voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
🚨 EUVD-2026-43650
📊 Score: 10.0/10 (CVSS v3.1)
📦 Product: Opcenter X
🏢 Vendor: Siemens
📅 Updated: 2026-07-14
📝 A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header.
This could allow an unauthenticated remote attacker to forge arbitrary J...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43650
🚨 EUVD-2026-43649
📊 Score: 6.0/10 (CVSS v3.1)
📦 Product: SIMATIC S7-PLCSIM Advanced
🏢 Vendor: Siemens
📅 Updated: 2026-07-14
📝 A vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All versions). Affected devices do not properly handle high-volume multicast network traffic, which can exhaust available memory resources in the affected application. This...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43649
🚨 EUVD-2025-210460
📊 Score: 8.5/10 (CVSS v3.1)
📦 Product: COMOS V10.6, Designcenter NX, Simcenter Femap V2506 (+13 more)
🏢 Vendor: Siemens
📅 Updated: 2026-07-14
📝 A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.0.2), COMOS V10.6 (All versions < V10.6.1), Designcenter NX (All versions < V2512.7000), Simcenter 3D (All versions < V2512....
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-210460
🚨 EUVD-2024-55651
📊 Score: 7.5/10 (CVSS v3.1)
📦 Product: Eclipse Jetty, Eclipse Jetty
🏢 Vendor: Eclipse Foundation
📅 Updated: 2026-07-14
📝 For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak.
This is particularly the case for 100-Continue, but any request where the network is slow can leak.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-55651
🚨 EUVD-2026-43647
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Eclipse Jetty, Eclipse Jetty
🏢 Vendor: Eclipse Foundation
📅 Updated: 2026-07-14
📝 In Eclipse Jetty, an HTTP URI of this form:
/public;/../admin/secret.txt
results in an unresolved path of:
/public/../admin/secret.txt
instead of the expected:
/admin/secret.txt
Jetty its...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43647
🚨 EUVD-2026-43646
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Eclipse Jetty, Eclipse Jetty, Eclipse Jetty (+2 more)
🏢 Vendor: Eclipse Foundation
📅 Updated: 2026-07-14
📝 In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and port) matches what provided in the Host header (if present).
This was not enf...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43646
🚨 EUVD-2026-43645
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: Eclipse Jetty, Eclipse Jetty
🏢 Vendor: Eclipse Foundation
📅 Updated: 2026-07-14
📝 In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests performed over the same connection.
Subsequent request that do not have trailers report the trailers of t...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43645
🚨 EUVD-2026-43644
📊 Score: 9.2/10 (CVSS v3.1)
📦 Product: Snowflake Spark Connector
🏢 Vendor: Snowflake
📅 Updated: 2026-07-14
📝 Multiple input validation vulnerabilities in the Snowflake Spark Connector (spark-snowflake) versions prior to 3.2.1 can allow attackers to exfiltrate OAuth client credentials, execute arbitrary SQL with the connector's Snowflake role, or...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43644
🚨 EUVD-2026-43643
📊 Score: 6.3/10 (CVSS v3.1)
📦 Product: Mint, Mint
🏢 Vendor: elixir-mint
📅 Updated: 2026-07-14
📝 Allocation of resources without limits vulnerability in elixir-mint mint allows a remote HTTP/2 server to exhaust memory on the client host and cause a denial of service.
The Mint.HTTP2.handle_continuation/3 function in lib/mint/http2.ex accumulates ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43643
🚨 EUVD-2026-43642
📊 Score: 8.2/10 (CVSS v3.1)
📦 Product: Mint, Mint
🏢 Vendor: elixir-mint
📅 Updated: 2026-07-14
📝 Allocation of resources without limits vulnerability in elixir-mint mint allows a remote HTTP server to exhaust memory on the client host and cause a denial of service.
The Mint.HTTP1.decode_headers/5 and Mint.HTTP1.decode_trailer_headers/4 functions...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43642
#chrome extension Venice AI to PDF: Export Venice AI Chats to PDF, Markdown, JSON seems malicious. Its #cybersecurity badness score is 96/100!
