voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]EUVD Bot » 🤖 🌐
@EUVD_Bot@mastodon.social

🚨 EUVD-2026-44855

📊 Score: 4.3/10 (CVSS v3.1)
📦 Product: Catch Themes Demo Import
🏢 Vendor: catchplugins
📅 Updated: 2026-07-16

📝 The Catch Themes Demo Import plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.3. This is due to the catch_themes_demo_import_activate_plugin() function, hooked on admin_init when the activa...

🔗 euvd.enisa.europa.eu/vulnerabi

    [?]EUVD Bot » 🤖 🌐
    @EUVD_Bot@mastodon.social

    🚨 EUVD-2026-44854

    📊 Score: 4.4/10 (CVSS v3.1)
    📦 Product: MxChat – AI Chatbot & Content Generation for WordPress
    🏢 Vendor: mxchat
    📅 Updated: 2026-07-16

    📝 The MxChat – AI Chatbot & Content Generation for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.10 due to insufficient inp...

    🔗 euvd.enisa.europa.eu/vulnerabi

      [?]TechWire ⚡ » 🤖 🌐
      @techwire@social.gamefan.net

      Legendary Gravis Ultrasound sound card gets new open-source clone — Beavis Ultrasound remake includes complete KiCad schematics, PCB layout, sample ROM, and more

      There’s a new remake of the legendary Gravis Ultrasound ISA soundcard on the block with the arrival of the open source Beavis Ultrasound project.

      tomshardware.com/pc-components

      [Tom's Hardware]

        [?]OTX Bot » 🤖 🌐
        @techbot@social.raytec.co

        OkoBot framework infection chain

        In January 2026, researchers identified a sophisticated malware framework dubbed OkoBot that targets cryptocurrency users through a multi-stage infection chain. The campaign begins with TookPS PowerShell scripts delivered via ClickFix attacks or fake software on GitHub. An automated SSH bot deploys over 20 malicious modules including HDUtil launcher, browser extension injectors installing Rilide stealer, and specialized tools like SeedHunter for wallet seed phrase theft and OkoSpyware for window capture. The framework uses VMProtect obfuscation, UAC bypass techniques, and maintains persistence through RDP access and scheduled tasks. Victims span more than 25 countries with concentrations in Brazil, Vietnam, Canada, Mexico, and Turkey. Attribution suggests Russian-speaking threat actors based on geoblocking patterns and Russian language artifacts.

        Pulse ID: 6a5775d2afd24bb0357b62c1
        Pulse Link: otx.alienvault.com/pulse/6a577
        Pulse Author: AlienVault
        Created: 2026-07-15 11:58:10

        Be advised, this data is unverified and should be considered preliminary. Always do further verification.

          [?]TheHackerWire » 🤖 🌐
          @thehackerwire@mastodon.social

          🔴 CVE-2026-55652 - Critical (9.8)

          Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequestIp() in server/lib/headerLoginAuth.js to trust the client-supplied X-Forwarded-For header before the real socket address, allow...

          🔗 thehackerwire.com/vulnerabilit

          CVE Alert: CVE-2026-55652

          Alt...CVE Alert: CVE-2026-55652

            [?]TheHackerWire » 🤖 🌐
            @thehackerwire@mastodon.social

            🟠 CVE-2026-55234 - High (8.5)

            Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.js, server/permissions/lists.js, and server/permissions/swimlanes.js authorize against the stored source boardId and do not vali...

            🔗 thehackerwire.com/vulnerabilit

            CVE Alert: CVE-2026-55234

            Alt...CVE Alert: CVE-2026-55234

              [?]TheHackerWire » 🤖 🌐
              @thehackerwire@mastodon.social

              🔴 CVE-2026-54458 - Critical (9.6)

              WWBN AVideo is an open source video platform. Versions prior to 29.0 contain a stored DOM Cross-Site Scripting vulnerability in the YPTSocket plugin. Any unauthenticated remote attacker can execute arbitrary JavaScript in the authenticated origin ...

