voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]EUVD Bot » 🤖 🌐
@EUVD_Bot@mastodon.social

🚨 EUVD-2026-43508

📊 Score: 5.1/10 (CVSS v3.1)
📦 Product: hfs
🏢 Vendor: Rejetto
📅 Updated: 2026-07-13

📝 Rejetto HFS 3.0.0 through 3.2.0 accepts state-changing API requests via the GET method and exempts GET requests from its anti-CSRF header check. A remote attacker can perform administrative actions including account creation and configuration changes leading to...

🔗 euvd.enisa.europa.eu/vulnerabi

    [?]urlDNA.io :verified: » 🤖 🌐
    @urldna@infosec.exchange

    Possible Phishing 🎣
    on: ⚠️hxxp[:]//facebooktechnicalsupportnumber123[.]blogspot[.]com
    🧬 Analysis at: urldna.io/scan/6a54ccf03b77500

      [?]EUVD Bot » 🤖 🌐
      @EUVD_Bot@mastodon.social

      🚨 EUVD-2026-43507

      📊 Score: 8.7/10 (CVSS v3.1)
      📦 Product: shiori
      🏢 Vendor: go-shiori
      📅 Updated: 2026-07-13

      📝 Shiori contains a privilege escalation vulnerability in the account update endpoint that allows authenticated users to modify the owner field without authorization checks. Attackers can escalate to administrator by submitting a crafted PATCH request with ow...

      🔗 euvd.enisa.europa.eu/vulnerabi

        [?]EUVD Bot » 🤖 🌐
        @EUVD_Bot@mastodon.social

        🚨 EUVD-2026-43506

        📊 Score: 5.3/10 (CVSS v3.1)
        📦 Product: hfs
        🏢 Vendor: Rejetto
        📅 Updated: 2026-07-13

        📝 Rejetto HFS 3.0.0 through 3.2.0 renders log entries in the administration panel as HTML without sanitization. A remote unauthenticated attacker can submit a failed login with a crafted username that is written to the error log and executes JavaScript in an admi...

        🔗 euvd.enisa.europa.eu/vulnerabi

          [?]EUVD Bot » 🤖 🌐
          @EUVD_Bot@mastodon.social

          🚨 EUVD-2026-43505

          📊 Score: 9.3/10 (CVSS v3.1)
          📦 Product: hfs
          🏢 Vendor: Rejetto
          📅 Updated: 2026-07-13

          📝 Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login. A remote attacker can collect a small number of login ...

          🔗 euvd.enisa.europa.eu/vulnerabi

            [?]EUVD Bot » 🤖 🌐
            @EUVD_Bot@mastodon.social

            🚨 EUVD-2026-43504

            📊 Score: 9.2/10 (CVSS v3.1)
            📦 Product: mcp-gitlab
            🏢 Vendor: zereight
            📅 Updated: 2026-07-13

            📝 mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints. Attackers can supply crafted job_id values like ../../../user to escape the intende...

            🔗 euvd.enisa.europa.eu/vulnerabi

              [?]/G|T|R|O|N|I|X\ :python: :emacs: :nix: :linux: » 🌐
              @gtronix@infosec.exchange

              "CISA warns of actively exploited RCE flaws in Joomla extensions"

              "[...] Cybersecurity and Infrastructure Security Agency (CISA) is warning that attackers are exploiting vulnerabilities in the iCagenda and Balbooa Forms extensions for Joomla to achieve remote code execution through arbitrary file uploads. The U.S."

              bleepingcomputer.com/news/secu

                [?]BeyondMachines :verified: » 🤖 🌐
                @beyondmachines1@infosec.exchange

                Alta Orthopaedics Discloses Data Breach Exposing Patient Medical and Financial Data

                Alta Orthopaedics disclosed a data breach after unauthorized actors accessed files containing sensitive patient information, including medical records and Social Security numbers. The Incransom ransomware group claimed responsibility for the attack. The company notified law enforcement and offered credit monitoring to affected individuals.

                ****

                beyondmachines.net/event_detai

                  [?]CyberNetsecIO » 🌐
                  @netsecio@mastodon.social

                  📰 NSA Warns of Russian FSB Targeting Vulnerable Routers in Critical Infrastructure

                  NSA, CISA, FBI & Five Eyes partners warn Russian FSB actors (Berserk Bear) are actively exploiting vulnerable network routers in critical infrastructure. Advisory urges hardening SNMP, disabling unused protocols, and prompt patching. #...

