voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
🚨 EUVD-2026-44855
📊 Score: 4.3/10 (CVSS v3.1)
📦 Product: Catch Themes Demo Import
🏢 Vendor: catchplugins
📅 Updated: 2026-07-16
📝 The Catch Themes Demo Import plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.3. This is due to the catch_themes_demo_import_activate_plugin() function, hooked on admin_init when the activa...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44855
🚨 EUVD-2026-44854
📊 Score: 4.4/10 (CVSS v3.1)
📦 Product: MxChat – AI Chatbot & Content Generation for WordPress
🏢 Vendor: mxchat
📅 Updated: 2026-07-16
📝 The MxChat – AI Chatbot & Content Generation for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.10 due to insufficient inp...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44854
Legendary Gravis Ultrasound sound card gets new open-source clone — Beavis Ultrasound remake includes complete KiCad schematics, PCB layout, sample ROM, and more
There’s a new remake of the legendary Gravis Ultrasound ISA soundcard on the block with the arrival of the open source Beavis Ultrasound project.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
OkoBot framework infection chain
In January 2026, researchers identified a sophisticated malware framework dubbed OkoBot that targets cryptocurrency users through a multi-stage infection chain. The campaign begins with TookPS PowerShell scripts delivered via ClickFix attacks or fake software on GitHub. An automated SSH bot deploys over 20 malicious modules including HDUtil launcher, browser extension injectors installing Rilide stealer, and specialized tools like SeedHunter for wallet seed phrase theft and OkoSpyware for window capture. The framework uses VMProtect obfuscation, UAC bypass techniques, and maintains persistence through RDP access and scheduled tasks. Victims span more than 25 countries with concentrations in Brazil, Vietnam, Canada, Mexico, and Turkey. Attribution suggests Russian-speaking threat actors based on geoblocking patterns and Russian language artifacts.
Pulse ID: 6a5775d2afd24bb0357b62c1
Pulse Link: https://otx.alienvault.com/pulse/6a5775d2afd24bb0357b62c1
Pulse Author: AlienVault
Created: 2026-07-15 11:58:10
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Brazil #Browser #Canada #CyberSecurity #GitHub #InfoSec #Malware #Mexico #OTX #OpenThreatExchange #PowerShell #RAT #RDP #Russia #SSH #SpyWare #Turkey #Vietnam #bot #cryptocurrency #AlienVault
🔴 CVE-2026-55652 - Critical (9.8)
Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequestIp() in server/lib/headerLoginAuth.js to trust the client-supplied X-Forwarded-For header before the real socket address, allow...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55652/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-55234 - High (8.5)
Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.js, server/permissions/lists.js, and server/permissions/swimlanes.js authorize against the stored source boardId and do not vali...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55234/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🔴 CVE-2026-54458 - Critical (9.6)
WWBN AVideo is an open source video platform. Versions prior to 29.0 contain a stored DOM Cross-Site Scripting vulnerability in the YPTSocket plugin. Any unauthenticated remote attacker can execute arbitrary JavaScript in the authenticated origin ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54458/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Fake crypto scams try to piggyback off SpaceX IPO
Scammers are exploiting public interest in the SpaceX IPO through fraudulent investment portals impersonating SpaceX, Elon Musk, and major financial brands including Fidelity and Robinhood. The campaign uses themed domains to lure victims into fake onboarding processes that mimic legitimate investment procedures, including W-8BEN tax forms for non-U.S. investors. Victims are asked to select investment tiers and ultimately directed to deposit funds via cryptocurrency wallets for Bitcoin, Ethereum, and USDT. The operation mirrors techniques used by threat actor TA2730 but focuses on direct cryptocurrency theft rather than credential harvesting. One Bitcoin wallet associated with the campaign received approximately $8,700. The infrastructure includes randomized domains and SpaceX-themed domains designed to appear legitimate during the investment process.
