voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]CyberNetsecIO » 🌐
@netsecio@mastodon.social

📰 New 'Orexin' Ransomware Strain Discovered with Anti-Recovery Tactics

A new ransomware strain named 'Orexin' has been discovered by CYFIRMA. The malware uses Themida packer for evasion, deletes shadow copies to prevent recovery, and spreads to network shares.

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/ne

    [?]CyberNetsecIO » 🌐
    @netsecio@mastodon.social

    📰 Russian APT 'Laundry Bear' Targets West with Zero-Click Zimbra Exploit

    International advisory warns of Russian APT 'Laundry Bear' using a zero-click Zimbra exploit (CVE-2025-66376) in a widespread espionage campaign against Western targets. Actors steal emails & credentials.

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/ru

      [?]CyberNetsecIO » 🌐
      @netsecio@mastodon.social

      📰 Check Point Patches Actively Exploited SmartConsole Auth Bypass Flaw

      🚨 CRITICAL PATCH: Check Point fixes an actively exploited auth bypass zero-day (CVE-2026-16232, CVSS 9.3) in SmartConsole. Flaw allows full admin access. CISA added to KEV. Patch NOW.

      🌐 cyber[.]netsecops[.]io

      🔗 cyber.netsecops.io/articles/ch

        [?]TechWire ⚡ » 🤖 🌐
        @techwire@social.gamefan.net

        The BOOX Picco could be the tiny e-reader of your dreams

        It's got a 3.97" display and expandable storage.

        androidauthority.com/onyx-boox

        [Android Authority]

          [?]TheHackerWire » 🤖 🌐
          @thehackerwire@mastodon.social

          🟠 CVE-2026-66032 - High (8.8)

          libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a serv...

          🔗 thehackerwire.com/vulnerabilit

          CVE Alert: CVE-2026-66032

          Alt...CVE Alert: CVE-2026-66032

            [?]urlDNA.io :verified: » 🤖 🌐
            @urldna@infosec.exchange

            Possible Phishing 🎣
            on: ⚠️hxxps[:]//t[.]co/ClhH1ENrLL
            🧬 Analysis at: urldna.io/scan/6a6369923b77500

              [?]TheHackerWire » 🤖 🌐
              @thehackerwire@mastodon.social

              🟠 CVE-2026-66033 - High (7.5)

              libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AE...

              🔗 thehackerwire.com/vulnerabilit

              CVE Alert: CVE-2026-66033

              Alt...CVE Alert: CVE-2026-66033

                [?]TheHackerWire » 🤖 🌐
                @thehackerwire@mastodon.social

                🟠 CVE-2026-66034 - High (7.5)

                libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsy...

                🔗 thehackerwire.com/vulnerabilit

                CVE Alert: CVE-2026-66034

                Alt...CVE Alert: CVE-2026-66034

                  [?]EUVD Bot » 🤖 🌐
                  @EUVD_Bot@mastodon.social

                  🚨 EUVD-2026-46793

                  📊 Score: 9.8/10 (CVSS v3.1)
                  📦 Product: Service Delivery Platform, Service Delivery Platform
                  🏢 Vendor: Oracle Corporation
                  📅 Published: 2026-07-21 | Updated: 2026-07-24

                  📝 Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1....

                  🔗 euvd.enisa.europa.eu/vulnerabi

                    [?]BSides Edmonton » 🌐
                    @bsidesedmonton@infosec.exchange

                    The BSides Edmonton committee sincerely thank Arctic Wolf Networks Inc. arcticwolf.com/ for being a Gold Sponsor of Bsides Edmonton 2026. Your support directly fueled an amazing lineup of speakers, hands-on workshops, and invaluable networking sessions.

                    Be sure to visit them at our 9th annual event September 24–25, 2026.
                    If your company wants to be part of this year’s community-driven security event, Visit bsidesyeg.org/SponsorApplicati

                      [?]TechWire ⚡ » 🤖 🌐
                      @techwire@social.gamefan.net

                      Nothing rejects market exit rumors, insists global operations remain active

                      Nothing is firing back at a report alleging its existing 12 markets.

                      androidauthority.com/nothing-d

                      [Android Authority]

                        [?]CTI.FYI » 🤖 🌐
                        @CTI_FYI@infosec.exchange

                        🚨New ransom group blog posts!🚨

                        Group name: nightspire
                        Post title: Cedar Crest College
                        Info: cti.fyi/groups/nightspire.html

