voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
🚨 EUVD-2026-43508
📊 Score: 5.1/10 (CVSS v3.1)
📦 Product: hfs
🏢 Vendor: Rejetto
📅 Updated: 2026-07-13
📝 Rejetto HFS 3.0.0 through 3.2.0 accepts state-changing API requests via the GET method and exempts GET requests from its anti-CSRF header check. A remote attacker can perform administrative actions including account creation and configuration changes leading to...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43508
Possible Phishing 🎣
on: ⚠️hxxp[:]//facebooktechnicalsupportnumber123[.]blogspot[.]com
🧬 Analysis at: https://urldna.io/scan/6a54ccf03b77500004aeff31
#cybersecurity #phishing #infosec #urldna #scam #infosec
🚨 EUVD-2026-43507
📊 Score: 8.7/10 (CVSS v3.1)
📦 Product: shiori
🏢 Vendor: go-shiori
📅 Updated: 2026-07-13
📝 Shiori contains a privilege escalation vulnerability in the account update endpoint that allows authenticated users to modify the owner field without authorization checks. Attackers can escalate to administrator by submitting a crafted PATCH request with ow...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43507
🚨 EUVD-2026-43506
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: hfs
🏢 Vendor: Rejetto
📅 Updated: 2026-07-13
📝 Rejetto HFS 3.0.0 through 3.2.0 renders log entries in the administration panel as HTML without sanitization. A remote unauthenticated attacker can submit a failed login with a crafted username that is written to the error log and executes JavaScript in an admi...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43506
🚨 EUVD-2026-43505
📊 Score: 9.3/10 (CVSS v3.1)
📦 Product: hfs
🏢 Vendor: Rejetto
📅 Updated: 2026-07-13
📝 Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login. A remote attacker can collect a small number of login ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43505
🚨 EUVD-2026-43504
📊 Score: 9.2/10 (CVSS v3.1)
📦 Product: mcp-gitlab
🏢 Vendor: zereight
📅 Updated: 2026-07-13
📝 mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints. Attackers can supply crafted job_id values like ../../../user to escape the intende...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43504
"CISA warns of actively exploited RCE flaws in Joomla extensions"
"[...] Cybersecurity and Infrastructure Security Agency (CISA) is warning that attackers are exploiting vulnerabilities in the iCagenda and Balbooa Forms extensions for Joomla to achieve remote code execution through arbitrary file uploads. The U.S."
Alta Orthopaedics Discloses Data Breach Exposing Patient Medical and Financial Data
Alta Orthopaedics disclosed a data breach after unauthorized actors accessed files containing sensitive patient information, including medical records and Social Security numbers. The Incransom ransomware group claimed responsibility for the attack. The company notified law enforcement and offered credit monitoring to affected individuals.
****
#cybersecurity #infosec #incident #databreach
https://beyondmachines.net/event_details/alta-orthopaedics-discloses-data-breach-exposing-patient-medical-and-financial-data-i-4-1-v-1/gD2P6Ple2L
📰 NSA Warns of Russian FSB Targeting Vulnerable Routers in Critical Infrastructure
NSA, CISA, FBI & Five Eyes partners warn Russian FSB actors (Berserk Bear) are actively exploiting vulnerable network routers in critical infrastructure. Advisory urges hardening SNMP, disabling unused protocols, and prompt patching. #CyberSecurity #...
🌐 cyber[.]netsecops[.]io
📰 APT-C-60 Targets Japan with 'SpyGlace' Malware, Abusing Trusted Cloud Services
The APT-C-60 threat group is targeting organizations in Japan with 'SpyGlace' malware. The campaign abuses trusted services like GitHub, Proton Drive, and jsDelivr for payload delivery and C2 to evade detection. #APT #CyberSecurity #Japan #SpyGlace
🌐 cyber[.]netsecops[.]io
📰 New APT 'Armored Likho' Deploys 'BusySnake' Stealer Against Energy & Government
New APT group 'Armored Likho' targets government & energy sectors in Russia, Brazil, Kazakhstan. The group uses a new Python-based 'BusySnake Stealer' and AI-generated code for its espionage campaigns. 🐍 #APT #ThreatIntel #CyberSecurity #Malware
🌐 cyber[.]netsecops[.]io
U.S. sanctions VPN service used by ransomware groups, targeting infrastructure that enables cybercrime operations.
https://therecord.media/first-vpn-administrator-us-sanctions-ransomware-groups
#cybersecurity #ransomware #threatintel
An ITIL self-assessment evaluates your organization’s IT Service Management (ITSM) practices against ITIL 4 best practices. It identifies capability gaps, benchmarks performance, and highlights key areas to improve service delivery and organizational maturity.
