voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
🚨 EUVD-2026-45075
📊 Score: 7.5/10 (CVSS v3.1)
📦 Product: H2O
🏢 Vendor: h2o
📅 Updated: 2026-07-16
📝 h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 9265bdd, there is an HTTP/2 state amplification issue that combines HPACK decompression amplification with Slowloris-style stream stalling. Amplified decoded header state can be reta...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45075
🚨 EUVD-2026-45074
📊 Score: 7.5/10 (CVSS v3.1)
📦 Product: H2O
🏢 Vendor: h2o
📅 Updated: 2026-07-16
📝 h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 6b5370d, h2o is vulnerable to a Denial of Service attack when calling alloca under certain conditions. When serving static files, h2o builds the file path on stack, by calling alloca...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45074
🚨 EUVD-2026-45073
📊 Score: 5.9/10 (CVSS v3.1)
📦 Product: H2O
🏢 Vendor: h2o
📅 Updated: 2026-07-16
📝 h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 8dc37cb, when h2o receives a ClientHello message over TLS or QUIC and it contains a zero-length SNI extension, the h2o server runs over the zero-length hostname while trying to copy ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45073
🚨 EUVD-2026-45064
📊 Score: 10.0/10 (CVSS v3.1)
📦 Product: enterprise_gateway
🏢 Vendor: jupyter-server
📅 Updated: 2026-07-16
📝 Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In versions 2.0.0rc2 and above, prior to 3.3.0, the environment variables (KERNEL_XXX) used du...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45064
secsolutionforum: Bologna capitale della security 2026: di Lucia Dallavalle Dimenticate il solito palinsesto espositivo. La Mostra-Convegno secsolutionforum 2026, in programma il 7 e 8 ottobre a BolognaFiere, aspira esplicitamente a lasciare il segno. Organizzato da Ethos Media Group, secsolutionforum torna in presenza - dopo sei edizioni di successo...
#secsolutionforum #LuciaDallavalle #BolognaFiere #sicurezzafisica #cybersecurity http://dlvr.it/TTZRgt
The Patch Wars have begun
Microsoft released an unprecedented 622 vulnerability patches in July's Patch Tuesday, with 62 critical severity issues and three zero-days, two actively exploited. This represents more vulnerabilities than all of 2018 combined and marks a dramatic shift from the typical five patches issued in July two years prior. Microsoft attributes this surge to AI frontier model-accelerated vulnerability research. While major vendors like Microsoft possess resources to handle this volume, smaller companies face significant challenges. The concern extends beyond discovery to deployment, as traditional IT patch testing and stability review processes struggle under this unprecedented load. Organizations must differentiate between temporary surges and the new normal operational tempo, as continuous high-volume patching may become standard. This situation places extraordinary pressure on IT administrators and change management teams who must adapt to a sustained flood of KEV and EPSS notifications while maintaining infrast...
Pulse ID: 6a5947760995db41a09b5025
Pulse Link: https://otx.alienvault.com/pulse/6a5947760995db41a09b5025
Pulse Author: AlienVault
Created: 2026-07-16 21:04:54
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Microsoft #OTX #OpenThreatExchange #RAT #RCE #Vulnerability #ZeroDay #bot #AlienVault
Capital One has upgraded PANW with a $421 price target following joint CISA and FBI warnings regarding Russian cyber threats against critical infrastructure. CrowdStrike and Okta are seeing similar market momentum. #PANW #StockMarket #Cybersecurity #TechNews #Investing
https://blazetrends.com/palo-alto-networks-surges-to-421-target-as-russian-cyber-threats-force-infrastructure-upgrades/?fsp_sid=52917
🟢 Intelligence Disclosure | 5/10
🇺🇸 🇨🇳 🇷🇺
Release of Intelligence on Election Interference
Trump announced the immediate release of critical intelligence revealing vulnerabilities in US election infrastructure and Chinese interference.