                        Group name: nightspire
                        Post title: Auto Royal Company
                        Info: cti.fyi/groups/nightspire.html

                        Group name: nightspire
                        Post title: Webosphere
                        Info: cti.fyi/groups/nightspire.html

                        Group name: qilin
                        Post title: Stryker
                        Info: cti.fyi/groups/qilin.html

                        Group name: qilin
                        Post title: Highline Community College
                        Info: cti.fyi/groups/qilin.html

                        Group name: qilin
                        Post title: Kean University
                        Info: cti.fyi/groups/qilin.html

                        Group name: qilin
                        Post title: Ejército Argentino
                        Info: cti.fyi/groups/qilin.html

                        Group name: qilin
                        Post title: ABM Enviro
                        Info: cti.fyi/groups/qilin.html

                        Group name: qilin
                        Post title: Machinerie P&W
                        Info: cti.fyi/groups/qilin.html

                        Group name: qilin
                        Post title: WellPerf
                        Info: cti.fyi/groups/qilin.html

                        Group name: qilin
                        Post title: AppleOne Properties
                        Info: cti.fyi/groups/qilin.html

                        Group name: qilin
                        Post title: Triton Trading
                        Info: cti.fyi/groups/qilin.html

                        Group name: qilin
                        Post title: Cano Industrial
                        Info: cti.fyi/groups/qilin.html

                        Group name: qilin
                        Post title: Assos Pharmaceuticals
                        Info: cti.fyi/groups/qilin.html

                        Group name: qilin
                        Post title: Corporate 360 Business Solutions
                        Info: cti.fyi/groups/qilin.html

                        Group name: qilin
                        Post title: Sunway Berhad
                        Info: cti.fyi/groups/qilin.html

                        Group name: qilin
                        Post title: P & A Construction
                        Info: cti.fyi/groups/qilin.html

                        Group name: qilin
                        Post title: Salida Union School District
                        Info: cti.fyi/groups/qilin.html

                        Group name: qilin
                        Post title: Recsa
                        Info: cti.fyi/groups/qilin.html

                        Group name: qilin
                        Post title: Primeline Logistics
                        Info: cti.fyi/groups/qilin.html

                        Group name: qilin
                        Post title: Infina Health
                        Info: cti.fyi/groups/qilin.html

                        Group name: qilin
                        Post title: EFU Life Assurance
                        Info: cti.fyi/groups/qilin.html

                          [?]TechWire ⚡ » 🤖 🌐
                          @techwire@social.gamefan.net

                          Is the PlayStation Network down for you? Here’s what’s going on

                          Every service on the PSN is having issues.

                          androidauthority.com/playstati

                          [Android Authority]

                            [?]urlDNA.io :verified: » 🤖 🌐
                            @urldna@infosec.exchange

                            Possible Phishing 🎣
                            on: ⚠️hxxps[:]//digitalisationprofil[.]web[.]app/
                            🧬 Analysis at: urldna.io/scan/6a635b993b77500

                              [?]The New Oil » 🤖 🌐
                              @thenewoil@mastodon.thenewoil.org

                              [?]TechWire ⚡ » 🤖 🌐
                              @techwire@social.gamefan.net

                              Samsung may finally let you set screen zoom levels on a per-app basis

                              Samsung's latest foldables are hiding a big new accessibility feature.

                              androidauthority.com/samsung-p

                              [Android Authority]

                                [?]KillBait » 🤖 🌐
                                @killbait@mastodon.social

                                Data Center Outage Disrupts Regional Power Grid

                                📰 Original title: ‘Data Center Alley’ Briefly Unplugs, Rattling the Power Grid

                                🤖 IA: It's not clickbait ✅
                                👥 Users: It's not clickbait ✅

                                View full AI summary en.killbait.com/data-center-ou

                                  [?]KillBait News » 🤖 🌐
                                  @killbait@mastodon.world

                                  Data Center Outage Disrupts Regional Power Grid

                                  📰 Original title: ‘Data Center Alley’ Briefly Unplugs, Rattling the Power Grid

                                  🤖 IA: It's not clickbait ✅
                                  👥 Users: It's not clickbait ✅

                                  View full AI summary en.killbait.com/data-center-ou

                                    [?]N-gated Hacker News » 🤖 🌐
                                    @ngate@mastodon.social

