• Honey: all the news about PayPals alleged scam coupon app
    www.theverge.com
    GamersNexus is leading a new class action lawsuit against PayPal.The lawsuit joins other complaints filed since YouTuber MegaLags video accusing PayPals coupon-hunting Honey extension of hijacking affiliate links. The Legal Eagle channel filed one earlier this month as well.The 90-minute video recaps the concerns raised in MegaLags original video and includes interviews with lawyers explaining the legal process.
    0 Комментарии ·0 Поделились ·65 Просмотры
  • Critical SimpleHelp Flaws Allow File Theft, Privilege Escalation, and RCE Attacks
    thehackernews.com
    Jan 15, 2025Ravie LakshmananVulnerability / Server SecurityCybersecurity researchers have disclosed multiple security flaws in SimpleHelp remote access software that could lead to information disclosure, privilege escalation, and remote code execution.Horizon3.ai researcher Naveen Sunkavally, in a technical report detailing the findings, said the "vulnerabilities are trivial to reverse and exploit."The list of identified flaws is as follows -CVE-2024-57727 - An unauthenticated path traversal vulnerability that allows an attacker to download arbitrary files from the SimpleHelp server, including the serverconfig.xml file that contains hashed passwords for the SimpleHelpAdmin account and other local technician accountsCVE-2024-57728 - An arbitrary file upload vulnerability that allows an attacker with SimpleHelpAdmin privileges (or as a technician with admin privileges) to upload arbitrary files anywhere on the SimpleServer host, potentially leading to remote code executionCVE-2024-57726 - A privilege escalation vulnerability that allows an attacker who gains access as a low-privilege technician to elevate their privileges to an admin by taking advantage of missing backend authorization checksIn a hypothetical attack scenario, CVE-2024-57726 and CVE-2024-57728 could be chained by a bad actor to become an admin user and upload arbitrary payloads to seize control of the SimpleHelp server.Horizon3.ai said it's withholding additional technical details about the three vulnerabilities given their criticality and the ease of weaponization. Following responsible disclosure on January 6, 2025, the flaws have been addressed in SimpleHelp versions 5.3.9, 5.4.10, and 5.5.8 released on January 8 and 13.With threat actors known to leverage remote access tools to establish persistent remote access to target environments, it's crucial that users move quickly to apply the patches.In addition, SimpleHelp is recommending that users change the administrator password of the SimpleHelp server, rotate the passwords for Technician accounts, and restrict the IP addresses that the SimpleHelp server can expect Technician and administrator logins from.Found this article interesting? Follow us on Twitter and LinkedIn to read more exclusive content we post.SHARE
    0 Комментарии ·0 Поделились ·65 Просмотры
  • RemoteMore: DevOps Engineer
    weworkremotely.com
    The positionRemoteMore is helping a large tech company hire DevOps Engineers, SRE and Security Architects.The company is a major tech leader and works across many internal product teams. Multiple DevOps engineers will be hired and matched to the best-fit teams for their background/experience. The company culture is to focus on work delivered and not hours worked.Good work-life balance is encouraged. You can work from home or any other place of your choice.The position is full-time and fully remote.Your profileComing from a strong technical background, you are expected to have:Required technologies: AWS/Azure/GCP, Kubernetes, CI/CD pipelinesBonus points: Programming language proficiency (Python/JavaScript/Golang, etc); Docker; Jenkins; LinuxExceptional English Language Skills: Required to work as part of an international team.Top technical skills for your level of experience: Intermediate or Senior (3+ years of experience)The soft skills to work remotely: Strong individual contributor, strong communication skills.Passion for remote work: You understand the pros and cons of working remotelyWhy should YOU apply?Work from anywhere you want.Competitive compensation based on your skills.Work in a team with other top developers.Making a difference.To be considered for the position, please sign up to RemoteMore by following the apply button. Related Jobs See more DevOps and Sysadmin jobs
    0 Комментарии ·0 Поделились ·88 Просмотры
  • HTAs Wandsworth regeneration scheme faces rethink after developer exits
    www.architectsjournal.co.uk
