home.social

#pdf — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #pdf, aggregated by home.social.

fetched live
  1. China-based hackers-for-hire group staging espionage attacks alongside a cryptocurrency fraud business

    Jewelbug is a China-based threat actor conducting dual operations: espionage campaigns targeting foreign governments and militaries, alongside a for-profit cryptocurrency fraud business administered from the same control panel. Operating as a small development team with role-based access controls and documented roadmaps, the group recorded over one million implant check-ins, 580,000+ stolen browser cookies, and 2,300+ exfiltrated emails between February and May 2026. Espionage attacks targeted government entities in the Middle East, Southeast Asia, and South Asia with confirmed intrusions. The group deploys the Antino backdoor, a malicious Chrome/Firefox extension called 'PDF Viewer,' and a Linux implant named ClientKing targeting servers and routers. The financially motivated arm operates as a registered Hunan company running industrial-scale SEO poisoning funneling Chinese-speaking victims to fake cryptocurrency exchange sites.

    Pulse ID: 6a7da6cbe879002fadce7e53
    Pulse Link: otx.alienvault.com/pulse/6a7da
    Pulse Author: AlienVault
    Created: 2026-08-13 11:13:15

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #Browser #China #Chinese #Chrome #Cookies #CyberSecurity #Email #Espionage #FireFox #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #bot #cryptocurrency #AlienVault

  2. China-based hackers-for-hire group staging espionage attacks alongside a cryptocurrency fraud business

    Jewelbug is a China-based threat actor conducting dual operations: espionage campaigns targeting foreign governments and militaries, alongside a for-profit cryptocurrency fraud business administered from the same control panel. Operating as a small development team with role-based access controls and documented roadmaps, the group recorded over one million implant check-ins, 580,000+ stolen browser cookies, and 2,300+ exfiltrated emails between February and May 2026. Espionage attacks targeted government entities in the Middle East, Southeast Asia, and South Asia with confirmed intrusions. The group deploys the Antino backdoor, a malicious Chrome/Firefox extension called 'PDF Viewer,' and a Linux implant named ClientKing targeting servers and routers. The financially motivated arm operates as a registered Hunan company running industrial-scale SEO poisoning funneling Chinese-speaking victims to fake cryptocurrency exchange sites.

    Pulse ID: 6a7da6cbe879002fadce7e53
    Pulse Link: otx.alienvault.com/pulse/6a7da
    Pulse Author: AlienVault
    Created: 2026-08-13 11:13:15

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #Browser #China #Chinese #Chrome #Cookies #CyberSecurity #Email #Espionage #FireFox #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #bot #cryptocurrency #AlienVault

  3. APT Group Runs Espionage and Crypto Fraud Operations Side by Side

    Jewelbug is a China-based hackers-for-hire group conducting parallel operations: espionage campaigns targeting government ministries and militaries across the Middle East, Southeast Asia, and South Asia, alongside a cryptocurrency fraud business. Both missions operate from a single control panel called XG-Web, a browser-centric remote-access framework. The group's main implant is the Antino backdoor, complemented by a malicious browser extension disguised as 'PDF Viewer' and the ClientKing Linux/router implant. Their largest operation compromised over 15 government webmail tenants in a Middle Eastern country through a single watering-hole attack. The victim database recorded over one million implant check-ins and 580,000 stolen browser cookies within three months. Operators are linked to a registered Hunan Province company, with infrastructure supporting both espionage and commercial SEO poisoning operations targeting Chinese-speaking cryptocurrency users.

    Pulse ID: 6a7daa9c80273555f3d3ccd1
    Pulse Link: otx.alienvault.com/pulse/6a7da
    Pulse Author: AlienVault
    Created: 2026-08-13 11:29:32

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #Browser #China #Chinese #Cookies #CyberSecurity #Espionage #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #Webmail #bot #cryptocurrency #AlienVault

  4. APT Group Runs Espionage and Crypto Fraud Operations Side by Side

    Jewelbug is a China-based hackers-for-hire group conducting parallel operations: espionage campaigns targeting government ministries and militaries across the Middle East, Southeast Asia, and South Asia, alongside a cryptocurrency fraud business. Both missions operate from a single control panel called XG-Web, a browser-centric remote-access framework. The group's main implant is the Antino backdoor, complemented by a malicious browser extension disguised as 'PDF Viewer' and the ClientKing Linux/router implant. Their largest operation compromised over 15 government webmail tenants in a Middle Eastern country through a single watering-hole attack. The victim database recorded over one million implant check-ins and 580,000 stolen browser cookies within three months. Operators are linked to a registered Hunan Province company, with infrastructure supporting both espionage and commercial SEO poisoning operations targeting Chinese-speaking cryptocurrency users.

