voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]BeyondMachines :verified: » 🤖 🌐
@beyondmachines1@infosec.exchange

Community Health Center of Buffalo Reports Data Breach

Community Health Center of Buffalo confirmed data breaches affecting at least 501 individuals, exposing medical and personal information .

****

beyondmachines.net/event_detai

    [?]Negative PID SL » 🌐
    @negativepid@mastodon.social

    [?]Daily CyberSecurity » 🌐
    @DailyCyberSecurity@infosec.exchange

    Microsoft patched a severe Age of Empires CVE. Attackers exploited game lobbies for remote code execution. Update your game immediately to stay safe.

    securityonline.info/age-of-emp

      [?]TechWire ⚡ » 🤖 🌐
      @techwire@social.gamefan.net

      It’s settled: OnePlus is officially exiting North America and Europe

      OnePlus will stop selling all devices in North America and Europe as OPPO takes the wheel.

      androidauthority.com/oneplus-n

      [Android Authority]

        [?]InfosecK2K » 🌐
        @InfosecK2K@mastodon.social

        Still using passwords? Attackers are counting on it.

        MFA and passkeys reduce risk, simplify access, and strengthen security.

        Ready for passwordless authentication?

        Learn more: zurl.co/LwPj8

          [?]InfosecK2K » 🌐
          @InfosecK2K@mastodon.social

          One IAM audit isn't enough.

          Identity threats evolve constantly. Regular IAM assessments help uncover hidden access gaps, reduce risk, and strengthen compliance.

          Learn how we can help: zurl.co/O2xYL

            [?]OTX Bot » 🤖 🌐
            @techbot@social.raytec.co

            11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windows Host-Surveillance Payload

            Eleven malicious NuGet packages distributed as .NET command-line tools masquerade as game utilities and cheats for popular games including Albion Online, GTA5RP, GrandRP, and Throne and Liberty. Each package functions as a first-stage downloader that uses DNS-over-HTTPS to bypass local controls, requests UAC elevation to resync system time, and fetches a second-stage PyInstaller payload named pepesoft.exe from GitHub and Hugging Face under username pepegit666. The payload binds to hardware fingerprints, enforces licensing through Google Sheets telemetry, honors remote ban-lists, and in three variants exposes Telegram bot commands enabling screenshot capture and remote control. All packages share identical AWS credentials and mutex identifiers, linking them to a single Russian-speaking operator running a commercial game-automation service marketed through pepesoft.ru and Telegram channel pepesoft777.

            Pulse ID: 6a57b568d98a7ae03ccd6071
            Pulse Link: otx.alienvault.com/pulse/6a57b
            Pulse Author: AlienVault
            Created: 2026-07-15 16:29:28

            Be advised, this data is unverified and should be considered preliminary. Always do further verification.

              [?]TierraSapiens » 🤖 🌐
              @tierrasapiens@mastodon.social

              🖲️
              ⚫ Is 'Tech-xit' Imminent? UK Steps Up Sovereignty Push Amid AI Strife
              🔗 darkreading.com/cybersecurity-

              The US government's restrictions on Anthropic and OpenAI frontier models have intensified calls in the UK and other countries to reduce their reliance on US tech companies, with significant

                [?]TechWire ⚡ » 🤖 🌐
                @techwire@social.gamefan.net

                5 smart home gadgets I consider completely non-negotiable - and why

                These smart home gadgets elevate my home and routine. Here's why you may want them too.

                zdnet.com/article/5-smart-home

                [ZDNet]

                  [?]TechWire ⚡ » 🤖 🌐
                  @techwire@social.gamefan.net

                  I never leave for vacation without doing these 7 home security checks first

                  Burglars target empty homes, and insurers deny frozen-pipe claims. Here's the tech that solves these issues and others before you leave.

                  zdnet.com/article/7-home-secur

                  [ZDNet]

                    [?]TechWire ⚡ » 🤖 🌐
                    @techwire@social.gamefan.net

                    Ukraine conducts record drone strike of 2,500km after 12-hour flight — $55,000 unit made of plywood halts operations at Russia's largest gasoline producer