    The AJ100 Employer of the Years masterplan adds roughly 1,800 homes to the existing 795-home Winstanley and York Road estate, just north of Clapham Junction station.The scheme, given outline approval in 2021, was drawn up for a joint venture partnership between Wandsworth Council and Taylor Wimpey.But, Wandsworth announced last week (6 January) that its partnership with Taylor Wimpey had ended after delivering 139 replacement council homes on the site in the three years since permission was given.AdvertisementThe council said it would take a new approach to prioritise the delivery of affordable housing after a strategic review of the regeneration plans. It said the focus would be on delivering more social and affordable units.It told the AJ it was actively considering all options as part of its review of HTAs masterplan and that the practices role on the project would be clarified as we assess the best way forward.The AJ understands that new architects could be appointed to a refocused scheme. However, Wandsworth said it has made no specific decisions on the design team. HTA confirmed that it continues to have a role on the scheme.Wandsworth Council leader Simon Hogg said: The primary objective of the Winstanley and York Road regeneration project is to urgently deliver much-needed council housing.With this in mind, we have come to a mutual agreement to end our joint working. While we are disappointed to end our partnership with Taylor Wimpey, this provides us with an opportunity to review the scheme and seek to deliver even more affordable homes.AdvertisementTaylor Wimpey London managing director James Lidgate said: We recognise that a change in strategic direction of the project has meant that Wandsworth Council is best-placed to deliver the scheme alone moving forward.However, we are proud of the work that we have carried out to date to deliver the Winstanley and York Road scheme in partnership with the council. This is a significant regeneration project and we look forward to seeing its completion and the benefits it brings to the borough.So far, 139 replacement council homes, a new school, church, multi-use games area and play area have been successfully delivered in one block, the council says. A further 126 council homes are set to be finished early in the new year.Only last month, an updated part-outline and part-detailed planning application was submitted for the site, seeking permission for 2,500 homes in buildings ranging from three to thirty-one storeys.Current site view
    0 Комментарии ·0 Поделились ·72 Просмотры
  • Circuit: Staff Product Designer (Senior+, Lead, Principal Level)
    weworkremotely.com
    Located remotely Staff Product Designer salary 110,000 Reporting to Working in the Product Design Team (currently a team of four)Are you a Staff Product Designer (similar to Senior+, Lead, or even Principal roles in other companies) who loves building intuitive and user-centered mobile apps?Would you like to join a fully remote, independent, and profitable company? If youd like to work in a small, friendly, experienced team and tackle some interesting design challenges, wed love to hear from you.With one of our Co-founders being a Product Designer, design and user experience have been at the core of what we do since the start! If you love to dig deep into what makes users tick and turn this knowledge into simple and efficient productswe think youll be right at home here.Want to know more?We are fully remoteOur Co-founders are in different countries, and our team is spread across Europe, Brazil, and Canada. We dont have a head office for you to visit, and we never will.Flexible, asynchronous workingIt gives us task flexibility and work-life balance. Minimal meetings allow you to focus on deep work and get things done.Profitable. Independent. Long-Term Focus.We're a profitable company with a strong foundation. We operate independently, prioritizing long-term success and innovation.Equity options for everyoneWork at Circuit for a minimum of one year, vests over 5 years.Annual company performance bonusPaid in January and pro-rated to your start date in your joining year.The right laptop for youWell give you 3,200 every three years to buy the laptop of your choice.500 a year for new tech/home officeNeed a new desk, chair, keyboard, or headphones? Build a space to do your best work.32 days of paid holiday per yearYou can use it whenever you like. Four weeks in one go, one day off (almost) every other week, or anything in between.Invest in your wellbeing1000 a year for gym memberships, fitness classes, sports equipment, alternative therapies, mental health resources and more.Annual team meet-ups in 5-star locationsEnhanced parental leave16 weeks on full pay and up to 52 weeks in total; through birth or adoption, have the time and resources to welcome your new addition.Connect with each other1,000 a year for self-organized in-person work sessions. Plan team meetups to connect and build stronger bonds.There is so much more to tell you, but we cant cram it all into one job advert! Check out our Public Handbook and Careers Page to find out if we are right for you.Who we are, what we do, and how its goingBack in 2017, we saw an issue with last-mile deliveryit was too complicated and stressful for drivers. Circuit started a mission to change that by choosing to develop an app that put the driver, and their customers, first.We were astounded by the response we received. Within our first year, we had almost 1,000 customers, $100k in ARR, and a team consisting of our two co-founders, Jack and Pol. Today, we now help more than 100,000 drivers deliver over 1bn packages worldwide (about 20 a