voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
🚨 EUVD-2026-45129
📊 Score: 6.1/10 (CVSS v3.1)
📦 Product: WooCommerce Placetopay Gateway, WooCommerce Placetopay Gateway Honduras, WooCommerce Placetopay Gateway Colombia (+3 more)
🏢 Vendor: evertec
📅 Updated: 2026-07-17
📝 The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via th...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45129
Possible Phishing 🎣
on: ⚠️hxxps[:]//globalforwardingleadscount[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a5978693b775000045d2d9b
#cybersecurity #phishing #infosec #urldna #scam #infosec
🚨 EUVD-2026-45128
📊 Score: 4.3/10 (CVSS v3.1)
📦 Product: Ninja Forms - Excel Export
🏢 Vendor: SaturdayDrive
📅 Updated: 2026-07-17
📝 The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.6 via the 'spreadsheet_export_form_id' parameter due to missing validation on a user cont...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45128
🚨 EUVD-2026-45127
📊 Score: 4.3/10 (CVSS v3.1)
📦 Product: Ninja Forms - Excel Export
🏢 Vendor: SaturdayDrive
📅 Updated: 2026-07-17
📝 The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.6 via the 'spreadsheet_export_tmp_name' parameter. This makes it possible for authenticated attackers,...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45127
🚨 EUVD-2026-45126
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Fense Proxy & VPN Blocker
🏢 Vendor: devozon
📅 Updated: 2026-07-17
📝 The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce validation on the fense_bpvt_save_settings() function in versions up to, and including...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45126
CVE-2026-49805 in Windows WMI Providers allows local privilege escalation to SYSTEM. Microsoft has patched the flaw and rates exploitation as more likely. #Cybersecurity https://deafnews.it/en/article/windows-wmi-zdi-26-415-vulnerability-allows-escalation-to-system
📰 San Francisco Police Department's release of hours of drone footage from Skydio reveals extensive urban surveillance practices and potential online exposure of citizens' activities.
🔗 https://www.wired.com/story/sfpd-drone-video-leak-surveillance/
📰 AI has discovered a fundamental bug in Linux that was overlooked for 15 years, highlighting ongoing security vulnerabilities in open-source software.
📰 Scammers are exploiting hacked government websites to distribute ads for "leaked" OnlyFans content, prompting thousands of copyright complaints and deterring users from malicious links.
🔗 https://www.wired.com/story/onlyfans-creators-dmca-hacked-government-websites/
AMD Ryzen 7 7700X3D review: A slower 7800X3D, but not necessarily a cheaper one
The 7700X3D is a 7800X3D with lower boost clock speeds, but it doesn’t deliver the same value as we’ve seen with previous versions of this segmentation.
https://www.tomshardware.com/pc-components/cpus/amd-ryzen-7-7700x3d-cpu-review
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
Novel Starland RAT and bespoke WLDR C2 implant deployed in financially motivated campaign
A sophisticated Russian-speaking financially motivated adversary designated UAT-11795 has been conducting malicious operations targeting users in the United States and Europe since June 2025. The campaign delivers a Python-based remote access tool called Starland RAT and a PowerShell-based command-and-control memory implant known as the WLDR agent. The actor distributes trojanized installers disguised as legitimate software including MobaXterm, WebEx, Zoom, DBeaver, and FACEIT through likely ClickFix social engineering techniques. The operation targets victims' credentials and cryptocurrency wallet assets while establishing persistent connections for additional payload delivery. Alternative payloads include CastleStealer and Remcos RAT. The infrastructure utilizes distributed staging and C2 domains, Telegram bots for notifications, and a Polygon smart contract as a fallback mechanism for C2 domain resolution. The WLDR agent features encrypted beaconing, task queuing, and a Runspace execution engine for exe...
Pulse ID: 6a58c1aa702b1130710d1bfb
Pulse Link: https://otx.alienvault.com/pulse/6a58c1aa702b1130710d1bfb
Pulse Author: AlienVault
Created: 2026-07-16 11:34:02
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Europe #InfoSec #OTX #OpenThreatExchange #PowerShell #Python #RAT #Remcos #RemcosRAT #Russia #SocialEngineering #Telegram #Trojan #UnitedStates #Zoom #bot #cryptocurrency #AlienVault
Buying a new Apple device? You can get it tax-free in 8 states - but only on these dates
Certain states will let you buy items tax-free from different retailers, and Apple is one of them. Here's when and the products that qualify.
https://www.zdnet.com/article/apple-products-tax-free-shopping/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
6 cheap kitchen gadgets that will make your life easier for under $20 (I promise)
These kitchen gadgets won't break the bank, but will seriously upgrade your cooking.
https://www.zdnet.com/article/6-best-cheap-kitchen-gadgets/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
Amazon just cut $300 off the Google Pixel 10 Pro - and I'd recommend buying one
Google's Pixel 10 Pro has one of the best camera systems for an Android today. Grab it for $699 right now, one of the best prices we've seen.
https://www.zdnet.com/article/google-pixel-10-pro-deal/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
Security Alert: Even trusted browser extensions can become a security risk.
