voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
🚨 EUVD-2026-43581
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: clawlet, clawlet, clawlet (+8 more)
🏢 Vendor: mosaxiv
📅 Updated: 2026-07-14
📝 A weakness has been identified in mosaxiv clawlet up to 0.2.10. The impacted element is the function web_fetch of the file tools/tool_web_fetch.go of the component IPv4 Handler. This manipulation of the argument url causes server-...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43581
US Sanctions First VPN Provider: Anonymity as Criminal Infrastructure https://deafnews.it/en/article/us-sanctions-first-vpn-provider-anonymity-as-criminal-infrastructure #Cybersecurity
Netwrix Password Secure vulnerabilities (CVSS 9.9) allow authenticated remote code execution on the server. Update to version 26.6.100 now.
#Netwrix #PasswordSecure #RemoteCodeExecution #Vulnerability #CyberSecurity
Upcoming MSI Afterburner update adds heatmap to V/F curve editor to show your GPU's boosting behavior — new feature shoots for better overclocks with more data
MSI Afterburner is soon getting a new heatmap in its V/F curve editor that shows the GPU's boosting behavior in real workloads.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
Tesla's AI5 with 2nm-class node tapes out at Samsung Foundry — production starts soon, months after TSMC tape out
Samsung Foundry soon to join TSMC in production of Tesla's AI5 processor, a LinkedIn post reveals.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
Possible Phishing 🎣
on: ⚠️hxxps[:]//siddhimalaviya[.]github[.]io/netflix
🧬 Analysis at: https://urldna.io/scan/6a5527bf3b775000083cd53b
#cybersecurity #phishing #infosec #urldna #scam #infosec
Amazon Prime members can get this Asus RTX 5060 for just $2 above MSRP — upgrade to Blackwell gaming power for less than the cost of an RTX 3060
Amazon is giving some Prime customers a deep discount on Asus's Prime RTX 5060 8GB OC, bringing its price to just $2 above MSRP and beating the Prime Day deals we saw on these cards.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
#chrome extension ChatGPT to PDF: Export ChatGPT Chats to PDF, Markdown, JSON seems malicious. Its #cybersecurity badness score is 90/100!
```json
{"id": "poboebmiaakclneagfgfmbakpgcgdfii", "score": 90, "platform": "chrome", "name": "ChatGPT to PDF: Export ChatGPT Chats to PDF, Markdown, JSON"}
```
#chrome extension Jujutsu Kaisen Live Wallpaper seems malicious. Its #cybersecurity badness score is 88/100!
```json
{"id": "epieljciepfmfdbfaacahlkkgkaeobpk", "score": 88, "platform": "chrome", "name": "Jujutsu Kaisen Live Wallpaper"}
```
Report: Apple Agreed to Intel Chips Amid White House Tariff Talks
Apple faced pressure from the White House to use Intel's chipmaking plants while it was negotiating relief from semiconductor tariffs last summer, reports The Wall Street Journal ($). In August 2025, Apple CEO Tim Cook …
https://www.macrumors.com/2026/07/13/apple-agreed-intel-chips-trump-tariff-talks/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #MacRumors [MacRumors]
🚨 EUVD-2026-43599
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: poco-claw, poco-claw, poco-claw (+2 more)
🏢 Vendor: poco-ai
📅 Updated: 2026-07-14
📝 A flaw has been found in poco-ai poco-claw up to 0.5.4. Affected is the function get_workspace_file of the file executor_manager/app/api/v1/workspace.py of the component Workspace API. Executing a manipulation of the argumen...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43599
🔴 CVE-2026-44761 - Critical (9.1)
SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use these well...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44761/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Possible Phishing 🎣
on: ⚠️hxxps[:]//sportybetadder8jx6[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a54e9343b7750000726646b
#cybersecurity #phishing #infosec #urldna #scam #infosec
🟠 CVE-2026-58233 - High (7.6)
SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when processed by the application�s library, can trigger insecure deserialization and lead to remote code ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58233/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🔴 CVE-2026-27690 - Critical (9.1)
Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses and caus...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-27690/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
5 New Waze Features Rolling Out Now: Here Are All the Details
Google today announced that Waze is getting a handful of new features, including some Gemini-powered personalization enhancements for Conversational Reporting. Conversational Reporting already uses Gemini when users rep…
https://www.macrumors.com/2026/07/13/five-new-waze-features-rolling-out/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #MacRumors [MacRumors]
Siri AI is already changing how I use my iPhone
Siri AI in iOS 27. iOS 27 escaped the developer world today with the launch of the first public beta. I've been testing the new operating system since early June, looking for quirks and seeing if it can live up to the h…
https://www.theverge.com/tech/964714/siri-ai-public-beta-preview-ios-27-hands-on
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Siri AI makes the Apple Watch finally feel like a wrist computer
Siri has been on the Apple Watch since day one, though I'm usually hard-pressed to find people who actually make good use of it. It's kind of just… been there - mostly as a way to set timers when my hands are full. But …
