voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
Community Health Center of Buffalo Reports Data Breach
Community Health Center of Buffalo confirmed data breaches affecting at least 501 individuals, exposing medical and personal information .
****
#cybersecurity #infosec #incident #databreach
https://beyondmachines.net/event_details/community-health-center-of-buffalo-reports-data-breach-1-j-x-d-n/gD2P6Ple2L
AI and the next wave of conspiracies #negativepid #digitalInvestigations #OSINT #cybersecurity #AI #tech #onlineInvestigations #robotics #cyberpsychology #cybercrime https://negativepid.blog/ai-and-the-next-wave-of-conspiracies/?utm_source=mastodon&utm_medium=social&utm_campaign=fedica-Negative-PID-Blog
Microsoft patched a severe Age of Empires CVE. Attackers exploited game lobbies for remote code execution. Update your game immediately to stay safe.
#AgeOfEmpires #CVE202650663 #Cybersecurity #Microsoft #GameSecurity
It’s settled: OnePlus is officially exiting North America and Europe
OnePlus will stop selling all devices in North America and Europe as OPPO takes the wheel.
https://www.androidauthority.com/oneplus-north-america-europe-exit-plans-reasons-future-3687095/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Still using passwords? Attackers are counting on it.
MFA and passkeys reduce risk, simplify access, and strengthen security.
Ready for passwordless authentication?
Learn more: https://zurl.co/LwPj8
#Passkeys #MFA #Passwordless #CyberSecurity #IAM #ZeroTrust #InfoSecK2K
One IAM audit isn't enough.
Identity threats evolve constantly. Regular IAM assessments help uncover hidden access gaps, reduce risk, and strengthen compliance.
Learn how we can help: https://zurl.co/O2xYL
#IAM #CyberSecurity #ZeroTrust #IdentitySecurity #InfoSecK2K
11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windows Host-Surveillance Payload
Eleven malicious NuGet packages distributed as .NET command-line tools masquerade as game utilities and cheats for popular games including Albion Online, GTA5RP, GrandRP, and Throne and Liberty. Each package functions as a first-stage downloader that uses DNS-over-HTTPS to bypass local controls, requests UAC elevation to resync system time, and fetches a second-stage PyInstaller payload named pepesoft.exe from GitHub and Hugging Face under username pepegit666. The payload binds to hardware fingerprints, enforces licensing through Google Sheets telemetry, honors remote ban-lists, and in three variants exposes Telegram bot commands enabling screenshot capture and remote control. All packages share identical AWS credentials and mutex identifiers, linking them to a single Russian-speaking operator running a commercial game-automation service marketed through pepesoft.ru and Telegram channel pepesoft777.
Pulse ID: 6a57b568d98a7ae03ccd6071
Pulse Link: https://otx.alienvault.com/pulse/6a57b568d98a7ae03ccd6071
Pulse Author: AlienVault
Created: 2026-07-15 16:29:28
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #CyberSecurity #DNS #GitHub #Google #HTTP #HTTPS #HuggingFace #InfoSec #NET #NuGet #OTX #OpenThreatExchange #RAT #RCE #Russia #Telegram #Windows #bot #AlienVault
🖲️ #Cybersecurity #Ciberseguridad #Ciberseguranca #Security #Seguridad #Seguranca #News #Noticia #Noticias #Tecnologia #Technology
⚫ Is 'Tech-xit' Imminent? UK Steps Up Sovereignty Push Amid AI Strife
🔗 https://www.darkreading.com/cybersecurity-operations/tech-xit-uk-sovereignty-push-amid-ai-strife
The US government's restrictions on Anthropic and OpenAI frontier models have intensified calls in the UK and other countries to reduce their reliance on US tech companies, with significant
5 smart home gadgets I consider completely non-negotiable - and why
These smart home gadgets elevate my home and routine. Here's why you may want them too.
https://www.zdnet.com/article/5-smart-home-gadgets-i-consider-completely-non-negotiable-and-why/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
I never leave for vacation without doing these 7 home security checks first
Burglars target empty homes, and insurers deny frozen-pipe claims. Here's the tech that solves these issues and others before you leave.
