voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
Supply Chain Compromise via GitHub Actions
On July 14, 2026, an attacker exploited a misconfigured GitHub Actions workflow in the AsyncAPI generator repository through a 'pwn request' vulnerability. The attacker opened 37 pull requests, with one containing obfuscated JavaScript that exfiltrated a highly privileged Personal Access Token belonging to asyncapi-bot. Using the stolen credentials, the attacker published five malicious npm package versions under the @asyncapi namespace, which collectively receive over three million downloads weekly. The malware features a multi-stage payload that establishes persistence and connects to command and control infrastructure, executing on import rather than install. It includes capabilities for credential theft targeting browsers, SSH keys, cloud credentials, and cryptocurrency wallets. The payload shares technical characteristics with the Miasma malware framework but shows unique features including a comprehensive command framework.
Pulse ID: 6a5665a03fa69522f5e6c982
Pulse Link: https://otx.alienvault.com/pulse/6a5665a03fa69522f5e6c982
Pulse Author: AlienVault
Created: 2026-07-14 16:36:48
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Cloud #CyberSecurity #GitHub #ICS #InfoSec #Java #JavaScript #Malware #NPM #OTX #OpenThreatExchange #RAT #SSH #SupplyChain #Vulnerability #bot #cryptocurrency #AlienVault
Plex problems prevented users from streaming movies and shows
Plex services experienced some major issues on Tuesday, with multiple users reporting problems on Plex's forums and on Reddit. Many people use Plex as a way to stream shows and movies they host locally, but users are up…
https://www.theverge.com/tech/965518/plex-tv-down-outage-issues
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Google’s latest Pixel AI push keeps your data on your phone
Google is pushing Pixel AI beyond the cloud with powerful on-device tools.
https://www.androidauthority.com/google-gemma-4-e2b-for-tpu-unveiled-3687531/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Behind YouTube: Hurley, Chen, and Karim #negativepid #digitalInvestigations #OSINT #cybersecurity #AI #tech #onlineInvestigations #robotics #cyberpsychology #cybercrime https://negativepid.blog/behind-youtube-hurley-chen-and-karim/?utm_source=mastodon&utm_medium=social&utm_campaign=fedica-Negative-PID-Blog
🚨 EUVD-2026-44184
📊 Score: 7.8/10 (CVSS v3.1)
📦 Product: Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021, Microsoft Office 2019 (+8 more)
🏢 Vendor: Microsoft
📅 Updated: 2026-07-14
📝 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44184
🚨 EUVD-2026-44183
📊 Score: 7.8/10 (CVSS v3.1)
📦 Product: Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office LTSC 2024 (+5 more)
🏢 Vendor: Microsoft
📅 Updated: 2026-07-14
📝 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44183
🚨 EUVD-2026-44184
📊 Score: 7.8/10 (CVSS v3.1)
📦 Product: Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021, Microsoft Office 2019 (+8 more)
🏢 Vendor: Microsoft
📅 Updated: 2026-07-14
📝 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44184
🚨 EUVD-2026-44184
📊 Score: 7.8/10 (CVSS v3.1)
📦 Product: Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021, Microsoft Office 2019 (+8 more)
🏢 Vendor: Microsoft
📅 Updated: 2026-07-14
📝 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44184
🚨 EUVD-2026-44183
📊 Score: 7.8/10 (CVSS v3.1)
📦 Product: Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office LTSC 2024 (+5 more)
🏢 Vendor: Microsoft
📅 Updated: 2026-07-14
📝 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44183
🚨 EUVD-2026-44181
📊 Score: 8.4/10 (CVSS v3.1)