                  🌐 cyber[.]netsecops[.]io

                  🔗 cyber.netsecops.io/articles/ns

                    [?]CyberNetsecIO » 🌐
                    @netsecio@mastodon.social

                    📰 APT-C-60 Targets Japan with 'SpyGlace' Malware, Abusing Trusted Cloud Services

                    The APT-C-60 threat group is targeting organizations in Japan with 'SpyGlace' malware. The campaign abuses trusted services like GitHub, Proton Drive, and jsDelivr for payload delivery and C2 to evade detection.

                    🌐 cyber[.]netsecops[.]io

                    🔗 cyber.netsecops.io/articles/ja

                      [?]CyberNetsecIO » 🌐
                      @netsecio@mastodon.social

                      📰 New APT 'Armored Likho' Deploys 'BusySnake' Stealer Against Energy & Government

                      New APT group 'Armored Likho' targets government & energy sectors in Russia, Brazil, Kazakhstan. The group uses a new Python-based 'BusySnake Stealer' and AI-generated code for its espionage campaigns. 🐍

                      🌐 cyber[.]netsecops[.]io

                      🔗 cyber.netsecops.io/articles/ne

                        [?]Hackerdogs » 🌐
                        @hackerdogs@mastodon.social

                        U.S. sanctions VPN service used by ransomware groups, targeting infrastructure that enables cybercrime operations.
                        therecord.media/first-vpn-admi

                          [?]Black Cat White Hat Security » 🌐
                          @BCWHQuiz@defcon.social

                          An ITIL self-assessment evaluates your organization’s IT Service Management (ITSM) practices against ITIL 4 best practices. It identifies capability gaps, benchmarks performance, and highlights key areas to improve service delivery and organizational maturity.



                          Link: blackcatwhitehatsecurity.com

                          An ITIL self-assessment evaluates your organization’s IT Service Management (ITSM) practices against ITIL 4 best practices. It identifies capability gaps, benchmarks performance, and highlights key areas to improve service delivery and organizational maturity.

                          Alt...An ITIL self-assessment evaluates your organization’s IT Service Management (ITSM) practices against ITIL 4 best practices. It identifies capability gaps, benchmarks performance, and highlights key areas to improve service delivery and organizational maturity.

                            [?]Hugo | DevOps | Cybersecurity » 🌐
                            @hugovalters@mastodon.social

                            Zimbra: 47 CVEs, 8 exploited in CISA KEV, 100% unpatched. Trust Score: D. Email security risk—patch now.

                            valtersit.com/vendors/zimbra/

                              [?]TechWire ⚡ » 🤖 🌐
                              @techwire@social.gamefan.net

                              The best all-in-one computers of 2026: Expert tested and reviewed

                              We tested the best all-in-one computers that combine the power of a desktop PC with a slim, lightweight design.

                              zdnet.com/article/best-all-in-

                              [ZDNet]

                                [?]hackers-arise.official » 🌐
                                @hackers_arise@mastodon.social

                                [?]N-gated Hacker News » 🤖 🌐
                                @ngate@mastodon.social

                                🎉 Breaking news: Our tech-savvy protagonist just turned "data breach" into a personal hobby. 🤦‍♂️ Yes, because nothing screams like one-click uploading your life's work to xAI's servers. Bravo, truly on the cutting edge of comedy! 🏆
                                twitter.com/a_green_being/stat

                                  [?]gtbarry » 🌐
                                  @gtbarry@mastodon.social

                                  Crypto Sector Preps Defense Against Quantum Computing Threat

                                  the $2 trillion crypto market already has a history of hacks. Quantum computers could exacerbate this problem, as they could be used to unscramble the normal methods of encrypting digital ‌information

                                  pymnts.com/cryptocurrency/2026

                                    [?]TechWire ⚡ » 🤖 🌐
                                    @techwire@social.gamefan.net

                                    Samsung overtakes Apple as smartphone market sinks to a 13-year low

                                    A massive global memory crisis just pushed smartphone sales to a 13-year low.

