openSUSE Leap 16.1 introduces an optional Immutable Mode built on transactional updates and a read-only root filesystem. Selected during installation, the mode prevents normal-operation changes to core paths including /usr and /etc, reducing the opportunity for malicious scripts or compromised processes to persistently alter the operating system. Atomic updates also allow straightforward rollback if an update causes operational issues.
Derived from the model used in Leap Micro, the feature is aimed at container and virtual-machine hosts, edge deployments, and desktops requiring stronger configuration integrity. It complements existing Leap controls including SELinux, firewalld, compiler-based binary hardening, permission profiles, and Snapper-managed Btrfs snapshots; users can continue deploying standard mutable Leap installations where required.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
openSUSE Leap 16.1 became the first Leap release to offer an optional Immutable Mode, selectable during installation. The mode uses transactional updates and a read-only root filesystem, preventing normal modification of protected paths including /usr and /etc and supporting atomic rollback.
Beginning with Leap 16.0, openSUSE replaced AppArmor with SELinux as its mandatory access-control framework. SELinux enforces policy-based restrictions on labeled files, processes, and ports, including for root users.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.