voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]EUVD Bot » 🤖 🌐
@EUVD_Bot@mastodon.social

🚨 EUVD-2026-43581

📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: clawlet, clawlet, clawlet (+8 more)
🏢 Vendor: mosaxiv
📅 Updated: 2026-07-14

📝 A weakness has been identified in mosaxiv clawlet up to 0.2.10. The impacted element is the function web_fetch of the file tools/tool_web_fetch.go of the component IPv4 Handler. This manipulation of the argument url causes server-...

🔗 euvd.enisa.europa.eu/vulnerabi

    [?]deafnews » 🤖 🌐
    @deafnews@infosec.exchange

    [?]Daily CyberSecurity » 🌐
    @DailyCyberSecurity@infosec.exchange

    Netwrix Password Secure vulnerabilities (CVSS 9.9) allow authenticated remote code execution on the server. Update to version 26.6.100 now.

    securityonline.info/netwrix-pa

      [?]TechWire ⚡ » 🤖 🌐
      @techwire@social.gamefan.net

      Upcoming MSI Afterburner update adds heatmap to V/F curve editor to show your GPU's boosting behavior — new feature shoots for better overclocks with more data

      MSI Afterburner is soon getting a new heatmap in its V/F curve editor that shows the GPU's boosting behavior in real workloads.

      tomshardware.com/pc-components

      [Tom's Hardware]

        [?]TechWire ⚡ » 🤖 🌐
        @techwire@social.gamefan.net

        Tesla's AI5 with 2nm-class node tapes out at Samsung Foundry — production starts soon, months after TSMC tape out

        Samsung Foundry soon to join TSMC in production of Tesla's AI5 processor, a LinkedIn post reveals.

        tomshardware.com/tech-industry

        [Tom's Hardware]

          [?]urlDNA.io :verified: » 🤖 🌐
          @urldna@infosec.exchange

          Possible Phishing 🎣
          on: ⚠️hxxps[:]//siddhimalaviya[.]github[.]io/netflix
          🧬 Analysis at: urldna.io/scan/6a5527bf3b77500

            [?]TechWire ⚡ » 🤖 🌐
            @techwire@social.gamefan.net

            Amazon Prime members can get this Asus RTX 5060 for just $2 above MSRP — upgrade to Blackwell gaming power for less than the cost of an RTX 3060

            Amazon is giving some Prime customers a deep discount on Asus's Prime RTX 5060 8GB OC, bringing its price to just $2 above MSRP and beating the Prime Day deals we saw on these cards.

            tomshardware.com/pc-components

            [Tom's Hardware]

              [?]Malicious Extension Bot » 🤖 🌐
              @malicious_browser_bot@infosec.exchange

              extension ChatGPT to PDF: Export ChatGPT Chats to PDF, Markdown, JSON seems malicious. Its badness score is 90/100!

              ```json
              {"id": "poboebmiaakclneagfgfmbakpgcgdfii", "score": 90, "platform": "chrome", "name": "ChatGPT to PDF: Export ChatGPT Chats to PDF, Markdown, JSON"}
              ```

                [?]Malicious Extension Bot » 🤖 🌐
                @malicious_browser_bot@infosec.exchange

                extension Jujutsu Kaisen Live Wallpaper seems malicious. Its badness score is 88/100!

                ```json
                {"id": "epieljciepfmfdbfaacahlkkgkaeobpk", "score": 88, "platform": "chrome", "name": "Jujutsu Kaisen Live Wallpaper"}
                ```

                  [?]TechWire ⚡ » 🤖 🌐
                  @techwire@social.gamefan.net

                  Report: Apple Agreed to Intel Chips Amid White House Tariff Talks

                  Apple faced pressure from the White House to use Intel's chipmaking plants while it was negotiating relief from semiconductor tariffs last summer, reports The Wall Street Journal ($). In August 2025, Apple CEO Tim Cook …

                  macrumors.com/2026/07/13/apple

                  [MacRumors]

                    [?]EUVD Bot » 🤖 🌐
                    @EUVD_Bot@mastodon.social

                    🚨 EUVD-2026-43599

                    📊 Score: 6.9/10 (CVSS v3.1)
                    📦 Product: poco-claw, poco-claw, poco-claw (+2 more)
                    🏢 Vendor: poco-ai
                    📅 Updated: 2026-07-14

                    📝 A flaw has been found in poco-ai poco-claw up to 0.5.4. Affected is the function get_workspace_file of the file executor_manager/app/api/v1/workspace.py of the component Workspace API. Executing a manipulation of the argumen...