    Pulse ID: 6a7daa9c80273555f3d3ccd1
    Pulse Link: otx.alienvault.com/pulse/6a7da
    Pulse Author: AlienVault
    Created: 2026-08-13 11:29:32

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #Browser #China #Chinese #Cookies #CyberSecurity #Espionage #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #Webmail #bot #cryptocurrency #AlienVault

  5. Versión 2.14.3 de Stirling PDF, potente plataforma de edición de PDF de código abierto para Windows, macOS y Linux: dekazeta.net/foro/files/file/5

    #PDF #Windows #macOS #Linux

  6. Versión 2.14.3 de Stirling PDF, potente plataforma de edición de PDF de código abierto para Windows, macOS y Linux: dekazeta.net/foro/files/file/5

    #PDF #Windows #macOS #Linux

  7. Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side

    Indicators extracted from public reporting. Source: sed-cms.broadcom.com/sites/def

    Pulse ID: 6a7da2dc1ab7ab31faf83152
    Pulse Link: otx.alienvault.com/pulse/6a7da
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 10:56:27

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DoS #Espionage #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #PDF #RAT #RCE #bot #CyberHunter_NL

  8. Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side

    Indicators extracted from public reporting. Source: sed-cms.broadcom.com/sites/def

    Pulse ID: 6a7da2dc1ab7ab31faf83152
    Pulse Link: otx.alienvault.com/pulse/6a7da
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 10:56:27

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DoS #Espionage #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #PDF #RAT #RCE #bot #CyberHunter_NL

  9. State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit

    North Korea-affiliated Lazarus group has resurfaced with Operation Dream Job, leveraging a previously unknown Windows vulnerability (CVE-2026-68820) to target defense, aerospace, and aviation organizations. The campaign uses fake job offers from recruiters via platforms like LinkedIn to deliver malicious payloads through two infection chains: DLL sideloading with MISTPEN downloader and a trojanized PDF viewer called SecurityPDF that deploys the Troy backdoor. The zero-day exploit enables privilege escalation to deploy a rootkit that evades EDR detection. Attackers utilize compromised legitimate websites and Roundcube webmail servers running RelayShell as command and control infrastructure, masking malicious traffic as normal activity. Victims are concentrated in Europe, Asia, and South America, with particular focus on France, Germany, Brazil, and India. Microsoft patched the vulnerability following disclosure.

    Pulse ID: 6a7d8b5671a34dd89301bbbe
    Pulse Link: otx.alienvault.com/pulse/6a7d8
    Pulse Author: AlienVault
    Created: 2026-08-13 09:16:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #Brazil #CyberSecurity #EDR #Europe #France #Germany #India #InfoSec #Korea #Lazarus #LinkedIn #Microsoft #NorthKorea #OTX #OpenThreatExchange #PDF #RAT #Rootkit #SideLoading #SouthAmerica #Trojan #Vulnerability #Webmail #Windows #ZeroDay #bot #AlienVault

  10. State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit

    North Korea-affiliated Lazarus group has resurfaced with Operation Dream Job, leveraging a previously unknown Windows vulnerability (CVE-2026-68820) to target defense, aerospace, and aviation organizations. The campaign uses fake job offers from recruiters via platforms like LinkedIn to deliver malicious payloads through two infection chains: DLL sideloading with MISTPEN downloader and a trojanized PDF viewer called SecurityPDF that deploys the Troy backdoor. The zero-day exploit enables privilege escalation to deploy a rootkit that evades EDR detection. Attackers utilize compromised legitimate websites and Roundcube webmail servers running RelayShell as command and control infrastructure, masking malicious traffic as normal activity. Victims are concentrated in Europe, Asia, and South America, with particular focus on France, Germany, Brazil, and India. Microsoft patched the vulnerability following disclosure.