second!), $20m ARR, and a lean team of ~40.What you will be doingYou are an experienced Product Designer, so we won't go into the day-to-day! Joining our existing team of four, you will report directly to Pol, Co-Founder and Principal Designer. You'll work on Circuit Route Planner, our flagship producta sophisticated and intuitive tool designed to simplify and streamline the work of professional delivery drivers. Youll be involved in every aspect of its design, moving the product and the business forward by continually finding and implementing better solutions for our users.Our flagship mobile app has worked its way to being the #1 app in the category by focusing on product qualitymaking sure its very easy to learn but also extremely efficient. As a result, its a highly opinionated product that requires a very fine balancing act between these two goals.Working as an individual contributor, you will own and lead your design projects end-to-end and work closely with our developers, helping to make implementations as good as your designs.What you wont be doingDaily stand-ups and fortnightly sprints. Expect ~one meeting per week. Were not the right fit for you if you rely on regular meetings to keep on trackSacrificing quality. We have high standards and wont rush to meet an arbitrary deadlineManaging people. We hire senior people as ICs because we want a lean team and a flat structure. Youll need to be okay with doing more junior tasks.Wed love to hear from you if you:Have 5+ years of professional experience designing mobile apps, SaaS products, or power-user toolsLike to solve tricky problems and create products that are a joy to use!Are at your happiest working on projects from start to finish - talking to users, identifying & exploring issues, designing & implementing solutions, and monitoring their successInstinctively know when to take your time - and when to get things done quicklyEnjoy working autonomously, and know when to trust your gut or gather more dataLike to get things right and done on timeCome up with alternative ideas that accomplish goals with less complexityAre based in UTC-5 to UTC+2 time zonesCan speak and write in English at a professional levelHiring ProcessOur hiring process for this role has four stages and usually takes ~three weeks. At every step, you will have the opportunity to ask questions and make sure that we are the right choice for you.1 ApplyUpload your resume and portfolio, and fill out our application form. It takes about 10 minutes to complete, and we dont ask you to repeat anything thats already on your CV!2 Meet our TA Manager Youll have a 45-minute video call with our Talent Acquisition Manager, Sadie. She will tell you more about Circuit and ask questions to help get to know you too.3 Work DemonstrationYoull have a video call with Pol, the hiring manager, and Gabriel, Staff Product Designer, that will last around 45 minutes. During the call, you will have the opportunity to present some of your work4 Whiteboard exerciseAt this stage, we will invite you to take part in a live whiteboard exercise with Pol. It should take around an hour, and its a great way for both you and Pol to get a feel for how you approach a project. Offer!We invite you to join our team. If you need us to make any adjustments to our interview process, or if there is any way I can make you more comfortable for our first call, please let me know. Sadie
    0 Комментарии ·0 Поделились ·83 Просмотры
  • Today's NYT Strands Hints, Answers and Help for Jan. 15, #318
    www.cnet.com
    Looking for the most recent Strands answer?Click here for our daily Strands hints, as well as our daily answers and hints for The New York Times Mini Crossword, Wordle and Connections puzzles.Today'sStrandspuzzle is entertaining, especially if you're a fan of a certain large marine mammal. If you need hints and answers, read on.Also, I go into depth about therules for Strands in this story.If you're looking for today's Wordle, Connections and Mini Crossword answers, you can visitCNET's NYT puzzle hints page.Read more:NYT Connections Turns 1: These Are the 5 Toughest Puzzles So FarHint for today's Strands puzzleToday's Strands theme is:Thar she blows!If that doesn't help you, here's a clue: Moby DickClue words to unlock in-game hintsYour goal is to find hidden words that fit the puzzle's theme. If you're stuck, find any words you can. Every time you find three words of four letters or more, Strands will reveal one of the theme words. These are the words I used to get those hints, but any words of four or more letters that you find will work:GALE, PLAY, POSE, CLUE, POSER, GROPE, GROPES, ROPE, ROPES, SHELTER, HALE, HALES, MUSH, BALE, LACKAnswers for today's Strands puzzleThese are the answers that tie into the theme. The goal of the puzzle is to find them all, including the spangram, a theme word that reaches from one side of the puzzle to the other. When you've got all of them (I originally thought there were always eight but learned that the number can vary), every letter on the board will be used. Here are the nonspangram answers:BLUE, GRAY, ORCA, RIGHT, SPERM, BALEEN, BELUGA, HUMPBACK.Today's Strands spangramToday's Strands spangram isWHALES.To find it, start with the W that's five letters down on the first row on the left, and wind across. The completed NYT Strands puzzle for Jan. 15, 2025. NYT/Screenshot by CNET