                    Ukrainian FP-1 drones struck the Gazprom Neft oil refinery in Omsk, Siberia, on July 6 after flying roughly 2,500 km over more than 12 hours.

                    tomshardware.com/tech-industry

                    [Tom's Hardware]

                      [?]OTX Bot » 🤖 🌐
                      @techbot@social.raytec.co

                      Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor

                      Pulse ID: 6a585dc530cfef480c1f0bbd
                      Pulse Link: otx.alienvault.com/pulse/6a585
                      Pulse Author: Tr1sa111
                      Created: 2026-07-16 04:27:49

                      Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                        [?]OTX Bot » 🤖 🌐
                        @techbot@social.raytec.co

                        Inside an IoT Botnet Framework With LLM-Assisted Development

                        Pulse ID: 6a585dd1af5d4dd0ee2a8178
                        Pulse Link: otx.alienvault.com/pulse/6a585
                        Pulse Author: Tr1sa111
                        Created: 2026-07-16 04:28:01

                        Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                          [?]OTX Bot » 🤖 🌐
                          @techbot@social.raytec.co

                          OkoBot framework infection chain

                          Pulse ID: 6a585da609e274bccadebb0b
                          Pulse Link: otx.alienvault.com/pulse/6a585
                          Pulse Author: Tr1sa111
                          Created: 2026-07-16 04:27:18

                          Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                            [?]OTX Bot » 🤖 🌐
                            @techbot@social.raytec.co

                            Six Minutes to Compromise: How 'Patriot Bait' Actor Used AI to Build and Deploy a C&C Botnet

                            Pulse ID: 6a585d9ff9c385e8e021c1b5
                            Pulse Link: otx.alienvault.com/pulse/6a585
                            Pulse Author: Tr1sa111
                            Created: 2026-07-16 04:27:11

                            Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                              [?]TechWire ⚡ » 🤖 🌐
                              @techwire@social.gamefan.net

                              CXMT close to matching Micron's memory capacity in 2026, research claims — would put China on track to become world's second-largest DRAM producer

                              As CXMT's DRAM capacity set to match Micron's, China's DRAM industry could become world's second largest after South Korea.

                              tomshardware.com/pc-components

                              [Tom's Hardware]

                                [?]TechWire ⚡ » 🤖 🌐
                                @techwire@social.gamefan.net

                                Motorola new flagship killer looks great, until you check its terrible update policy

                                Two years of updates is just not okay for a 2026 flagship.

                                androidauthority.com/motorola-

                                [Android Authority]

                                  [?]urlDNA.io :verified: » 🤖 🌐
                                  @urldna@infosec.exchange

                                  Possible Phishing 🎣
                                  on: ⚠️hxxps[:]//webdekundencen[.]weebly[.]com
                                  🧬 Analysis at: urldna.io/scan/6a57c46f3b77500

                                    [?]EUVD Bot » 🤖 🌐
                                    @EUVD_Bot@mastodon.social

                                    🚨 EUVD-2026-44862

                                    📊 Score: 7.5/10 (CVSS v3.1)
                                    📦 Product: Loki
                                    🏢 Vendor: Grafana
                                    📅 Updated: 2026-07-16

                                    📝 Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy.

                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                      [?]EUVD Bot » 🤖 🌐
                                      @EUVD_Bot@mastodon.social

                                      🚨 EUVD-2026-44861

                                      📊 Score: 6.4/10 (CVSS v3.1)
                                      📦 Product: Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ
                                      🏢 Vendor: shapedplugin
                                      📅 Updated: 2026-07-16

                                      📝 The Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'align' Block Attribute in all versions up to, and includin...

                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                        [?]EUVD Bot » 🤖 🌐
                                        @EUVD_Bot@mastodon.social

                                        🚨 EUVD-2026-44860

                                        📊 Score: 6.5/10 (CVSS v3.1)
                                        📦 Product: MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions
                                        🏢 Vendor: wcmp
                                        📅 Updated: 2026-07-16

                                        📝 The MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions plugin for WordPress is vulnerable to generic SQL Injection via the 'order_by' parameter in all versions up to, and inclu...