    Pulse ID: 6a7d8b5671a34dd89301bbbe
    Pulse Link: otx.alienvault.com/pulse/6a7d8
    Pulse Author: AlienVault
    Created: 2026-08-13 09:16:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #Brazil #CyberSecurity #EDR #Europe #France #Germany #India #InfoSec #Korea #Lazarus #LinkedIn #Microsoft #NorthKorea #OTX #OpenThreatExchange #PDF #RAT #Rootkit #SideLoading #SouthAmerica #Trojan #Vulnerability #Webmail #Windows #ZeroDay #bot #AlienVault

  11. Master Hsu Yun (虚云) A Brief Biography By Upasaka Lu K’uan Yu – THE MOUNTAIN PATH / Vol. 1 – OCTOBER 1964

    Hsu-Yun_Dharma-WordsHerunterladen #1964 #ABriefBiography #Dharma #HsuYun #LuKUanYü #PDF #Zen
  12. PDF magazine: Pitstop Retro, issue 2

    By issue 8/2026, the second release of the PDF magazine Pitstop Retro has been published, a free gaming magazine for C64 and Amiga. Topics include "The Adventure of Node", "Eclipse", "Rex: Into the Shadow Realm" and "The Voyage of the Beano", among others.

    amiga-news.de/en/news/AN-2026-

  13. PDF magazine: Pitstop Retro, issue 2

    By issue 8/2026, the second release of the PDF magazine Pitstop Retro has been published, a free gaming magazine for C64 and Amiga. Topics include "The Adventure of Node", "Eclipse", "Rex: Into the Shadow Realm" and "The Voyage of the Beano", among others.

    amiga-news.de/en/news/AN-2026-

    #pdf #magazine #Amiga #C64 #games

  14. @mos_8502 I have another script that creates a PDF of qrcodes... Encrypted files encoded to codegroup-qrcodes that you can store in a drawer... or laser etch onto something.

    pastebin.com/eq6zPftU

    #pdf #qr

  15. @mos_8502 I have another script that creates a PDF of qrcodes... Encrypted files encoded to codegroup-qrcodes that you can store in a drawer... or laser etch onto something.

    pastebin.com/eq6zPftU

    #pdf #qr

  16. PSA: EPUBs are better than PDFs!

    I saw some misinformation and had a rant that calmed down into a PSA lol.

    https://blog.pomnavi.net/posts/0029-psa-epubs-are-better-than-pdfs/

    #Blog #ebooks #epub #pdf

  17. We're replacing the browser print dialog for PDF-creation with something better for Fidus Writer 5.0.

    New PDF exporter demo (Vivliostyle + PDF-lib):
    → CSS-based page layout
    → Crop marks & custom metadata
    → Source document embedding
    → 100% browser-based = E2E encryption friendly

    fiduswriter.github.io/vivliost

    What PDF output features are missing from your current workflow?

    #FidusWriter #Vivliostyle #CSS #PDF #OpenSource

  18. We're replacing the browser print dialog for PDF-creation with something better for Fidus Writer 5.0.

    New PDF exporter demo (Vivliostyle + PDF-lib):
    → CSS-based page layout
    → Crop marks & custom metadata
    → Source document embedding
    → 100% browser-based = E2E encryption friendly

    fiduswriter.github.io/vivliost

    What PDF output features are missing from your current workflow?

    #FidusWriter #Vivliostyle #CSS #PDF #OpenSource

  19. «Versteckter Text in einem PDF reicht aus, um über Atlassians KI-Agent Rovo sensible Daten zu stehlen:
    Atlassians KI-Agent Rovo ist anfällig für eine sogenannte indirekte Prompt Injection, die es Angreifern ermöglicht, sensible Unternehmensdaten aus Jira-Tickets und Confluence-Dokumenten abzugreifen.»

    Ich lasse das mal hier so stehen…

    🔑 the-decoder.de/versteckter-tex

    #pdf #ki #daten #sensibel #rovo #text #verstecken #injection #dokument #jira #itsicherheit #jiratickets

  20. «Versteckter Text in einem PDF reicht aus, um über Atlassians KI-Agent Rovo sensible Daten zu stehlen:
    Atlassians KI-Agent Rovo ist anfällig für eine sogenannte indirekte Prompt Injection, die es Angreifern ermöglicht, sensible Unternehmensdaten aus Jira-Tickets und Confluence-Dokumenten abzugreifen.»