Pulse ID: 6a57f270713faa71010c16ad
Pulse Link: https://otx.alienvault.com/pulse/6a57f270713faa71010c16ad
Pulse Author: AlienVault
Created: 2026-07-15 20:49:52
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BitCoin #CredentialHarvesting #CyberSecurity #InfoSec #Mimic #OTX #OpenThreatExchange #RAT #RobinHood #bot #cryptocurrency #AlienVault
Dutch police have successfully dismantled an international cryptocurrency investment fraud ring that stole an estimated €100 million per month. The operation employed over 700 people globally and utilized completely fabricated trading platforms. #CyberSecurity #Crypto #Fraud #TechNews
https://blazetrends.com/e100m-crypto-fraud-ring-busted-by-dutch-police-hacker-mastermind-arrested/?fsp_sid=52125
xAI sues a man for using Grok to generate CSAM ‘deepfakes’
The Elon Musk-owned xAI is suing a South Carolina man who allegedly used the company's Grok AI chatbot to generate child sexual abuse material (CSAM). In a lawsuit reported earlier by Reuters, xAI claims Terry Wayne Har…
https://www.theverge.com/ai-artificial-intelligence/966293/xai-grok-user-lawsuit-csam
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Valve says iFixit will keep selling Steam Deck batteries after all
The Steam Deck’s internals, including the L-shaped battery. Valve has been incredibly friendly to customers who need repairs - which is why it was so surprising to hear that Valve was already discontinuing the battery f…
https://www.theverge.com/games/966106/valve-ifixit-will-keep-selling-steam-deck-lcd-battery
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Apple’s reportedly raising the price for AppleCare Plus on Macs and iPads
An AppleCare Plus subscription for a Mac or iPad will cost more soon, with prices going up by $0.50 per month or $5 per year for new sign-ups while remaining the same for existing subscribers, according to Bloomberg's M…
https://www.theverge.com/tech/966219/apple-care-plus-price-increase
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
HP’s OLED-equipped 2-in-1 laptop is a solid back-to-school deal
HP’s convertible OmniBook has a great feature set for the price. | Image: HP With storage and memory prices still at an all-time high, we’re happy to tell you about a solid deal on a good laptop when we find one, rare a…
https://www.theverge.com/gadgets/966209/hp-omnibook-x-flip-oled-laptop-windows-11-deal-sale
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Waze just gave me 5 new reasons to switch from Apple Maps
None of these new Waze features is offered in Apple Maps.
https://www.zdnet.com/article/waze-update-may-beat-apple-maps/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
🚨 EUVD-2026-44825
📊 Score: 7.7/10 (CVSS v3.1)
📦 Product: AVideo
🏢 Vendor: WWBN
📅 Updated: 2026-07-15
📝 WWBN AVideo is an open source video platform. Versions 29.0 and below contain a Stored XSS vulnerability through the autoEvalCodeOnHTML parameter in the MessageSQLite WebSocket Handler. The MessageSQLite.php handler only strips autoEvalCodeOnHTML from $json['msg...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44825
Possible Phishing 🎣
on: ⚠️hxxps[:]//barclays-banking[.]net/landing/form/652e1755-3215-4d33-ad3a-b8a16444b4ba
🧬 Analysis at: https://urldna.io/scan/6a577e1f3b775000091fa190
#cybersecurity #phishing #infosec #urldna #scam #infosec
Intel: 892 CVEs, avg CVSS 6.21. 94% unpatched. Trust Score: C. Chip-level flaws linger. Patch your firmware NOW. #Intel #cybersecurity #infosec
Skullcandy’s bass-boosting Crusher headphones now come with Bose’s ANC
Skullcandy announced a new version of its Crusher wireless headphones today featuring a few of Bose's audio technologies including its QuietControl ANC and head-tracking spatial audio. The Crusher headphone line differe…
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
I highly recommend Nomad's chargers, phone cases, and watch bands - and my favorites are on sale now
Nomad's tech accessories rarely go on sale, but now is your chance to scoop up some of our favorites at over 20% off.
https://www.zdnet.com/article/nomad-anniversary-sale-2026/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
Possible Phishing 🎣
on: ⚠️hxxps[:]//kuyhaa-me[.]pw/dhtanx/Office/index[.]php
🧬 Analysis at: https://urldna.io/scan/6a577e0b3b775000091fa16a
#cybersecurity #phishing #infosec #urldna #scam #infosec
How to use Gemini to plan your next summer vacation - in minutes
This Gemini prompt can find flights, stays, and things to do for you. It'll even build an itinerary doc.
https://www.zdnet.com/article/gemini-prompt-to-plan-vacation-build-itinerary-doc/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
CyberIntel Weekly: New Process Parameter Poisoning Technique Hides Shellcode in Windows Startup Data
CyberIntel Weekly: New Process Parameter Poisoning Technique Hides Shellcode in Windows Startup Data
I tested all three OpenVPN tiers: Why the free version is still the best choice for most users
OpenVPN offers three modes of deployment with varied pricing based on the same underlying protocol. Here are the pros, cons, and costs associated with each.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
🚨 EUVD-2026-44837
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: SecPath F1000-C8300
🏢 Vendor: H3C
📅 Updated: 2026-07-15
📝 A flaw has been found in H3C SecPath F1000-C8300 up to 20260522. This impacts an unknown function of the file /webui/?g=log_fw_nbc_mail_jsondata. Executing a manipulation of the argument subject can lead to sql injection. The attack can be executed r...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44837
Possible Phishing 🎣
on: ⚠️hxxps[:]//www[.]powr[.]io/media-gallery/i/41161241
🧬 Analysis at: https://urldna.io/scan/6a581f073b775000033620e5
#cybersecurity #phishing #infosec #urldna #scam #infosec
📰 The Canadian spy agency reported hacking activities targeting drug traffickers, extremists, and a ransomware gang last year, highlighting national security concerns.
