic and I cannot find anything from Microsoft about this issue right away, but I do find many victims. Anti-Virus companies, affected users and experts alike are all drawing attention to this problem. Eventually, thanks to Reddit I find a similar experience from a commentor who managed to find the reported exploit listed by Microsoft. You can find many more threads on the issue on Reddit with a search.

“Looking into the report we have a "Exploit:O97M/CVE-2017-11882.AZA!MTB" match, which doesn't seem to be that ominous since it requires the file to be executed on a non-updated Office/WordPad, still it ain't something I'd like to find lying around because the app found it was a good thing to download it, without my consent.” - JVMTG, Reddit, 2023

It is a known software error marked as severe on their own security intelligence website, with 24 exploits under the O97M CVE. I’d like to say I have more details from Microsoft but I do not, instead they offer very little default cybersecurity steps, such as "remain up to date and don’t click a phish".

This does seem rather severe. It locally caches attachments from emails including those which have not been opened to the windowscommunicationsapps folder from the Outlook App. It will then auto sync the data in the folder to all devices using the same credentials in their Outlook App on their phones, laptops, desktops, anywhere the Outlook App runs.

The only step missing for a full compromise is that infected files are auto-run… a feature I feel sure Microsoft are working on at this exact moment!

Attacks are becoming more complex, in 2022 they were able to add the dropper, which very slowly downloaded a fairly rubbish Trojan, which was easily removed. Recently there were 74 password protected files and multiple Trojans appearing as game applications in the same appdata folder. These were located only weeks after a fresh OS install and could not be explained by known activities on the machine or entirely resolved by AV due to the encryption of the folders they were located in.

Impact

Take a moment to think about how many commercial users of the Outlook application have auto-sync enabled in daily use. All those using Office 365 who sync between devices on their smartphone, personal devices and company equipment, or amongst family member's tablets and laptops. You should be concerned. And then get mad as hell, because it seems Microsoft have created their own quite special service for propagating malware, one that's been ongoing since at least 2020.

I have wasted countless hours re-installing OS’s, searching files, reading reports and researching this issue to find my only salvation in Reddit. Reddit of all places! This looks like something Microsoft rather wanted to sweep under the rug.

If you sync with Outlook App between devices with the same MS account, you are vulnerable to this malware propagation. Microsoft insist users take advantage of auto-synced features across devices and use this as a clear marketing tool especially for commercial settings. It seems my trust in this feature was misplaced.

Mitigation And Loss of Trust

Some will say that this is "just a feature" of sync. I disagree because like so many Microsoft processes it feels out of control. It does not just synchonise expected user data. It inappropriately populates and copies undocumented files into system folders and, without any knowledge or intervention from the user, replicates them across devices.

The mitigation is you must live without synchronisation in Microsoft applications. So far it has worked 100%. Turning off sync across applications does work. This can be done during an OS install by refusing all sync options when prompted. You must also make sure it is off in the account settings for the user. This can be done from the settings panel when logged on to Windows. There are many guides available like this one from Process.st. Even with sync off, you can still access email and other services using the web applications, which will sync files and emails but will not store these to the local machine.

If like myself, you have lost trust in the applications themselves, removing windows apps entirely may be more fitting, this allows the folder

microsoft.windowscommunicationsapps_8wekyb3d8bbwe

to be deleted and does not appear, like a lurking background threat at a later date just in case you change your mind. My gaming rig has only one MS app remaining, Xbox and that is the way it will stay until the situation is openly discussed by MS and the vulnerability resolved. No more Appdata Phishes please.

In summary, no amount of phishing training will prevent a bad design in the operating system. Caching malware infected attachments to system folders and replicating them is bad design in my opinion. In this case, the operating system has been phished, not the human.

Other Recent Tux Machines' Posts

Valve Quietly Open-Sources Its Android Compatibility Layer
The Lepton project is aimed at game developers who want to bring VR-focused Android titles over to Steam Frame
Software Freedom Day (2026) Celebrated in At Least Four Continents [original]
in Australia two such events have already ended
Ubuntu 26.10 “Stonking Stingray” Snapshot 4 Is Out for Public Testing with Linux 7.2
Ubuntu 26.10 “Stonking Stingray” Snapshot 4 is now available for public testing for early adopters and application developers.
openSUSE and Fedora/Red Hat, Another Slopfest
lots of slop promotion
GNOME Updates: Patrik Sivek, Allan Day (IBM), Alice Mikhaylenko, Sam Thursfield
GNOME posts
EasyOS Updates and Advice, Bugfixes Reported
EasyOS updates from BK
LLM Slop is Ruining Projects Dealing With Sony Consoles
several reports
GNOME 51 “A Coruña” Desktop Environment Officially Released, This Is What’s New
GNOME 51 desktop environment is now available as a major release that introduces numerous new features and improvements. Here’s what’s new!
Spending Our Fifteenth Year Fighting for Britain's Digital Sovereignty [original]
Against Imperialism
 