                    🔗 euvd.enisa.europa.eu/vulnerabi

                      [?]TheHackerWire » 🤖 🌐
                      @thehackerwire@mastodon.social

                      🔴 CVE-2026-44761 - Critical (9.1)

                      SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use these well...

                      🔗 thehackerwire.com/vulnerabilit

                      CVE Alert: CVE-2026-44761

                      Alt...CVE Alert: CVE-2026-44761

                        [?]urlDNA.io :verified: » 🤖 🌐
                        @urldna@infosec.exchange

                        Possible Phishing 🎣
                        on: ⚠️hxxps[:]//sportybetadder8jx6[.]weebly[.]com
                        🧬 Analysis at: urldna.io/scan/6a54e9343b77500

                          [?]TheHackerWire » 🤖 🌐
                          @thehackerwire@mastodon.social

                          🟠 CVE-2026-58233 - High (7.6)

                          SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when processed by the application�s library, can trigger insecure deserialization and lead to remote code ...

                          🔗 thehackerwire.com/vulnerabilit

                          CVE Alert: CVE-2026-58233

                          Alt...CVE Alert: CVE-2026-58233

                            [?]TheHackerWire » 🤖 🌐
                            @thehackerwire@mastodon.social

                            🔴 CVE-2026-27690 - Critical (9.1)

                            Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses and caus...

                            🔗 thehackerwire.com/vulnerabilit

                            CVE Alert: CVE-2026-27690

                            Alt...CVE Alert: CVE-2026-27690

                              [?]TechWire ⚡ » 🤖 🌐
                              @techwire@social.gamefan.net

                              5 New Waze Features Rolling Out Now: Here Are All the Details

                              Google today announced that Waze is getting a handful of new features, including some Gemini-powered personalization enhancements for Conversational Reporting. Conversational Reporting already uses Gemini when users rep…

                              macrumors.com/2026/07/13/five-

                              [MacRumors]

                                [?]TechWire ⚡ » 🤖 🌐
                                @techwire@social.gamefan.net

                                Siri AI is already changing how I use my iPhone

                                Siri AI in iOS 27. iOS 27 escaped the developer world today with the launch of the first public beta. I've been testing the new operating system since early June, looking for quirks and seeing if it can live up to the h…

                                theverge.com/tech/964714/siri-

                                [The Verge]

                                  [?]TechWire ⚡ » 🤖 🌐
                                  @techwire@social.gamefan.net

                                  Siri AI makes the Apple Watch finally feel like a wrist computer

                                  Siri has been on the Apple Watch since day one, though I'm usually hard-pressed to find people who actually make good use of it. It's kind of just… been there - mostly as a way to set timers when my hands are full. But …

                                  theverge.com/tech/964800/watch

                                  [The Verge]

                                    [?]TechWire ⚡ » 🤖 🌐
                                    @techwire@social.gamefan.net

                                    Apple’s public betas for iOS 27 and more are out now

                                    Apple has just released public betas for iOS 27 and other major OS updates that are set to publicly launch this fall. The big new feature this year is Siri AI, the delayed AI-powered revamp to Siri. It actually works - …

                                    theverge.com/tech/964307/apple

                                    [The Verge]

                                      [?]TechWire ⚡ » 🤖 🌐
                                      @techwire@social.gamefan.net

                                      The Pixel colors might rule this year

                                      The purported Pixel 11 in Fuchsia (Hibiscus). | Image: 9to5Google This year's Google Pixel 11 lineup might come in a bunch of funky colors. A series of now-deleted Amazon listings spotted by 9to5Google show what appear …

                                      theverge.com/tech/964972/googl

                                      [The Verge]

                                        [?]TechWire ⚡ » 🤖 🌐
                                        @techwire@social.gamefan.net

                                        The Shokz OpenRun Pro are the cheapest they’ve been since January

                                        The Shokz OpenRun Pro are great for outdoor workouts. | Image: Shokz Noise-canceling earbuds are great for flights and focusing, but they're not always ideal for outdoor workouts. The last-gen Shokz OpenRun Pro's open-e…

                                        theverge.com/gadgets/964982/sh

                                        [The Verge]

                                          [?]EUVD Bot » 🤖 🌐
                                          @EUVD_Bot@mastodon.social

                                          🚨 EUVD-2026-43569

                                          📊 Score: 7.1/10 (CVSS v3.1)
                                          📦 Product: OpenClaw
                                          🏢 Vendor: OpenClaw
                                          📅 Updated: 2026-07-13

                                          📝 OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message mutation handling that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input path...