📦 Product: Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC 2021, Microsoft SharePoint Server Subscription Edition (+8 more)
🏢 Vendor: Microsoft
📅 Updated: 2026-07-14
📝 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44181
🚨 EUVD-2026-44182
📊 Score: 5.5/10 (CVSS v3.1)
📦 Product: Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac (+8 more)
🏢 Vendor: Microsoft
📅 Updated: 2026-07-14
📝 Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44182
🚨 EUVD-2026-44182
📊 Score: 5.5/10 (CVSS v3.1)
📦 Product: Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac (+8 more)
🏢 Vendor: Microsoft
📅 Updated: 2026-07-14
📝 Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44182
🚨 EUVD-2026-44184
📊 Score: 7.8/10 (CVSS v3.1)
📦 Product: Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021, Microsoft Office 2019 (+8 more)
🏢 Vendor: Microsoft
📅 Updated: 2026-07-14
📝 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44184
🚨 EUVD-2026-44182
📊 Score: 5.5/10 (CVSS v3.1)
📦 Product: Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac (+8 more)
🏢 Vendor: Microsoft
📅 Updated: 2026-07-14
📝 Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44182
🚨 EUVD-2026-44184
📊 Score: 7.8/10 (CVSS v3.1)
📦 Product: Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021, Microsoft Office 2019 (+8 more)
🏢 Vendor: Microsoft
📅 Updated: 2026-07-14
📝 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44184
🚨 EUVD-2026-44175
📊 Score: 7.3/10 (CVSS v3.1)
📦 Product: Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Enterprise Server 2016
🏢 Vendor: Microsoft
📅 Updated: 2026-07-14
📝 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44175
🚨 EUVD-2026-44184
📊 Score: 7.8/10 (CVSS v3.1)
📦 Product: Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021, Microsoft Office 2019 (+8 more)
🏢 Vendor: Microsoft
📅 Updated: 2026-07-14
📝 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44184
🚨 EUVD-2026-44184
📊 Score: 7.8/10 (CVSS v3.1)
📦 Product: Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021, Microsoft Office 2019 (+8 more)
🏢 Vendor: Microsoft
📅 Updated: 2026-07-14
📝 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44184
🚨 EUVD-2026-44184
📊 Score: 7.8/10 (CVSS v3.1)
📦 Product: Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021, Microsoft Office 2019 (+8 more)
🏢 Vendor: Microsoft
📅 Updated: 2026-07-14
📝 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44184
🚨 EUVD-2026-44184
📊 Score: 7.8/10 (CVSS v3.1)
📦 Product: Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021, Microsoft Office 2019 (+8 more)
🏢 Vendor: Microsoft
📅 Updated: 2026-07-14
📝 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44184
Possible Phishing 🎣
on: ⚠️hxxp[:]//hpromise[.]hyundai-motom[.]ru/wp-God/adobe/?email=3mail@b[.]c
🧬 Analysis at: https://urldna.io/scan/6a5610763b7750000825b491
#cybersecurity #phishing #infosec #urldna #scam #infosec
ArcGIS Server Path Traversal Masqueraded as Moderate: CVSS Jumps from 7.5 to 9.8 in Two Days https://deafnews.it/en/article/arcgis-server-path-traversal-masqueraded-as-moderate-cvss-jumps-from-75-to-98-in-two-days #Cybersecurity
Philips Hue’s budget-friendly Essential starter kit has hit a new low price
You can buy four bulbs and a Hue Bridge for just $80. | Image: Philips Hue Although most of Prime Day’s unusually good Philips Hue deals have ended, a few remain, and some, including the black Philips Hue Twilight Sleep…
https://www.theverge.com/gadgets/965476/philips-hue-essential-starter-kit-hue-bridge-deal-sale
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Homelab hardware quiz — the answer is $60
You don't need a rack: a $60 used office mini-PC runs 30+ self-hosted services at 3% CPU. Two questions to recalibrate what 'server' means.