    0 Комментарии ·0 Поделились ·81 Просмотры
  • Redefining Single-Channel Speech Enhancement: The xLSTM-SENet Approach
    www.marktechpost.com
    Speech processing systems often struggle to deliver clear audio in noisy environments. This challenge impacts applications such as hearing aids, automatic speech recognition (ASR), and speaker verification. Conventional single-channel speech enhancement (SE) systems use neural network architectures like LSTMs, CNNs, and GANs, but they are not without limitations. For instance, attention-based models such as Conformers, while powerful, require extensive computational resources and large datasets, which can be impractical for certain applications. These constraints highlight the need for scalable and efficient alternatives.Introducing xLSTM-SENetTo address these challenges, researchers from Aalborg University and Oticon A/S developed xLSTM-SENet, the first xLSTM-based single-channel SE system. This system builds on the Extended Long Short-Term Memory (xLSTM) architecture, which refines traditional LSTM models by introducing exponential gating and matrix memory. These enhancements resolve some of the limitations of standard LSTMs, such as restricted storage capacity and limited parallelizability. By integrating xLSTM into the MP-SENet framework, the new system can effectively process both magnitude and phase spectra, offering a streamlined approach to speech enhancement.Technical Overview and AdvantagesxLSTM-SENet is designed with a time-frequency (TF) domain encoder-decoder structure. At its core are TF-xLSTM blocks, which use mLSTM layers to capture both temporal and frequency dependencies. Unlike traditional LSTMs, mLSTMs employ exponential gating for more precise storage control and a matrix-based memory design for increased capacity. The bidirectional architecture further enhances the models ability to utilize contextual information from both past and future frames. Additionally, the system includes specialized decoders for magnitude and phase spectra, which contribute to improved speech quality and intelligibility. These innovations make xLSTM-SENet efficient and suitable for devices with constrained computational resources.Performance and FindingsEvaluations using the VoiceBank+DEMAND dataset highlight the effectiveness of xLSTM-SENet. The system achieves results comparable to or better than state-of-the-art models such as SEMamba and MP-SENet. For example, it recorded a Perceptual Evaluation of Speech Quality (PESQ) score of 3.48 and a Short-Time Objective Intelligibility (STOI) of 0.96. Additionally, composite metrics like CSIG, CBAK, and COVL showed notable improvements. Ablation studies underscored the importance of features like exponential gating and bidirectionality in enhancing performance. While the system requires longer training times than some attention-based models, its overall performance demonstrates its value.ConclusionxLSTM-SENet offers a thoughtful response to the challenges in single-channel speech enhancement. By leveraging the capabilities of the xLSTM architecture, the system balances scalability and efficiency with robust performance. This work not only advances the state of speech enhancement technology but also opens doors for its application in real-world scenarios, such as hearing aids and speech recognition systems. As these techniques continue to evolve, they promise to make high-quality speech processing more accessible and practical for diverse needs.Check out the Paper. All credit for this research goes to the researchers of this project. Also,dont forget to follow us onTwitter and join ourTelegram Channel andLinkedIn Group. Dont Forget to join our65k+ ML SubReddit.(Promoted) Nikhil+ postsNikhil is an intern consultant at Marktechpost. He is pursuing an integrated dual degree in Materials at the Indian Institute of Technology, Kharagpur. Nikhil is an AI/ML enthusiast who is always researching applications in fields like biomaterials and biomedical science. With a strong background in Material Science, he is exploring new advancements and creating opportunities to contribute. Meet 'Height':The only autonomous project management tool (Sponsored)
    0 Комментарии ·0 Поделились ·54 Просмотры
  • Assemble wins competition to upgrade Scottish Highlands cultural hub
    www.architectsjournal.co.uk
