#inotify
Researchers at the Graz University of Technology Austria demonstrated a new attack that can track you via file change events "on all systems," allowing for various data leaks.
New Attack Can Track You Across Operating Systems Without Elevated Privileges
Researchers at the Graz University of Technology Austria demonstrated a new attack that can track you via file change events "on all systems," allowing for various data leaks. > Modern operating systems like Linux, Windows, and macOS provide built-in subsystems to monitor filesystem events: inotify, ReadDirectoryChangesW, and FSEvents. User processes can subscribe to receive file-operation notifications when actions like accessing, writing, opening, and closing are performed on a monitored file or directory. While applications being able to see file change events seems rather innocuous, the researchers showed that it can actually leak a lot more than you'd think. The attack assumes an attacker that has local, unprivileged access to a system and requires read access to a set of files in order to carry it out. But the set of files that are globally readable is "vast" and still leaks enough information to compromise sensitive data. On Linux, they were able to achieve a keystroke timing attack, a type of side-channel attack that measures the timing between keypresses in order to infer information about the text being typed, including the actual text. This attack can leak passwords and any sensitive text being typed such as private messages. They were also able to perform a fingerprinting attack on the top-100 websites since visiting certain websites would trigger specific access patterns for fonts in `/usr/share/fonts/`. From just this alone, an attacker can figure out what websites you're visiting. In KDE specifically, they created a fake authentication pop up that could steal a user's password. Desktop environments implement focus-stealing protection that is meant to prevent attacks like this, but the KDE implementation is broken. Android, also a Linux-based family of operating systems, fared better than desktop Linux, but still leaks the existence of files and filenames, which can be highly revealing in a private messenger such as WhatsApp. In Windows, full paths of all files, including ones they didn't have permission to read, were accessible, an undocumented behavior. On Windows they could monitor the website visits of all users in real time. There are no false positives, since they can directly measure it rather than relying on a side-channel. On macOS, they were able to read connectivity settings such as Bluetooth activation or plugging/unplugging a network cable. Installing, updating, and other application behavior were observable as well. The researchers say they responsibly disclosed the attacks to the vendors. In particular, Microsoft stated that the the private data leakage was actually there by design.
www.privacyguides.org
September 28, 2026 at 5:43 PM
File Notification APIs in Windows, Linux, and Android Are Leaking What You Do on Your Computer #Android #Antivirus #apis
File Notification APIs in Windows, Linux, and Android Are Leaking What You Do on Your Computer
  A research team from Graz University of Technology in Austria has shown that a routine feature built into virtually every major operating system can be turned into a surveillance channel that tracks keystrokes, visited websites, and private messaging activity without needing administrator access. The feature is the file-change notification system. Every major platform ships one: Linux has inotify and fanotify, Windows uses ReadDirectoryChangesW, and Android and macOS have their own equivalents. Text editors, antivirus software, cloud sync clients, and file managers depend on these APIs to react when files are created, modified, or deleted. The catch is that subscribing to those notifications requires no special privileges, only read access to the directory being watched. What these APIs never hand over is actual file content. What they do leak, the researchers found, is file names and the exact timing of events. That combination is enough to reconstruct meaningful details about what other users on the same machine are doing throughout the day. Linux: Keystrokes Through