🚨 EUVD-2026-43708
📊 Score: 7.3/10 (CVSS v3.1)
📦 Product: Studio 5000 Logix Designer
🏢 Vendor: Rockwell Automation
📅 Updated: 2026-07-14
📝 A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of external tools configured wit...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43708
🚨 EUVD-2026-43707
📊 Score: 5.4/10 (CVSS v3.1)
📦 Product: Studio 5000 Logix Designer
🏢 Vendor: Rockwell Automation
📅 Updated: 2026-07-14
📝 A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embedded in the ACD file structu...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43707
🚨 EUVD-2026-43706
📊 Score: 9.1/10 (CVSS v3.1)
📦 Product: ueberauth_apple, ueberauth_apple
🏢 Vendor: ueberauth
📅 Updated: 2026-07-14
📝 Authentication Bypass by Spoofing vulnerability in ueberauth ueberauth_apple allows account takeover via unvalidated ID token claims.
The Ueberauth.Strategy.Apple.Token.payload/2 function verifies the JWT signature of the callback...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43706
🚨 EUVD-2026-43705
📊 Score: 2.6/10 (CVSS v3.1)
📦 Product: easyappointments
🏢 Vendor: alextselegidis
📅 Updated: 2026-07-14
📝 Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 allow administrators to define a custom "booking disabled" message through the booking settings page. That value is stored in the `disable_booking_message` sett...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43705
🚨 EUVD-2026-43704
📊 Score: 7.2/10 (CVSS v3.1)
📦 Product: FactoryTalk ThinManager
🏢 Vendor: Rockwell Automation
📅 Updated: 2026-07-14
📝 A path traversal security issue exists within Rockwell Automation ThinManager® software due to improper limitation of file save operations within the API. An authenticated attacker could exploit this vulnerability to write arbitra...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43704
🚨 EUVD-2026-43692
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: easyappointments
🏢 Vendor: alextselegidis
📅 Updated: 2026-07-14
📝 Easy!Appointments is a self hosted appointment scheduler. In versions up to and including 1.5.2, the booking reschedule view at `/index.php/booking/reschedule/{appointment_hash}` (handled by `Booking::index()`) embeds the entire customer reco...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43692
🚨 EUVD-2026-43703
📊 Score: 5.9/10 (CVSS v3.1)
📦 Product: FortiPAM, FortiPAM, FortiSASE (+13 more)
🏢 Vendor: Fortinet
📅 Updated: 2026-07-14
📝 A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, Fo...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43703
🚨 EUVD-2026-43702
📊 Score: 8.4/10 (CVSS v3.1)
📦 Product: FactoryTalk® DataMosaix™ Private Cloud
🏢 Vendor: Rockwell Automation
📅 Updated: 2026-07-14
📝 A Stored Cross-Site Scripting security issue exists within FactoryTalk® DataMosaix™ Private Cloud. The vulnerability stems from improper neutralization of user-supplied input within the Workflows configuration. An a...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43702
🚨 EUVD-2025-210463
📊 Score: 9.2/10 (CVSS v3.1)
📦 Product: CompactLogix® 5380 Recovery Image Compact GuardLogix® 5380 Recovery Image CompactLogix® 5480 Recovery Image ControlLogix® 5580 Recovery Image GuardLogix® 5580 Recovery Image
🏢 Vendor: Rockwell Automation
📅 Updated: 2026-07-14
📝 A denial-of-service issue exists in 5380/5480/5580 control...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-210463
🚨 EUVD-2026-43688
📊 Score: 8.8/10 (CVSS v3.1)
📦 Product: SIP
🏢 Vendor: Dan-in-CA
📅 Updated: 2026-07-14
📝 Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a mass assignment vulnerability that allows unauthenticated attackers to overwrite sensitive configuration settings by supplying arbitrary parameter names in HTTP requests. Attackers can man...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43688
🚨 EUVD-2026-43689
📊 Score: 6.3/10 (CVSS v3.1)
📦 Product: SIP
🏢 Vendor: Dan-in-CA
📅 Updated: 2026-07-14
📝 Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated attackers to make the device issue arbitrary HTTP requests by supplying a malicious callback URL when the optio...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43689
🚨 EUVD-2026-43686
📊 Score: 8.7/10 (CVSS v3.1)
📦 Product: BE12 Pro
🏢 Vendor: Tenda
📅 Updated: 2026-07-14
📝 A flaw has been found in Tenda BE12 Pro 16.03.66.23. The affected element is the function fromDhcpListClient of the file /goform/DhcpListClient. This manipulation of the argument page causes stack-based buffer overflow. The attack can be initiated remotely. T...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43686
Possible Phishing 🎣
on: ⚠️hxxps[:]//lamail7[.]godaddysites[.]com/
🧬 Analysis at: https://urldna.io/scan/6a55a6423b775000029fdfc0
#cybersecurity #phishing #infosec #urldna #scam #infosec
Every endpoint has a purpose. A login page, an API endpoint, and a contact form all require different security considerations. AIWAF uses AST analysis to understand application context before making security decisions, reducing assumptions and improving automation.