              🔗 thehackerwire.com/vulnerabilit

              CVE Alert: CVE-2026-54458

              Alt...CVE Alert: CVE-2026-54458

                [?]OTX Bot » 🤖 🌐
                @techbot@social.raytec.co

                Fake crypto scams try to piggyback off SpaceX IPO

                Scammers are exploiting public interest in the SpaceX IPO through fraudulent investment portals impersonating SpaceX, Elon Musk, and major financial brands including Fidelity and Robinhood. The campaign uses themed domains to lure victims into fake onboarding processes that mimic legitimate investment procedures, including W-8BEN tax forms for non-U.S. investors. Victims are asked to select investment tiers and ultimately directed to deposit funds via cryptocurrency wallets for Bitcoin, Ethereum, and USDT. The operation mirrors techniques used by threat actor TA2730 but focuses on direct cryptocurrency theft rather than credential harvesting. One Bitcoin wallet associated with the campaign received approximately $8,700. The infrastructure includes randomized domains and SpaceX-themed domains designed to appear legitimate during the investment process.

                Pulse ID: 6a57f270713faa71010c16ad
                Pulse Link: otx.alienvault.com/pulse/6a57f
                Pulse Author: AlienVault
                Created: 2026-07-15 20:49:52

                Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                  [?]Blaze Trends » 🌐
                  @theblazetrends@mastodon.social

                  Dutch police have successfully dismantled an international cryptocurrency investment fraud ring that stole an estimated €100 million per month. The operation employed over 700 people globally and utilized completely fabricated trading platforms.
                  blazetrends.com/e100m-crypto-f

                    [?]TechWire ⚡ » 🤖 🌐
                    @techwire@social.gamefan.net

                    xAI sues a man for using Grok to generate CSAM ‘deepfakes’

                    The Elon Musk-owned xAI is suing a South Carolina man who allegedly used the company's Grok AI chatbot to generate child sexual abuse material (CSAM). In a lawsuit reported earlier by Reuters, xAI claims Terry Wayne Har…

                    theverge.com/ai-artificial-int

                    [The Verge]

                      [?]TechWire ⚡ » 🤖 🌐
                      @techwire@social.gamefan.net

                      Valve says iFixit will keep selling Steam Deck batteries after all

                      The Steam Deck’s internals, including the L-shaped battery. Valve has been incredibly friendly to customers who need repairs - which is why it was so surprising to hear that Valve was already discontinuing the battery f…

                      theverge.com/games/966106/valv

                      [The Verge]

                        [?]TechWire ⚡ » 🤖 🌐
                        @techwire@social.gamefan.net

                        Apple’s reportedly raising the price for AppleCare Plus on Macs and iPads

                        An AppleCare Plus subscription for a Mac or iPad will cost more soon, with prices going up by $0.50 per month or $5 per year for new sign-ups while remaining the same for existing subscribers, according to Bloomberg's M…

                        theverge.com/tech/966219/apple

                        [The Verge]

                          [?]TechWire ⚡ » 🤖 🌐
                          @techwire@social.gamefan.net

                          HP’s OLED-equipped 2-in-1 laptop is a solid back-to-school deal

                          HP’s convertible OmniBook has a great feature set for the price. | Image: HP With storage and memory prices still at an all-time high, we’re happy to tell you about a solid deal on a good laptop when we find one, rare a…

                          theverge.com/gadgets/966209/hp

                          [The Verge]

                            [?]TechWire ⚡ » 🤖 🌐
                            @techwire@social.gamefan.net

                            Waze just gave me 5 new reasons to switch from Apple Maps

                            None of these new Waze features is offered in Apple Maps.

                            zdnet.com/article/waze-update-

                            [ZDNet]

                              [?]EUVD Bot » 🤖 🌐
                              @EUVD_Bot@mastodon.social

                              🚨 EUVD-2026-44825

                              📊 Score: 7.7/10 (CVSS v3.1)
                              📦 Product: AVideo
                              🏢 Vendor: WWBN
                              📅 Updated: 2026-07-15

                              📝 WWBN AVideo is an open source video platform. Versions 29.0 and below contain a Stored XSS vulnerability through the autoEvalCodeOnHTML parameter in the MessageSQLite WebSocket Handler. The MessageSQLite.php handler only strips autoEvalCodeOnHTML from $json['msg...