Games: Factorio, EVE Vanguard, BELTFED, and More
GamingOnLinux picks
Android Leftovers
The end of Android Fire Sticks is coming, here's what to expect
PearOS is the MacOS of Linux, and the latest version is better than ever
With the latest release, the developer refines pearOS' Liquid Glass look with a host of improvements
My 5 favorite Linux distros for AI – and why
If you want to use AI with Linux
4 innocent-looking Linux commands that can ruin your day
If you use Linux, you'll eventually want to get comfortable with the terminal
CachyOS is how I finally understood Arch Linux without the installation nightmare
When I came across CachyOS
TechRefreshing Linux – beginner-friendly Debian-based desktop distribution
TechRefreshing Linux, also known as TR Linux
Inside Linux-AI OS: I tested a distro with built-in local AI
Linux AI OS is another distribution that includes AI
My 6 favorite Microsoft Office alternatives for Linux – and why
Here are my favorite Linux office suites
Best Free and Open Source Software
This is free and open source software
Linux 95 – lightweight distribution recreating the Windows 95 experience
Linux 95 is a minimalist Linux distribution designed to recreate the look and feel of Microsoft Windows 95 while retaining a modern Linux foundation
This Week in Plasma: Let the Polishing Begin
This week, Plasma folks shifted to bug-fixing and polishing work for Plasma 6.8. As of the time of writing
This Week in GNOME: #266 Fifty One!
Update on what happened across the GNOME project in the week from September 11 to September 18
Slimbook Executive report 15 - The good streak did not last
Very silly and not a good look for the Plasma desktop
Today in Techrights
Some of the latest articles
GNU/Linux and BSD Leftovers
mostly GNU/Linux
Free, Libre, and Open Source Software, Standards, and Digital Sovereignty
common motif
Content Management Systems (CMS) / Static Site Generators (SSG): 11ty, WordPress, and Kiwi TCMS 16.5
3 platforms for the Web
Linux-Centric Devices and Open Hardware
hardware picks
Canonical/Ubunt: Upselling Patches, Android Development, and Slop
3 picks
Security Leftovers
Security bugs and more
Mozilla Promotes Slop and Spying, Mozilla Firefox Nightly Report
Firefox and more
This Week In Rust, Weird Security Advice, and Copycats of GNU Whose Purpose is to Remove Copyleft (Reciprocity) and Put Microsoft in Control
Rust picks
Programming Leftovers
Development related news
Applications and Games: ScummVM, PostgreSQL/pgAdmin, and More
4 stories for now
NVIDIA and SteamOS (valve) Target GNU/Linux Gamers
3 picks for today
GNU/Linux Approaching 10% in Cameroon, a Very Large Country (53rd in the World by Area, 51st by Population) [original]
Based on what Cloudflare sees coming from Cameroon, almost 1 in 10 desktop/laptop (thick client) requests comes from GNU/Linux
Games: Forefront, Aniimo, and More
5 stories from GamingOnLinux
BSD: NetBSD, Google Summer of Code 2026, and OpenBSD Routing Table
BSD leftovers
Open Hardware/Modding: Weekly GNU-like Mobile Linux Update, ESP32, and Adafruit
hardware leftovers
today's howtos
Instructionals/Technical
Calibre 9.15 E-Book Manager Introduces “Create Your Own Adventure” Writing Game
Calibre 9.16 open-source e-book manager is now available for download with the ability to write interactive storytelling with an AI managing the world you create, and other changes.
Android Leftovers
Google killed Duo, and Android video calling has never really recovered
Free and Open Source Software
This is free and open source software
FangOS – Arch-based KDE Plasma Linux distribution
FangOS is an Arch-based Linux distribution built around the KDE Plasma desktop
Planet KDE: Meet Marknote's New Block Editor
A block editor is an easy to use rich text editor which treats every component of your text as a block
CompuLab i.MX952 Linux-capable module showcases 2.5GbE, Wi-Fi 6 and PCIe Gen 3
For software, CompuLab lists Debian Linux, Yocto Project, and RTOS support, along with Board Support Packages
Software Freedom Day 2026 Events at Melbourne PC User Group and Inspire9 at Melbourne, Events Planned in Canada and Europe as Well [original]
