voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
Ostatnio było tu nieco ciszej, ale na blogu niedługo coś się pojawi. Aktualnie trwają testy płatności zbliżeniowych na GrapheneOS.
Równolegle czekam na sprzęt, który posłuży jako fundament pod nowy eksperyment. Chcę sprawdzić w praktyce, jak daleko można przesunąć granice prywatności i modelu zero trust na fabrycznym flagowcu, opierając się na rygorystycznej kontroli sieciowej zamiast na alternatywnym systemie operacyjnym.
Gdy tylko urządzenie do mnie dotrze i przejdzie konfigurację oraz testy, na blogu pojawi się szczegółowy opis tej drogi.
#InfoSec #CyberSecurity #Privacy #Android #GrapheneOS #ZeroTrust #DeGoogle #MobileSecurity
🚨 EUVD-2026-44778
📊 Score: 7.1/10 (CVSS v3.1)
📦 Product: dataease
🏢 Vendor: dataease
📅 Updated: 2026-07-15
📝 DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase SQL preview exposes DatasetDataApi.previewSql/previewSqlCheck through /de2api/datasetData/previewSql, accepts PreviewSqlDTO.sql, PreviewSqlDTO.datasourceId, and Pre...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44778
🚨 EUVD-2026-44764
📊 Score: 5.4/10 (CVSS v3.1)
📦 Product: TDengine
🏢 Vendor: taosdata
📅 Updated: 2026-07-15
📝 TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a Data Reader admin_user on a TDengine Cloud DB instance could run create udf even though standard users should have read-only permissions for non...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44764
🚨 EUVD-2026-44765
📊 Score: 9.3/10 (CVSS v3.1)
📦 Product: @cap-js/postgres, @cap-js/sqlite, @cap-js/db-service
🏢 Vendor: cap-js, @cap-js/db-service
📅 Updated: 2026-07-15
📝 The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL database services for that tool. On April 29, 2...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44765
🚨 EUVD-2026-44777
📊 Score: 8.5/10 (CVSS v3.1)
📦 Product: dataease
🏢 Vendor: dataease
📅 Updated: 2026-07-15
📝 DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase template saves call TemplateManageService#save, StaticResourceServer#saveFilesToServe, and the /de2api/templateManage/save endpoint with attacker-controlled staticR...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44777
🔴 CVE-2026-49445 - Critical (9.2)
Cilium is a networking, observability, and security solution. Prior to 1.17.14, 1.18.8, and 1.19.2, when Cilium L7 functionality is enabled, the embedded or standalone Envoy instance creates a world-accessible admin.sock on cluster nodes, allowing...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49445/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🚨 EUVD-2026-44768
📊 Score: 8.4/10 (CVSS v3.1)
📦 Product: jsii
🏢 Vendor: aws
📅 Updated: 2026-07-15
📝 OS command injection in the npm package loading component in AWS jsii-diff before 1.131.0 might allow context-dependent attackers to execute arbitrary commands via crafted package specifiers passed to the npm: source argument.
To mitigate this issue, users shoul...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44768
🚨 EUVD-2026-44776
📊 Score: 8.7/10 (CVSS v3.1)
📦 Product: dataease
🏢 Vendor: dataease
📅 Updated: 2026-07-15
📝 DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase datasource connection status checks concatenate configuration.getSchema() into getTablesSql and execute the resulting SQL with executeQuery in io.dataease.datasourc...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44776
🚨 EUVD-2026-44775
📊 Score: 9.0/10 (CVSS v3.1)
📦 Product: dataease
🏢 Vendor: dataease
📅 Updated: 2026-07-15
📝 DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase Redshift datasource connections can load attacker-controlled rsjdbc.ini configuration from System.getProperty("java.io.tmpdir"), setting socketFactory=org.springfra...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44775
🚨 EUVD-2026-44774
📊 Score: 5.4/10 (CVSS v3.1)
📦 Product: cilium
🏢 Vendor: cilium
📅 Updated: 2026-07-15
📝 Cilium is a networking, observability, and security solution. From 1.19.0 to 1.19.4, standard Kubernetes NetworkPolicy specifications using CIDR-based ipBlock rules without pod or namespace selectors erroneously generate a wildcard namespace allow rule when Ci...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44774
🚨 EUVD-2026-44773
📊 Score: 5.9/10 (CVSS v3.1)
📦 Product: cilium, cilium, cilium
🏢 Vendor: cilium
📅 Updated: 2026-07-15
📝 Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to create or update namespaced HTTPRoutes to mirror HTTP traffic to any Service ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44773
🚨 EUVD-2026-44772
📊 Score: 9.2/10 (CVSS v3.1)
📦 Product: cilium, cilium, cilium
🏢 Vendor: cilium
📅 Updated: 2026-07-15
📝 Cilium is a networking, observability, and security solution. Prior to 1.17.14, 1.18.8, and 1.19.2, when Cilium L7 functionality is enabled, the embedded or standalone Envoy instance creates a world-accessible admin.sock on cluster nodes, allow...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44772
🚨 EUVD-2026-44769
📊 Score: 5.4/10 (CVSS v3.1)
📦 Product: TDengine
🏢 Vendor: taosdata
📅 Updated: 2026-07-15
📝 TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, TDengine Enterprise allowed an authenticated low-privilege SQL user to run KILL SSMIGRATE <id> against an active shared-storage migration because mndProcessKill...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44769
🚨 EUVD-2026-44766
📊 Score: 7.2/10 (CVSS v3.1)
📦 Product: TDengine
🏢 Vendor: taosdata
📅 Updated: 2026-07-15
📝 TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a user with create udf privilege could upload a crafted shared library and install it as a user-defined function, such as eval, then execute arbit...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44766
🚨 EUVD-2026-44757
📊 Score: 6.8/10 (CVSS v3.1)
📦 Product: repomix
🏢 Vendor: yamadashy
📅 Updated: 2026-07-15
📝 Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, the Repomix MCP server attach_packed_output and read_repomix_output flow can register and read arbitrary local .json, .txt, .md, or .xml files without the file_system_read_f...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44757
🔒 HalluSquatting: hacker creano botnet con AI coding agent
Nuovo attacco: registrano pacchetti simili a librerie popolari. Quando Cursor, Copilot scaricano codice, migliaia di dispositivi si infettano automaticamente.