Researchers discovered that the popular ModHeader Chrome and Edge extension installed by approximately 1.6 million users contained dormant data exfiltration capabilities capable of collecting and encrypting browsing-domain data before sending it to a remote server. While Google and Microsoft have removed the extension from their stores, existing installations must still be manually removed.
This is another reminder that browser extensions deserve the same scrutiny as any other software. Regularly audit installed extensions, remove those you no longer use, and limit permissions to only what’s necessary.
Trust but verify. Your browser is one of the most targeted attack surfaces in your environment.
https://cybersecuritynews.com/chrome-extension-used-million-users-data-exfiltration/amp/
#CyberSecurity #InfoSec #ThreatIntelligence #DataSecurity #Chrome #BrowserSecurity #Privacy #BlueTeam #SecurityAwareness #RiskManagement #ModHeader
From the CyberIntel archive: Hacker Leak Reveals Madison Square Garden's Internal Surveillance Database of VIP Celebrities
Amazon dropped this Blink video doorbell and security camera bundle to 43% off - and we recommend it
This Blink Video Doorbell and Outdoor 4 security camera bundle deal will help you set up a home security system for less.
https://www.zdnet.com/article/amazon-blink-video-doorbell-outdoor-4-bundled-deal/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
📰 Meta denies using AI to terminate workers with disabilities and medical problems in a lawsuit claiming the company's layoff decisions were made by AI, not humans.
📰 The US military deployed explosive drone boats into combat for the first time, striking an Iranian naval port as tensions escalate.
📰 Conductive ink painted directly onto skin forms colorful custom designs that dry into working electrodes, potentially revolutionizing wearable biosensors for health monitoring and other applications.
4 surprise products we could see at Samsung Galaxy Unpacked (including the Galaxy Glasses)
We're expecting some curveballs at Samsung's 2026 Galaxy Unpacked event. Here's everything we know.
https://www.zdnet.com/article/samsung-galaxy-unpacked-what-to-expect-2026/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
Possible Phishing 🎣
on: ⚠️hxxps[:]//docs[.]google[.]com/forms/d/e/1FAIpQLSe4Z9s29VQVkPXF3Shl75RC7dBgxApad0o8mqxc8jImSA55yA/viewform
🧬 Analysis at: https://urldna.io/scan/6a5907c33b7750000587a1e6
#cybersecurity #phishing #infosec #urldna #scam #infosec
🚨 EUVD-2026-45079
📊 Score: 7.5/10 (CVSS v3.1)
📦 Product: wazuh, wazuh
🏢 Vendor: wazuh
📅 Updated: 2026-07-16
📝 Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.0.0 through 4.10.3 and 4.11.0 through 4.14.4, a logic flaw affects the Wazuh Manager's enrollment daemon (authd) and synchronization daemon (remote...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45079
🚨 EUVD-2026-45078
📊 Score: 7.5/10 (CVSS v3.1)
📦 Product: wazuh
🏢 Vendor: wazuh
📅 Updated: 2026-07-16
📝 Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 1.0.0 and above, prior to 4.14.5, a heap buffer overflow in wazuh-analysisd allows an unauthenticated remote attacker to crash the Wazuh manager's analysis ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45078
🚨 EUVD-2026-45077
📊 Score: 6.5/10 (CVSS v3.1)
📦 Product: wazuh
🏢 Vendor: wazuh
📅 Updated: 2026-07-16
📝 Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.9.0 and above, prior to 4.14.5, a remote attacker can trigger memory exhaustion in the cluster protocol parser by sending a crafted message header with an...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45077
🚨 EUVD-2026-45076
📊 Score: 4.3/10 (CVSS v3.1)
📦 Product: wazuh
🏢 Vendor: wazuh
📅 Updated: 2026-07-16
📝 Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.6.0 and above, prior to 4.14.5, a logic error in CheckRateLimitsMiddleware.dispatch() causes the /events endpoint rate check to unconditionally overwrite ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45076
🚨 EUVD-2026-45075
📊 Score: 7.5/10 (CVSS v3.1)
📦 Product: H2O
🏢 Vendor: h2o
📅 Updated: 2026-07-16
📝 h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 9265bdd, there is an HTTP/2 state amplification issue that combines HPACK decompression amplification with Slowloris-style stream stalling. Amplified decoded header state can be reta...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45075
🚨 EUVD-2026-45074
📊 Score: 7.5/10 (CVSS v3.1)
📦 Product: H2O
🏢 Vendor: h2o
📅 Updated: 2026-07-16
📝 h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 6b5370d, h2o is vulnerable to a Denial of Service attack when calling alloca under certain conditions. When serving static files, h2o builds the file path on stack, by calling alloca...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45074
🚨 EUVD-2026-45073
📊 Score: 5.9/10 (CVSS v3.1)
📦 Product: H2O
🏢 Vendor: h2o
📅 Updated: 2026-07-16
