Zoom’s Linux client reads clipboard, Android adds SELinux
Photo by Tara Winstead on Pexels
Zoom’s Linux client was observed pulling every string written to the X11 clipboard. The behavior raises immediate privacy concerns for developers and power users who rely on the clipboard for secret tokens, passwords, and code snippets.123
A Hacker News thread posted a link to a report that the Zoom desktop client on Linux reads the clipboard proactively, without user interaction. The finding sparked a flurry of comments about the lack of a permission model for clipboard access on X11. Users who run Zoom alongside other sensitive tools now have to consider a new attack surface: any process that can see the clipboard can also see what Zoom sees.1234
Android 4.2 is set to ship a suite of security upgrades that will please sysadmins. The new build embeds Security‑Enhanced Linux (SELinux) into the kernel and adds a VPN lockdown toggle that forces all traffic through a VPN or cuts off the network entirely.5
The SELinux integration appears as a status line on the About Phone screen, offering three modes: disabled, permissive (logging only) and enforcing. According to the Android teardown, the feature is optional and aimed at enterprise or government deployments rather than the consumer market. The VPN lockdown option, also discovered in the Settings APK, disables ordinary internet access unless a VPN tunnel is active, a change that could simplify compliance for organizations that require all data to travel over encrypted channels.5
Qualys announced a partnership with Red Hat to embed its Cloud Agent directly into Red Hat Enterprise Linux CoreOS and OpenShift. The integration brings continuous vulnerability discovery to the container stack without the need for privileged sidecar containers.678
The Qualys Cloud Agent is described as a lightweight daemon that typically consumes about 2 % of CPU, spiking to 5 % under load. It runs self‑updating and self‑healing code, taking a full configuration snapshot of the host and pushing it to the Qualys Cloud Platform. When the agent is baked into a container image, it enables policy‑driven monitoring and runtime blocking of unwanted behavior, regardless of where the container is instantiated.
Aaron Levey, Red Hat’s Head of Security Partner Ecosystem, said, “Qualys’ Cloud Platform and Cloud Agent helps administrators gain deeper visibility into known vulnerabilities that may be present on their Red Hat Enterprise Linux CoreOS nodes with pointers to associated Red Hat Security Advisories.” Sumedh Thakar, Qualys’s president and CEO, added, “By collaborating with Red Hat, we have built a unique approach to secure Red Hat Enterprise Linux CoreOS that provides complete control over containerized workloads enhancing Qualys’ ability to help customers discover, track, and continuously secure containers.”
These three developments illustrate a broader shift toward tighter default security on open‑source platforms. The Zoom clipboard issue shows how legacy desktop protocols like X11 still lack granular permissions, exposing user data to any well‑behaved application. Android’s SELinux enforcement and VPN lockdown reflect Google’s push to bring enterprise‑grade controls to a platform that historically prioritized openness over hardening. Qualys and Red Hat’s joint effort demonstrates that cloud‑native workloads are finally receiving the same continuous assessment that traditional VMs have enjoyed for years.12345
Historically, Linux desktop environments have treated the clipboard as a global resource. X11 provides no sandboxing, meaning any client can read or write the selection buffer at any time. Some Wayland compositors have begun to enforce per‑application policies, but most users still run X11 on their workstations. The Zoom case underscores why the community has been advocating for a permission‑based clipboard API for over a decade.1
SELinux itself originated in the early 2000s as an NSA‑backed set of kernel extensions that enforce mandatory access controls. Android adopted a permissive default for years, only enabling enforcing mode on a handful of devices. The move to expose SELinux status in the UI and to ship it as a core component of Android 4.2 signals a maturation of the platform’s security posture, aligning mobile devices with the expectations of corporate IT departments.
Container security has long suffered from the “host‑sidecar” model, where agents run with elevated privileges to monitor workloads. By embedding Qualys code directly into images, Red Hat and Qualys eliminate the need for such sidecars, reducing the attack surface and simplifying operations. The approach also dovetails with the industry’s shift toward supply‑chain scanning, where vulnerabilities are caught before containers ever run in production.7
What to watch: The Zoom client is expected to release a patched version that respects user consent for clipboard access; tracking the release notes will reveal whether the change is permanent. Android 4.2’s SELinux enforcement will be confirmed once the final OTA lands, and developers should test their apps against the new policy. Finally, the Qualys‑Red Hat integration will roll out across OpenShift clusters in the next quarter; monitoring adoption rates and any reported performance impacts will indicate how quickly enterprises embrace continuous container hardening.
Footnotes
Related Articles
Google TV Streamer’s $150 price tag forces a rethink on cheap
Google hikes its TV Streamer from $100 to $150, sparking debate over hardware pricing, security lapses, and AI copyright battles.
KOReader Gains 236 Votes on Hacker News
KOReader, SQLite tuning, Wayland multi‑cursor, Kimi K3 on M1 Max, and Codex Security each drew major attention on Hacker News, sparking deep technical discussion.
Linux Hit by Second Severe Vulnerability in Weeks
Linux faces another severe vulnerability, TanStack NPM packages compromised, and more tech news