```json
{"id": "dpeabmlbmhjbokfijjcpcebgkgkjknkm", "score": 96, "platform": "chrome", "name": "Venice AI to PDF: Export Venice AI Chats to PDF, Markdown, JSON"}
```
🚨 EUVD-2026-43641
📊 Score: 6.3/10 (CVSS v3.1)
📦 Product: Eclipse GlassFish, Eclipse GlassFish
🏢 Vendor: Eclipse Foundation
📅 Updated: 2026-07-14
📝 Eclipse Grizzly in versions before 5.0.2, cannot properly parse the trailer section in malformed trailer header's line, which can be leveraged to perform HTTP request smuggling.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43641
🚨 EUVD-2026-43640
📊 Score: n/a
📦 Product: Apache Tomcat, Apache Tomcat, Apache Tomcat (+2 more)
🏢 Vendor: Apache Software Foundation
📅 Updated: 2026-07-14
📝 Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented.
This issue affects Apache Tomcat: from 11....
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43640
#chrome extension Google AI Studio to PDF: Export Google AI Studio Chats to PDF, Markdown, J seems malicious. Its #cybersecurity badness score is 87/100!
```json
{"id": "lhgbhgflgoedbhlfbghcikonigcgiibo", "score": 87, "platform": "chrome", "name": "Google AI Studio to PDF: Export Google AI Studio Chats to PDF, Markdown, J"}
```
#chrome extension Anime Girl Night Thunder City Lights Live Wallpaper seems malicious. Its #cybersecurity badness score is 86/100!
```json
{"id": "ojhigfemmjpjnmhidflhdlcahgdiiija", "score": 86, "platform": "chrome", "name": "Anime Girl Night Thunder City Lights Live Wallpaper"}
```
#chrome extension Free Fire seems malicious. Its #cybersecurity badness score is 95/100!
```json
{"id": "fmgnpannkbkfpejjdkeoekpjfhpmnhfn", "score": 95, "platform": "chrome", "name": "Free Fire"}
```
TriWest Healthcare Alliance Reports Data Breach Affecting 11,844 Military Beneficiaries
TriWest Healthcare Alliance reports a security breach where an unauthorized actor accessed and downloaded the personal health information of 11,844 military beneficiaries. The company has implemented new security controls and is offering credit monitoring services to the affected individuals.
****
#cybersecurity #infosec #incident #databreach
https://beyondmachines.net/event_details/triwest-healthcare-alliance-reports-data-breach-affecting-11844-military-beneficiaries-m-1-f-d-0/gD2P6Ple2L
Gemini in Chrome is expanding to even more desktop users
Chrome's helpful Gemini integration finally makes its way across the pond.
https://www.androidauthority.com/gemini-chrome-ask-gemini-desktop-expansion-3687239/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
🟠 CVE-2026-44745 - High (8.1)
SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could lead to un...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44745/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🔴 CVE-2026-44747 - Critical (9.9)
SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability. This has high ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44747/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-44752 - High (8.2)
SAP NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScript through crafted URLs. When a victim accesses such a URL, the script executes in the user's browser, allowing the attacker to access sensitive s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44752/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
iOS 27 and iPadOS 27 Now Available to Public Beta Testers
Apple today released the first public betas of iOS 27 and iPadOS 27, allowing anyone with a compatible device to download and test the new software. Subscribe to the MacRumors YouTube channel for more videos. You can ge…
https://www.macrumors.com/2026/07/13/apple-seeds-ios-27-public-beta-1/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #MacRumors [MacRumors]
Age verification laws are spreading fast, and it’s a massive privacy trainwreck. Forcing users to hand over IDs or biometric scans kills anonymity & builds giant honeypots for hackers.
Track the creep with @proton.me’s map: https://proton.me/age-verification
Hackers actively exploit critical Joomla extension vulnerabilities in iCagenda and Balbooa Forms. Patch immediately to prevent severe remote code execution.