📝 h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 8dc37cb, when h2o receives a ClientHello message over TLS or QUIC and it contains a zero-length SNI extension, the h2o server runs over the zero-length hostname while trying to copy ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45073
🚨 EUVD-2026-45064
📊 Score: 10.0/10 (CVSS v3.1)
📦 Product: enterprise_gateway
🏢 Vendor: jupyter-server
📅 Updated: 2026-07-16
📝 Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In versions 2.0.0rc2 and above, prior to 3.3.0, the environment variables (KERNEL_XXX) used du...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45064
secsolutionforum: Bologna capitale della security 2026: di Lucia Dallavalle Dimenticate il solito palinsesto espositivo. La Mostra-Convegno secsolutionforum 2026, in programma il 7 e 8 ottobre a BolognaFiere, aspira esplicitamente a lasciare il segno. Organizzato da Ethos Media Group, secsolutionforum torna in presenza - dopo sei edizioni di successo...
#secsolutionforum #LuciaDallavalle #BolognaFiere #sicurezzafisica #cybersecurity http://dlvr.it/TTZRgt
The Patch Wars have begun
Microsoft released an unprecedented 622 vulnerability patches in July's Patch Tuesday, with 62 critical severity issues and three zero-days, two actively exploited. This represents more vulnerabilities than all of 2018 combined and marks a dramatic shift from the typical five patches issued in July two years prior. Microsoft attributes this surge to AI frontier model-accelerated vulnerability research. While major vendors like Microsoft possess resources to handle this volume, smaller companies face significant challenges. The concern extends beyond discovery to deployment, as traditional IT patch testing and stability review processes struggle under this unprecedented load. Organizations must differentiate between temporary surges and the new normal operational tempo, as continuous high-volume patching may become standard. This situation places extraordinary pressure on IT administrators and change management teams who must adapt to a sustained flood of KEV and EPSS notifications while maintaining infrast...
Pulse ID: 6a5947760995db41a09b5025
Pulse Link: https://otx.alienvault.com/pulse/6a5947760995db41a09b5025
Pulse Author: AlienVault
Created: 2026-07-16 21:04:54
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Microsoft #OTX #OpenThreatExchange #RAT #RCE #Vulnerability #ZeroDay #bot #AlienVault
Capital One has upgraded PANW with a $421 price target following joint CISA and FBI warnings regarding Russian cyber threats against critical infrastructure. CrowdStrike and Okta are seeing similar market momentum. #PANW #StockMarket #Cybersecurity #TechNews #Investing
https://blazetrends.com/palo-alto-networks-surges-to-421-target-as-russian-cyber-threats-force-infrastructure-upgrades/?fsp_sid=52917
🟢 Intelligence Disclosure | 5/10
🇺🇸 🇨🇳 🇷🇺
Release of Intelligence on Election Interference
Trump announced the immediate release of critical intelligence revealing vulnerabilities in US election infrastructure and Chinese interference.
Intel becomes the first company to ship high-volume logic chips made with ASML's High NA EUV — select Panther Lake layers on 18A are now dual-qualified for 0.55 NA scanners
Intel is using ASML’s High-NA EUV tools to pattern select Panther Lake layers, marking the technology’s first use in high-volume logic production
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
Verizon is cutting jobs and selling hundreds of stores to turn its fortune around
Verizon is parting ways with hundreds of retail stores.
https://www.androidauthority.com/verizon-selling-hundreds-of-stores-3688400/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Gemini gets ready to let you fine-tune its voice models
Gemini voice customization will let you tweak energy, warmth, and more
https://www.androidauthority.com/gemini-voice-customization-3688391/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Why are people buying so many CDs?
CD sales are apparently going up, reportedly thanks to fans realizing they're an affordable way to support their favorite artists. According to a new report from research firm Luminate, 16.3 million CDs were sold in the…
https://www.theverge.com/entertainment/966726/cd-sales-vinyl-physical-media-luminate
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
#California Steps Back From Dangerous Expansion of its Age-Gating Law
https://www.eff.org/deeplinks/2026/07/california-steps-back-dangerous-expansion-its-age-gating-law
"Health data is increasingly an important part of law enforcement or government investigations. Wearable data has been critical in a number of cases, where information about heart rate and steps was used to determine the whereabouts of individuals. And the surveillance company Penlink calls fitness trackers and wearables an “overlooked source” for law enforcement since they tend to show movement patterns and changes in heart rates. Law enforcement can try to get access to this data through subpoenas or warrants.