                                    androidauthority.com/counterpo

                                    [Android Authority]

                                      [?]Negative PID SL » 🌐
                                      @negativepid@mastodon.social

                                      [?]Hacker News » 🤖 🌐
                                      @h4ckernews@mastodon.social

                                      [?]EUVD Bot » 🤖 🌐
                                      @EUVD_Bot@mastodon.social

                                      🚨 EUVD-2026-43458

                                      📊 Score: 7.1/10 (CVSS v3.1)
                                      📦 Product: JobSearch
                                      🏢 Vendor: eyecix
                                      📅 Updated: 2026-07-13

                                      📝 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch wp-jobsearch allows Stored XSS.This issue affects JobSearch: from n/a through <= 3.2.9.

                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                        [?]EUVD Bot » 🤖 🌐
                                        @EUVD_Bot@mastodon.social

                                        🚨 EUVD-2026-43457

                                        📊 Score: 7.1/10 (CVSS v3.1)
                                        📦 Product: Simple File List
                                        🏢 Vendor: Mitchell Bennis
                                        📅 Updated: 2026-07-13

                                        📝 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mitchell Bennis Simple File List simple-file-list allows Reflected XSS.This issue affects Simple File List: from n/a through <= 6.3.8.

                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                          [?]EUVD Bot » 🤖 🌐
                                          @EUVD_Bot@mastodon.social

                                          🚨 EUVD-2026-43456

                                          📊 Score: 8.8/10 (CVSS v3.1)
                                          📦 Product: aBlocks
                                          🏢 Vendor: Kodezen LLC
                                          📅 Updated: 2026-07-13

                                          📝 Incorrect Privilege Assignment vulnerability in Kodezen LLC aBlocks ablocks allows Privilege Escalation.This issue affects aBlocks: from n/a through < 2.9.1.

                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                            [?]EUVD Bot » 🤖 🌐
                                            @EUVD_Bot@mastodon.social

                                            🚨 EUVD-2026-43455

                                            📊 Score: 7.1/10 (CVSS v3.1)
                                            📦 Product: PropertyHive
                                            🏢 Vendor: Property Hive
                                            📅 Updated: 2026-07-13

                                            📝 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows Reflected XSS.This issue affects PropertyHive: from n/a through <= 2.2.3.

                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                              [?]EUVD Bot » 🤖 🌐
                                              @EUVD_Bot@mastodon.social

                                              🚨 EUVD-2026-43454

                                              📊 Score: 7.1/10 (CVSS v3.1)
                                              📦 Product: FormyChat
                                              🏢 Vendor: WPPOOL
                                              📅 Updated: 2026-07-13

                                              📝 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL FormyChat social-contact-form allows Stored XSS.This issue affects FormyChat: from n/a through <= 2.15.3.

                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                [?]EUVD Bot » 🤖 🌐
                                                @EUVD_Bot@mastodon.social

                                                🚨 EUVD-2026-43453

                                                📊 Score: 7.1/10 (CVSS v3.1)
                                                📦 Product: Extensions for Leaflet Map
                                                🏢 Vendor: hupe13
                                                📅 Updated: 2026-07-13

                                                📝 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hupe13 Extensions for Leaflet Map extensions-leaflet-map allows DOM-Based XSS.This issue affects Extensions for Leaflet Map: from n/a thro...

                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                  [?]EUVD Bot » 🤖 🌐
                                                  @EUVD_Bot@mastodon.social

                                                  🚨 EUVD-2026-43452

                                                  📊 Score: 7.5/10 (CVSS v3.1)
                                                  📦 Product: Advanced Forms
                                                  🏢 Vendor: Phil Kurth
                                                  📅 Updated: 2026-07-13

                                                  📝 Missing Authorization vulnerability in Phil Kurth Advanced Forms advanced-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Forms: from n/a through <= 1.9.3.7.

                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                    [?]EUVD Bot » 🤖 🌐
                                                    @EUVD_Bot@mastodon.social

                                                    🚨 EUVD-2026-43449

                                                    📊 Score: 6.5/10 (CVSS v3.1)
                                                    📦 Product: MStore API
                                                    🏢 Vendor: FluxBuilder
                                                    📅 Updated: 2026-07-13

                                                    📝 Missing Authorization vulnerability in FluxBuilder MStore API mstore-api allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MStore API: from n/a through <= 4.18.4.

                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                      [?]EUVD Bot » 🤖 🌐
                                                      @EUVD_Bot@mastodon.social

                                                      🚨 EUVD-2026-43444

                                                      📊 Score: 7.1/10 (CVSS v3.1)
                                                      📦 Product: ElementInvader Addons for Elementor
                                                      🏢 Vendor: Element Invader
                                                      📅 Updated: 2026-07-13

                                                      📝 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows DOM-Based XSS.This issue ...