    Ich lasse das mal hier so stehen…

    🔑 the-decoder.de/versteckter-tex

    #pdf #ki #daten #sensibel #rovo #text #verstecken #injection #dokument #jira #itsicherheit #jiratickets

  21. Max-severity Exchange server flaw under active exploitation by Kremlin hackers

    Indicators extracted from public reporting. Source: media.defense.gov/2026/Jul/22/

    Pulse ID: 6a79ace8ce2eec075b55ddb0
    Pulse Link: otx.alienvault.com/pulse/6a79a
    Pulse Author: CyberHunter_NL
    Created: 2026-08-10 10:50:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #PDF #Phishing #RCE #Russia #Zimbra #bot #CyberHunter_NL

  22. Max-severity Exchange server flaw under active exploitation by Kremlin hackers

    Indicators extracted from public reporting. Source: media.defense.gov/2026/Jul/22/

    Pulse ID: 6a79ace8ce2eec075b55ddb0
    Pulse Link: otx.alienvault.com/pulse/6a79a
    Pulse Author: CyberHunter_NL
    Created: 2026-08-10 10:50:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #PDF #Phishing #RCE #Russia #Zimbra #bot #CyberHunter_NL

  23. I want to get rid of all these paper manuals.
    Either download or maybe scan and then some folder to archive.
    Is there something less complex than paperless to access/manage them with a Web UI?
    I have paperless for important documents, but there is no need to have advanced features. Just folders and maybe tags should be sufficient.
    #pdf #archive #archiving #opensource #dumpster #docker #selfhosting

  24. Can you recommend Linux tools for extracting the text of scanned, OCRed PDFs?

    #pdf #linux #tools #AskFedi

  25. Can you recommend Linux tools for extracting the text of scanned, OCRed PDFs?

    #pdf #linux #tools #AskFedi

  26. @deuchnord @Framasoft

    De ce que j'ai lu, Framasoft PDF n'a pas le certificat de conformité eIDAS.
    En tout cas, ils n'en font pas mention.

    En cherchant autour de [eIDAS], j'ai trouvé ça :
    aidocx.ai/fr/blog/best-free-es

    mais ça ne va pas très loin.

    Va falloir fouiller, je pense et veiller aux certifications.

    #EIDAS #Signature #PDF

    🐞

  27. @deuchnord @Framasoft

    De ce que j'ai lu, Framasoft PDF n'a pas le certificat de conformité eIDAS.
    En tout cas, ils n'en font pas mention.

    En cherchant autour de [eIDAS], j'ai trouvé ça :
    aidocx.ai/fr/blog/best-free-es

    mais ça ne va pas très loin.

    Va falloir fouiller, je pense et veiller aux certifications.

    #EIDAS #Signature #PDF

    🐞

  28. Fake PDFs and Chat Apps Let Patchwork Spy on PCs and Android Phones

    Indicators extracted from public reporting. Source: picussecurity.com/resource/blo

    Pulse ID: 6a75c7e5ba5f5ced0fa6825a
    Pulse Link: otx.alienvault.com/pulse/6a75c
    Pulse Author: CyberHunter_NL
    Created: 2026-08-07 11:56:21

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #CyberSecurity #Espionage #HTTP #HTTPS #ICS #InfoSec #OTX #OpenThreatExchange #PDF #RCE #bot #CyberHunter_NL

  29. Fake PDFs and Chat Apps Let Patchwork Spy on PCs and Android Phones

    Indicators extracted from public reporting. Source: picussecurity.com/resource/blo

    Pulse ID: 6a75c7e5ba5f5ced0fa6825a
    Pulse Link: otx.alienvault.com/pulse/6a75c
    Pulse Author: CyberHunter_NL
    Created: 2026-08-07 11:56:21

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #CyberSecurity #Espionage #HTTP #HTTPS #ICS #InfoSec #OTX #OpenThreatExchange #PDF #RCE #bot #CyberHunter_NL

  30. Cześć Mamuciska!
    Znajoma osoba pracująca w jednym z urzędów o ogólnopolskim zasięgu niedawno otrzymała e-mail z informacją o tym, że wkrótce z komputerów służbowych zostanie odinstalowany Adobe Acrobat, gdyż... zajmuje zbyt dużo miejsca na dysku i potrzebuje do działania zbyt dużo RAM-u. Dziwne, że dopiero teraz zaczęło to przeszkadzać. Czy rzeczywiście jest tak zasobożerny?
    Zatem jak odtąd będą przeglądać PDF-y? Ano kierownictwo zaleciło otwierać je za pomocą... przeglądarek. Do wyboru Edge lub Chrome. Czy dane z tych dokumentów są narażone w nich na ,,podgląd" z Sieci? Czy to niesie ze sobą ryzyko ich wycieku?