                              🔗 euvd.enisa.europa.eu/vulnerabi

                                [?]urlDNA.io :verified: » 🤖 🌐
                                @urldna@infosec.exchange

                                Possible Phishing 🎣
                                on: ⚠️hxxps[:]//barclays-banking[.]net/landing/form/652e1755-3215-4d33-ad3a-b8a16444b4ba
                                🧬 Analysis at: urldna.io/scan/6a577e1f3b77500

                                  [?]Hugo | DevOps | Cybersecurity » 🌐
                                  @hugovalters@mastodon.social

                                  Intel: 892 CVEs, avg CVSS 6.21. 94% unpatched. Trust Score: C. Chip-level flaws linger. Patch your firmware NOW.

                                  valtersit.com/vendors/intel/

                                    [?]TechWire ⚡ » 🤖 🌐
                                    @techwire@social.gamefan.net

                                    Skullcandy’s bass-boosting Crusher headphones now come with Bose’s ANC

                                    Skullcandy announced a new version of its Crusher wireless headphones today featuring a few of Bose's audio technologies including its QuietControl ANC and head-tracking spatial audio. The Crusher headphone line differe…

                                    theverge.com/tech/966022/skull

                                    [The Verge]

                                      [?]TechWire ⚡ » 🤖 🌐
                                      @techwire@social.gamefan.net

                                      I highly recommend Nomad's chargers, phone cases, and watch bands - and my favorites are on sale now

                                      Nomad's tech accessories rarely go on sale, but now is your chance to scoop up some of our favorites at over 20% off.

                                      zdnet.com/article/nomad-annive

                                      [ZDNet]

                                        [?]urlDNA.io :verified: » 🤖 🌐
                                        @urldna@infosec.exchange

                                        Possible Phishing 🎣
                                        on: ⚠️hxxps[:]//kuyhaa-me[.]pw/dhtanx/Office/index[.]php
                                        🧬 Analysis at: urldna.io/scan/6a577e0b3b77500

                                          [?]TechWire ⚡ » 🤖 🌐
                                          @techwire@social.gamefan.net

                                          How to use Gemini to plan your next summer vacation - in minutes

                                          This Gemini prompt can find flights, stays, and things to do for you. It'll even build an itinerary doc.

                                          zdnet.com/article/gemini-promp

                                          [ZDNet]

                                            [?]CyberIntel News » 🌐
                                            @cyberintelnews@mastodon.social

                                            CyberIntel Weekly: New Process Parameter Poisoning Technique Hides Shellcode in Windows Startup Data

                                            cyberintelnews.com/

                                              [?]CyberIntel News » 🌐
                                              @cyberintelnews@mastodon.social

                                              CyberIntel Weekly: New Process Parameter Poisoning Technique Hides Shellcode in Windows Startup Data

                                              cyberintelnews.com/

                                                [?]TechWire ⚡ » 🤖 🌐
                                                @techwire@social.gamefan.net

                                                I tested all three OpenVPN tiers: Why the free version is still the best choice for most users

                                                OpenVPN offers three modes of deployment with varied pricing based on the same underlying protocol. Here are the pros, cons, and costs associated with each.

                                                zdnet.com/article/managed-self

                                                [ZDNet]

                                                  [?]EUVD Bot » 🤖 🌐
                                                  @EUVD_Bot@mastodon.social

                                                  🚨 EUVD-2026-44837

                                                  📊 Score: 6.9/10 (CVSS v3.1)
                                                  📦 Product: SecPath F1000-C8300
                                                  🏢 Vendor: H3C
                                                  📅 Updated: 2026-07-15

                                                  📝 A flaw has been found in H3C SecPath F1000-C8300 up to 20260522. This impacts an unknown function of the file /webui/?g=log_fw_nbc_mail_jsondata. Executing a manipulation of the argument subject can lead to sql injection. The attack can be executed r...

                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                    [?]urlDNA.io :verified: » 🤖 🌐
                                                    @urldna@infosec.exchange

                                                    Possible Phishing 🎣
                                                    on: ⚠️hxxps[:]//www[.]powr[.]io/media-gallery/i/41161241
                                                    🧬 Analysis at: urldna.io/scan/6a581f073b77500

                                                      [?]SagaLinked » 🤖 🌐
                                                      @sagalinked@mastodon.social

                                                      📰 The Canadian spy agency reported hacking activities targeting drug traffickers, extremists, and a ransomware gang last year, highlighting national security concerns.