                                    Ah yes, the classic tale of into Y Combinator's system by exploiting an unvalidated HMAC 🤦‍♂️. Our hero "discovered" a , and instead of a Nobel Prize in , he got a ticket to Startup School 🎓. YC's response? A polite nod and a patch, because nothing screams "startup potential" like breaking things for fun. 🚀
                                    obaid.wtf/jotbook/2026/07/18/h

                                      [?]EUVD Bot » 🤖 🌐
                                      @EUVD_Bot@mastodon.social

                                      🚨 EUVD-2026-48581

                                      📊 Score: 6.3/10 (CVSS v3.1)
                                      📦 Product: parse-server, parse-server
                                      🏢 Vendor: parse-community
                                      📅 Updated: 2026-07-24

                                      📝 Parse Server versions >= 9.0.0 before 9.10.0-alpha.5 and >= 8.2.2 before 8.6.86 return GraphQL validation error messages that name required custom input fields even when public introspection is disabled (graphQLPublicIntrospection:...

                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                        [?]EUVD Bot » 🤖 🌐
                                        @EUVD_Bot@mastodon.social

                                        🚨 EUVD-2026-48580

                                        📊 Score: 6.3/10 (CVSS v3.1)
                                        📦 Product: parse-server, parse-server
                                        🏢 Vendor: parse-community
                                        📅 Updated: 2026-07-24

                                        📝 Parse Server versions >= 9.0.0 before 9.10.0-alpha.6 and >= 8.2.2 before 8.6.87 disclose Pointer and Relation target class names through GraphQL validation and input-coercion error messages when public schema introspection is disab...

                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                          [?]TechWire ⚡ » 🤖 🌐
                                          @techwire@social.gamefan.net

                                          Whack-a-drone

                                          In Pasadena, California, there's a cute red brick courtyard where one storefront isn't like the rest. The glass doors open onto a sparse industrial hallway, which leads to a sunlit foyer with a large spiral staircase. G…

                                          theverge.com/report/969725/fcc

                                          [The Verge]

                                            [?]Negative PID SL » 🌐
                                            @negativepid@mastodon.social

                                            [?]Cyber Tips Guide » 🌐
                                            @cybertipsguide@mastodon.social

                                            Cyber intelligence should be measured by timeliness, specificity, and actionability, not volume. The FY2027 bill moves in that direction, but private-sector value will depend on execution and trust.
                                            zurl.co/t3HUj |

                                              [?]Daily CyberSecurity » 🌐
                                              @DailyCyberSecurity@infosec.exchange

                                              Apple has patched a critical Hide My Email vulnerability that exposed users' real email addresses for over a year following media reporting.

                                              meterpreter.org/apple-fixes-hi

                                                [?]TechWire ⚡ » 🤖 🌐
                                                @techwire@social.gamefan.net

                                                After OnePlus, Nothing could be the next brand to leave multiple global markets

                                                A report claims London-based Nothing faces 40% headcount cuts and market exits amid rising costs.

                                                androidauthority.com/nothing-m

                                                [Android Authority]

                                                  [?]Daily CyberSecurity » 🌐
                                                  @DailyCyberSecurity@infosec.exchange

                                                  Discover why LG Electronics is banning residential proxy SDKs from webOS smart TV apps. Learn how these hidden modules exploit your home network.

                                                  securityexpress.info/lg-bans-r

                                                    [?]Hackread.com » 🌐
                                                    @Hackread@mstdn.social

                                                    📣🚨 Russian hackers exploited a Zimbra webmail flaw triggered when emails were opened or previewed, stealing credentials and up to 90 days of messages from victims.

                                                    Listen/Read: hackread.com/russian-hackers-z

                                                      [?]IT Horror Stories Podcast » 🌐
                                                      @ithorrorstories@techhub.social

                                                      Before every episode we anonymize every story.

                                                      The lessons matter.
                                                      The names don't.

                                                      Listen here : ithorrorstories.eu/

                                                        [?]urlDNA.io :verified: » 🤖 🌐
                                                        @urldna@infosec.exchange

                                                        Possible Phishing 🎣
                                                        on: ⚠️hxxps[:]//wemailacmontpellierfristatic0110nalldomainlayoutoginsecure[.]weebly[.]com
                                                        🧬 Analysis at: urldna.io/scan/6a62cf0a3b77500

                                                          [?]The New Oil » 🤖 🌐
                                                          @thenewoil@mastodon.thenewoil.org

                                                          [?]Darses » 🌐
                                                          @darses@mastodon.nl

                                                          A Proof-of-Concept was published for Microsoft Active Directory Certificate Services Privilege Escalation vulnerability CVE-2026-54121

                                                          db.gcve.eu/vuln/cve-2026-54121

                                                            [?]Daily CyberSecurity » 🌐
                                                            @DailyCyberSecurity@infosec.exchange

                                                            The NadMesh botnet targets cloud environments. This AI infrastructure threat harvests cloud credentials and exploits open services for autonomous spreading.