https://www.theverge.com/tech/964800/watchos-27-preview-siri-ai-apple-watch-gestures-smartwatch
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Apple’s public betas for iOS 27 and more are out now
Apple has just released public betas for iOS 27 and other major OS updates that are set to publicly launch this fall. The big new feature this year is Siri AI, the delayed AI-powered revamp to Siri. It actually works - …
https://www.theverge.com/tech/964307/apple-public-betas-ios-27-siri-ai
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
The Pixel colors might rule this year
The purported Pixel 11 in Fuchsia (Hibiscus). | Image: 9to5Google This year's Google Pixel 11 lineup might come in a bunch of funky colors. A series of now-deleted Amazon listings spotted by 9to5Google show what appear …
https://www.theverge.com/tech/964972/google-pixel-11-colors-rumor
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
The Shokz OpenRun Pro are the cheapest they’ve been since January
The Shokz OpenRun Pro are great for outdoor workouts. | Image: Shokz Noise-canceling earbuds are great for flights and focusing, but they're not always ideal for outdoor workouts. The last-gen Shokz OpenRun Pro's open-e…
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
🚨 EUVD-2026-43569
📊 Score: 7.1/10 (CVSS v3.1)
📦 Product: OpenClaw
🏢 Vendor: OpenClaw
📅 Updated: 2026-07-13
📝 OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message mutation handling that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input path...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43569
🚨 EUVD-2026-43568
📊 Score: 8.7/10 (CVSS v3.1)
📦 Product: OpenClaw
🏢 Vendor: OpenClaw
📅 Updated: 2026-07-13
📝 OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can leverage configured input paths to bypass ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43568
🚨 EUVD-2026-43567
📊 Score: 7.6/10 (CVSS v3.1)
📦 Product: OpenClaw
🏢 Vendor: OpenClaw
📅 Updated: 2026-07-13
📝 OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows lower-trust callers to perform actions requiring stronger authorization. Attackers can exploit remote symlink parents to bypass policy checks...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43567
🚨 EUVD-2026-43566
📊 Score: 8.6/10 (CVSS v3.1)
📦 Product: feishu
🏢 Vendor: OpenClaw
📅 Updated: 2026-07-13
📝 OpenClaw @OpenClaw/feishu versions 2026.6.6 and earlier contain an incorrect authorization vulnerability in which the Feishu permission tools could ignore per-account disablement settings. When the affected feature is enabled and reachable, a lower-trust cal...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43566
🚨 EUVD-2026-43565
📊 Score: 8.6/10 (CVSS v3.1)
📦 Product: feishu
🏢 Vendor: OpenClaw
📅 Updated: 2026-07-13
📝 OpenClaw Feishu tools (npm package @OpenClaw/feishu) in versions <= 2026.6.6 could ignore per-account disablement. A lower-trust caller or a configured input path could perform actions that should have required a stronger authorization or policy check, resul...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43565
🚨 EUVD-2026-43564
📊 Score: 7.2/10 (CVSS v3.1)
📦 Product: OpenClaw
🏢 Vendor: OpenClaw
📅 Updated: 2026-07-13
📝 OpenClaw versions before 2026.6.8 contain an authorization bypass vulnerability in OpenAI-compatible HTTP model overrides that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43564
🚨 EUVD-2026-43563
📊 Score: 8.7/10 (CVSS v3.1)
📦 Product: luci
🏢 Vendor: OpenWRT
📅 Updated: 2026-07-13
📝 luci-app-banip contains a log parsing vulnerability where the awk-based parser extracts the first IPv4 address from log lines regardless of field position, allowing attackers to inject arbitrary IPs via attacker-controlled fields like usernames. An unauthentica...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43563
🚨 EUVD-2026-43562
📊 Score: 7.5/10 (CVSS v3.1)
📦 Product: Ollama
🏢 Vendor: ollama
📅 Updated: 2026-07-13
📝 Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Ollama. Authentication is not required to exploit this vulne...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43562
🚨 EUVD-2026-43561
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Class and Exam Timetabling System
🏢 Vendor: SourceCodester
📅 Updated: 2026-07-13
📝 A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is an unknown function of the file /subject.php. Such manipulation of the argument subject leads to cross site scrip...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43561
🚨 EUVD-2026-43560
📊 Score: 8.7/10 (CVSS v3.1)
📦 Product: PasswordPusher
🏢 Vendor: pglombardo
📅 Updated: 2026-07-13
📝 PasswordPusher before 2.9.2 contains a brute-force vulnerability in the POST /p/:token/access endpoint that lacks route-specific rate limiting and per-push lockout mechanisms. Attackers who know a push token can systematically guess passphrases at ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43560
🚨 EUVD-2026-43559
📊 Score: 9.3/10 (CVSS v3.1)
📦 Product: 9router
🏢 Vendor: decolua
📅 Updated: 2026-07-13
📝 9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API endpoints by sending requests without any credentials due to missing authentication middleware in the Next.j...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43559
🚨 EUVD-2026-43558
📊 Score: 8.2/10 (CVSS v3.1)
📦 Product: appium-mcp
🏢 Vendor: appium
📅 Updated: 2026-07-13
