voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
📰 New 'Orexin' Ransomware Strain Discovered with Anti-Recovery Tactics
A new ransomware strain named 'Orexin' has been discovered by CYFIRMA. The malware uses Themida packer for evasion, deletes shadow copies to prevent recovery, and spreads to network shares. #Ransomware #Malware #CyberSecurity #Orexin
🌐 cyber[.]netsecops[.]io
📰 Russian APT 'Laundry Bear' Targets West with Zero-Click Zimbra Exploit
International advisory warns of Russian APT 'Laundry Bear' using a zero-click Zimbra exploit (CVE-2025-66376) in a widespread espionage campaign against Western targets. Actors steal emails & credentials. #ThreatIntel #Zimbra #CyberSecurity
🌐 cyber[.]netsecops[.]io
📰 Check Point Patches Actively Exploited SmartConsole Auth Bypass Flaw
🚨 CRITICAL PATCH: Check Point fixes an actively exploited auth bypass zero-day (CVE-2026-16232, CVSS 9.3) in SmartConsole. Flaw allows full admin access. CISA added to KEV. Patch NOW. #CyberSecurity #ZeroDay #CheckPoint #Infosec
🌐 cyber[.]netsecops[.]io
The BOOX Picco could be the tiny e-reader of your dreams
It's got a 3.97" display and expandable storage.
https://www.androidauthority.com/onyx-boox-picco-3691216/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
🟠 CVE-2026-66032 - High (8.8)
libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a serv...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66032/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Possible Phishing 🎣
on: ⚠️hxxps[:]//t[.]co/ClhH1ENrLL
🧬 Analysis at: https://urldna.io/scan/6a6369923b77500004f591be
#cybersecurity #phishing #infosec #urldna #scam #infosec
🟠 CVE-2026-66033 - High (7.5)
libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AE...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66033/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-66034 - High (7.5)
libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsy...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66034/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🚨 EUVD-2026-46793
📊 Score: 9.8/10 (CVSS v3.1)
📦 Product: Service Delivery Platform, Service Delivery Platform
🏢 Vendor: Oracle Corporation
📅 Published: 2026-07-21 | Updated: 2026-07-24
📝 Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1....
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46793
The BSides Edmonton committee sincerely thank Arctic Wolf Networks Inc. https://arcticwolf.com/ for being a Gold Sponsor of Bsides Edmonton 2026. Your support directly fueled an amazing lineup of speakers, hands-on workshops, and invaluable networking sessions.
Be sure to visit them at our 9th annual event September 24–25, 2026.
If your company wants to be part of this year’s community-driven security event, Visit https://bsidesyeg.org/SponsorApplication
Nothing rejects market exit rumors, insists global operations remain active
Nothing is firing back at a report alleging its existing 12 markets.
https://www.androidauthority.com/nothing-denies-market-exit-3691221/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
🚨New ransom group blog posts!🚨
Group name: nightspire
Post title: Cedar Crest College
Info: https://cti.fyi/groups/nightspire.html
Group name: nightspire
Post title: Auto Royal Company
Info: https://cti.fyi/groups/nightspire.html
Group name: nightspire
Post title: Webosphere
Info: https://cti.fyi/groups/nightspire.html
Group name: qilin
Post title: Stryker
Info: https://cti.fyi/groups/qilin.html
Group name: qilin
Post title: Highline Community College
Info: https://cti.fyi/groups/qilin.html
Group name: qilin
Post title: Kean University
Info: https://cti.fyi/groups/qilin.html
Group name: qilin
Post title: Ejército Argentino
Info: https://cti.fyi/groups/qilin.html
Group name: qilin
Post title: ABM Enviro
Info: https://cti.fyi/groups/qilin.html
Group name: qilin
Post title: Machinerie P&W
Info: https://cti.fyi/groups/qilin.html
Group name: qilin
Post title: WellPerf
Info: https://cti.fyi/groups/qilin.html
Group name: qilin
Post title: AppleOne Properties
Info: https://cti.fyi/groups/qilin.html
Group name: qilin
Post title: Triton Trading
Info: https://cti.fyi/groups/qilin.html
Group name: qilin
Post title: Cano Industrial
Info: https://cti.fyi/groups/qilin.html
Group name: qilin
Post title: Assos Pharmaceuticals
Info: https://cti.fyi/groups/qilin.html
Group name: qilin
Post title: Corporate 360 Business Solutions
Info: https://cti.fyi/groups/qilin.html
Group name: qilin
Post title: Sunway Berhad
Info: https://cti.fyi/groups/qilin.html
Group name: qilin
Post title: P & A Construction
Info: https://cti.fyi/groups/qilin.html
Group name: qilin
Post title: Salida Union School District
Info: https://cti.fyi/groups/qilin.html
Group name: qilin
Post title: Recsa
Info: https://cti.fyi/groups/qilin.html
Group name: qilin
Post title: Primeline Logistics
Info: https://cti.fyi/groups/qilin.html
Group name: qilin
Post title: Infina Health
Info: https://cti.fyi/groups/qilin.html
Group name: qilin
Post title: EFU Life Assurance
Info: https://cti.fyi/groups/qilin.html
#ransomware #cti #threatintelligence #cybersecurity #infosec
Is the PlayStation Network down for you? Here’s what’s going on
Every service on the PSN is having issues.