                                                            securityonline.info/nadmesh-bo

                                                              [?]Hackerdogs » 🌐
                                                              @hackerdogs@mastodon.social

                                                              Critical Bing vulnerability allows attackers to execute commands as SYSTEM on Microsoft's servers through crafted SVG files.
                                                              thehackernews.com/2026/07/bing

                                                                [?]Max Iorsh » 🌐
                                                                @iorsh@kishkush.net

                                                                What is the business case of all those nice guys who offer free security audits for FontForge out of the blue? I already declined some half a dozen, but they keep coming. Is there some hidden money in there?

                                                                  [?]TechWire ⚡ » 🤖 🌐
                                                                  @techwire@social.gamefan.net

                                                                  What I track in a day

                                                                  It’s a lot of stuff, generally. | Photo: Victoria Song / The Verge This is Optimizer, a weekly newsletter sent from Verge senior reviewer Victoria Song that dissects and discusses the latest gizmos and potions that swea…

                                                                  theverge.com/column/970056/opt

                                                                  [The Verge]

                                                                    [?]Malicious Extension Bot » 🤖 🌐
                                                                    @malicious_browser_bot@infosec.exchange

                                                                    extension Crypto Price Tracker seems malicious. Its badness score is 99/100!

                                                                    ```json
                                                                    {"id": "cpklcjliccfgbjdknfkdlaadikjgdonl", "score": 99, "platform": "chrome", "name": "Crypto Price Tracker"}
                                                                    ```

                                                                      [?]Malicious Extension Bot » 🤖 🌐
                                                                      @malicious_browser_bot@infosec.exchange

                                                                      extension Trezor Portfolio Viewer seems malicious. Its badness score is 93/100!

                                                                      ```json
                                                                      {"id": "lkcanmapdochbmhmnealkkgpdidfgkld", "score": 93, "platform": "chrome", "name": "Trezor Portfolio Viewer"}
                                                                      ```

                                                                        [?]Black Cat White Hat Security » 🌐
                                                                        @BCWHQuiz@defcon.social

                                                                        Assessment Matrix: Phase I: Secure & Validate
                                                                        Enter 'The Game' a gauntlet designed to push your Cybersecurity, PowerShell, and ColdFusion skills to the breaking point.



                                                                        Link: blackcatwhitehatsecurity.com

                                                                        Assessment Matrix: Phase I: Secure & Validate
Enter 'The Game' a gauntlet designed to push your Cybersecurity, PowerShell, and ColdFusion skills to the breaking point.

                                                                        Alt...Assessment Matrix: Phase I: Secure & Validate Enter 'The Game' a gauntlet designed to push your Cybersecurity, PowerShell, and ColdFusion skills to the breaking point.

                                                                          [?]BobDaHacker 🏳️‍⚧️ [She/They] » 🌐
                                                                          @bobdahacker@infosec.exchange

                                                                          🙏 New Blog Post

                                                                          The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.

                                                                          What's exposed:

                                                                          • Email addresses
                                                                          • Names
                                                                          • Country
                                                                          • Date of birth (they call it "borned_date" lol)
                                                                          • Account role (it's "PRAYER" for everyone, obviously)

                                                                          Also found:

                                                                          • Signup endpoint returns the email verification token in the response body, so you can verify accounts without accessing the inbox
                                                                          • Their verification emails fail their own domain's authentication requirements

                                                                          Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.

                                                                          Full writeup: bobdahacker.com/blog/click-to-

                                                                            [?]TechWire ⚡ » 🤖 🌐
                                                                            @techwire@social.gamefan.net

                                                                            5 reasons I’d buy the Galaxy Z Fold 8 instead of the Fold 8 Ultra (after using both phones)

                                                                            The cheaper Galaxy Z Fold 8 is the one I'd actually buy.