Fonte: Ars Technica
Segui 👇
#AI #Cybersecurity 🔐💻🛡️
#chrome extension Squid Game 2 Live Wallpaper seems malicious. Its #cybersecurity badness score is 88/100!
```json
{"id": "caobnfncoamhhbgpccglkjdfepojgjgj", "score": 88, "platform": "chrome", "name": "Squid Game 2 Live Wallpaper"}
```
#chrome extension Retro Games Offline seems malicious. Its #cybersecurity badness score is 88/100!
```json
{"id": "diehbglpgicpogjinfcfpmjfdleifohl", "score": 88, "platform": "chrome", "name": "Retro Games Offline"}
```
#chrome extension HTML to Elementor – Web Page Converter seems malicious. Its #cybersecurity badness score is 95/100!
```json
{"id": "ilkdaiednajbdbjfpcjcpecjmincmkkl", "score": 95, "platform": "chrome", "name": "HTML to Elementor \u2013 Web Page Converter"}
```
You can finally create Google Chat group convos with external guests
It's now easier than ever to collaborate with people outside your organization.
https://www.androidauthority.com/external-google-chat-group-conversations-3688004/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Miasma Worm Returns to npm
Four AsyncAPI npm packages were compromised in July 2026, delivering Miasma v3, a new variant of the worm previously found in Red Hat packages. The malicious versions (@asyncapi/generator, @asyncapi/generator-helpers, @asyncapi/generator-components, and @asyncapi/specs) were published through AsyncAPI's legitimate GitHub Actions workflow using npm's OIDC integration, creating packages with valid provenance attestations. Unlike previous variants, this attack triggers when applications load the poisoned library rather than during installation. The payload downloads a second stage from IPFS, establishing a persistent Node.js backdoor with arbitrary shell command execution capabilities. While the codebase contains credential theft, propagation, and AI-tool poisoning modules, this deployment primarily functions as a remote access trojan. The attack began with an unauthorized commit to the repository's release branch, highlighting the importance of branch protection even when using trusted-publisher mechanisms.
Pulse ID: 6a579712c94f47186288661d
Pulse Link: https://otx.alienvault.com/pulse/6a579712c94f47186288661d
Pulse Author: AlienVault
Created: 2026-07-15 14:20:02
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #GitHub #InfoSec #NPM #Nodejs #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Rust #SMS #Trojan #Worm #bot #AlienVault
🖲️ #Cybersecurity #Ciberseguridad #Ciberseguranca #Security #Seguridad #Seguranca #News #Noticia #Noticias #Tecnologia #Technology
⚫ 2-Click Cursor Exploit Enables Dev Environment Takeover
🔗 https://www.darkreading.com/application-security/2-click-cursor-exploit-dev-environment-takeover
Simple age-old bugs give bad actors access to developers' secrets and source code-rich environments.
🔴 CVE-2026-61736 - Critical (9.3)
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, the server defaults to CORS_ORIGINS=* combined with allow_credentials=True in lightrag/api/lightrag_server.py, causing Starlette CORSMiddleware to effectively whitel...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61736/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-61835 - High (7.7)
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, the SSRF protection on Directus's file-import-from-URL feature can be bypassed using the address 0.0.0.0 because api/src/request/is-denied-ip.ts trea...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61835/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-61836 - High (8.6)
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, when response caching is enabled, the cache-key derivation in api/src/utils/get-cache-key.ts includes version, path, query, and accountability.user b...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61836/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🖲️ #Cybersecurity #Ciberseguridad #Ciberseguranca #Security #Seguridad #Seguranca #News #Noticia #Noticias #Tecnologia #Technology
⚫ 6 GHz Wi-Fi Flaws Could Disrupt Critical Systems
🔗 https://www.darkreading.com/perimeter/6-ghz-wi-fi-flaws-disrupt-critical-systems
Automated Frequency Coordination systems by default trust client-side data, which could lead to location spoofing and other attacks that disrupt traffic.