https://www.androidauthority.com/playstation-network-july-24-outage-3691238/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Possible Phishing 🎣
on: ⚠️hxxps[:]//digitalisationprofil[.]web[.]app/
🧬 Analysis at: https://urldna.io/scan/6a635b993b775000051b3b8b
#cybersecurity #phishing #infosec #urldna #scam #infosec
Samsung may finally let you set screen zoom levels on a per-app basis
Samsung's latest foldables are hiding a big new accessibility feature.
https://www.androidauthority.com/samsung-per-app-zoom-3691219/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Data Center Outage Disrupts Regional Power Grid
📰 Original title: ‘Data Center Alley’ Briefly Unplugs, Rattling the Power Grid
🤖 IA: It's not clickbait ✅
👥 Users: It's not clickbait ✅
View full AI summary https://en.killbait.com/data-center-outage-disrupts-regional-power-grid.html?utm_source=mastodon_social&utm_medium=social&utm_campaign=killbait.mastodon_social
Data Center Outage Disrupts Regional Power Grid
📰 Original title: ‘Data Center Alley’ Briefly Unplugs, Rattling the Power Grid
🤖 IA: It's not clickbait ✅
👥 Users: It's not clickbait ✅
View full AI summary https://en.killbait.com/data-center-outage-disrupts-regional-power-grid.html?utm_source=mastodon_world&utm_medium=social&utm_campaign=killbait.mastodon_world
Ah yes, the classic tale of #hacking into Y Combinator's system by exploiting an unvalidated HMAC 🤦♂️. Our hero "discovered" a #vulnerability, and instead of a Nobel Prize in #cybersecurity, he got a ticket to Startup School 🎓. YC's response? A polite nod and a patch, because nothing screams "startup potential" like breaking things for fun. 🚀
https://obaid.wtf/jotbook/2026/07/18/how-i-got-into-yc-by-hacking-it.html #YCombinator #StartupSchool #techhumor #exploits #HackerNews #ngated
🚨 EUVD-2026-48581
📊 Score: 6.3/10 (CVSS v3.1)
📦 Product: parse-server, parse-server
🏢 Vendor: parse-community
📅 Updated: 2026-07-24
📝 Parse Server versions >= 9.0.0 before 9.10.0-alpha.5 and >= 8.2.2 before 8.6.86 return GraphQL validation error messages that name required custom input fields even when public introspection is disabled (graphQLPublicIntrospection:...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-48581
🚨 EUVD-2026-48580
📊 Score: 6.3/10 (CVSS v3.1)
📦 Product: parse-server, parse-server
🏢 Vendor: parse-community
📅 Updated: 2026-07-24
📝 Parse Server versions >= 9.0.0 before 9.10.0-alpha.6 and >= 8.2.2 before 8.6.87 disclose Pointer and Relation target class names through GraphQL validation and input-coercion error messages when public schema introspection is disab...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-48580
Whack-a-drone
In Pasadena, California, there's a cute red brick courtyard where one storefront isn't like the rest. The glass doors open onto a sparse industrial hallway, which leads to a sunlit foyer with a large spiral staircase. G…
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Cyber intelligence should be measured by timeliness, specificity, and actionability, not volume. The FY2027 bill moves in that direction, but private-sector value will depend on execution and trust.
https://zurl.co/t3HUj | #Cybersecurity #ThreatIntel
Apple has patched a critical Hide My Email vulnerability that exposed users' real email addresses for over a year following media reporting.
After OnePlus, Nothing could be the next brand to leave multiple global markets
A report claims London-based Nothing faces 40% headcount cuts and market exits amid rising costs.
https://www.androidauthority.com/nothing-market-exits-layoffs-rumor-3691156/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Discover why LG Electronics is banning residential proxy SDKs from webOS smart TV apps. Learn how these hidden modules exploit your home network.
#LGwebOS #ResidentialProxy #SmartTVSecurity #Cybersecurity #DataPrivacy
📣🚨 Russian hackers exploited a Zimbra webmail flaw triggered when emails were opened or previewed, stealing credentials and up to 90 days of messages from victims.
Listen/Read: https://hackread.com/russian-hackers-zimbra-0-day-steal-emails-link-clicks/
Before every episode we anonymize every story.
The lessons matter.
The names don't.
Listen here : https://www.ithorrorstories.eu/
Possible Phishing 🎣
on: ⚠️hxxps[:]//wemailacmontpellierfristatic0110nalldomainlayoutoginsecure[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a62cf0a3b775000051b2b18
#cybersecurity #phishing #infosec #urldna #scam #infosec
A Proof-of-Concept was published for Microsoft Active Directory Certificate Services Privilege Escalation vulnerability CVE-2026-54121
The NadMesh botnet targets cloud environments. This AI infrastructure threat harvests cloud credentials and exploits open services for autonomous spreading.
