voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
🚨 EUVD-2026-43707
📊 Score: 5.4/10 (CVSS v3.1)
📦 Product: Studio 5000 Logix Designer
🏢 Vendor: Rockwell Automation
📅 Updated: 2026-07-14
📝 A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embedded in the ACD file structu...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43707
🚨 EUVD-2026-43706
📊 Score: 9.1/10 (CVSS v3.1)
📦 Product: ueberauth_apple, ueberauth_apple
🏢 Vendor: ueberauth
📅 Updated: 2026-07-14
📝 Authentication Bypass by Spoofing vulnerability in ueberauth ueberauth_apple allows account takeover via unvalidated ID token claims.
The Ueberauth.Strategy.Apple.Token.payload/2 function verifies the JWT signature of the callback...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43706
🚨 EUVD-2026-43705
📊 Score: 2.6/10 (CVSS v3.1)
📦 Product: easyappointments
🏢 Vendor: alextselegidis
📅 Updated: 2026-07-14
📝 Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 allow administrators to define a custom "booking disabled" message through the booking settings page. That value is stored in the `disable_booking_message` sett...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43705
🚨 EUVD-2026-43704
📊 Score: 7.2/10 (CVSS v3.1)
📦 Product: FactoryTalk ThinManager
🏢 Vendor: Rockwell Automation
📅 Updated: 2026-07-14
📝 A path traversal security issue exists within Rockwell Automation ThinManager® software due to improper limitation of file save operations within the API. An authenticated attacker could exploit this vulnerability to write arbitra...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43704
🚨 EUVD-2026-43692
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: easyappointments
🏢 Vendor: alextselegidis
📅 Updated: 2026-07-14
📝 Easy!Appointments is a self hosted appointment scheduler. In versions up to and including 1.5.2, the booking reschedule view at `/index.php/booking/reschedule/{appointment_hash}` (handled by `Booking::index()`) embeds the entire customer reco...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43692
🚨 EUVD-2026-43703
📊 Score: 5.9/10 (CVSS v3.1)
📦 Product: FortiPAM, FortiPAM, FortiSASE (+13 more)
🏢 Vendor: Fortinet
📅 Updated: 2026-07-14
📝 A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, Fo...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43703
🚨 EUVD-2026-43702
📊 Score: 8.4/10 (CVSS v3.1)
📦 Product: FactoryTalk® DataMosaix™ Private Cloud
🏢 Vendor: Rockwell Automation
📅 Updated: 2026-07-14
📝 A Stored Cross-Site Scripting security issue exists within FactoryTalk® DataMosaix™ Private Cloud. The vulnerability stems from improper neutralization of user-supplied input within the Workflows configuration. An a...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43702
🚨 EUVD-2025-210463
📊 Score: 9.2/10 (CVSS v3.1)
📦 Product: CompactLogix® 5380 Recovery Image Compact GuardLogix® 5380 Recovery Image CompactLogix® 5480 Recovery Image ControlLogix® 5580 Recovery Image GuardLogix® 5580 Recovery Image
🏢 Vendor: Rockwell Automation
📅 Updated: 2026-07-14
📝 A denial-of-service issue exists in 5380/5480/5580 control...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-210463
🚨 EUVD-2026-43688
📊 Score: 8.8/10 (CVSS v3.1)
📦 Product: SIP
🏢 Vendor: Dan-in-CA
📅 Updated: 2026-07-14
📝 Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a mass assignment vulnerability that allows unauthenticated attackers to overwrite sensitive configuration settings by supplying arbitrary parameter names in HTTP requests. Attackers can man...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43688
🚨 EUVD-2026-43689
📊 Score: 6.3/10 (CVSS v3.1)
📦 Product: SIP
🏢 Vendor: Dan-in-CA
📅 Updated: 2026-07-14
📝 Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated attackers to make the device issue arbitrary HTTP requests by supplying a malicious callback URL when the optio...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43689
🚨 EUVD-2026-43686
📊 Score: 8.7/10 (CVSS v3.1)
📦 Product: BE12 Pro
🏢 Vendor: Tenda
📅 Updated: 2026-07-14
📝 A flaw has been found in Tenda BE12 Pro 16.03.66.23. The affected element is the function fromDhcpListClient of the file /goform/DhcpListClient. This manipulation of the argument page causes stack-based buffer overflow. The attack can be initiated remotely. T...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43686
Possible Phishing 🎣
on: ⚠️hxxps[:]//lamail7[.]godaddysites[.]com/
🧬 Analysis at: https://urldna.io/scan/6a55a6423b775000029fdfc0
#cybersecurity #phishing #infosec #urldna #scam #infosec
Every endpoint has a purpose. A login page, an API endpoint, and a contact form all require different security considerations. AIWAF uses AST analysis to understand application context before making security decisions, reducing assumptions and improving automation.
