Pacific Block, an image and video blocker for Safari, now supports Shortcuts

I’ve mentioned the Pacific Block extension for Safari in passing a few times before. It’s a content blocker, but instead of ads and trackers, it blocks images, audio, and video. It’s great for saving data on a limited mobile plan (like a pay-as-you-go carrier plan) and for speeding up web browsing on unstable connections.

Back in November 2025, I suggested a feature to Jeremy, the developer of Pacific Block: integration with the Shortcuts app, to enable automations. It shipped in version 1.8, released on the 15th.

It works! Well, it actually started working four days later, once a fix for automation uses landed in version 1.9.

I built an automation in Shortcuts exactly the way I’d pictured it a year earlier: whenever I disconnect from any Wi-Fi network, turn on both blocks (images and audio/video) in Pacific Block. Connect to a Wi-Fi network and both turn off again.

I still need to tweak it a bit. I was on a flaky wireless network the other day and noticed the automations kept firing constantly, every time iOS dropped the connection and immediately picked it back up. I think adding a couple of minutes of delay between state changes, and/or some conditionals (if… then) should fix that.

Pacific Block is a universal purchase for USD 2.99 on the App Store.

Wipr 2 expands Safari ad blocking to all other apps

Wipr 2 icon.Wipr 2, the Safari ad blocker created by Kaylee Serena (and the one I use), got a new feature that extends its functionality system-wide: Filtr.

Developed over the past ten months, it makes use of a new technology introduced in version 26 of Apple’s operating systems, the URL Filter. According to Kaylee, it allows you to “to block network requests system-wide without having access to any network traffic at all, and with more granularity than previous solutions.” She says this is the first app to make use of the URL Filter.

(more…)

Firefox joins Chrome and Edge in the problem of dormant extensions that spy on users 
malwarebytes.com

The Malwarebytes blog warns of a new wave of compromised browser extensions. The technique used, called steganography, is ingenious:

The use of malicious code in images is a technique called steganography. Earlier GhostPoster extensions hid JavaScript loader code inside PNG icons such as logo.png for Firefox extensions like “Free VPN Forever,” using a marker (for example, three equals signs) in the raw bytes to separate image data from payload.

Newer variants moved to embedding payloads in arbitrary images inside the extension bundle, then decoding and decrypting them at runtime. This makes the malicious code much harder for researchers to detect.

A group of researchers found 17 new contaminated extensions in Firefox. They have attractive names, such as “Ads Block Ultimate” and “Youtube Download.”

The focus of malicious actors on browser extensions is understandable. They have privileged access to the most intimate app we use on a daily basis, update automatically, and, with few exceptions, aren’t household names — I believe that extensions are searched for more by purpose than by name. Another problem is the market for buying and selling popular extensions, which change owners with no transparency.

A good way to mitigate damage is to limit yourself to extensions endorsed by browser stores. In Firefox, they have a "Recommended" seal. In Chrome, extensions reviewed by Google get a green “Featured” seal, according to the store's help section. In search results, you can filter them to display only featured extensions.