https://www.zdnet.com/article/7-home-security-checks-before-vacation/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
Ukraine conducts record drone strike of 2,500km after 12-hour flight — $55,000 unit made of plywood halts operations at Russia's largest gasoline producer
Ukrainian FP-1 drones struck the Gazprom Neft oil refinery in Omsk, Siberia, on July 6 after flying roughly 2,500 km over more than 12 hours.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor
Pulse ID: 6a585dc530cfef480c1f0bbd
Pulse Link: https://otx.alienvault.com/pulse/6a585dc530cfef480c1f0bbd
Pulse Author: Tr1sa111
Created: 2026-07-16 04:27:49
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #bot #Tr1sa111
Inside an IoT Botnet Framework With LLM-Assisted Development
Pulse ID: 6a585dd1af5d4dd0ee2a8178
Pulse Link: https://otx.alienvault.com/pulse/6a585dd1af5d4dd0ee2a8178
Pulse Author: Tr1sa111
Created: 2026-07-16 04:28:01
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #IoT #OTX #OpenThreatExchange #bot #botnet #Tr1sa111
OkoBot framework infection chain
Pulse ID: 6a585da609e274bccadebb0b
Pulse Link: https://otx.alienvault.com/pulse/6a585da609e274bccadebb0b
Pulse Author: Tr1sa111
Created: 2026-07-16 04:27:18
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #Tr1sa111
Six Minutes to Compromise: How 'Patriot Bait' Actor Used AI to Build and Deploy a C&C Botnet
Pulse ID: 6a585d9ff9c385e8e021c1b5
Pulse Link: https://otx.alienvault.com/pulse/6a585d9ff9c385e8e021c1b5
Pulse Author: Tr1sa111
Created: 2026-07-16 04:27:11
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CandC #CyberSecurity #InfoSec #IoT #OTX #OpenThreatExchange #bot #botnet #Tr1sa111
CXMT close to matching Micron's memory capacity in 2026, research claims — would put China on track to become world's second-largest DRAM producer
As CXMT's DRAM capacity set to match Micron's, China's DRAM industry could become world's second largest after South Korea.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
Motorola new flagship killer looks great, until you check its terrible update policy
Two years of updates is just not okay for a 2026 flagship.
https://www.androidauthority.com/motorola-edge-70-max-software-updates-3688045/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Possible Phishing 🎣
on: ⚠️hxxps[:]//webdekundencen[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a57c46f3b775000033615e5
#cybersecurity #phishing #infosec #urldna #scam #infosec
🚨 EUVD-2026-44862
📊 Score: 7.5/10 (CVSS v3.1)
📦 Product: Loki
🏢 Vendor: Grafana
📅 Updated: 2026-07-16
📝 Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44862
🚨 EUVD-2026-44861
📊 Score: 6.4/10 (CVSS v3.1)
📦 Product: Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ
🏢 Vendor: shapedplugin
📅 Updated: 2026-07-16
📝 The Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'align' Block Attribute in all versions up to, and includin...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44861
🚨 EUVD-2026-44860
📊 Score: 6.5/10 (CVSS v3.1)
📦 Product: MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions
🏢 Vendor: wcmp
📅 Updated: 2026-07-16
📝 The MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions plugin for WordPress is vulnerable to generic SQL Injection via the 'order_by' parameter in all versions up to, and inclu...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44860
🚨 EUVD-2026-44858
📊 Score: 4.3/10 (CVSS v3.1)
📦 Product: Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages
🏢 Vendor: umarbajwa
📅 Updated: 2026-07-16
📝 The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44858
🚨 EUVD-2026-44859
📊 Score: 6.4/10 (CVSS v3.1)
📦 Product: GiveWP – Donation Plugin and Fundraising Platform
🏢 Vendor: StellarWP
📅 Updated: 2026-07-16
📝 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting in all versions up to, and including, 4.16.3 du...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44859
🚨 EUVD-2026-44856
📊 Score: 4.3/10 (CVSS v3.1)
📦 Product: List category posts
🏢 Vendor: fernandobt
📅 Updated: 2026-07-16
📝 The List category posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 0.95.0 via the sanitize_status. This makes it possible for authenticated attackers, with contributor-level acces...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44856
🚨 EUVD-2026-44857
📊 Score: 7.5/10 (CVSS v3.1)
📦 Product: Advance Product Search- Voice & Ajax Search for WooCommerce
🏢 Vendor: ThemeHunk
📅 Updated: 2026-07-16