the Filesystem On Linux, if a process is blocked from watching a specific file directly, it can still receive that file's events by watching the parent directory, as long as that directory is readable. The researchers applied this to device files under /dev that represent keyboard hardware. The result is that an unprivileged process can detect every keystroke another user makes, though not which key was pressed. That gap offers less protection than it appears to. Research going back more than two decades has established that the rhythm of inter-keystroke timing can help reconstruct what was typed. In tests with seven participants, the attack scored between 93.1% and 100% on standard accuracy measures. Input that never echoes to the screen, such as a password entered during a sudo prompt, does not generate filesystem events and stays invisible to the attack. The team also demonstrated website fingerprinting by watching which system fonts Firefox loads for a given page. Against the top 100 sites, that technique reached 87.9% accuracy. A third Linux attack targeted KDE Plasma 6 on Wayland: a malicious process running as the victim can detect when a real authentication dialog is about to appear and draw a counterfeit one over it to capture credentials before the legitimate prompt ever loads. Android: No Permissions Required On Android, an application requesting zero permissions can watch the private storage directory of a completely separate app. Testing against WhatsApp on a Google Pixel and a Samsung Galaxy device, the researchers extracted file names and event timing that revealed when photos, videos, and documents were sent or received. The attack also exposed when that media was later deleted, offering a window into communication patterns that the app's own privacy controls do not address. Windows: One Watch, Every User's Files The most consequential Windows scenario arises when a process watches the root of the system drive. Windows reports the full path of every file that changes anywhere on the machine, including paths inside other users' home directories that the monitoring account has no direct permission to access. Because Firefox names profile subdirectories after associated websites, an unprivileged user watching the drive root can track which sites another logged-in account is browsing in near-real time. Across the top 1,000 websites, the researchers hit 97.8% accuracy against Firefox and 48.5% against Edge, which creates far fewer site-named folders. This behavior comes from the same ReadDirectoryChangesW API that was flagged under CVE-2007-0843 for a similar class of issue almost two decades ago. Microsoft's position has not shifted. The company told the researchers the behavior is working as designed, on the grounds that file contents remain inaccessible. A Microsoft spokesperson told SecurityWeek that "the technique requires an attacker to already have the ability to run code locally on a device under a separate user account and does not provide access to file contents." Microsoft did note that administrators can enable optional protections it documented in April 2025 covering some path-disclosure scenarios tied to directory change notifications. macOS came out the least exposed of the four platforms. Its equivalent API can only monitor globally readable files, which limits the attack surface, though the researchers still demonstrated tracking of application launches, app interactions, and settings changes. The Linux kernel received a targeted patch under CVE-2025-68788, which stops the fsnotify subsystem from generating access and modify events for special files, including the device files representing keyboard input. The researchers describe this as addressing the most serious Linux issue, but other attack paths from their research remain open. Apple and Google have not responded to requests for comment, and no fixes have been announced for Android or macOS. The researchers say they have found no evidence of active exploitation in the wild. Proof-of-concept code for the full set of attacks has been published on GitHub at isec-tugraz/file-notification-attacks.
dlvr.it
September 28, 2026 at 3:15 PM
Nieuwe aanvalstechniek misbruikt bestandssysteemmeldingen voor heimelijke survei