Intel becomes the first company to ship high-volume logic chips made with ASML's High NA EUV — select Panther Lake layers on 18A are now dual-qualified for 0.55 NA scanners
Intel is using ASML’s High-NA EUV tools to pattern select Panther Lake layers, marking the technology’s first use in high-volume logic production
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
Verizon is cutting jobs and selling hundreds of stores to turn its fortune around
Verizon is parting ways with hundreds of retail stores.
https://www.androidauthority.com/verizon-selling-hundreds-of-stores-3688400/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Gemini gets ready to let you fine-tune its voice models
Gemini voice customization will let you tweak energy, warmth, and more
https://www.androidauthority.com/gemini-voice-customization-3688391/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Why are people buying so many CDs?
CD sales are apparently going up, reportedly thanks to fans realizing they're an affordable way to support their favorite artists. According to a new report from research firm Luminate, 16.3 million CDs were sold in the…
https://www.theverge.com/entertainment/966726/cd-sales-vinyl-physical-media-luminate
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
#California Steps Back From Dangerous Expansion of its Age-Gating Law
https://www.eff.org/deeplinks/2026/07/california-steps-back-dangerous-expansion-its-age-gating-law
"Health data is increasingly an important part of law enforcement or government investigations. Wearable data has been critical in a number of cases, where information about heart rate and steps was used to determine the whereabouts of individuals. And the surveillance company Penlink calls fitness trackers and wearables an “overlooked source” for law enforcement since they tend to show movement patterns and changes in heart rates. Law enforcement can try to get access to this data through subpoenas or warrants.
There are many potential privacy issues with these sorts of devices, including whether the companies who make them share or sell information to third-parties. But here we are choosing to focus on two facets we’re concerned with around health data itself: 1) whether the company shares information with law enforcement and governments and 2) if they offer end-to-end encryption, which means the company itself can’t access that health data to begin with."
#SmartObjects #SmartWatches #SmartRings #IoT #Surveillance #Privacy #CyberSecurity #Encryption
"This technical analysis provides the most detailed view yet into the inner workings of the Pegasus spyware system. This includes confirmation of key technical capabilities such as the infection vectors and methodologies used to infect devices, supported by analysis of internal NSO Group documents, that until now had only been identified via forensic investigations. It also presents new material further validating the accuracy and significance of the dataset underpinning the original Pegasus Project investigation. Finally, this research provides an updated analysis, drawing on previously published Pegasus forensic evidence and newly released materials, to validate the technical methodology used to forensically link Pegasus spyware attacks targeting different victims as originating from the same Pegasus customer.
A key aim of this publication is to document and demystify the functionality and operations of technological systems like Pegasus. We hope that it will inform the wider spyware accountability community on how complex surveillance systems such as Pegasus are used by government customers, and also illustrate the key and ongoing role of spyware vendors in keeping such systems operational. We believe this public understanding is of critical value to technologists, researchers, and policy makers and others with an interest in understanding the targeted surveillance ecosystem and threats posed to human rights by surveillance technologies.
The contents of this technical research draw heavily on a large pool of confidential NSO Group training material, presentations and internal technical documentation which were disclosed as part of a long-running civil case taken by WhatsApp and Meta against NSO Group in U.S. court. This new material provides an unprecedented insight into the evolution of NSO Group’s spyware."
#CyberSecurity #Spyware #NSOGroup #Pegasus #Surveillance #Privacy
Engadget: A hacker accessed Suno source code that reportedly details how the company scraped millions of songs . “Suno — an app that vomits out soulless audio in the form of AI-generated ‘music’ — has been hacked. According to 404 Media, the hacker accessed data related to Suno’s training practices, as well as details on its customers.”