🟠 CVE-2026-62685 - High (8.1)
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, File Browser builds new user scopes from usernames passed through cleanUsername() when Signu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62685/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-60005 - High (8.2)
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-60005/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-55242 - High (8.8)
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, an authenticated user with a standard operational role can trigger server-side template injection through a configuration field, resulting in unaut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55242/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Meet the next batch of emoji that you’ll be using next year
Get an early peek at the next batch of emoji coming your way.
https://www.androidauthority.com/emoji-18-finalized-designs-preview-3687827/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
The CMF Watch Pro 2 falls to $39 in a return to its Prime Day price
This deal cuts 43% off the retail price and packs GPS, IP68 protection, over 100 sports modes, and AMOLED.
https://www.androidauthority.com/deal-cmf-watch-pro-2-3687863/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Google Search AI is under fire after safety report slams its safeguards
Google’s AI Overviews pose an 'unacceptable risk' to kids, report warns.
https://www.androidauthority.com/report-says-google-search-ai-harmful-for-kids-3687868/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
🚨 EUVD-2026-44701
📊 Score: 10.0/10 (CVSS v3.1)
📦 Product: Metabase, Metabase, Metabase (+4 more)
🏢 Vendor: metabase
📅 Updated: 2026-07-15
📝 Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase user with permission to add or edit a database conne...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44701
🚨 EUVD-2026-44698
📊 Score: 7.7/10 (CVSS v3.1)
📦 Product: penpot
🏢 Vendor: penpot
📅 Updated: 2026-07-15
📝 Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot's remote image import passed the user-controlled url from frontend/src/app/main/data/workspace/media.cljs into the backend RPC method :create-file-media-object-from...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44698
🚨 EUVD-2026-44693
📊 Score: 8.3/10 (CVSS v3.1)
📦 Product: vaultwarden
🏢 Vendor: dani-garcia
📅 Updated: 2026-07-15
📝 Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO authorization flow did not bind the OAuth state parameter accepted by /connect/authorize to the initiating browser session, allowed attacker-controlled P...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44693
🚨 EUVD-2026-44692
📊 Score: 7.8/10 (CVSS v3.1)
📦 Product: tabby
🏢 Vendor: Eugeny
📅 Updated: 2026-07-15
📝 Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.234, Tabby inserts dropped file paths from tabby-electron/src/pathDrop.ts into the active shell without neutralizing command substitution metacharacters such as $(…) and `…`, so ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44692
🚨 EUVD-2026-44690
📊 Score: 8.5/10 (CVSS v3.1)
📦 Product: nixpkgs, nixpkgs
🏢 Vendor: NixOS
📅 Updated: 2026-07-15
📝 Nixpkgs is a collection of software packages that can be installed with the Nix package manager. Prior to the 25.11 and 26.05 channel fixes, the NixOS module for MySQL services.mysql initializes the MySQL database in a way that allows local users, suc...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44690
🟠 CVE-2026-50147 - High (7.6)
Metabase is an open-source business intelligence and embedded analytics tool. From 1.57.0 until 1.57.19.1, 1.58.14.1, 1.59.10, and 1.60.4, an attacker who can configure a Metabase database connection can read arbitrary files from the Metabase serv...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-50147/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🔴 CVE-2026-50148 - Critical (10)
Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase user with permission to add or edit a database connection can achieve remo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-50148/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
The tiniest MMO
At its peak, around 12 million people subscribed to World of Warcraft so that they could explore the realm of Azeroth together. The audience for PointlessQuest is quite a bit smaller. On launch day, the game hit a peak …
https://www.theverge.com/entertainment/965621/playdate-mmo-pointlessquest
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
#chrome extension Anime Girl Daisy Eyes Live Wallpaper seems malicious. Its #cybersecurity badness score is 88/100!
```json
{"id": "falodpolphfpahjajahbbnpkimeiaggo", "score": 88, "platform": "chrome", "name": "Anime Girl Daisy Eyes Live Wallpaper"}
```
#chrome extension Nissan GTR R34 Neon Retro Japanese Street Live Wallpaper seems malicious. Its #cybersecurity badness score is 92/100!
```json
{"id": "eohnaddlogkpnndjpopflicgdhmapgia", "score": 92, "platform": "chrome", "name": "Nissan GTR R34 Neon Retro Japanese Street Live Wallpaper"}
```
#chrome extension Katsuki Bakugo Wallpaper seems malicious. Its #cybersecurity badness score is 91/100!
```json
{"id": "edhdedomkophnkkchgcpgdoediablnhj", "score": 91, "platform": "chrome", "name": "Katsuki Bakugo Wallpaper"}
```
#chrome extension Cristiano Ronaldo Wallpaper seems malicious. Its #cybersecurity badness score is 89/100!
```json
{"id": "eagbeockkodhfmcgdmnijchjalbefked", "score": 89, "platform": "chrome", "name": "Cristiano Ronaldo Wallpaper"}
```