#AppSec #CyberSecurity #OpenSource #Python #AST #DeveloperTools
Lucide Proxy: Turning Student Web Proxies into DDoS Bots
A sophisticated campaign deployed 148 malicious npm packages disguised as student web proxy applications under brands like Riverbend Tutoring and Northstar Tutoring. Published by accounts terminal3airport and eerikakirk, these packages weaponized visitor browsers into distributed denial-of-service botnets while generating advertising revenue. The applications functioned as working proxies but secretly executed mutable remote code and high-performance WebSocket traffic generators compatible with the Wisp protocol. During a critical two-week period in May 2026, active deployments launched HTTP floods generating 2GB/s aggregate traffic and control-plane attacks establishing 10,240 socket connections per second against target servers. The campaign abused npm as a content delivery network, affecting users who visited proxy instances rather than through traditional dependency infection.
Pulse ID: 6a5660720f790923b2946df9
Pulse Link: https://otx.alienvault.com/pulse/6a5660720f790923b2946df9
Pulse Author: AlienVault
Created: 2026-07-14 16:14:42
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #DDoS #DoS #HTTP #InfoSec #NPM #OTX #OpenThreatExchange #Proxy #RAT #TorBrowser #bot #botnet #AlienVault
Progress Orders ShareFile Shutdown: Third Critical Incident in Three Years https://deafnews.it/en/article/progress-orders-sharefile-shutdown-third-critical-incident-in-three-years #Cybersecurity
It was nice while it lasted: Samsung reportedly ending free storage upgrades
Samsung may drop its free storage upgrades and the RAM and storage crisis is to blame.
https://www.androidauthority.com/samsung-ending-free-storage-upgrade-offer-3687401/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
🚨 Progress just confirmed a ShareFile Zero-Day.
After ordering customers to **shut down internet-facing Storage Zone Controllers**, Progress has now revealed the cause: a high-severity path traversal vulnerability affecting all 5.x and 6.x versions.
⚠️ If you're running ShareFile Storage Zone Controllers:
✅ Update to **v5.12.5 or v6.0.2
✅ Review admin activity & logs
✅ Bring servers online only after patching
Enterprise file transfer platforms continue to be prime targets after MOVEit. Don't wait to patch.
🔗 Read the full breakdown:
https://thecybersecguru.com/news/progress-sharefile-storage-zone-controller-0-day/
#CyberSecurity #ZeroDay #ShareFile #ProgressSoftware #Vulnerability #ThreatIntelligence #InfoSec #BlueTeam #SOC #SysAdmin #WindowsServer #SecurityNews #CyberThreats #PatchNow #DataSecurity
☕ #Cybersecurity #Ciberseguridad #Ciberseguranca #Security #Seguridad #Seguranca #News #Noticia #Noticias #Tecnologia #Technology
🟣 Así es como Apple está actualizando sus funciones de seguridad infantil en iOS 27
🔗 https://es.wired.com/articulos/asi-es-como-apple-esta-actualizando-sus-funciones-de-seguridad-infantil-en-ios-27
Apple ha anunciado varias funciones nuevas de seguridad infantil que estarán disponibles próximamente en los iPhone y otros dispositivos con iOS 27. Esto es lo que
Spotify is putting a conversational chatbot right inside its app
The new "Talk to Spotify" feature lets Premium subscribers type or speak to control audio and analyze listening habits.
https://www.androidauthority.com/talk-to-spotify-conversational-ai-beta-3687332/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Scam victimology: why did they pick me? #negativepid #digitalInvestigations #OSINT #cybersecurity #AI #tech #onlineInvestigations #robotics #cyberpsychology #cybercrime https://negativepid.blog/scam-victimology-why-did-they-pick-me/?utm_source=mastodon&utm_medium=social&utm_campaign=fedica-Negative-PID-Blog
NicFab Newsletter #29 is out — Privacy, Data Protection, AI, Cybersecurity & Tech Law.