https://rbfirehose.com/2026/07/16/engadget-a-hacker-accessed-suno-source-code-that-reportedly-details-how-the-company-scraped-millions-of-songs/🚨 EUVD-2026-45019
📊 Score: 7.5/10 (CVSS v3.1)
📦 Product: coredns
🏢 Vendor: coredns
📅 Updated: 2026-07-16
📝 CoreDNS is a DNS server written in Go. Prior to 1.14.4, a single 28-byte UDP datagram can crash the CoreDNS process when the proxyproto plugin is enabled because plugin/pkg/proxyproto/proxyproto.go PacketConn.ReadFrom handles a PROXY v2 header with non-UDP t...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45019
🚨 EUVD-2026-45018
📊 Score: 3.7/10 (CVSS v3.1)
📦 Product: coredns
🏢 Vendor: coredns
📅 Updated: 2026-07-16
📝 CoreDNS is a DNS server written in Go. From 1.9.4 until 1.14.5, a network DNS client allowed to request AXFR for a CoreDNS zone can trigger a panic when CoreDNS is configured with k8s_external headless-service zone transfers and Kubernetes contains a headles...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45018
🚨 EUVD-2026-45017
📊 Score: 7.3/10 (CVSS v3.1)
📦 Product: cert-manager, cert-manager
🏢 Vendor: cert-manager
📅 Updated: 2026-07-16
📝 cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the process of obtaining, renewing and using those certificates. From 1.18.0 until 1.19.6 and 1.20.3, Challenge resources ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45017
🚨 EUVD-2026-45016
📊 Score: 8.7/10 (CVSS v3.1)
📦 Product: centrifugo
🏢 Vendor: centrifugal
📅 Updated: 2026-07-16
📝 Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.4, Centrifugo unidirectional WebSocket transport with uni_websocket.compression enabled enforced uni_websocket.message_size_limit against compressed wire-frame length in in...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45016
🚨 EUVD-2026-45015
📊 Score: 8.2/10 (CVSS v3.1)
📦 Product: centrifugo
🏢 Vendor: centrifugal
📅 Updated: 2026-07-16
📝 Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.1, Centrifugo dynamic JWKS endpoint verification could reuse a key for one allowed issuer to verify a JWT for another allowed issuer because the JWKS cache and singleflight...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45015
🚨 EUVD-2026-45014
📊 Score: 9.1/10 (CVSS v3.1)
📦 Product: illumos-gate, SmartOS, OmniOS (+3 more)
🏢 Vendor: OmniOS, Triton Data Center, illumos
📅 Updated: 2026-07-16
📝 The illumos SCTP inbound path performs association lookup for INIT ACK chunks without adequately validating the address parameters carried in the chunk. Since this lookup runs during packet classifi...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45014
🚨 EUVD-2026-45013
📊 Score: 9.0/10 (CVSS v3.1)
📦 Product: wg-easy, wg-easy
🏢 Vendor: wg-easy
📅 Updated: 2026-07-16
📝 WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation vulnerability that allows unauthenticated network attackers to recover WireGuard peer credentials by brute-forcing a keyspace of...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45013
🚨 EUVD-2026-45034
📊 Score: 5.8/10 (CVSS v3.1)
📦 Product: OmniOS, OmniOS, OmniOS (+3 more)
🏢 Vendor: illumos, Triton Data Center, OmniOS
📅 Updated: 2026-07-16
📝 A time-of-check to time-of-use (TOCTOU) flaw in the illumos data-link pseudo-driver (dld) affects handling of the DLDIOC_GETMACPROP and DLDIOC_SETMACPROP ioctls on /dev/dld. drv_ioc_prop_common() in usr/sr...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45034
🚨 EUVD-2026-45033
📊 Score: 6.1/10 (CVSS v3.1)
📦 Product: bunkerweb
🏢 Vendor: bunkerity
📅 Updated: 2026-07-16
📝 bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). Prior to BunkerWeb 1.6.12 and BunkerWeb PRO 0.57, authenticated Host header handling in the BunkerWeb UI and API improperly validated and neutralized user-controlled input in...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45033
🚨 EUVD-2026-45032
📊 Score: 5.4/10 (CVSS v3.1)
📦 Product: bunkerweb
🏢 Vendor: bunkerity
📅 Updated: 2026-07-16
📝 bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). From 1.6.2 until 1.6.12, the BunkerWeb web UI BiscuitMiddleware authorization bypass list included the /cache/ URL prefix, so routes in src/ui/app/routes/cache.py protected o...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45032
🚨 EUVD-2026-45031
📊 Score: 7.1/10 (CVSS v3.1)
📦 Product: genql, genql
🏢 Vendor: remorses