#Joomla #Vulnerability #CyberSecurity #iCagenda #BalbooaForms #CISA
Women who shaped vulnerability disclosure #negativepid #digitalInvestigations #OSINT #cybersecurity #AI #tech #onlineInvestigations #robotics #cyberpsychology #cybercrime https://negativepid.blog/women-who-shaped-vulnerability-disclosure/?utm_source=mastodon&utm_medium=social&utm_campaign=fedica-Negative-PID-Blog
Google could put your IMEI number on the lock screen, but there’s no need to worry
Showing your IMEI number on the lock screen is a double-edged sword, so we're glad to see a toggle in the works.
https://www.androidauthority.com/imei-number-lock-screen-toggle-apk-teardown-3687103/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
#chrome extension Cool Boy Anime Satoru Gojo Live Wallpaper seems malicious. Its #cybersecurity badness score is 100/100!
```json
{"id": "flngfakcmiaiphlcgaeinomijimgndji", "score": 100, "platform": "chrome", "name": "Cool Boy Anime Satoru Gojo Live Wallpaper"}
```
#chrome extension Lilo and Stitch Adventures Live Wallpaper seems malicious. Its #cybersecurity badness score is 100/100!
```json
{"id": "chdhbhcnoefmhdgkakmhkhmgkpnikaob", "score": 100, "platform": "chrome", "name": "Lilo and Stitch Adventures Live Wallpaper"}
```
#chrome extension Itachi Scarlet Forest Live Wallpaper seems malicious. Its #cybersecurity badness score is 86/100!
```json
{"id": "kaeodbillcikbbgfkiefbbelhmpnjlin", "score": 86, "platform": "chrome", "name": "Itachi Scarlet Forest Live Wallpaper"}
```
#chrome extension Sakura Haruno Naruto Live Wallpaper seems malicious. Its #cybersecurity badness score is 98/100!
```json
{"id": "iiipfibaanaikcolgdhchaelbkddfdon", "score": 98, "platform": "chrome", "name": "Sakura Haruno Naruto Live Wallpaper"}
```
#chrome extension Sanrio Strawberry News April seems malicious. Its #cybersecurity badness score is 100/100!
```json
{"id": "gpkdlejeihbcehnpioaajogdiioccili", "score": 100, "platform": "chrome", "name": "Sanrio Strawberry News April"}
```
#chrome extension Kuromi Cheeky but Charming live Wallpaper seems malicious. Its #cybersecurity badness score is 91/100!
```json
{"id": "edpknjgbbikjifabfaakkgkoadhmbalh", "score": 91, "platform": "chrome", "name": "Kuromi Cheeky but Charming live Wallpaper"}
```
#chrome extension Free Palestine Live Wallpaper seems malicious. Its #cybersecurity badness score is 96/100!
```json
{"id": "bhiojednmkccobaimaopnmocbgaeemnh", "score": 96, "platform": "chrome", "name": "Free Palestine Live Wallpaper"}
```
🚨 EUVD-2026-43621
📊 Score: 4.8/10 (CVSS v3.1)
📦 Product: picobot, picobot
🏢 Vendor: louisho5
📅 Updated: 2026-07-14
📝 A vulnerability was found in louisho5 picobot up to 0.2.0. This issue affects the function ExecTool.Execute of the file internal/agent/tools/exec.go of the component exec Tool. The manipulation results in os command injection. The attack requires a...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43621
🚨 EUVD-2026-43620
📊 Score: 3.1/10 (CVSS v3.1)
📦 Product: keras-team/keras
🏢 Vendor: Keras-team
📅 Updated: 2026-07-14
📝 A vulnerability in keras-team/keras version 3.12.0 allows an attacker to craft a malicious tar archive that bypasses the `filter_safe_tarinfos` validation in `keras/src/utils/file_utils.py`. Specifically, symlink entries are not subjected to the ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43620
Possible Phishing 🎣
on: ⚠️hxxps[:]//netflixclone-chi-ten[.]vercel[.]app
🧬 Analysis at: https://urldna.io/scan/6a550b8d3b77500004af0866
#cybersecurity #phishing #infosec #urldna #scam #infosec
Phpgurukul: 99% unpatched across 884 CVEs. 86 critical/high, max CVSS 9.9. Trust Score: C. Student projects ≠ secure software. #Phpgurukul #cybersecurity #infosec
☕ #Cybersecurity #Ciberseguridad #Ciberseguranca #Security #Seguridad #Seguranca #News #Noticia #Noticias #Tecnologia #Technology
🟣 “La IA no se ve igual en todos los países”: el reto de la ONU para construir una discusión realmente global
🔗 https://es.wired.com/articulos/la-ia-no-se-ve-igual-en-todos-los-paises-el-reto-de-la-onu-para-construir-una-discusion-realmente-global
Carlos Coello, integrante del Panel Científico Internacional Independiente sobre Inteligencia Artificial de la ONU,
Snapseed for Android gets ‘massively expanded’ RAW support with new update
Snapseed might just become my go-to photo editor once again.