    #AdobeAcrobat #PDF #przeglądarka #Edge #Chrome #bezpieczeństwodanych

  31. Cześć Mamuciska!
    Znajoma osoba pracująca w jednym z urzędów o ogólnopolskim zasięgu niedawno otrzymała e-mail z informacją o tym, że wkrótce z komputerów służbowych zostanie odinstalowany Adobe Acrobat, gdyż... zajmuje zbyt dużo miejsca na dysku i potrzebuje do działania zbyt dużo RAM-u. Dziwne, że dopiero teraz zaczęło to przeszkadzać. Czy rzeczywiście jest tak zasobożerny?
    Zatem jak odtąd będą przeglądać PDF-y? Ano kierownictwo zaleciło otwierać je za pomocą... przeglądarek. Do wyboru Edge lub Chrome. Czy dane z tych dokumentów są narażone w nich na ,,podgląd" z Sieci? Czy to niesie ze sobą ryzyko ich wycieku?

    #AdobeAcrobat #PDF #przeglądarka #Edge #Chrome #bezpieczeństwodanych

  32. New freeCodeCamp article 📄

    How to build a browser-based PDF Color Inverter with JavaScript—fast, private, and no backend required.

    freecodecamp.org/news/build-pd

    #WebDevelopment #PDF #Privacy

  33. Vulnerability in ngx-extended-pdf-viewer (HIGH): Bundled pdf.js exposes XFA (enabled by default), risking JS execution via malicious PDFs (CVE-2026-16633). Update to 29.0.0-rc.3 or disable XFA for mitigation. radar.offseq.com/threat/ngx-ex #OffSeq #Vulnerability #PDF #Infosec

  34. Fake CAPTCHA, Real Business: Traffic Distribution for Hire

    A sophisticated traffic distribution system has been operating for over 14 months, using more than 12,700 structurally similar fake CAPTCHA PDFs hosted on Webflow's CDN. The operation begins with search engine optimization, where victims searching for legitimate content encounter malicious PDFs through Google searches. These documents contain fake CAPTCHA panels that route users through a custom Elixir/Phoenix traffic distribution system employing IP filtering, bot detection, and geographic targeting. The infrastructure sorts visitors and redirects qualifying traffic to three distinct endpoints: Legion Loader distribution, a TDS reseller gate, and premium-SMS subscription scams targeting Spanish-speaking users. Non-qualifying traffic is monetized through search-arbitrage advertising. The operation primarily targets English-speaking countries and has recently been surfaced by AI assistants including Google Gemini and Claude, expanding its reach beyond traditional search engines.

    Pulse ID: 6a734a570822e0edf4d1fdb5
    Pulse Link: otx.alienvault.com/pulse/6a734
    Pulse Author: AlienVault
    Created: 2026-08-05 14:36:07

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CAPTCHA #CDN #CyberSecurity #Endpoint #Google #InfoSec #OTX #OpenThreatExchange #PDF #RAT #SMS #bot #AlienVault

  35. Fake CAPTCHA, Real Business: Traffic Distribution for Hire

    A sophisticated traffic distribution system has been operating for over 14 months, using more than 12,700 structurally similar fake CAPTCHA PDFs hosted on Webflow's CDN. The operation begins with search engine optimization, where victims searching for legitimate content encounter malicious PDFs through Google searches. These documents contain fake CAPTCHA panels that route users through a custom Elixir/Phoenix traffic distribution system employing IP filtering, bot detection, and geographic targeting. The infrastructure sorts visitors and redirects qualifying traffic to three distinct endpoints: Legion Loader distribution, a TDS reseller gate, and premium-SMS subscription scams targeting Spanish-speaking users. Non-qualifying traffic is monetized through search-arbitrage advertising. The operation primarily targets English-speaking countries and has recently been surfaced by AI assistants including Google Gemini and Claude, expanding its reach beyond traditional search engines.

    Pulse ID: 6a734a570822e0edf4d1fdb5
    Pulse Link: otx.alienvault.com/pulse/6a734
    Pulse Author: AlienVault
    Created: 2026-08-05 14:36:07

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CAPTCHA #CDN #CyberSecurity #Endpoint #Google #InfoSec #OTX #OpenThreatExchange #PDF #RAT #SMS #bot #AlienVault

  36. Yes, markdown, or *any* other format should be used, but basically, the PDF feels bloated, and it has some links that overlap, text seems jumbled, as in, like, suddenly on a new line, I am not sure if anyone is making you use PDFs but personally, PDF should be illegal, punishable with jail time and a hefty fine if someone *willingly* hands me a PDF, that is how much I hate PDFs and I will never understand why sighted folk love them. @Sobex #PDF

  37. Versión 1.7.1 de KillerPDF, editor de PDF gratuito y de código abierto para Windows: dekazeta.net/foro/files/file/5

    #PDF #Windows