📅 Updated: 2026-07-16
📝 remorses/genql before version 6.3.4 allows an authenticated attacker with control of the GraphQL schema that is passed to genql to inject arbitrary JavaScript or TypeScript. The malicious code is injected into the generated schema.ts file and executes ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45031
🚨 EUVD-2026-45030
📊 Score: 8.7/10 (CVSS v3.1)
📦 Product: Whistle
🏢 Vendor: avwo
📅 Updated: 2026-07-16
📝 Whistle is an HTTP, HTTP2, HTTPS, and WebSocket debugging proxy. Prior to 2.10.3, lib/service/service.js handles GET /cgi-bin/temp/get by reading req.query.filename, joining it to TEMP_FILES_PATH only when it matches the temporary file pattern, and otherwise pa...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45030
🚨 EUVD-2026-45029
📊 Score: 8.9/10 (CVSS v3.1)
📦 Product: argo-workflows, argo-workflows
🏢 Vendor: argoproj
📅 Updated: 2026-07-16
📝 Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 3.7.15 and 4.0.6, the allow-list fix for CVE-2026-31892 is incomplete because workflow/util/merge.go ValidateUse...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45029
🚨 EUVD-2026-45028
📊 Score: 5.9/10 (CVSS v3.1)
📦 Product: activepieces
🏢 Vendor: activepieces
📅 Updated: 2026-07-16
📝 Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the git-sync feature clones a user-configured Git repository into a temporary directory on the server and then writes flow, table, and connection state into it before ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45028
🚨 EUVD-2026-45027
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: activepieces
🏢 Vendor: activepieces
📅 Updated: 2026-07-16
📝 Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /v1/step-files/signed download endpoint verified the supplied JWT against the shared signing secret but did not check the token's audience, and combined with a mis...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45027
🚨 EUVD-2026-44994
📊 Score: 6.2/10 (CVSS v3.1)
📦 Product: dasel
🏢 Vendor: TomWright
📅 Updated: 2026-07-16
📝 Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.10.1, the selector lexer matchRegexPattern closure in (*Tokenizer).parseCurRune in selector/lexer/tokenize.go loops while tokenizing an unt...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44994
Possible Phishing 🎣
on: ⚠️hxxps[:]//pub-eec4ae31337347448b4d9a7013a85762[.]r2[.]dev/eknt[.]html
🧬 Analysis at: https://urldna.io/scan/6a58abdc3b775000058796c1
#cybersecurity #phishing #infosec #urldna #scam #infosec
Google is working on a fix for those annoying Pixel Watch permissions errors
There's no fix ready just yet, but Google says that it's aware of the problem and working on one.
https://www.androidauthority.com/pixel-watch-permissions-errors-3688428/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
🖲️ #Cybersecurity #Ciberseguridad #Ciberseguranca #Security #Seguridad #Seguranca #News #Noticia #Noticias #Tecnologia #Technology
⚫ Frontier AI: The Genie's Out of the Bottle, But Where's the Rulebook?
🔗 https://www.darkreading.com/cybersecurity-operations/frontier-ai-genie-out-of-bottle-where-rulebook
Cutting-edge artificial intelligence models are deploying with more independence and less human oversight. Several state governments are trying to legislate transparency in their use.
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery
On July 14, 2026, a coordinated supply chain attack compromised the @asyncapi npm organization, affecting five package versions across four packages. The attack originated from a GitHub Actions workflow vulnerability that exposed privileged credentials, enabling unauthorized code injection. Unlike typical postinstall attacks, this campaign executes at module import time, bypassing common npm install --ignore-scripts protections. The malicious code spawned hidden processes that fetched a second-stage payload from IPFS, deploying the Miasma modular runtime with command-and-control capabilities, persistence mechanisms, and credential harvesting features. The payload included disabled modules for supply-chain propagation, AI-tool poisoning, and sandbox evasion. All compromised packages were published through legitimate GitHub OIDC workflows with valid provenance signatures, masking the malicious activity within trusted release processes.