    The practices will carry out a feasibility study into how to upgrade and enhance the heritage and art institution which was founded in 1987 in the Scottish Highlands.They beat five other finalist teams, led by Dualchas Architects, Moxon Architects, Rural Design and Konishi Gaffney Architects.Key aims of the project include boosting sustainability, accessibility, and community involvement at the 600m waterfront cultural centre which uses arts and heritage to promote political, social, cultural, environmental, and communal change.AdvertisementThe feasibility study is supported by Museums Galleries Scotland and the National Lottery Heritage Fund.Timespan director and curator Giulla Gregnaninsaid: Assemble and Office Corr Higgins have been chosen as the perfect partners for Timespan. Their focus on empowering communities, their commitment to enhancing local context while advancing Timespans global ambitions, and their visionary interdisciplinary approach resonate deeply with our ethos.We are thrilled to embark on this collaboration, confident that their expertise will help shape a bold and transformative future for Timespan and our communities.Assemble and Office Core Higgins said: Timespan is an inspirational and vital cultural resource for the north of Scotland. The project is a fantastic opportunity to create a locally embedded, globally connected venue in the Scottish Highlands, combining fascinating local history with an ambitious and vibrant art programme.It promises to be a wonderful project with a great team and amazing site we cant wait to get started.AdvertisementWinning team: Assemble and Office Corr HigginsTimespan was founded in 1987 and hosts local history and contemporary art displays as well as featuring a geology and herb garden, a shop and a caf. It is based inside a former herring curing yard overlooking the River Helmsdale.The feasibility study, due to complete in July, will guide future strategic investment in the building and its displays. The winning team will receive approximately 30,000 to compile a comprehensive report featuring designs and costs up to RIBA Stage 1.Timespan hopes to deliver a more coherent built presence and better facilities for visitors and staff, with a focus on local materials and character while also reducing the organisations environmental impact.RIAS chief executive Tamsie Thomson said: At the start of this process we said that Timespan is an organisation that punches above its weight, and were delighted to be part of a project that harnesses architecture to allow Timespan to fully realise its potential.RIAS Consultancy exists to bring organisations of all shapes and sizes together with great architectural talent, and were thrilled to have played a part to support Timespan and its exciting plans for the future.
    0 Комментарии ·0 Поделились ·72 Просмотры
  • Only CD Projekt Red knows when The Witcher 4 is going to come out, so it's a good thing that animated Netflix movie finally has proper trailer to tide us over
    www.vg247.com
    CD Projekt Red won't be telling us when The Witcher 4 is coming for quite a while, so be thankful that the Netflix animated movie has an actual trailer now. Read more
    0 Комментарии ·0 Поделились ·91 Просмотры
  • Creator of Gas and tbh makes an app for disappearing photos via iMessage
    techcrunch.com
    Nikita Bier, creator of popular apps like the anonymous polling app tbh (acquired by Facebook) and the anonymous compliments app Gas (acquired by Discord), has created a new app called Explode, which focuses on disappearing messages on iMessage.Explode works as a mini app for Apples Messages app. It helps you send disappearing messages to other folks. Users can see the text or images once, and then it explodes. The app blocks users from taking screenshots as well. In a post on X, Bier said that only the sender needs to have the Explode app.While the app is free to download, users can sign up to Explode+ for $39.99 per year or $7.99 per month to unlock all features. Paid users receive screenshot alerts, can block screenshots altogether, can replay photos that they previously sent, and can lock photo viewing after sending them.Biers posts on X about Explode slant heavily towards taking a dig at Snapchat. In a post, he said after he had talks with Snap about acquiring Gas, the social media company kicked Gas off of the SnapKit developer platform.Two years ago, I met with Snapchats CEO to discuss acquiring my previous company. I openly shared how fast we were growing. Just a week later over the Thanksgiving holiday Snapchat kicked our app off the SnapKit platform, abruptly halting our growth, he said.In a screenshot of an email seen by TechCrunch, Snap sent an email to developers saying that Gas was using URL attachments to make friend recommendations without the explicit intention of the sender Snap thought this violated its policy and attempted to replicate Snaps functionality. Bier said that Gas operated on contacts and didnt rely on Snaps social graph.However, Snap was a major growth driver for the app. In a post in October 2022, Bier said that 23% of Snapchats U.S. user base had viewed a Gas story. He said that sharing a Gas poll with Snapchat was placed as a primary button in the app, and Snaps action broke the app for seven days. Gas apps interface Image Credits: Nikita BierSnap didnt immediately comment on the story. Discord eventually acquired Gas in January 2023 and shut it down in November 2023.At the moment, the app is only available in the U.S. and other countries like Canada, the UK, Australia, the US, France, Germany, and Italy.
    0 Комментарии ·0 Поделились ·83 Просмотры