                                                      🔗 techcrunch.com/2026/07/06/cana

                                                        [?]SagaLinked | CYBER NEWS » 🤖 🌐
                                                        @sagalinked@infosec.exchange

                                                        📰 The Canadian spy agency reported hacking activities targeting drug traffickers, extremists, and a ransomware gang last year, highlighting national security concerns.

                                                        🔗 techcrunch.com/2026/07/06/cana

                                                          [?]selfhost.directory » 🤖 🌐
                                                          @selfhost_discovery@mastodon.social

                                                          Umami: analytics without spying

                                                          Umami — analytics without spying. No cookies, GDPR-clean. One lightweight script. Free and open-source. Install guides, alternatives and screenshots in the directory.

                                                          selfhost.directory/project/uma

                                                            [?]Tom Eston :verified: » 🌐
                                                            @agent0x0@infosec.exchange

                                                            Encrypted messaging is great...

                                                            Until an attacker steals the account, adds a linked device, or tricks someone out of a recovery key.

                                                            In episode 441 of Shared Security, Tom and Kevin discuss the FBI warning about Russian intelligence targeting Signal, WhatsApp, and Telegram users and why endpoint/account security still matters.

                                                            Watch this episode on YouTube:
                                                            youtu.be/fxFfY_e_MOI

                                                            Listen and subscribe wherever you like to get your podcasts:
                                                            sharedsecurity.net/subscribe
                                                            sharedsecurity.net/2026/07/13/

                                                            Alt..."Obviously if you're a journalist if you're working in the government you have a certain position or level this could be a concern for you. I think the theme of this story is around some of the new phishing attacks we've seen around recovery keys and the recovery codes — to me feels like the core of this story, not so much the 'Oh my gosh, Russian hackers guys, they're targeting us, we're all doomed.'"

                                                              [?]TechWire ⚡ » 🤖 🌐
                                                              @techwire@social.gamefan.net

                                                              Android 17 QPR1 Beta 7 drops a few bugfixes for die-hard Pixel testers

                                                              It's Google's first release since Android 17 QPR1 hit Platform Stability earlier this month.

                                                              androidauthority.com/android-1

                                                              [Android Authority]

                                                                [?]CyberIntel News » 🌐
                                                                @cyberintelnews@mastodon.social

                                                                Cybersecurity. National Security. Intelligence (artificial and otherwise).

                                                                Exactly what you need to know. In your inbox every Monday morning. Free. Never any spam.

                                                                If you don't get it, you don't get it.

                                                                Subscribe today: cyberintelnews.com

                                                                  [?]ChiefGyk3D » 🌐
                                                                  @chiefgyk3d@social.chiefgyk3d.com

                                                                  Meshcore madness is HERE 🔴!

                                                                  Dive into a hacker summer camp vibe.
                                                                  Cybersecurity deep dives + rants.
                                                                  Chill Linux gaming sesh incoming.

                                                                  Let's build something wild. 🔥

                                                                  twitch.tv/chiefgyk3d

                                                                  🔴 LIVE • 1 viewers • Just Chatting

                                                                  Alt...🔴 LIVE • 1 viewers • Just Chatting

                                                                    [?]ChiefGyk3D » 🌐
                                                                    @chiefgyk3d@social.chiefgyk3d.com

                                                                    Meshcore madness is HERE 🔴!

                                                                    Dive deep into cybersecurity with a Hacker Summer Camp vibe. Expect rants, chill Linux tinkering, and some gaming thrown in for good measure. Let's build and watch the chaos unfold. 🎮

                                                                    youtube.com/@chiefgyk3d/live

                                                                    🔴 LIVE

                                                                    Alt...🔴 LIVE

                                                                      [?]ChiefGyk3D » 🌐
                                                                      @chiefgyk3d@social.chiefgyk3d.com

                                                                      Meshcore madness is ON! 🔴

                                                                      Diving deep into cybersecurity with a hacker summer camp vibe. Expect rants, chill Linux tinkering, and some gaming thrown in for good measure. Let's build something interesting and watch the chaos unfold. 🎮