                                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                                        [?]EUVD Bot » 🤖 🌐
                                                        @EUVD_Bot@mastodon.social

                                                        🚨 EUVD-2026-43442

                                                        📊 Score: 6.5/10 (CVSS v3.1)
                                                        📦 Product: WowAddons
                                                        🏢 Vendor: wpxpo
                                                        📅 Updated: 2026-07-13

                                                        📝 Missing Authorization vulnerability in WPXPO WowAddons product-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WowAddons: from n/a through <= 1.6.8.

                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                          [?]EUVD Bot » 🤖 🌐
                                                          @EUVD_Bot@mastodon.social

                                                          🚨 EUVD-2026-43451

                                                          📊 Score: 6.5/10 (CVSS v3.1)
                                                          📦 Product: Better Payment – Instant Payments, Donations, Fundraising with Subscriptions &amp; More
                                                          🏢 Vendor: WPDeveloper
                                                          📅 Updated: 2026-07-13

                                                          📝 Improper Validation of Specified Quantity in Input vulnerability in WPDeveloper Better Payment – Instant Payments, Donations, Fundraising with Subscriptions &amp; More better...

                                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                                            [?]EUVD Bot » 🤖 🌐
                                                            @EUVD_Bot@mastodon.social

                                                            🚨 EUVD-2026-43450

                                                            📊 Score: 7.1/10 (CVSS v3.1)
                                                            📦 Product: Jobmonster
                                                            🏢 Vendor: NooTheme
                                                            📅 Updated: 2026-07-13

                                                            📝 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobmonster noo-jobmonster allows Reflected XSS.This issue affects Jobmonster: from n/a through <= 4.8.5.

                                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                                              [?]EUVD Bot » 🤖 🌐
                                                              @EUVD_Bot@mastodon.social

                                                              🚨 EUVD-2026-43448

                                                              📊 Score: 7.2/10 (CVSS v3.1)
                                                              📦 Product: WPJAM Basic
                                                              🏢 Vendor: Denishua
                                                              📅 Updated: 2026-07-13

                                                              📝 Server-Side Request Forgery (SSRF) vulnerability in denishua WPJAM Basic wpjam-basic allows Server Side Request Forgery.This issue affects WPJAM Basic: from n/a through <= 7.0.

                                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                                [?]EUVD Bot » 🤖 🌐
                                                                @EUVD_Bot@mastodon.social

                                                                🚨 EUVD-2026-43447

                                                                📊 Score: 8.8/10 (CVSS v3.1)
                                                                📦 Product: WPJAM Basic
                                                                🏢 Vendor: Denishua
                                                                📅 Updated: 2026-07-13

                                                                📝 Deserialization of Untrusted Data vulnerability in denishua WPJAM Basic wpjam-basic allows Object Injection.This issue affects WPJAM Basic: from n/a through <= 7.0.

                                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                                  [?]EUVD Bot » 🤖 🌐
                                                                  @EUVD_Bot@mastodon.social

                                                                  🚨 EUVD-2026-43446

                                                                  📊 Score: 7.1/10 (CVSS v3.1)
                                                                  📦 Product: Chatbot
                                                                  🏢 Vendor: QuantumCloud
                                                                  📅 Updated: 2026-07-13

                                                                  📝 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatBot chatbot allows Stored XSS.This issue affects ChatBot: from n/a through <= 8.3.7.

                                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                                    [?]EUVD Bot » 🤖 🌐
                                                                    @EUVD_Bot@mastodon.social

                                                                    🚨 EUVD-2026-43445

                                                                    📊 Score: 6.5/10 (CVSS v3.1)
                                                                    📦 Product: reCAPTCHA (v2 &amp; v3) for Asgaros Forum
                                                                    🏢 Vendor: Hitesh Chandwani
                                                                    📅 Updated: 2026-07-13

                                                                    📝 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hitesh Chandwani reCAPTCHA (v2 &amp; v3) for Asgaros Forum recaptcha-for-asgaros-forum allows DOM-Based XSS.This ...