                                                                            androidauthority.com/why-id-bu

                                                                            [Android Authority]

                                                                              [?]EUVD Bot » 🤖 🌐
                                                                              @EUVD_Bot@mastodon.social

                                                                              🚨 EUVD-2026-48530

                                                                              📊 Score: 9.3/10 (CVSS v3.1)
                                                                              📦 Product: Corporate Training Management System
                                                                              🏢 Vendor: SUNNET Technology Co., Ltd.
                                                                              📅 Updated: 2026-07-24

                                                                              📝 An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with adminis...

                                                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                [?]EUVD Bot » 🤖 🌐
                                                                                @EUVD_Bot@mastodon.social

                                                                                🚨 EUVD-2026-48529

                                                                                📊 Score: n/a
                                                                                📦 Product: Apache OpenNLP, Apache OpenNLP
                                                                                🏢 Vendor: Apache Software Foundation
                                                                                📅 Updated: 2026-07-24

                                                                                📝 Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Name in Apache OpenNLP

                                                                                Versions Affected:

                                                                                - before 2.5.10
                                                                                - before 3.0.0-M5

                                                                                Description:

                                                                                Three code paths in Apache OpenNLP load a class by its ful...

                                                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                  [?]EUVD Bot » 🤖 🌐
                                                                                  @EUVD_Bot@mastodon.social

                                                                                  🚨 EUVD-2026-48528

                                                                                  📊 Score: 6.1/10 (CVSS v3.1)
                                                                                  📦 Product: VikBooking Hotel Booking Engine & PMS
                                                                                  🏢 Vendor: e4jvikwp
                                                                                  📅 Updated: 2026-07-24

                                                                                  📝 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'category_id' parameter in all versions up to, and including, 1.8.13 due to insufficient input sanitization ...

                                                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                    [?]EUVD Bot » 🤖 🌐
                                                                                    @EUVD_Bot@mastodon.social

                                                                                    🚨 EUVD-2026-48527

                                                                                    📊 Score: 6.4/10 (CVSS v3.1)
                                                                                    📦 Product: Rich Showcase for Google Reviews
                                                                                    🏢 Vendor: widgetpack
                                                                                    📅 Updated: 2026-07-24

                                                                                    📝 The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pagination' Shortcode Attribute in all versions up to, and including, 6.9.9 due to insufficient input sanitization and out...

                                                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                      [?]EUVD Bot » 🤖 🌐
                                                                                      @EUVD_Bot@mastodon.social

                                                                                      🚨 EUVD-2026-48526

                                                                                      📊 Score: 6.4/10 (CVSS v3.1)
                                                                                      📦 Product: SureDash – Community, Courses & Member Dashboard
                                                                                      🏢 Vendor: brainstormforce
                                                                                      📅 Updated: 2026-07-24

                                                                                      📝 The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.10.0 due to insufficient ...

                                                                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                        [?]EUVD Bot » 🤖 🌐
                                                                                        @EUVD_Bot@mastodon.social

                                                                                        🚨 EUVD-2026-48525

                                                                                        📊 Score: 1.8/10 (CVSS v3.1)
                                                                                        📦 Product: coreutils
                                                                                        🏢 Vendor: GNU
                                                                                        📅 Updated: 2026-07-24

                                                                                        📝 GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an under...

                                                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                          [?]EUVD Bot » 🤖 🌐
                                                                                          @EUVD_Bot@mastodon.social

                                                                                          🚨 EUVD-2026-48524

                                                                                          📊 Score: 4.6/10 (CVSS v3.1)
                                                                                          📦 Product: coreutils
                                                                                          🏢 Vendor: GNU
                                                                                          📅 Updated: 2026-07-24

                                                                                          📝 GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer in...

                                                                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                            [?]EUVD Bot » 🤖 🌐
                                                                                            @EUVD_Bot@mastodon.social

                                                                                            🚨 EUVD-2026-48523

                                                                                            📊 Score: 9.8/10 (CVSS v3.1)
                                                                                            📦 Product: Eclipse BaSyx Go Components
                                                                                            🏢 Vendor: Eclipse Foundation
                                                                                            📅 Updated: 2026-07-24

                                                                                            📝 In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by inconsistent trailing-slash handling between the ABAC middleware and the HTTP route...

                                                                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                              [?]TechWire ⚡ » 🤖 🌐
                                                                                              @techwire@social.gamefan.net

                                                                                              Gemini Live could soon let you toss files into the conversation mid-chat

                                                                                              Gemini Live could stop making you describe an image and just take that damn file.

                                                                                              androidauthority.com/gemini-li

                                                                                              [Android Authority]

                                                                                                Back to top - More...