                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                          [?]EUVD Bot » 🤖 🌐
                                          @EUVD_Bot@mastodon.social

                                          🚨 EUVD-2026-44858

                                          📊 Score: 4.3/10 (CVSS v3.1)
                                          📦 Product: Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages
                                          🏢 Vendor: umarbajwa
                                          📅 Updated: 2026-07-16

                                          📝 The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ...

                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                            [?]EUVD Bot » 🤖 🌐
                                            @EUVD_Bot@mastodon.social

                                            🚨 EUVD-2026-44859

                                            📊 Score: 6.4/10 (CVSS v3.1)
                                            📦 Product: GiveWP – Donation Plugin and Fundraising Platform
                                            🏢 Vendor: StellarWP
                                            📅 Updated: 2026-07-16

                                            📝 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting in all versions up to, and including, 4.16.3 du...

                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                              [?]EUVD Bot » 🤖 🌐
                                              @EUVD_Bot@mastodon.social

                                              🚨 EUVD-2026-44856

                                              📊 Score: 4.3/10 (CVSS v3.1)
                                              📦 Product: List category posts
                                              🏢 Vendor: fernandobt
                                              📅 Updated: 2026-07-16

                                              📝 The List category posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 0.95.0 via the sanitize_status. This makes it possible for authenticated attackers, with contributor-level acces...

                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                [?]EUVD Bot » 🤖 🌐
                                                @EUVD_Bot@mastodon.social

                                                🚨 EUVD-2026-44857

                                                📊 Score: 7.5/10 (CVSS v3.1)
                                                📦 Product: Advance Product Search- Voice & Ajax Search for WooCommerce
                                                🏢 Vendor: ThemeHunk
                                                📅 Updated: 2026-07-16

                                                📝 The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 's' and 'match' parameter in all versions up to, and including, 1.4.4 du...

                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                  [?]EUVD Bot » 🤖 🌐
                                                  @EUVD_Bot@mastodon.social

                                                  🚨 EUVD-2026-44855

                                                  📊 Score: 4.3/10 (CVSS v3.1)
                                                  📦 Product: Catch Themes Demo Import
                                                  🏢 Vendor: catchplugins
                                                  📅 Updated: 2026-07-16

                                                  📝 The Catch Themes Demo Import plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.3. This is due to the catch_themes_demo_import_activate_plugin() function, hooked on admin_init when the activa...

                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                    [?]EUVD Bot » 🤖 🌐
                                                    @EUVD_Bot@mastodon.social

                                                    🚨 EUVD-2026-44854

                                                    📊 Score: 4.4/10 (CVSS v3.1)
                                                    📦 Product: MxChat – AI Chatbot & Content Generation for WordPress
                                                    🏢 Vendor: mxchat
                                                    📅 Updated: 2026-07-16

                                                    📝 The MxChat – AI Chatbot & Content Generation for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.10 due to insufficient inp...

                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                      [?]TechWire ⚡ » 🤖 🌐
                                                      @techwire@social.gamefan.net

                                                      Legendary Gravis Ultrasound sound card gets new open-source clone — Beavis Ultrasound remake includes complete KiCad schematics, PCB layout, sample ROM, and more

                                                      There’s a new remake of the legendary Gravis Ultrasound ISA soundcard on the block with the arrival of the open source Beavis Ultrasound project.

                                                      tomshardware.com/pc-components

                                                      [Tom's Hardware]

                                                        [?]OTX Bot » 🤖 🌐
                                                        @techbot@social.raytec.co

                                                        OkoBot framework infection chain

                                                        In January 2026, researchers identified a sophisticated malware framework dubbed OkoBot that targets cryptocurrency users through a multi-stage infection chain. The campaign begins with TookPS PowerShell scripts delivered via ClickFix attacks or fake software on GitHub. An automated SSH bot deploys over 20 malicious modules including HDUtil launcher, browser extension injectors installing Rilide stealer, and specialized tools like SeedHunter for wallet seed phrase theft and OkoSpyware for window capture. The framework uses VMProtect obfuscation, UAC bypass techniques, and maintains persistence through RDP access and scheduled tasks. Victims span more than 25 countries with concentrations in Brazil, Vietnam, Canada, Mexico, and Turkey. Attribution suggests Russian-speaking threat actors based on geoblocking patterns and Russian language artifacts.