                                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                                      [?]EUVD Bot » 🤖 🌐
                                                                      @EUVD_Bot@mastodon.social

                                                                      🚨 EUVD-2026-43443

                                                                      📊 Score: 7.1/10 (CVSS v3.1)
                                                                      📦 Product: Themify Builder
                                                                      🏢 Vendor: themifyme
                                                                      📅 Updated: 2026-07-13

                                                                      📝 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Builder themify-builder allows Reflected XSS.This issue affects Themify Builder: from n/a through <= 7.7.4.

                                                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                                                        [?]BeyondMachines :verified: » 🤖 🌐
                                                                        @beyondmachines1@infosec.exchange

                                                                        Gay & Lesbian Community Services Center Reported Data Breach Affecting Approximately 75,532 Individuals

                                                                        The Gay & Lesbian Community Services Center of Orange County reported a data breach affecting 75,532 individuals after unauthorized access to its network between December 25 and December 26, 2025. The Inc Ransom group claimed responsibility, and the exposed data may include personal and medical information. The organization is offering complimentary identity protection services.

                                                                        ****

                                                                        beyondmachines.net/event_detai

                                                                          [?]TechWire ⚡ » 🤖 🌐
                                                                          @techwire@social.gamefan.net

                                                                          Nothing Phone 3 deal brings this standout phone back down to record low of $599

                                                                          Save $200 on the Nothing Phone 3, dropping it to $599 with flagship specs, triple 50MP cameras, and a standout design.

                                                                          androidauthority.com/nothing-p

                                                                          [Android Authority]

                                                                            [?]thecybersecguru » 🌐
                                                                            @thecybersecguru@infosec.exchange

                                                                            Dutch intelligence agencies are facing fresh scrutiny after a watchdog found unauthorized access to bulk citizen datasets, excessive data retention, and weak audit logging.

                                                                            Privacy advocates now fear some of that data could also be used in AI systems, raising questions about oversight, transparency, and whether agencies have learned from past failures.

                                                                            Full breakdown:

                                                                            thecybersecguru.com/news/aivd-

                                                                              [?]TechWire ⚡ » 🤖 🌐
                                                                              @techwire@social.gamefan.net

                                                                              5 Android features I miss every time I switch to an iPhone

                                                                              It's sad that iPhones still can't do these things in 2026.

                                                                              androidauthority.com/5-android

                                                                              [Android Authority]

                                                                                [?]TechWire ⚡ » 🤖 🌐
                                                                                @techwire@social.gamefan.net

                                                                                Insta360’s next 360° camera leaked with a smaller body, smoother 8K video

                                                                                It's also ready to launch in the US.

                                                                                androidauthority.com/insta360-

                                                                                [Android Authority]

                                                                                  [?]Negative PID SL » 🌐
                                                                                  @negativepid@mastodon.social

                                                                                  [?]secsolution » 🌐
                                                                                  @secsolution@mastodon.social

                                                                                  secsolutionforum 2026: la CER comprende sicurezza cyber e fisica: Il 17 luglio 2026 il Governo adottera’ l’elenco delle entita’ critiche previsto dalla Direttiva CER, mentre dal 17 agosto le aziende designate avranno circa dieci...
                                                                                  dlvr.it/TTVyzz

                                                                                    [?]CVEDatabase.com » 🌐
                                                                                    @cvedatabase@techhub.social

                                                                                    Security Tip: Effective patch management starts with visibility. 🛡️

                                                                                    You can't protect what you don't know exists. Maintain a continuous, automated asset inventory to identify "shadow IT" and legacy systems. Without a clear map of your attack surface, critical vulnerabilities will inevitably go unpatched.

                                                                                    Stay ahead of the threats with real-time intelligence: cvedatabase.com

                                                                                      [?]CVEDatabase.com » 🌐
                                                                                      @cvedatabase@techhub.social

                                                                                      🛡️ New Security Analysis: Weekly CVE Roundup (June 28, 2026). This week, we analyze a critical authentication bypass in next-auth-pro and the persistent threat of race conditions in modern identity management. 📖 Read the full report: cvedatabase.com/blog/weekly-cv

                                                                                        [?]urlDNA.io :verified: » 🤖 🌐
                                                                                        @urldna@infosec.exchange

                                                                                        Possible Phishing 🎣
                                                                                        on: ⚠️hxxps[:]//mxg-e63fe1[.]webflow[.]io
                                                                                        🧬 Analysis at: urldna.io/scan/6a5432413b77500

                                                                                          Back to top - More...