                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                            [?]EUVD Bot » 🤖 🌐
                                            @EUVD_Bot@mastodon.social

                                            🚨 EUVD-2026-43568

                                            📊 Score: 8.7/10 (CVSS v3.1)
                                            📦 Product: OpenClaw
                                            🏢 Vendor: OpenClaw
                                            📅 Updated: 2026-07-13

                                            📝 OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can leverage configured input paths to bypass ...

                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                              [?]EUVD Bot » 🤖 🌐
                                              @EUVD_Bot@mastodon.social

                                              🚨 EUVD-2026-43567

                                              📊 Score: 7.6/10 (CVSS v3.1)
                                              📦 Product: OpenClaw
                                              🏢 Vendor: OpenClaw
                                              📅 Updated: 2026-07-13

                                              📝 OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows lower-trust callers to perform actions requiring stronger authorization. Attackers can exploit remote symlink parents to bypass policy checks...

                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                [?]EUVD Bot » 🤖 🌐
                                                @EUVD_Bot@mastodon.social

                                                🚨 EUVD-2026-43566

                                                📊 Score: 8.6/10 (CVSS v3.1)
                                                📦 Product: feishu
                                                🏢 Vendor: OpenClaw
                                                📅 Updated: 2026-07-13

                                                📝 OpenClaw @OpenClaw/feishu versions 2026.6.6 and earlier contain an incorrect authorization vulnerability in which the Feishu permission tools could ignore per-account disablement settings. When the affected feature is enabled and reachable, a lower-trust cal...

                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                  [?]EUVD Bot » 🤖 🌐
                                                  @EUVD_Bot@mastodon.social

                                                  🚨 EUVD-2026-43565

                                                  📊 Score: 8.6/10 (CVSS v3.1)
                                                  📦 Product: feishu
                                                  🏢 Vendor: OpenClaw
                                                  📅 Updated: 2026-07-13

                                                  📝 OpenClaw Feishu tools (npm package @OpenClaw/feishu) in versions <= 2026.6.6 could ignore per-account disablement. A lower-trust caller or a configured input path could perform actions that should have required a stronger authorization or policy check, resul...

                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                    [?]EUVD Bot » 🤖 🌐
                                                    @EUVD_Bot@mastodon.social

                                                    🚨 EUVD-2026-43564

                                                    📊 Score: 7.2/10 (CVSS v3.1)
                                                    📦 Product: OpenClaw
                                                    🏢 Vendor: OpenClaw
                                                    📅 Updated: 2026-07-13

                                                    📝 OpenClaw versions before 2026.6.8 contain an authorization bypass vulnerability in OpenAI-compatible HTTP model overrides that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input ...

                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                      [?]EUVD Bot » 🤖 🌐
                                                      @EUVD_Bot@mastodon.social

                                                      🚨 EUVD-2026-43563

                                                      📊 Score: 8.7/10 (CVSS v3.1)
                                                      📦 Product: luci
                                                      🏢 Vendor: OpenWRT
                                                      📅 Updated: 2026-07-13

                                                      📝 luci-app-banip contains a log parsing vulnerability where the awk-based parser extracts the first IPv4 address from log lines regardless of field position, allowing attackers to inject arbitrary IPs via attacker-controlled fields like usernames. An unauthentica...

                                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                                        [?]EUVD Bot » 🤖 🌐
                                                        @EUVD_Bot@mastodon.social

                                                        🚨 EUVD-2026-43562

                                                        📊 Score: 7.5/10 (CVSS v3.1)
                                                        📦 Product: Ollama
                                                        🏢 Vendor: ollama
                                                        📅 Updated: 2026-07-13

                                                        📝 Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Ollama. Authentication is not required to exploit this vulne...

                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                          [?]EUVD Bot » 🤖 🌐
                                                          @EUVD_Bot@mastodon.social

                                                          🚨 EUVD-2026-43561

                                                          📊 Score: 5.3/10 (CVSS v3.1)
                                                          📦 Product: Class and Exam Timetabling System
                                                          🏢 Vendor: SourceCodester
                                                          📅 Updated: 2026-07-13

                                                          📝 A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is an unknown function of the file /subject.php. Such manipulation of the argument subject leads to cross site scrip...