#AppSec #CyberSecurity #OpenSource #Python #AST #DeveloperTools
Lucide Proxy: Turning Student Web Proxies into DDoS Bots
A sophisticated campaign deployed 148 malicious npm packages disguised as student web proxy applications under brands like Riverbend Tutoring and Northstar Tutoring. Published by accounts terminal3airport and eerikakirk, these packages weaponized visitor browsers into distributed denial-of-service botnets while generating advertising revenue. The applications functioned as working proxies but secretly executed mutable remote code and high-performance WebSocket traffic generators compatible with the Wisp protocol. During a critical two-week period in May 2026, active deployments launched HTTP floods generating 2GB/s aggregate traffic and control-plane attacks establishing 10,240 socket connections per second against target servers. The campaign abused npm as a content delivery network, affecting users who visited proxy instances rather than through traditional dependency infection.
Pulse ID: 6a5660720f790923b2946df9
Pulse Link: https://otx.alienvault.com/pulse/6a5660720f790923b2946df9
Pulse Author: AlienVault
Created: 2026-07-14 16:14:42
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #DDoS #DoS #HTTP #InfoSec #NPM #OTX #OpenThreatExchange #Proxy #RAT #TorBrowser #bot #botnet #AlienVault
Progress Orders ShareFile Shutdown: Third Critical Incident in Three Years https://deafnews.it/en/article/progress-orders-sharefile-shutdown-third-critical-incident-in-three-years #Cybersecurity
It was nice while it lasted: Samsung reportedly ending free storage upgrades
Samsung may drop its free storage upgrades and the RAM and storage crisis is to blame.
https://www.androidauthority.com/samsung-ending-free-storage-upgrade-offer-3687401/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
🚨 Progress just confirmed a ShareFile Zero-Day.
After ordering customers to **shut down internet-facing Storage Zone Controllers**, Progress has now revealed the cause: a high-severity path traversal vulnerability affecting all 5.x and 6.x versions.
⚠️ If you're running ShareFile Storage Zone Controllers:
✅ Update to **v5.12.5 or v6.0.2
✅ Review admin activity & logs
✅ Bring servers online only after patching
Enterprise file transfer platforms continue to be prime targets after MOVEit. Don't wait to patch.
🔗 Read the full breakdown:
https://thecybersecguru.com/news/progress-sharefile-storage-zone-controller-0-day/
#CyberSecurity #ZeroDay #ShareFile #ProgressSoftware #Vulnerability #ThreatIntelligence #InfoSec #BlueTeam #SOC #SysAdmin #WindowsServer #SecurityNews #CyberThreats #PatchNow #DataSecurity
☕ #Cybersecurity #Ciberseguridad #Ciberseguranca #Security #Seguridad #Seguranca #News #Noticia #Noticias #Tecnologia #Technology
🟣 Así es como Apple está actualizando sus funciones de seguridad infantil en iOS 27
🔗 https://es.wired.com/articulos/asi-es-como-apple-esta-actualizando-sus-funciones-de-seguridad-infantil-en-ios-27
Apple ha anunciado varias funciones nuevas de seguridad infantil que estarán disponibles próximamente en los iPhone y otros dispositivos con iOS 27. Esto es lo que