Pulse ID: 6a58813c09a76d1819c69bb0
Pulse Link: https://otx.alienvault.com/pulse/6a58813c09a76d1819c69bb0
Pulse Author: AlienVault
Created: 2026-07-16 06:59:08
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CodeInjection #CredentialHarvesting #CyberSecurity #GitHub #InfoSec #NPM #OTX #OpenThreatExchange #Rust #SMS #SupplyChain #Vulnerability #bot #AlienVault
Identity Attacks Overtake Exploits as Top Ransomware Cause
#exploit #news #hacker #identity #attack #security #cybersecurity
https://www.darkreading.com/identity-access-management-security/identity-attacks-overtake-exploits-top-ransomware-cause
Google Search’s AI Mode can now handle tasks beyond the search bar
Why app-hop when Google Search can do the busywork for you?
https://www.androidauthority.com/google-ai-mode-connected-apps-3688202/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Hisense’s latest 50-inch E7 Cinema Series Fire TV returns to its Prime Day price
Amazon just cut the Hisense 50-inch E7 to $397.99. You get 4K, Mini-LED, Hi-QLED, and 144Hz for under $400.
https://www.androidauthority.com/hisense-50-inch-e7-cinema-series-4k-uhd-smart-fire-tv-deal-3688301/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Lenovo’s Tab Plus Gen 2 tablet with that giant speaker is now up for grabs in the US
Lenovo’s power-packed Tab Plus Gen 2 has officially reached US shores following its launch in Europe last month.
https://www.androidauthority.com/lenovo-tab-plus-gen-2-us-launch-3688281/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
🚨 EUVD-2026-44947
📊 Score: 6.5/10 (CVSS v3.1)
📦 Product: UFO
🏢 Vendor: Microsoft
📅 Updated: 2026-07-16
📝 Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.7, the COMMAND_RESULTS handler in ufo/server/ws/handler.py called get_or_create_session in ufo/server/services/session_manager.py without owner_client_id,...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44947
🚨 EUVD-2026-44946
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Perfect Support Ticketing & Document Management System
🏢 Vendor: Ultimate Fosters
📅 Updated: 2026-07-16
📝 Perfect Support Ticketing & Document Management System through 1.7 contains a broken access control vulnerability that allows authenticated attackers with Agent-level privileges to manipulate the Suppor...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44946
🚨 EUVD-2026-44938
📊 Score: 9.3/10 (CVSS v3.1)
📦 Product: o365-moodle, o365-moodle, o365-moodle
🏢 Vendor: Microsoft
📅 Updated: 2026-07-16
📝 The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0.5, and 5.1.1, the Microsoft Office 365 Integration plugin local_o365 Teams S...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44938
🚨 EUVD-2026-44945
📊 Score: 5.1/10 (CVSS v3.1)
📦 Product: Perfect Support Ticketing & Document Management System
🏢 Vendor: Ultimate Fosters
📅 Updated: 2026-07-16
📝 Perfect Support Ticketing & Document Management System through 1.7 contains a stored cross-site scripting vulnerability that allows authenticated attackers with Agent-level privileges to inject maliciou...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44945
🚨 EUVD-2026-44944
📊 Score: 6.8/10 (CVSS v3.1)
📦 Product: Axivion, Axivion, Axivion (+2 more)
🏢 Vendor: Qt
📅 Updated: 2026-07-16
📝 An Open Redirect vulnerability (CWE-601) exists in the OAuth/OIDC authentication implementation of the Axivion Dashboard. The login flow did not properly restrict the post-authentication redirect to the application's own origin, so a u...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44944
🚨 EUVD-2026-44943
📊 Score: 4.3/10 (CVSS v3.1)
📦 Product: UFO
🏢 Vendor: Microsoft
📅 Updated: 2026-07-16
📝 Microsoft UFO open-source framework for intelligent automation across devices and platforms. From 3.0.0 until 3.0.6, a client connected to the UFO WebSocket server as a DEVICE could call DEVICE_INFO_REQUEST with another device's target_id and receive that devi...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44943
🚨 EUVD-2026-44941
📊 Score: 4.3/10 (CVSS v3.1)
📦 Product: simplechat
🏢 Vendor: Microsoft
📅 Updated: 2026-07-16
📝 SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.203, the authenticated GET /api/user/info/<user_id> and GET /api/user/profile-image/<user_id> endpoints in applicati...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44941