This week: Garante fines Character.AI €158k; EDPB guidelines on anonymisation and web scraping for GenAI; the EP shields end-to-end encryption; the CJEU on the journalistic exemption; Apple stays a gatekeeper — plus my new book "Agentic AI".
EN: https://www.nicfab.eu/en/newsletter-issues/2026-07-14-issue-29/
IT: https://www.nicfab.eu/it/newsletter-issues/2026-07-14-issue-29/
🚨 EUVD-2026-43669
📊 Score: 7.0/10 (CVSS v3.1)
📦 Product: Arena® Simulation
🏢 Vendor: Rockwell Auotmation
📅 Updated: 2026-07-14
📝 A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the expmt.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds w...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43669
🚨 EUVD-2026-43670
📊 Score: 6.0/10 (CVSS v3.1)
📦 Product: Trellix HX Console
🏢 Vendor: Trellix
📅 Updated: 2026-07-14
📝 An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger decompression of a large file that consumes an excessive amount of system resources thus ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43670
Possible Phishing 🎣
on: ⚠️hxxps[:]//bit[.]ly/3YhRZeM
🧬 Analysis at: https://urldna.io/scan/6a5624ea3b775000029fef09
#cybersecurity #phishing #infosec #urldna #scam #infosec
🚨 EUVD-2026-43671
📊 Score: 6.3/10 (CVSS v3.1)
📦 Product: TYPO3 CMS
🏢 Vendor: TYPO3
📅 Updated: 2026-07-14
📝 Users were able to upload files with arbitrary MIME types to forms using FileUpload or ImageUpload elements with allowedMimeTypes configured. The restriction was not enforced server-side because the MimeTypeValidator was registered during form building befor...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43671
🚨 EUVD-2026-43672
📊 Score: 7.0/10 (CVSS v3.1)
📦 Product: Arena® Simulation
🏢 Vendor: Rockwell Automation
📅 Updated: 2026-07-14
📝 A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the linker.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43672
🚨 EUVD-2026-43673
📊 Score: 7.0/10 (CVSS v3.1)
📦 Product: Arena® Simulation
🏢 Vendor: Rockwell Automation
📅 Updated: 2026-07-14
📝 A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the siman.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds w...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43673
🚨 EUVD-2026-43674
📊 Score: 8.5/10 (CVSS v3.1)
📦 Product: Secure Access Client for Windows, Citrix Endpoint Analysis Client for Windows
🏢 Vendor: Citrix
📅 Updated: 2026-07-14
📝 Improper Privilege Management vulnerability in Citrix Secure Access Client for Windows, Citrix Citrix Endpoint Analysis Client for Windows.
This issue affects Secure Access Client for Wind...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43674
🚨 EUVD-2026-43675
📊 Score: 10.0/10 (CVSS v3.1)
📦 Product: 1715 EtherNet/IP Communications Module
🏢 Vendor: Rockwell Auotmation
📅 Updated: 2026-07-14
📝 A security issue exists within the 1715-AENTR EtherNet/IP Adapter. The affected product exposes a network-accessible debug port that does not enforce proper privilege controls, allowing unauthenticated remote acces...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43675
🚨 EUVD-2026-43677
📊 Score: 8.7/10 (CVSS v3.1)
📦 Product: BE12 Pro
🏢 Vendor: Tenda
📅 Updated: 2026-07-14
📝 A security vulnerability has been detected in Tenda BE12 Pro 16.03.66.23. This issue affects the function fromSafeMacFilter of the file /goform/SafeMacFilter. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to initia...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43677
🚨 EUVD-2026-43676
📊 Score: 6.8/10 (CVSS v3.1)
📦 Product: Citrix Secure Access client for Windows
🏢 Vendor: Citrix
📅 Updated: 2026-07-14
📝 Out-of-bounds read vulnerability in Citrix Citrix Secure Access Client for Windows.
