[Findings on 17 Apr 2026 Friday] Now I believe APT hackers did not hack into my pfsense firewall based on FreeBSD at home
Subject: [Findings on 17 Apr 2026 Friday] Now I believe APT hackers did not hack into my pfsense firewall based on FreeBSD at home
Good day from Singapore,
Today 17 Apr 2026 Friday, I discovered that Kiwi Syslog Server on my Windows 11 Home edition home desktop computer had stopped receiving firewall logs at 4.47 AM in the morning.
Upon checking Windows Event Viewer logs, I found out that Windows Update had caused my Windows 11 Home Edition home desktop computer to restart.
17/4/2026 4:44:29 am:
The process C:\Windows\uus\packages\preview\AMD64\MoUsoCoreWorker.exe (TEO-EN-MING-PC) has initiated the restart of computer TEO-EN-MING-PC on behalf of user NT AUTHORITY\SYSTEM for the following reason:
Operating System: Service pack (Planned)
Reason Code: 0x80020010
Shutdown Type: restart
Comment:
17/4/2026 4:49:55 am:
The process C:\Windows\servicing\TrustedInstaller.exe (TEO-EN-MING-PC) has initiated the restart of computer TEO-EN-MING-PC on behalf of user NT AUTHORITY\SYSTEM for the following reason: Operating System: Upgrade (Planned)
Reason Code: 0x80020003
Shutdown Type: restart
Comment:
My best guess is this: After syslogd in my pfsense firewall with FreeBSD at home failed to send firewall logs to Kiwi Syslog Server for many hours or many days, syslogd process will hang and completely stop all logging in my
pfsense firewall with FreeBSD at home.
Hence, at this point in time, I believe that Advanced Persistent Threats (APT) hackers did not hack into and compromise my pfsense firewall with FreeBSD at home.
I have implemented a workaround to the above problem with Windows 11 updates by creating Cron jobs to restart syslogd in my pfsense firewall with FreeBSD at home 3 times daily.
Then Kiwi Syslog Server in Windows 11 will continue to receive firewall logs from my pfsense firewall with FreeBSD at home.
Alternatives would be to implement Linux-based or BSD-based syslog servers instead of Kiwi Syslog Server which is frequently subjected to Windows Updates and reboots.
Regards,
Mr. Turritopsis Dohrnii Teo En Ming
Extremely Democratic People's Republic of Singapore
17 Apr 2026 Friday 11.52 am Singapore Time
REFERENCES
=============
[1] https://lists.freebsd.org/archives/freebsd-amd64/2026-April/000247.html
[2] mail-archive.com - NIL
[3] https://marc.info/?l=freebsd-amd64&m=177640064130912&w=2
Comments
Post a Comment