                                                        Pulse ID: 6a5775d2afd24bb0357b62c1
                                                        Pulse Link: otx.alienvault.com/pulse/6a577
                                                        Pulse Author: AlienVault
                                                        Created: 2026-07-15 11:58:10

                                                        Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                                          [?]TheHackerWire » 🤖 🌐
                                                          @thehackerwire@mastodon.social

                                                          🔴 CVE-2026-55652 - Critical (9.8)

                                                          Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequestIp() in server/lib/headerLoginAuth.js to trust the client-supplied X-Forwarded-For header before the real socket address, allow...

                                                          🔗 thehackerwire.com/vulnerabilit

                                                          CVE Alert: CVE-2026-55652

                                                          Alt...CVE Alert: CVE-2026-55652

                                                            [?]TheHackerWire » 🤖 🌐
                                                            @thehackerwire@mastodon.social

                                                            🟠 CVE-2026-55234 - High (8.5)

                                                            Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.js, server/permissions/lists.js, and server/permissions/swimlanes.js authorize against the stored source boardId and do not vali...

                                                            🔗 thehackerwire.com/vulnerabilit

                                                            CVE Alert: CVE-2026-55234

                                                            Alt...CVE Alert: CVE-2026-55234

                                                              [?]TheHackerWire » 🤖 🌐
                                                              @thehackerwire@mastodon.social

                                                              🔴 CVE-2026-54458 - Critical (9.6)

                                                              WWBN AVideo is an open source video platform. Versions prior to 29.0 contain a stored DOM Cross-Site Scripting vulnerability in the YPTSocket plugin. Any unauthenticated remote attacker can execute arbitrary JavaScript in the authenticated origin ...

                                                              🔗 thehackerwire.com/vulnerabilit

                                                              CVE Alert: CVE-2026-54458

                                                              Alt...CVE Alert: CVE-2026-54458

                                                                [?]OTX Bot » 🤖 🌐
                                                                @techbot@social.raytec.co

                                                                Fake crypto scams try to piggyback off SpaceX IPO

                                                                Scammers are exploiting public interest in the SpaceX IPO through fraudulent investment portals impersonating SpaceX, Elon Musk, and major financial brands including Fidelity and Robinhood. The campaign uses themed domains to lure victims into fake onboarding processes that mimic legitimate investment procedures, including W-8BEN tax forms for non-U.S. investors. Victims are asked to select investment tiers and ultimately directed to deposit funds via cryptocurrency wallets for Bitcoin, Ethereum, and USDT. The operation mirrors techniques used by threat actor TA2730 but focuses on direct cryptocurrency theft rather than credential harvesting. One Bitcoin wallet associated with the campaign received approximately $8,700. The infrastructure includes randomized domains and SpaceX-themed domains designed to appear legitimate during the investment process.

                                                                Pulse ID: 6a57f270713faa71010c16ad
                                                                Pulse Link: otx.alienvault.com/pulse/6a57f
                                                                Pulse Author: AlienVault
                                                                Created: 2026-07-15 20:49:52

                                                                Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                                                  [?]Blaze Trends » 🌐
                                                                  @theblazetrends@mastodon.social

                                                                  Dutch police have successfully dismantled an international cryptocurrency investment fraud ring that stole an estimated €100 million per month. The operation employed over 700 people globally and utilized completely fabricated trading platforms.
                                                                  blazetrends.com/e100m-crypto-f

                                                                    [?]TechWire ⚡ » 🤖 🌐
                                                                    @techwire@social.gamefan.net

                                                                    xAI sues a man for using Grok to generate CSAM ‘deepfakes’

                                                                    The Elon Musk-owned xAI is suing a South Carolina man who allegedly used the company's Grok AI chatbot to generate child sexual abuse material (CSAM). In a lawsuit reported earlier by Reuters, xAI claims Terry Wayne Har…

                                                                    theverge.com/ai-artificial-int

                                                                    [The Verge]

                                                                      [?]TechWire ⚡ » 🤖 🌐
                                                                      @techwire@social.gamefan.net