https://www.androidauthority.com/snapseed-android-expanded-raw-support-3687123/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Discover how new prompt injection attacks threaten AI security. Hackers use prompt injection techniques to manipulate AI agents and bypass safety controls.
Update on Attacks by Threat Group APT-C-60 in 2026
APT-C-60 continues targeting organizations in Japan with evolved tactics observed throughout 2026. The threat group employs spear-phishing emails containing Proton Drive links or direct attachments with RAR archives. Victims extract LNK files that execute JavaScript via mshta.exe, leading to multi-stage payload delivery. The attackers abuse legitimate services including GitHub, GitLab, jsDelivr, and Codeberg as infrastructure for hosting malicious components. Git.exe is leveraged to execute scripts that deploy downloaders and loaders, ultimately delivering SpyGlace malware versions 3.1.15 through 3.1.18. The attack chain involves multiple obfuscated JavaScript files and persistence mechanisms similar to previous campaigns. By utilizing developer-oriented services and CDNs commonly allowed in corporate environments, the threat actor attempts to evade detection and blend malicious traffic with legitimate communications.
Pulse ID: 6a54e01e0597d81e8ad9f7d0
Pulse Link: https://otx.alienvault.com/pulse/6a54e01e0597d81e8ad9f7d0
Pulse Author: AlienVault
Created: 2026-07-13 12:54:54
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CDN #CyberSecurity #DNS #Email #GitHub #ICS #InfoSec #Japan #Java #JavaScript #LNK #Malware #OTX #OpenThreatExchange #Phishing #RAT #SMS #SpearPhishing #bot #AlienVault
Cooler Master HAF II 500 Case Review: New HAF delivers on its name, with impressive airflow and a roomy c…
Cooler Master’s HAF II 500 revives the HAF legacy with massive 220mm fans, excellent airflow, and solid thermal performance. Its cooling capability, spacious interior, flexible building options, and quiet operation make…
https://www.tomshardware.com/pc-components/pc-cases/cooler-master-haf-ii-500-case-review
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
Intel's new space-grade Starfire chip is a Panther Lake SoC that puts an 18A CPU into orbit — chip designed for the US government leverages Intel 3 for the GPU
Intel has unveiled Starfire, a space-grade system-on-chip designed for the U.S. government.
https://www.tomshardware.com/tech-industry/semiconductors/intel-shows-off-starfire-space-grade-chip
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
Micron commits $500 million to GlobalWafers' Texas wafer plant as it raises U.S. spending to $250 billion — memory maker aims to manufacture 40% of DRAM in the US by 2035
Running until 2035, the $250 billion spending target is attached to a goal of making 40% of Micron's DRAM in the U.S. by the mid-2030s.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
🚨 EUVD-2026-43583
📊 Score: 8.4/10 (CVSS v3.1)
📦 Product: SAProuter on Microsoft Windows, SAProuter on Microsoft Windows, SAProuter on Microsoft Windows (+10 more)
🏢 Vendor: SAP_SE
📅 Updated: 2026-07-14
📝 SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location, allowing them to execute malicious code...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43583
🚨 EUVD-2026-43582
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: clawlet, clawlet, clawlet (+8 more)
🏢 Vendor: mosaxiv
📅 Updated: 2026-07-14
📝 A security vulnerability has been detected in mosaxiv clawlet up to 0.2.10. This affects the function tools.webFetch of the file tools/tool_web_fetch.go. Such manipulation leads to server-side request forgery. The attack can be la...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43582