This issue affects Citrix Secure Access Client for Windows: before 26.6.1.20.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43676
🚨 EUVD-2026-43668
📊 Score: 7.0/10 (CVSS v3.1)
📦 Product: Arena® Simulation
🏢 Vendor: Rockwell Automation
📅 Updated: 2026-07-14
📝 A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds w...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43668
Russia continues to attack critical EU infrastructure. Sectors affected are, for example, defence, energy or healthcare.
A joint cybersecurity advisory of about 20 cybersecurity agencies urges providers of critical infrastructure to update their SNMP configurations and to harden Cisco devices if they are in operation.
Link to the advisory: https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF
🖲️ #Cybersecurity #Ciberseguridad #Ciberseguranca #Security #Seguridad #Seguranca #News #Noticia #Noticias #Tecnologia #Technology
⚫ GigaWiper Lets Threat Actors Choose Their Own Destructive Attack
🔗 https://www.darkreading.com/cyberattacks-data-breaches/gigawiper-threat-actors-choose-their-own-destructive-attack
A modular implant borrows from various malware families to combine both backdoor and wiper activities to maximize impact and minimize operational output.
Lucide Proxy: Turning Student Web Proxies into DDoS Bots - JFrog Security Research
Pulse ID: 6a564e9f244614e57f27b22a
Pulse Link: https://otx.alienvault.com/pulse/6a564e9f244614e57f27b22a
Pulse Author: CyberHunter_NL
Created: 2026-07-14 14:58:39
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DDoS #DoS #InfoSec #OTX #OpenThreatExchange #Proxy #bot #CyberHunter_NL
Microsoft Revokes 11 Legacy UEFI Shims: Secure Boot Bypassed via Signed Bootloaders https://deafnews.it/en/article/microsoft-revokes-11-legacy-uefi-shims-secure-boot-bypassed-via-signed-bootloaders #Cybersecurity
Samsung’s entire Galaxy Unpacked lineup just leaked
Huge Samsung leak just spoiled the next Galaxy Unpacked.
https://www.androidauthority.com/galaxy-unpacked-line-up-revealed-in-full-3687308/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
CrashStealer: C++ macOS Infostealer Posing as Crash Reporter
A newly discovered macOS infostealer, implemented in native C++, impersonates Apple's crash-reporting framework to harvest sensitive data. The malware is distributed through a signed and notarized dropper application that bypasses Gatekeeper, then downloads and installs the payload from attacker infrastructure. The stealer validates victim passwords locally using dscl, unlocks the login keychain, and collects browser credentials, cryptocurrency wallet extensions, password manager data, and keychain material. Collected data is encrypted using AES-GCM before being packaged into hidden ZIP archives and exfiltrated to a command-and-control server. The malware establishes persistence by copying itself to a hidden directory and installing a LaunchAgent. It employs control-flow flattening, encrypted strings, and anti-debugging techniques to resist analysis. The campaign uses GitHub for initial staging and multiple fake collaboration software domains as lures.
Pulse ID: 6a55ec60c2d64907df771c4c
Pulse Link: https://otx.alienvault.com/pulse/6a55ec60c2d64907df771c4c
Pulse Author: AlienVault
Created: 2026-07-14 07:59:28
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #ELF #GitHub #InfoSec #InfoStealer #Mac #MacOS #Malware #OTX #OpenThreatExchange #Password #Passwords #RAT #Word #ZIP #bot #cryptocurrency #AlienVault
🚨 EUVD-2026-43652
📊 Score: 5.2/10 (CVSS v3.1)
📦 Product: Checkmk, Checkmk, Checkmk (+1 more)
🏢 Vendor: Checkmk GmbH
📅 Updated: 2026-07-14
📝 Privilege escalation in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows a local unprivileged user to execute arbitrary commands as root by starting a process crafted...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43652
🚨 EUVD-2026-43651
📊 Score: 4.8/10 (CVSS v3.1)
📅 Updated: 2026-07-14
📝 The fix for CVE-2026-0716 (commit 6ff7ef0, libsoup 3.6.6) placed the integer overflow guard inside the if (masked) block, leaving unmasked server-to-client frames unprotected. A malicious WebSocket server can send a crafted unmasked frame with a payload length near UINT64_MAX to trigger an OOB ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43651