I discovered some obfuscated code in the PDF Toolbox extension which is used by more than 2 million people. The code is meant to download a “config” file from serasearchtop[.]com after which it will run some functions according to this configuration. I didn’t see a non-empty configuration yet. However, given the specific call pattern used, I’m mostly certain that the idea here is injecting arbitrary JavaScript code into every website when it loads.

I suspect that this is part of the extension’s monetization strategy, most likely goal being injecting ads into all websites. But it could really be anything, and it might be spying on people as they enter their online banking credentials or credit card numbers.

palant.info/2023/05/16/malicio…

#Tusky v22 beta 4 is released. Only one change, but if you've been using beta 3 with multiple accounts and have been inundated with repeat notifications that's been fixed.

One caveat; if you share access to an account with multiple people and you've all been using beta 3 you'll keep getting repeat notifications until everyone's upgraded past beta 3.

This entry was edited (2 years ago)

Wer es immer noch nicht glaubt: eine mit Passwort versehene ZIP Datei darf man nicht als "sicher verschlüsselt" betrachten! Schon gar nicht in der #Microsoft #Cloud

Malware detected: Microsoft-Cloud hebelt ZIP-Passwortschutz aus
tarnkappe.info/artikel/it-sich…

Today's #AndroidAppRain at apt.izzysoft.de/fdroid brings you 8 updated and 2 added apps:

* Mobilinkd TNC: configure your Mobilinkd Battery-powered Bluetooth TNC
* SDAI: generate Stable Diffusion AI assets on your own WebUI server instance

Enjoy your #free #Android #apps with #FDroid and the #IzzySoftRepo :awesome:

FediScience is accepting registrations again.

If you have #scientist friends or colleagues still looking for a server to call home, feel free to tell them that they can sign up with us.

Basically the same admission criteria as before are in place, but we tried to broaden them a bit and explain them better.

Details are on our about page:
fediscience.org/about

#TwitterMigration

This entry was edited (2 years ago)

Apple has released their #accessibility preview. 🤩 One part in particular is near and dear to my heart, and it's deeply emotional to see it coming to light. I'm so happy for the team and thrilled to see what they're doing this year. Sending all my love to Cupertino! 💙💙💙

apple.com/au/newsroom/2023/05/…

Now THIS is #community! Names/usernames of volunteers who've helped the #LibreOffice project in May – and there are more to come 💪 Get on the list too: blog.documentfoundation.org/bl…

LibreOffice reshared this.

in reply to LibreOffice

Thanks! (Can I claim a third pack by reporting a bug my patch introduced? :D)

I think Month of LibreOffice & the sticker packs are a great way to get more people involved long-term - after all the first patch/translation/bug report is often the most cumbersome one due to all the setup overhead.

I always try to lower the barriers I bump into along the way, eg. submitted this patch to #fedora to include all build debs ootb:
src.fedoraproject.org/rpms/lib…

Official #flatpak build env when?

wow, exciting new #Accessibility features from #Apple coming hopefully in iOs 17.
1. Assistive access. Reduces the feature set and design of apps to minimum, to lessen cognitive load.
2. Live speech. Type text and phone reads it out loud or through an ongoing call.
3. Personal voice. iOs clones your voice to output with 15 minutes of data to train.
4. Point and speak. In magnifier, the phone reads out a text on a button, such as home appliance, a person is pointing at with their finger.
and more, such as siri voices being better at faster speech rates, MFI hearing aids get macOs support, its easier to customise text size in MacOs and you can use your switch control as a game controller.
apple.com/newsroom/2023/05/app…

reshared this

True story: Mozilla's @mconley is a legend. (Also, he worked on Mozilla Messenger, and is responsible for #Ubuntu shipping with Thunderbird!)

His enthusiasm is so contagious that just listening to this podcast might turn you into a software engineer! Join us for ThunderCast episode 2 as we reminisce about the early days of the internet, and talk about Firefox features more people should be using.
blog.thunderbird.net/2023/05/t…

#Thunderbird #Firefox #Podcast

in reply to Thunderbird: Free Your Inbox

@killyourfm Just discovered the thundercast last weekend and today I've listened the second episode. Great to listen to you guys, I feel like I could have been one of you by the memories you share, but unfortunately I went to the dark side on my career and working as a SAP system administrator. To compensate I use linux at home and all the opensource tools I can everywhere. Keep up the good job!

Company preemptively considered (most?) Hacks people are suggesting to get a 'free tv' only to then undo the surveillance parts of the hostile surveillance tech:

Also there is a 'discrete' camera in the middle bezel of the top screen that will 'continually monitor the area in front of the TV in order to provide better ads and services'

theverge.com/2023/5/15/2372167…

202 sticker packs have already been awarded this month, to #LibreOffice community members! But we're only half-way through. Join them, and get yours: blog.documentfoundation.org/bl… #opensource #community

LibreOffice reshared this.

“I can get my bank statement or a gas bill in accessible formats, but yet I still receive health information that I can’t read. What could be more personal than your health status?” So true! #accessibility #communication #blind #deafblind #disability @disability | Blind people at risk due to ‘inaccessible’ health information from NHS, charity warns | The Independent independent.co.uk/news/health/…

Amazon's Alexa Is About To Get A Lot More Capable, CEO Says | Jada Jones | ZDNet
zdnet.com/article/amazons-alex…

Publisher (Di Blasi): I'd be willing to wager more than a Starbucks run that it is. Alexa is, with minimal argument, the most capable voice assistant ever created. It achieved that status not only through AI, but through more-accurate-than-most, instantaneous voice recognition via the cloud. Put another way, Amazon hasn't yet incorporated true generative AI into the Alexa model. At least...

Los siete candidatos de EH Bildu condenados por delitos de sangre renuncian a las listas electorales publico.es/politica/siete-cand… #Política

Here's an effect plugin that separates voice, voice reverb, and ambient noise into three separate channels with controls to mute, solo, or adjust the volume of each. I haven't spent too long testing this yet, but it seems to open up a ton of possibilities--boosting the dialog of movies, removing the noise and echo from recordings, making a bad audio setup sound clearer on voice calls ... and that's just off the top of my head. I have no idea what kind of black magic this is, but somehow it's able to run in real time on my setup with minimal CPU load. goyo.app/