There are many potential privacy issues with these sorts of devices, including whether the companies who make them share or sell information to third-parties. But here we are choosing to focus on two facets we’re concerned with around health data itself: 1) whether the company shares information with law enforcement and governments and 2) if they offer end-to-end encryption, which means the company itself can’t access that health data to begin with."
#SmartObjects #SmartWatches #SmartRings #IoT #Surveillance #Privacy #CyberSecurity #Encryption
"This technical analysis provides the most detailed view yet into the inner workings of the Pegasus spyware system. This includes confirmation of key technical capabilities such as the infection vectors and methodologies used to infect devices, supported by analysis of internal NSO Group documents, that until now had only been identified via forensic investigations. It also presents new material further validating the accuracy and significance of the dataset underpinning the original Pegasus Project investigation. Finally, this research provides an updated analysis, drawing on previously published Pegasus forensic evidence and newly released materials, to validate the technical methodology used to forensically link Pegasus spyware attacks targeting different victims as originating from the same Pegasus customer.
A key aim of this publication is to document and demystify the functionality and operations of technological systems like Pegasus. We hope that it will inform the wider spyware accountability community on how complex surveillance systems such as Pegasus are used by government customers, and also illustrate the key and ongoing role of spyware vendors in keeping such systems operational. We believe this public understanding is of critical value to technologists, researchers, and policy makers and others with an interest in understanding the targeted surveillance ecosystem and threats posed to human rights by surveillance technologies.
The contents of this technical research draw heavily on a large pool of confidential NSO Group training material, presentations and internal technical documentation which were disclosed as part of a long-running civil case taken by WhatsApp and Meta against NSO Group in U.S. court. This new material provides an unprecedented insight into the evolution of NSO Group’s spyware."
#CyberSecurity #Spyware #NSOGroup #Pegasus #Surveillance #Privacy
Engadget: A hacker accessed Suno source code that reportedly details how the company scraped millions of songs . “Suno — an app that vomits out soulless audio in the form of AI-generated ‘music’ — has been hacked. According to 404 Media, the hacker accessed data related to Suno’s training practices, as well as details on its customers.”
https://rbfirehose.com/2026/07/16/engadget-a-hacker-accessed-suno-source-code-that-reportedly-details-how-the-company-scraped-millions-of-songs/🚨 EUVD-2026-45019
📊 Score: 7.5/10 (CVSS v3.1)
📦 Product: coredns
🏢 Vendor: coredns
📅 Updated: 2026-07-16
📝 CoreDNS is a DNS server written in Go. Prior to 1.14.4, a single 28-byte UDP datagram can crash the CoreDNS process when the proxyproto plugin is enabled because plugin/pkg/proxyproto/proxyproto.go PacketConn.ReadFrom handles a PROXY v2 header with non-UDP t...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45019
🚨 EUVD-2026-45018
📊 Score: 3.7/10 (CVSS v3.1)
📦 Product: coredns
🏢 Vendor: coredns
📅 Updated: 2026-07-16
📝 CoreDNS is a DNS server written in Go. From 1.9.4 until 1.14.5, a network DNS client allowed to request AXFR for a CoreDNS zone can trigger a panic when CoreDNS is configured with k8s_external headless-service zone transfers and Kubernetes contains a headles...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45018
🚨 EUVD-2026-45017
📊 Score: 7.3/10 (CVSS v3.1)
📦 Product: cert-manager, cert-manager
🏢 Vendor: cert-manager
📅 Updated: 2026-07-16
📝 cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the process of obtaining, renewing and using those certificates. From 1.18.0 until 1.19.6 and 1.20.3, Challenge resources ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45017
🚨 EUVD-2026-45016
📊 Score: 8.7/10 (CVSS v3.1)
📦 Product: centrifugo
🏢 Vendor: centrifugal
📅 Updated: 2026-07-16
📝 Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.4, Centrifugo unidirectional WebSocket transport with uni_websocket.compression enabled enforced uni_websocket.message_size_limit against compressed wire-frame length in in...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45016
🚨 EUVD-2026-45015
📊 Score: 8.2/10 (CVSS v3.1)
📦 Product: centrifugo
🏢 Vendor: centrifugal
📅 Updated: 2026-07-16
📝 Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.1, Centrifugo dynamic JWKS endpoint verification could reuse a key for one allowed issuer to verify a JWT for another allowed issuer because the JWKS cache and singleflight...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45015