                                                                      Valve says iFixit will keep selling Steam Deck batteries after all

                                                                      The Steam Deck’s internals, including the L-shaped battery. Valve has been incredibly friendly to customers who need repairs - which is why it was so surprising to hear that Valve was already discontinuing the battery f…

                                                                      theverge.com/games/966106/valv

                                                                      [The Verge]

                                                                        [?]TechWire ⚡ » 🤖 🌐
                                                                        @techwire@social.gamefan.net

                                                                        Apple’s reportedly raising the price for AppleCare Plus on Macs and iPads

                                                                        An AppleCare Plus subscription for a Mac or iPad will cost more soon, with prices going up by $0.50 per month or $5 per year for new sign-ups while remaining the same for existing subscribers, according to Bloomberg's M…

                                                                        theverge.com/tech/966219/apple

                                                                        [The Verge]

                                                                          [?]TechWire ⚡ » 🤖 🌐
                                                                          @techwire@social.gamefan.net

                                                                          HP’s OLED-equipped 2-in-1 laptop is a solid back-to-school deal

                                                                          HP’s convertible OmniBook has a great feature set for the price. | Image: HP With storage and memory prices still at an all-time high, we’re happy to tell you about a solid deal on a good laptop when we find one, rare a…

                                                                          theverge.com/gadgets/966209/hp

                                                                          [The Verge]

                                                                            [?]TechWire ⚡ » 🤖 🌐
                                                                            @techwire@social.gamefan.net

                                                                            Waze just gave me 5 new reasons to switch from Apple Maps

                                                                            None of these new Waze features is offered in Apple Maps.

                                                                            zdnet.com/article/waze-update-

                                                                            [ZDNet]

                                                                              [?]EUVD Bot » 🤖 🌐
                                                                              @EUVD_Bot@mastodon.social

                                                                              🚨 EUVD-2026-44825

                                                                              📊 Score: 7.7/10 (CVSS v3.1)
                                                                              📦 Product: AVideo
                                                                              🏢 Vendor: WWBN
                                                                              📅 Updated: 2026-07-15

                                                                              📝 WWBN AVideo is an open source video platform. Versions 29.0 and below contain a Stored XSS vulnerability through the autoEvalCodeOnHTML parameter in the MessageSQLite WebSocket Handler. The MessageSQLite.php handler only strips autoEvalCodeOnHTML from $json['msg...

                                                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                [?]urlDNA.io :verified: » 🤖 🌐
                                                                                @urldna@infosec.exchange

                                                                                Possible Phishing 🎣
                                                                                on: ⚠️hxxps[:]//barclays-banking[.]net/landing/form/652e1755-3215-4d33-ad3a-b8a16444b4ba
                                                                                🧬 Analysis at: urldna.io/scan/6a577e1f3b77500

                                                                                  [?]Hugo | DevOps | Cybersecurity » 🌐
                                                                                  @hugovalters@mastodon.social

                                                                                  Intel: 892 CVEs, avg CVSS 6.21. 94% unpatched. Trust Score: C. Chip-level flaws linger. Patch your firmware NOW.

                                                                                  valtersit.com/vendors/intel/

                                                                                    [?]TechWire ⚡ » 🤖 🌐
                                                                                    @techwire@social.gamefan.net

                                                                                    Skullcandy’s bass-boosting Crusher headphones now come with Bose’s ANC

                                                                                    Skullcandy announced a new version of its Crusher wireless headphones today featuring a few of Bose's audio technologies including its QuietControl ANC and head-tracking spatial audio. The Crusher headphone line differe…

                                                                                    theverge.com/tech/966022/skull

                                                                                    [The Verge]

                                                                                      [?]TechWire ⚡ » 🤖 🌐
                                                                                      @techwire@social.gamefan.net

                                                                                      I highly recommend Nomad's chargers, phone cases, and watch bands - and my favorites are on sale now

                                                                                      Nomad's tech accessories rarely go on sale, but now is your chance to scoop up some of our favorites at over 20% off.

                                                                                      zdnet.com/article/nomad-annive

                                                                                      [ZDNet]

                                                                                        Back to top - More...