485: Destination Linux 485: Craig from Sandfly on Linux Malware Trends, OpenRGB Upgrades & Big Distro News
Sep 28, 2026 · 1h 8m
Summary
Hosts Ryan, Jill, and Zeb discuss community feedback regarding Arch Linux's AUR security, defending the distro against recent malware incidents. Guest Craig from Sandfly Security shares insights from his upcoming Oslo conference talk on Linux network implants, covering trends like Golang-based cross-platform malware, fileless memfd attacks, and kernel rootkits. The episode also highlights the OpenRGB 1.0 release for managing LED lighting and announces a live Discord hangout for podcast patrons.
Topics discussed
Welcome and introduction of hosts and guest Craig
Announcement of the upcoming Patron Hangout on Discord
Discussion on Arch Linux, AUR security, and supply chain attacks
Craig's experience with Arch and general supply chain risks
Jill's Arch usage and the XZ backdoor incident
Sandfly Security promotional segment
New Destination Linux merchandise and hat reveal
Craig's upcoming talk on Linux network implants in Oslo
Security concerns for open conferences and red teaming ethics
Analysis of Golang malware and fileless memfd attacks
How Sandfly detects in-memory malware and packed binaries
IoT device vulnerabilities and proxy network risks
Kernel thread masquerading and rootkit compilation risks
Firmware update incompatibilities and Sandfly blog promotion
Sandfly 6.0 launch plans and Systemd jokes
Jill's pink setup and vintage refrigerator story
OpenRGB 1.0 release features and hardware support updates
Peppermint OS news and the X11 vs Wayland debate
Ubuntu 26.0 kernel selection and hardware enablement
MX Linux DDoS attack, updates, and community support stories
Listen ad-free on Castria