#NadMeshBotnet #CyberSecurity #Malware #AIThreat
http://securityonline.info/nadmesh-botnet-ai-threat/?utm_source=mastodon&utm_medium=jetpack_social
Critical Bing vulnerability allows attackers to execute commands as SYSTEM on Microsoft's servers through crafted SVG files.
https://thehackernews.com/2026/07/bing-images-flaws-let-crafted-svgs-run.html
#cybersecurity #vulnerability #bing
What is the business case of all those nice guys who offer free security audits for FontForge out of the blue? I already declined some half a dozen, but they keep coming. Is there some hidden money in there?
What I track in a day
It’s a lot of stuff, generally. | Photo: Victoria Song / The Verge This is Optimizer, a weekly newsletter sent from Verge senior reviewer Victoria Song that dissects and discusses the latest gizmos and potions that swea…
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
#chrome extension Crypto Price Tracker seems malicious. Its #cybersecurity badness score is 99/100!
```json
{"id": "cpklcjliccfgbjdknfkdlaadikjgdonl", "score": 99, "platform": "chrome", "name": "Crypto Price Tracker"}
```
#chrome extension Trezor Portfolio Viewer seems malicious. Its #cybersecurity badness score is 93/100!
```json
{"id": "lkcanmapdochbmhmnealkkgpdidfgkld", "score": 93, "platform": "chrome", "name": "Trezor Portfolio Viewer"}
```
Assessment Matrix: Phase I: Secure & Validate
Enter 'The Game' a gauntlet designed to push your Cybersecurity, PowerShell, and ColdFusion skills to the breaking point.
#cybersecurity #governance #risk #technology #gaming #programming #ai #business #engineering
Link: https://blackcatwhitehatsecurity.com
🙏 New Blog Post
The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.
What's exposed:
Also found:
Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.
Full writeup: https://bobdahacker.com/blog/click-to-pray
#InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Security #CyberSecurity #Privacy #DataExposure #ClickToPray #Vatican #APISecurity
5 reasons I’d buy the Galaxy Z Fold 8 instead of the Fold 8 Ultra (after using both phones)
The cheaper Galaxy Z Fold 8 is the one I'd actually buy.
https://www.androidauthority.com/why-id-buy-galaxy-z-fold-8-instead-of-fold-8-ultra-3690261/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
🚨 EUVD-2026-48530
📊 Score: 9.3/10 (CVSS v3.1)
📦 Product: Corporate Training Management System
🏢 Vendor: SUNNET Technology Co., Ltd.
📅 Updated: 2026-07-24
📝 An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with adminis...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-48530
🚨 EUVD-2026-48529
📊 Score: n/a
📦 Product: Apache OpenNLP, Apache OpenNLP
🏢 Vendor: Apache Software Foundation
📅 Updated: 2026-07-24
📝 Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Name in Apache OpenNLP
Versions Affected:
- before 2.5.10
- before 3.0.0-M5
Description:
Three code paths in Apache OpenNLP load a class by its ful...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-48529
🚨 EUVD-2026-48528
📊 Score: 6.1/10 (CVSS v3.1)
📦 Product: VikBooking Hotel Booking Engine & PMS
🏢 Vendor: e4jvikwp
📅 Updated: 2026-07-24
📝 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'category_id' parameter in all versions up to, and including, 1.8.13 due to insufficient input sanitization ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-48528
🚨 EUVD-2026-48527
📊 Score: 6.4/10 (CVSS v3.1)
📦 Product: Rich Showcase for Google Reviews
🏢 Vendor: widgetpack
📅 Updated: 2026-07-24
📝 The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pagination' Shortcode Attribute in all versions up to, and including, 6.9.9 due to insufficient input sanitization and out...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-48527
🚨 EUVD-2026-48526
📊 Score: 6.4/10 (CVSS v3.1)
📦 Product: SureDash – Community, Courses & Member Dashboard
🏢 Vendor: brainstormforce
📅 Updated: 2026-07-24
📝 The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.10.0 due to insufficient ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-48526
🚨 EUVD-2026-48525
📊 Score: 1.8/10 (CVSS v3.1)
📦 Product: coreutils
🏢 Vendor: GNU
📅 Updated: 2026-07-24
📝 GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an under...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-48525
🚨 EUVD-2026-48524
📊 Score: 4.6/10 (CVSS v3.1)
📦 Product: coreutils
🏢 Vendor: GNU
📅 Updated: 2026-07-24
📝 GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer in...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-48524
🚨 EUVD-2026-48523
📊 Score: 9.8/10 (CVSS v3.1)
📦 Product: Eclipse BaSyx Go Components
🏢 Vendor: Eclipse Foundation
📅 Updated: 2026-07-24
📝 In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by inconsistent trailing-slash handling between the ABAC middleware and the HTTP route...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-48523
Gemini Live could soon let you toss files into the conversation mid-chat
Gemini Live could stop making you describe an image and just take that damn file.
https://www.androidauthority.com/gemini-live-files-google-drive-attachment-3691025/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]