Een nieuwe cross-platform aanvalstechniek, bekend als een side-channel aanval, maakt gebruik van bestandssysteem-notificatiediensten om gebruikersactiviteit te monitoren zonder de noodzaak van verhoogde systeem...
Nieuwe aanvalstechniek misbruikt bestandssysteemmeldingen voor heimelijke surveillance
Een nieuwe cross-platform aanvalstechniek, bekend als een side-channel aanval, maakt gebruik van bestandssysteem-notificatiediensten om gebruikersactiviteit te monitoren zonder de noodzaak van verhoogde systeemrechten. Deze diensten, zoals inotify op Linux, ReadDirectoryChangesW op Windows en FSEvents op macOS, waarschuwen applicaties normaal gesproken voor wijzigingen in bestanden. De aanval transformeert deze legitieme mechanismen echter in een surveillance-instrument. De aanval is gebaseerd op het observeren en correleren van de timing en bestandspaden van deze besturingssysteemmeldingen met specifieke gebruikersacties. In plaats van kwetsbaarheden in geheugen te exploiteren, maakt deze...
newsfacts.info
September 28, 2026 at 3:00 PM
September 27, 2026 at 5:02 PM
1/6

Latest Slackware current update:

18 updates

Fri Sep 25 23:47:46 UTC 2026
a/inotify-tools-4.26.262-x86_64-1.txz: Upgraded.
a/kbd-2.10.0-x86_64-5.txz: Rebuilt.
rc.font: skip fonts that don't load.
Add a couple extra font list examples.
September 26, 2026 at 2:01 AM
Изследователи от Техническия университет в Грац, Австрия са открили уязвимости в реализацията на функциите за уведомяване на операционната система за файлови операции - те засягат най-известните операционни системи Android, Linux, macOS и Windows. Поради тези уязвимости възниква риск от...
Сериозни уязвимости в Android, Linux, Windows и macOS позволяват шпиониране на потребителите чрез файлови операции
Изследователи от Техническия университет в Грац, Австрия са открили уязвимости в реализацията на функциите за уведомяване на операционната система за файлови операции - те засягат най-известните операционни системи Android, Linux, macOS и Windows. Поради тези уязвимости възниква риск от изтичане на поверителна информация. Проблемът засяга механизмите Linux inotify (от 2005 година), Google Android FileObserver (от 2008 година), Microsoft Windows ReadDirectoryChangesW (от 2000 година) и Apple macOS FSEvents (от 2007 година). Те уведомяват операционната система, че даден файл е бил отворен, променен, записан или изтрит. Тези функции не разкриват съдържанието на файловете, но информацията за събитията, свързани с тях служи като страничен канал, който помага на хипотетичен злонамерен потребител да прави изводи за действията на другите потребители на компютъра.
www.kaldata.com
September 25, 2026 at 9:06 AM
Salt beacons run in salt-minion, emit events only on change: inotify for file integrity, load/diskusage/journal for anomalies. Cheaper than cron polling. Guide for https://www.valtersit.com/vault/deploy-salt-beacons-for-realtime-file-integrity-monitoring-03507e/ #saltstack #beacons #inotify
Deploy Salt Beacons for Real-Time File Integrity Monitoring
www.valtersit.com
September 24, 2026 at 8:00 PM
TIL in Syncthing you need to turn off watching folders (inotify) when syncing a lot of files, like a new clone. With that on it copies about 10 files / second, with it off about 1000 files / second. Unclear exactly what's wrong, the AI's guess is that syncthing is seeing its own writes and […]
Original post on tech.lgbt
tech.lgbt
September 19, 2026 at 3:22 PM
FreeBSD 14.5 adds Linux-compatible inotify APIs, resolves UEFI and loader boot issues, updates LLVM and OpenSSL, and deprecates lpr printing tools.
alternativeto.net/news/2026/9...
September 8, 2026 at 11:59 PM
FreeBSD 14.5-RELEASE brings Linux-compatible inotify, updated toolchains, and fixes UEFI boot issues.
FreeBSD 14.5 makes the Unix system more suitable for everyday use.
FreeBSD 14.5-RELEASE brings Linux-compatible inotify, updated toolchains, and fixes UEFI boot issues.
www.heise.de
September 8, 2026 at 1:38 PM
FreeBSD 14.5-RELEASE bringt Linux-kompatibles inotify, aktualisierte Toolchains und behebt UEFI-Boot-Probleme.
FreeBSD 14.5 macht das Unix-System alltagstauglicher
www.heise.de
September 8, 2026 at 12:39 PM
FreeBSD 14.5-RELEASE bringt Linux-kompatibles inotify, aktualisierte Toolchains und behebt UEFI-Boot-Probleme. #FreeBSD
FreeBSD 14.5 macht das Unix-System alltagstauglicher
FreeBSD 14.5-RELEASE bringt Linux-kompatibles inotify, aktualisierte Toolchains und behebt UEFI-Boot-Probleme.
www.heise.de
September 8, 2026 at 12:24 PM
🆕 #FreeBSD 14.5-RELEASE já está disponível! 🔒 Dezenas de correções de segurança, suporte aprimorado para Macs com GPU dupla, compatibilidade com o inotify e muito mais. Saiba tudo no nosso artigo completo! -> tinyurl.com/bddssx8c
FreeBSD 14.5-RELEASE: O que mudou, por que atualizar e como fazer
Blog com notícias sobre, Linux, Android, Segurança , etc
tinyurl.com
September 8, 2026 at 11:21 AM
Files are tools. Tools are files. Agents can list, use inotify, or tail a file.

However, agents also chat with each other directly and consume from D-Bus.
September 4, 2026 at 7:23 PM
how do receivers know there‘s a new message ? inotify of some kind ?
September 4, 2026 at 7:19 PM
There are rare tutorial about inotify, even as it was maintained for ages. May be time for a new one?

reintech.io/blog/beginne...
A Beginner's Guide to the PHP Inotify Library for Filesystem Monitoring
Reintech is the hiring marketplace for software engineers — vetted on how they think, hired in days. Global employment handled.
reintech.io
August 28, 2026 at 4:48 AM
Have you used inotify in your PHP projects?

How do you monitor file changes in your development setup?

Share your experience in the comments.

4/4
August 27, 2026 at 8:00 PM