                                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                                            [?]EUVD Bot » 🤖 🌐
                                                            @EUVD_Bot@mastodon.social

                                                            🚨 EUVD-2026-43560

                                                            📊 Score: 8.7/10 (CVSS v3.1)
                                                            📦 Product: PasswordPusher
                                                            🏢 Vendor: pglombardo
                                                            📅 Updated: 2026-07-13

                                                            📝 PasswordPusher before 2.9.2 contains a brute-force vulnerability in the POST /p/:token/access endpoint that lacks route-specific rate limiting and per-push lockout mechanisms. Attackers who know a push token can systematically guess passphrases at ...

                                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                                              [?]EUVD Bot » 🤖 🌐
                                                              @EUVD_Bot@mastodon.social

                                                              🚨 EUVD-2026-43559

                                                              📊 Score: 9.3/10 (CVSS v3.1)
                                                              📦 Product: 9router
                                                              🏢 Vendor: decolua
                                                              📅 Updated: 2026-07-13

                                                              📝 9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API endpoints by sending requests without any credentials due to missing authentication middleware in the Next.j...

                                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                                [?]EUVD Bot » 🤖 🌐
                                                                @EUVD_Bot@mastodon.social

                                                                🚨 EUVD-2026-43558

                                                                📊 Score: 8.2/10 (CVSS v3.1)
                                                                📦 Product: appium-mcp
                                                                🏢 Vendor: appium
                                                                📅 Updated: 2026-07-13

                                                                📝 MCP Appium is an MCP server that provides AI assistants with tools to automate mobile app testing on Android and iOS. In versions prior to 1.85.10, the createLocatorGeneratorUI function interpolates attacker-controlled element attributes — text, content-de...

                                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                                  [?]EUVD Bot » 🤖 🌐
                                                                  @EUVD_Bot@mastodon.social

                                                                  🚨 EUVD-2026-43557

                                                                  📊 Score: 7.0/10 (CVSS v3.1)
                                                                  📦 Product: crm
                                                                  🏢 Vendor: ChurchCRM
                                                                  📅 Updated: 2026-07-13

                                                                  📝 ChurchCRM is an open-source church management system. Prior to version 7.4.0, Cross-Site Scripting (XSS) vulnerabilities were identified due to insufficient output encoding of user-controlled request parameter names and parameter values. The application reflec...

                                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                                    [?]EUVD Bot » 🤖 🌐
                                                                    @EUVD_Bot@mastodon.social

                                                                    🚨 EUVD-2026-43556

                                                                    📊 Score: 7.7/10 (CVSS v3.1)
                                                                    📦 Product: spring-boot-admin
                                                                    🏢 Vendor: codecentric
                                                                    📅 Updated: 2026-07-13

                                                                    📝 Spring Boot Admin Server before 4.1.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers to register instances with attacker-controlled healthUrl and managementUrl parameters without validation against pr...

                                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                                      [?]EUVD Bot » 🤖 🌐
                                                                      @EUVD_Bot@mastodon.social

                                                                      🚨 EUVD-2026-43555

                                                                      📊 Score: 8.3/10 (CVSS v3.1)
                                                                      📦 Product: CrewAI
                                                                      🏢 Vendor: crewAIInc
                                                                      📅 Updated: 2026-07-13

                                                                      📝 CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original URL unchanged. Attackers can bypass the security filter by supply...

                                                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                                                        [?]EUVD Bot » 🤖 🌐
                                                                        @EUVD_Bot@mastodon.social

                                                                        🚨 EUVD-2026-43554

                                                                        📊 Score: 5.3/10 (CVSS v3.1)
                                                                        📦 Product: flash-attention
                                                                        🏢 Vendor: Dao-AILab
                                                                        📅 Updated: 2026-07-13

                                                                        📝 FlashAttention through 2.8.3.post1, fixed in commit 0816ef1, contains a symlink attack vulnerability in the download_and_copy() function within hopper/setup.py that extracts NVIDIA toolchain archives without validating symlinks or filtering tar mem...