📝 The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 's' and 'match' parameter in all versions up to, and including, 1.4.4 du...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44857
🚨 EUVD-2026-44855
📊 Score: 4.3/10 (CVSS v3.1)
📦 Product: Catch Themes Demo Import
🏢 Vendor: catchplugins
📅 Updated: 2026-07-16
📝 The Catch Themes Demo Import plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.3. This is due to the catch_themes_demo_import_activate_plugin() function, hooked on admin_init when the activa...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44855
🚨 EUVD-2026-44854
📊 Score: 4.4/10 (CVSS v3.1)
📦 Product: MxChat – AI Chatbot & Content Generation for WordPress
🏢 Vendor: mxchat
📅 Updated: 2026-07-16
📝 The MxChat – AI Chatbot & Content Generation for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.10 due to insufficient inp...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44854
Legendary Gravis Ultrasound sound card gets new open-source clone — Beavis Ultrasound remake includes complete KiCad schematics, PCB layout, sample ROM, and more
There’s a new remake of the legendary Gravis Ultrasound ISA soundcard on the block with the arrival of the open source Beavis Ultrasound project.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
OkoBot framework infection chain
In January 2026, researchers identified a sophisticated malware framework dubbed OkoBot that targets cryptocurrency users through a multi-stage infection chain. The campaign begins with TookPS PowerShell scripts delivered via ClickFix attacks or fake software on GitHub. An automated SSH bot deploys over 20 malicious modules including HDUtil launcher, browser extension injectors installing Rilide stealer, and specialized tools like SeedHunter for wallet seed phrase theft and OkoSpyware for window capture. The framework uses VMProtect obfuscation, UAC bypass techniques, and maintains persistence through RDP access and scheduled tasks. Victims span more than 25 countries with concentrations in Brazil, Vietnam, Canada, Mexico, and Turkey. Attribution suggests Russian-speaking threat actors based on geoblocking patterns and Russian language artifacts.
Pulse ID: 6a5775d2afd24bb0357b62c1
Pulse Link: https://otx.alienvault.com/pulse/6a5775d2afd24bb0357b62c1
Pulse Author: AlienVault
Created: 2026-07-15 11:58:10
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Brazil #Browser #Canada #CyberSecurity #GitHub #InfoSec #Malware #Mexico #OTX #OpenThreatExchange #PowerShell #RAT #RDP #Russia #SSH #SpyWare #Turkey #Vietnam #bot #cryptocurrency #AlienVault
🔴 CVE-2026-55652 - Critical (9.8)
Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequestIp() in server/lib/headerLoginAuth.js to trust the client-supplied X-Forwarded-For header before the real socket address, allow...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55652/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-55234 - High (8.5)
Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.js, server/permissions/lists.js, and server/permissions/swimlanes.js authorize against the stored source boardId and do not vali...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55234/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🔴 CVE-2026-54458 - Critical (9.6)
WWBN AVideo is an open source video platform. Versions prior to 29.0 contain a stored DOM Cross-Site Scripting vulnerability in the YPTSocket plugin. Any unauthenticated remote attacker can execute arbitrary JavaScript in the authenticated origin ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54458/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Fake crypto scams try to piggyback off SpaceX IPO
Scammers are exploiting public interest in the SpaceX IPO through fraudulent investment portals impersonating SpaceX, Elon Musk, and major financial brands including Fidelity and Robinhood. The campaign uses themed domains to lure victims into fake onboarding processes that mimic legitimate investment procedures, including W-8BEN tax forms for non-U.S. investors. Victims are asked to select investment tiers and ultimately directed to deposit funds via cryptocurrency wallets for Bitcoin, Ethereum, and USDT. The operation mirrors techniques used by threat actor TA2730 but focuses on direct cryptocurrency theft rather than credential harvesting. One Bitcoin wallet associated with the campaign received approximately $8,700. The infrastructure includes randomized domains and SpaceX-themed domains designed to appear legitimate during the investment process.