                                                                      kick.com/chiefgyk3d

                                                                      🔴 LIVE • 1 viewers • Just Chatting

                                                                      Alt...🔴 LIVE • 1 viewers • Just Chatting

                                                                        [?]The New Oil » 🤖 🌐
                                                                        @thenewoil@mastodon.thenewoil.org

                                                                        [?]TheHackerWire » 🤖 🌐
                                                                        @thehackerwire@mastodon.social

                                                                        🟠 CVE-2026-62349 - High (8.3)

                                                                        TDengine is an open source, time-series database optimized for Internet of Things devices. In 3.4.1.6 and earlier, source/libs/parser/src/parUtil.c trimString() checks space for only one byte before processing SQL string escape sequences \%, \_, o...

                                                                        🔗 thehackerwire.com/vulnerabilit

                                                                        CVE Alert: CVE-2026-62349

                                                                        Alt...CVE Alert: CVE-2026-62349

                                                                          [?]TheHackerWire » 🤖 🌐
                                                                          @thehackerwire@mastodon.social

                                                                          🟠 CVE-2026-62351 - High (7.5)

                                                                          TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, source/libs/transport/src/transComm.c transDecompressMsg() read STransCompMsg.contLen when pHead->comp == 1 without first validating that the RPC packe...

                                                                          🔗 thehackerwire.com/vulnerabilit

                                                                          CVE Alert: CVE-2026-62351

                                                                          Alt...CVE Alert: CVE-2026-62351

                                                                            [?]TheHackerWire » 🤖 🌐
                                                                            @thehackerwire@mastodon.social

                                                                            🟠 CVE-2026-46485 - High (8.2)

                                                                            Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to the main config.yaml through the config-saving functionality despite con...

                                                                            🔗 thehackerwire.com/vulnerabilit

                                                                            CVE Alert: CVE-2026-46485

                                                                            Alt...CVE Alert: CVE-2026-46485

                                                                              [?]TierraSapiens » 🤖 🌐
                                                                              @tierrasapiens@mastodon.social

                                                                              🖲️
                                                                              ⚫ ClickFix's Mushrooming Ecosystem Demands New Defense Tactics
                                                                              🔗 darkreading.com/cyberattacks-d

                                                                              The attack vector is available for rent at scale, and evades AV and EDR, leaving YARA analysis as the best detection option.

                                                                                [?]TheHackerWire » 🤖 🌐
                                                                                @thehackerwire@mastodon.social

                                                                                🟠 CVE-2026-52870 - High (7.6)

                                                                                The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by server.experimental.enable_tasks() for tasks/list, tasks/get, tasks/result, and tasks/c...

                                                                                🔗 thehackerwire.com/vulnerabilit

                                                                                CVE Alert: CVE-2026-52870

                                                                                Alt...CVE Alert: CVE-2026-52870

                                                                                  [?]The New Oil » 🤖 🌐
                                                                                  @thenewoil@mastodon.thenewoil.org

                                                                                  [?]TechWire ⚡ » 🤖 🌐
                                                                                  @techwire@social.gamefan.net

                                                                                  Google fires back at report claiming Search’s AI tools are unsafe for kids

                                                                                  Google slams child safety report on Search's AI features.

                                                                                  androidauthority.com/google-de

                                                                                  [Android Authority]

                                                                                    [?]TechWire ⚡ » 🤖 🌐
                                                                                    @techwire@social.gamefan.net

                                                                                    The FCC is getting involved with T-Mobile’s forced plan migrations

                                                                                    An affected user has reportedly filed complaints and gotten the FCC on the case.

                                                                                    androidauthority.com/t-mobile-

                                                                                    [Android Authority]

                                                                                      [?]TechWire ⚡ » 🤖 🌐
                                                                                      @techwire@social.gamefan.net

                                                                                      Mario Kart Wiicompiled will soon bring Nintendo’s classic racing action to your PC

                                                                                      Paving the way for more Wii games on modern hardware.

                                                                                      androidauthority.com/mario-kar

                                                                                      [Android Authority]

                                                                                        Back to top - More...