there are events in less than 24 hours in Melbourne PC User Group and Inspire9 at Melbourne
Today in Techrights
Some of the latest articles
PipeWire 1.6.9 Improves Bluetooth, JACK, ALSA Plugin, Pulse Server, and More
PipeWire 1.6.9 audio/video server for Linux is now available for download with improved JACK object callbacks, improved passthrough format handling in audioconvert, and more.
HP Linux Imaging and Printing (HPLIP) 3.26.6 Drivers Add Support for More Printers
HP Linux Imaging and Printing (HPLIP) 3.26.6 drivers are now available for download with support for new HP printers.
Security Leftovers
Security picks
Android Leftovers
I only use my phone in landscape mode, and this Android launcher respects my decision
Free, Libre, and Open Source Software and More
FOSS leftovers for the most part
LibreOffice and Euro-Office Picks
office suites leftovers
GNU/Linux and UNIX Leftovers
mostly GNU/Linux
Fedora, Flatpack, and GNOME
3 picks
FSF for Software Freedom, OSI for Openwashing and Slop (Plagiarism)
4 picks
Mozilla Leftovers
Mozilla picks
Debian and Ubuntu Leftovers
3 stories
Open Hardware/Modding: Fairphone, ESP32, and More
hardware leftovers
SUSE/OpenSUSE: Tumbleweed ARM and Real-Time Enterprise Linux
SUSE leftovers
FreeBSD, OpenSMTPD, and OpenBSD
BSD news
Slop in Linux and Linux 6.11 on an ESP32-S3
kernel picks
Applications: HPLIP and Nheko
pair of stories
Denuvo Lawsuit for DRM, GeForce NOW on GNU/Linux
Games and more
today's howtos
Instructionals/Technical
Fedora Linux 45 Beta Released with Linux 7.2, GNOME 51, and KDE Plasma 6.7
Fedora Linux 45 distribution is now available for public beta testing powered by Linux kernel 7.2 and featuring the GNOME 51 desktop environment. Here’s what to expect from the final release.
Best Free and Open Source Software
Only free and open source software is eligible for inclusion
ACIAH-Linux – accessible Linux Mint-based distribution
ACIAH-Linux is a Linux distribution designed to make everyday computing easier for people who may find conventional desktop interfaces difficult to use
Canonical/Ubuntu: Qualcomm Dragonwing, Stonking Stingray, and WSL Lies From a Microsoft Site Still Circulating
Ubuntu stories
KDED refactoring Progress Update!
The past couple of weeks moved on to the other half of the editor work
Still Planning to Go to the Court of Appeal [original]
we might go to the Court of Appeal, one level below the Supreme Court
Oxygen 6.8 – more polish for KDE’s classic theme
The big KDE Plasma 6.7 release ushered in the summer
Games: Big Break Showcase, SUPERHOT VR, and More
new from GamingOnLinux
IBM/Red Hat Promoting Kafka, OpenShift, Slop Plagiarism, and Fake Endorsements From "Gartner"
latest from redhat.com
Watch Out for Fake Supporters of Freedom [original]
Their aim is to exclude
Android Leftovers
Google rolling out Android 17 QPR2 Beta 5 for Pixel
Stop avoiding the Linux terminal—here's how to actually get comfortable with it
If you're new to Linux, you might wonder whether you really need to use the terminal
You don't need a powerful PC for these 8 surprisingly useful Linux projects
Keep Fedora, Ubuntu, Debian, Alpine, and other installers on the server
Linux taught me these 5 commands first, and I barely use any of them anymore
When I started using Linux, I memorized several commands and used them so often that they became muscle memory
My favorite Linux distro has been overlooked for years—here's why I use it instead of Mint or Ubuntu
Whenever you start reading about the best Linux distros for beginners
LWN on Tiered-memory Systems and TCMalloc
a couple of pages outside paywall now
Programming Leftovers
Development and Rust (politics)
Best Free and Open Source Software, and Many More
Here are our recommended free and open source alternatives
Krita 5.3.4 Released!
Today we're releasing Krita 5.3.4 and 6.0.4, containing many bugfixes and improvements across the board
Good News! CERN is Migrating Over 2,200 Control Systems to Debian 13
The migration would move accelerator control computers out of the Red Hat ecosystem
Today in Techrights
Some of the latest articles