Destination Linux Destination Linux

485: Destination Linux 485: Craig from Sandfly on Linux Malware Trends, OpenRGB Upgrades & Big Distro News

Sep 28, 2026 · 1h 8m

Summary

Hosts Ryan, Jill, and Zeb discuss community feedback regarding Arch Linux's AUR security, defending the distro against recent malware incidents. Guest Craig from Sandfly Security shares insights from his upcoming Oslo conference talk on Linux network implants, covering trends like Golang-based cross-platform malware, fileless memfd attacks, and kernel rootkits. The episode also highlights the OpenRGB 1.0 release for managing LED lighting and announces a live Discord hangout for podcast patrons.

Topics discussed

Welcome and introduction of hosts and guest Craig Announcement of the upcoming Patron Hangout on Discord Discussion on Arch Linux, AUR security, and supply chain attacks Craig's experience with Arch and general supply chain risks Jill's Arch usage and the XZ backdoor incident Sandfly Security promotional segment New Destination Linux merchandise and hat reveal Craig's upcoming talk on Linux network implants in Oslo Security concerns for open conferences and red teaming ethics Analysis of Golang malware and fileless memfd attacks How Sandfly detects in-memory malware and packed binaries IoT device vulnerabilities and proxy network risks Kernel thread masquerading and rootkit compilation risks Firmware update incompatibilities and Sandfly blog promotion Sandfly 6.0 launch plans and Systemd jokes Jill's pink setup and vintage refrigerator story OpenRGB 1.0 release features and hardware support updates Peppermint OS news and the X11 vs Wayland debate Ubuntu 26.0 kernel selection and hardware enablement MX Linux DDoS attack, updates, and community support stories
Listen ad-free on Castria