📰 The Canadian spy agency reported hacking activities targeting drug traffickers, extremists, and a ransomware gang last year, highlighting national security concerns.
Umami: analytics without spying
Umami — analytics without spying. No cookies, GDPR-clean. One lightweight script. Free and open-source. Install guides, alternatives and screenshots in the directory.
https://selfhost.directory/project/umami
#Datahoarder #Cybersecurity #Degoogle #Devops #Selfhosted #Sysadmin #Umami
Encrypted messaging is great...
Until an attacker steals the account, adds a linked device, or tricks someone out of a recovery key.
In episode 441 of Shared Security, Tom and Kevin discuss the FBI warning about Russian intelligence targeting Signal, WhatsApp, and Telegram users and why endpoint/account security still matters.
Watch this episode on YouTube:
https://youtu.be/fxFfY_e_MOI
Listen and subscribe wherever you like to get your podcasts:
https://sharedsecurity.net/subscribe
https://sharedsecurity.net/2026/07/13/signal-phishing-and-russian-intelligence-targeting-messaging-apps/
Android 17 QPR1 Beta 7 drops a few bugfixes for die-hard Pixel testers
It's Google's first release since Android 17 QPR1 hit Platform Stability earlier this month.
https://www.androidauthority.com/android-17-qpr1-beta-7-3688027/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Cybersecurity. National Security. Intelligence (artificial and otherwise).
Exactly what you need to know. In your inbox every Monday morning. Free. Never any spam.
If you don't get it, you don't get it.
Subscribe today: http://cyberintelnews.com
Meshcore madness is HERE 🔴!
Dive into a hacker summer camp vibe.
Cybersecurity deep dives + rants.
Chill Linux gaming sesh incoming.
Let's build something wild. 🔥 #Meshcore #Cybersecurity #Linux
Meshcore madness is HERE 🔴!
Dive deep into cybersecurity with a Hacker Summer Camp vibe. Expect rants, chill Linux tinkering, and some gaming thrown in for good measure. Let's build and watch the chaos unfold. 🎮
Meshcore madness is ON! 🔴
Diving deep into cybersecurity with a hacker summer camp vibe. Expect rants, chill Linux tinkering, and some gaming thrown in for good measure. Let's build something interesting and watch the chaos unfold. 🎮
🟠 CVE-2026-62349 - High (8.3)
TDengine is an open source, time-series database optimized for Internet of Things devices. In 3.4.1.6 and earlier, source/libs/parser/src/parUtil.c trimString() checks space for only one byte before processing SQL string escape sequences \%, \_, o...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62349/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-62351 - High (7.5)
TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, source/libs/transport/src/transComm.c transDecompressMsg() read STransCompMsg.contLen when pHead->comp == 1 without first validating that the RPC packe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62351/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-46485 - High (8.2)
Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to the main config.yaml through the config-saving functionality despite con...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-46485/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🖲️ #Cybersecurity #Ciberseguridad #Ciberseguranca #Security #Seguridad #Seguranca #News #Noticia #Noticias #Tecnologia #Technology
⚫ ClickFix's Mushrooming Ecosystem Demands New Defense Tactics
🔗 https://www.darkreading.com/cyberattacks-data-breaches/clickfixs-ecosystem-demands-new-defense
The attack vector is available for rent at scale, and evades AV and EDR, leaving YARA analysis as the best detection option.
🟠 CVE-2026-52870 - High (7.6)
The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by server.experimental.enable_tasks() for tasks/list, tasks/get, tasks/result, and tasks/c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52870/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Google fires back at report claiming Search’s AI tools are unsafe for kids
Google slams child safety report on Search's AI features.
https://www.androidauthority.com/google-denies-search-ai-tools-harmful-to-kids-3687921/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
The FCC is getting involved with T-Mobile’s forced plan migrations
An affected user has reportedly filed complaints and gotten the FCC on the case.
https://www.androidauthority.com/t-mobile-plan-migrations-fcc-3687945/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Mario Kart Wiicompiled will soon bring Nintendo’s classic racing action to your PC
Paving the way for more Wii games on modern hardware.
https://www.androidauthority.com/mario-kart-wii-recomp-3687890/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]