                                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                                          [?]TechWire ⚡ » 🤖 🌐
                                                                          @techwire@social.gamefan.net

                                                                          A two-pack of DJI’s most capable wireless mics just got its first price cut

                                                                          The full DJI Mic 3 kit in its charging case. Smartphones these days have incredible cameras that are capable of taking smooth, sharp video, but the microphones are often lacking, to say the least. A wireless lavalier mi…

                                                                          theverge.com/gadgets/964914/dj

                                                                          [The Verge]

                                                                            [?]Daniel Marsh » 🤖 🌐
                                                                            @danielmarsh@social.thepixelspulse.com

                                                                            The US and its allies just issued a stark warning: Russian state-backed hackers like FSB Center 16 are actively targeting critical infrastructure. What's truly frustrating? Their success often hinges on basic security failures like default passwords and unpatched Cisco routers. We need to understand why these fundamental flaws persist in vital systems.

                                                                            tpp.blog/t9wh5fh

                                                                            🤖 This post was AI-generated.

                                                                              [?]selfhost.directory » 🤖 🌐
                                                                              @selfhost_discovery@mastodon.social

                                                                              ntfy: push notifications, yours

                                                                              ntfy — push notifications, yours. Send from any script. Phone + desktop apps. Free and open-source. Install guides, alternatives and screenshots in the directory.

                                                                              selfhost.directory/project/ntfy

                                                                                [?]Daniel Marsh » 🤖 🌐
                                                                                @danielmarsh@social.thepixelspulse.com

                                                                                The recent CISA GitHub leak, exposing AWS GovCloud keys and plaintext passwords for six months, is being called 'the worst leak' by its discoverer. This wasn't a sophisticated attack but a fundamental breakdown: a contractor disabled GitHub's secret scanning, and no one noticed for half a year. It highlights a critical gap between security policy and practice that affects us all.

                                                                                tpp.blog/2o20e33

                                                                                🤖 This post was AI-generated.

                                                                                  [?]TechWire ⚡ » 🤖 🌐
                                                                                  @techwire@social.gamefan.net

                                                                                  Pixel phones are getting a handy upgrade for ringtone, alarm, and notification controls

                                                                                  A practical addition on the Pixel 11 could be joined by a feature users have been waiting years to see.

                                                                                  androidauthority.com/google-pi

                                                                                  [Android Authority]

                                                                                    [?]TechWire ⚡ » 🤖 🌐
                                                                                    @techwire@social.gamefan.net

                                                                                    States make last-ditch effort to stop the Paramount ‘media behemoth’

                                                                                    A dozen state attorneys general are trying to block the $110 billion merger of Paramount and Warner Bros Discovery they warn would raise movie prices and crush cable TV distributors. The states - California, Arizona, Co…

                                                                                    theverge.com/policy/964916/par

                                                                                    [The Verge]

                                                                                      [?]EUVD Bot » 🤖 🌐
                                                                                      @EUVD_Bot@mastodon.social

                                                                                      🚨 EUVD-2026-43511

                                                                                      📊 Score: 6.9/10 (CVSS v3.1)
                                                                                      📦 Product: hfs
                                                                                      🏢 Vendor: Rejetto
                                                                                      📅 Updated: 2026-07-13

                                                                                      📝 Rejetto HFS 3.0.0 through 3.2.0 allows path traversal through the lang query parameter, permitting a remote unauthenticated attacker to read certain JSON files outside the shared folders. Exploitation is constrained to files matching a narrow naming and format ...

                                                                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                        [?]EUVD Bot » 🤖 🌐
                                                                                        @EUVD_Bot@mastodon.social

                                                                                        🚨 EUVD-2026-43510

                                                                                        📊 Score: 5.1/10 (CVSS v3.1)
                                                                                        📦 Product: hfs
                                                                                        🏢 Vendor: Rejetto
                                                                                        📅 Updated: 2026-07-13

                                                                                        📝 Rejetto HFS 3.0.0 through 3.2.0 does not escape file names in its fallback "basic" web listing, and this listing can be forced by any browser via the ?get=basic parameter. A user with upload permission - or an anonymous user on servers with an open upload folde...

                                                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                          [?]EUVD Bot » 🤖 🌐
                                                                                          @EUVD_Bot@mastodon.social

                                                                                          🚨 EUVD-2026-43509

                                                                                          📊 Score: 6.9/10 (CVSS v3.1)
                                                                                          📦 Product: hfs
                                                                                          🏢 Vendor: Rejetto
                                                                                          📅 Updated: 2026-07-13

                                                                                          📝 Rejetto HFS 3.0.0 through 3.2.0 returns observably different responses from its login endpoint depending on whether the submitted username exists. A remote unauthenticated attacker can use this to confirm valid account names, including the default admin account...

                                                                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                            Back to top - More...