Pulse ID: 6a57f270713faa71010c16ad
Pulse Link: https://otx.alienvault.com/pulse/6a57f270713faa71010c16ad
Pulse Author: AlienVault
Created: 2026-07-15 20:49:52
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BitCoin #CredentialHarvesting #CyberSecurity #InfoSec #Mimic #OTX #OpenThreatExchange #RAT #RobinHood #bot #cryptocurrency #AlienVault
Dutch police have successfully dismantled an international cryptocurrency investment fraud ring that stole an estimated €100 million per month. The operation employed over 700 people globally and utilized completely fabricated trading platforms. #CyberSecurity #Crypto #Fraud #TechNews
https://blazetrends.com/e100m-crypto-fraud-ring-busted-by-dutch-police-hacker-mastermind-arrested/?fsp_sid=52125
xAI sues a man for using Grok to generate CSAM ‘deepfakes’
The Elon Musk-owned xAI is suing a South Carolina man who allegedly used the company's Grok AI chatbot to generate child sexual abuse material (CSAM). In a lawsuit reported earlier by Reuters, xAI claims Terry Wayne Har…
https://www.theverge.com/ai-artificial-intelligence/966293/xai-grok-user-lawsuit-csam
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Valve says iFixit will keep selling Steam Deck batteries after all
The Steam Deck’s internals, including the L-shaped battery. Valve has been incredibly friendly to customers who need repairs - which is why it was so surprising to hear that Valve was already discontinuing the battery f…
https://www.theverge.com/games/966106/valve-ifixit-will-keep-selling-steam-deck-lcd-battery
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Apple’s reportedly raising the price for AppleCare Plus on Macs and iPads
An AppleCare Plus subscription for a Mac or iPad will cost more soon, with prices going up by $0.50 per month or $5 per year for new sign-ups while remaining the same for existing subscribers, according to Bloomberg's M…
https://www.theverge.com/tech/966219/apple-care-plus-price-increase
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
HP’s OLED-equipped 2-in-1 laptop is a solid back-to-school deal
HP’s convertible OmniBook has a great feature set for the price. | Image: HP With storage and memory prices still at an all-time high, we’re happy to tell you about a solid deal on a good laptop when we find one, rare a…
https://www.theverge.com/gadgets/966209/hp-omnibook-x-flip-oled-laptop-windows-11-deal-sale
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Waze just gave me 5 new reasons to switch from Apple Maps
None of these new Waze features is offered in Apple Maps.
https://www.zdnet.com/article/waze-update-may-beat-apple-maps/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
🚨 EUVD-2026-44825
📊 Score: 7.7/10 (CVSS v3.1)
📦 Product: AVideo
🏢 Vendor: WWBN
📅 Updated: 2026-07-15
📝 WWBN AVideo is an open source video platform. Versions 29.0 and below contain a Stored XSS vulnerability through the autoEvalCodeOnHTML parameter in the MessageSQLite WebSocket Handler. The MessageSQLite.php handler only strips autoEvalCodeOnHTML from $json['msg...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44825
Possible Phishing 🎣
on: ⚠️hxxps[:]//barclays-banking[.]net/landing/form/652e1755-3215-4d33-ad3a-b8a16444b4ba
🧬 Analysis at: https://urldna.io/scan/6a577e1f3b775000091fa190
#cybersecurity #phishing #infosec #urldna #scam #infosec
Intel: 892 CVEs, avg CVSS 6.21. 94% unpatched. Trust Score: C. Chip-level flaws linger. Patch your firmware NOW. #Intel #cybersecurity #infosec
Skullcandy’s bass-boosting Crusher headphones now come with Bose’s ANC
Skullcandy announced a new version of its Crusher wireless headphones today featuring a few of Bose's audio technologies including its QuietControl ANC and head-tracking spatial audio. The Crusher headphone line differe…
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
I highly recommend Nomad's chargers, phone cases, and watch bands - and my favorites are on sale now
Nomad's tech accessories rarely go on sale, but now is your chance to scoop up some of our favorites at over 20% off.
https://www.zdnet.com/article/nomad-anniversary-sale-2026/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]