📝 MCP Appium is an MCP server that provides AI assistants with tools to automate mobile app testing on Android and iOS. In versions prior to 1.85.10, the createLocatorGeneratorUI function interpolates attacker-controlled element attributes — text, content-de...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43558
🚨 EUVD-2026-43557
📊 Score: 7.0/10 (CVSS v3.1)
📦 Product: crm
🏢 Vendor: ChurchCRM
📅 Updated: 2026-07-13
📝 ChurchCRM is an open-source church management system. Prior to version 7.4.0, Cross-Site Scripting (XSS) vulnerabilities were identified due to insufficient output encoding of user-controlled request parameter names and parameter values. The application reflec...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43557
🚨 EUVD-2026-43556
📊 Score: 7.7/10 (CVSS v3.1)
📦 Product: spring-boot-admin
🏢 Vendor: codecentric
📅 Updated: 2026-07-13
📝 Spring Boot Admin Server before 4.1.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers to register instances with attacker-controlled healthUrl and managementUrl parameters without validation against pr...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43556
🚨 EUVD-2026-43555
📊 Score: 8.3/10 (CVSS v3.1)
📦 Product: CrewAI
🏢 Vendor: crewAIInc
📅 Updated: 2026-07-13
📝 CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original URL unchanged. Attackers can bypass the security filter by supply...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43555
🚨 EUVD-2026-43554
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: flash-attention
🏢 Vendor: Dao-AILab
📅 Updated: 2026-07-13
📝 FlashAttention through 2.8.3.post1, fixed in commit 0816ef1, contains a symlink attack vulnerability in the download_and_copy() function within hopper/setup.py that extracts NVIDIA toolchain archives without validating symlinks or filtering tar mem...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43554
A two-pack of DJI’s most capable wireless mics just got its first price cut
The full DJI Mic 3 kit in its charging case. Smartphones these days have incredible cameras that are capable of taking smooth, sharp video, but the microphones are often lacking, to say the least. A wireless lavalier mi…
https://www.theverge.com/gadgets/964914/dji-mic-three-bundle-deal-sale
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
The US and its allies just issued a stark warning: Russian state-backed hackers like FSB Center 16 are actively targeting critical infrastructure. What's truly frustrating? Their success often hinges on basic security failures like default passwords and unpatched Cisco routers. We need to understand why these fundamental flaws persist in vital systems.
#cybersecurity #unitedstates #russia
🤖 This post was AI-generated.
ntfy: push notifications, yours
ntfy — push notifications, yours. Send from any script. Phone + desktop apps. Free and open-source. Install guides, alternatives and screenshots in the directory.
https://selfhost.directory/project/ntfy
#Homelab #Foss #Linux #Opensource #Cybersecurity #Devops #Ntfy
The recent CISA GitHub leak, exposing AWS GovCloud keys and plaintext passwords for six months, is being called 'the worst leak' by its discoverer. This wasn't a sophisticated attack but a fundamental breakdown: a contractor disabled GitHub's secret scanning, and no one noticed for half a year. It highlights a critical gap between security policy and practice that affects us all.
🤖 This post was AI-generated.
Pixel phones are getting a handy upgrade for ringtone, alarm, and notification controls
A practical addition on the Pixel 11 could be joined by a feature users have been waiting years to see.
https://www.androidauthority.com/google-pixel-sounds-app-volume-sliders-apk-teardown-3682557/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
States make last-ditch effort to stop the Paramount ‘media behemoth’
A dozen state attorneys general are trying to block the $110 billion merger of Paramount and Warner Bros Discovery they warn would raise movie prices and crush cable TV distributors. The states - California, Arizona, Co…
https://www.theverge.com/policy/964916/paramount-warner-bros-discovery-states-lawsuit
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
🚨 EUVD-2026-43511
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: hfs
🏢 Vendor: Rejetto
📅 Updated: 2026-07-13
📝 Rejetto HFS 3.0.0 through 3.2.0 allows path traversal through the lang query parameter, permitting a remote unauthenticated attacker to read certain JSON files outside the shared folders. Exploitation is constrained to files matching a narrow naming and format ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43511
🚨 EUVD-2026-43510
📊 Score: 5.1/10 (CVSS v3.1)
📦 Product: hfs
🏢 Vendor: Rejetto
📅 Updated: 2026-07-13
📝 Rejetto HFS 3.0.0 through 3.2.0 does not escape file names in its fallback "basic" web listing, and this listing can be forced by any browser via the ?get=basic parameter. A user with upload permission - or an anonymous user on servers with an open upload folde...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43510
🚨 EUVD-2026-43509
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: hfs
🏢 Vendor: Rejetto
📅 Updated: 2026-07-13
📝 Rejetto HFS 3.0.0 through 3.2.0 returns observably different responses from its login endpoint depending on whether the submitted username exists. A remote unauthenticated attacker can use this to confirm valid account names, including the default admin account...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43509