#cybersecurity #governance #risk #technology #gaming #programming #ai #business #engineering
Link: https://blackcatwhitehatsecurity.com
Zimbra: 47 CVEs, 8 exploited in CISA KEV, 100% unpatched. Trust Score: D. Email security risk—patch now. #Zimbra #cybersecurity #infosec
The best all-in-one computers of 2026: Expert tested and reviewed
We tested the best all-in-one computers that combine the power of a desktop PC with a slim, lightweight design.
https://www.zdnet.com/article/best-all-in-one-computer/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
🎉 Breaking news: Our tech-savvy protagonist just turned "data breach" into a personal hobby. 🤦♂️ Yes, because nothing screams #digital #security like one-click uploading your life's work to xAI's servers. Bravo, truly on the cutting edge of #cybersecurity comedy! 🏆 #oops
https://twitter.com/a_green_being/status/2076598897779020159 #data #breach #comedy #tech #news #HackerNews #ngated
Crypto Sector Preps Defense Against Quantum Computing Threat
the $2 trillion crypto market already has a history of hacks. Quantum computers could exacerbate this problem, as they could be used to unscramble the normal methods of encrypting digital information
#Crypto #Quantum #QuantumComputing #encryption #security #cybersecurity
Samsung overtakes Apple as smartphone market sinks to a 13-year low
A massive global memory crisis just pushed smartphone sales to a 13-year low.
https://www.androidauthority.com/counterpoint-research-q2-2026-smartphone-shipment-report-3686931/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
The digital mind: how technology shapes mental health #negativepid #digitalInvestigations #OSINT #cybersecurity #AI #tech #onlineInvestigations #robotics #cyberpsychology #cybercrime https://negativepid.blog/the-digital-mind-how-technology-shapes-mental-health/?utm_source=mastodon&utm_medium=social&utm_campaign=fedica-Negative-PID-Blog
Grok uploaded my user directory to xAI's servers
https://twitter.com/a_green_being/status/2076598897779020159
Comments: https://news.ycombinator.com/item?id=48892512
#HackerNews #Grok #xAI #userdirectory #data #privacy #cybersecurity
🚨 EUVD-2026-43458
📊 Score: 7.1/10 (CVSS v3.1)
📦 Product: JobSearch
🏢 Vendor: eyecix
📅 Updated: 2026-07-13
📝 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch wp-jobsearch allows Stored XSS.This issue affects JobSearch: from n/a through <= 3.2.9.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43458
🚨 EUVD-2026-43457
📊 Score: 7.1/10 (CVSS v3.1)
📦 Product: Simple File List
🏢 Vendor: Mitchell Bennis
📅 Updated: 2026-07-13
📝 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mitchell Bennis Simple File List simple-file-list allows Reflected XSS.This issue affects Simple File List: from n/a through <= 6.3.8.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43457
🚨 EUVD-2026-43456
📊 Score: 8.8/10 (CVSS v3.1)
📦 Product: aBlocks
🏢 Vendor: Kodezen LLC
📅 Updated: 2026-07-13
📝 Incorrect Privilege Assignment vulnerability in Kodezen LLC aBlocks ablocks allows Privilege Escalation.This issue affects aBlocks: from n/a through < 2.9.1.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43456
🚨 EUVD-2026-43455
📊 Score: 7.1/10 (CVSS v3.1)
📦 Product: PropertyHive
🏢 Vendor: Property Hive
📅 Updated: 2026-07-13
📝 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows Reflected XSS.This issue affects PropertyHive: from n/a through <= 2.2.3.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43455
🚨 EUVD-2026-43454
📊 Score: 7.1/10 (CVSS v3.1)
📦 Product: FormyChat
🏢 Vendor: WPPOOL
📅 Updated: 2026-07-13
📝 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL FormyChat social-contact-form allows Stored XSS.This issue affects FormyChat: from n/a through <= 2.15.3.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43454
🚨 EUVD-2026-43453
📊 Score: 7.1/10 (CVSS v3.1)
📦 Product: Extensions for Leaflet Map
🏢 Vendor: hupe13
📅 Updated: 2026-07-13
📝 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hupe13 Extensions for Leaflet Map extensions-leaflet-map allows DOM-Based XSS.This issue affects Extensions for Leaflet Map: from n/a thro...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43453
🚨 EUVD-2026-43452
📊 Score: 7.5/10 (CVSS v3.1)
📦 Product: Advanced Forms
🏢 Vendor: Phil Kurth
📅 Updated: 2026-07-13
📝 Missing Authorization vulnerability in Phil Kurth Advanced Forms advanced-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Forms: from n/a through <= 1.9.3.7.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43452
🚨 EUVD-2026-43449
📊 Score: 6.5/10 (CVSS v3.1)
📦 Product: MStore API
🏢 Vendor: FluxBuilder
📅 Updated: 2026-07-13
📝 Missing Authorization vulnerability in FluxBuilder MStore API mstore-api allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MStore API: from n/a through <= 4.18.4.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43449
🚨 EUVD-2026-43444
📊 Score: 7.1/10 (CVSS v3.1)
📦 Product: ElementInvader Addons for Elementor
🏢 Vendor: Element Invader
📅 Updated: 2026-07-13
📝 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows DOM-Based XSS.This issue ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43444
🚨 EUVD-2026-43442
📊 Score: 6.5/10 (CVSS v3.1)
📦 Product: WowAddons
🏢 Vendor: wpxpo
📅 Updated: 2026-07-13
📝 Missing Authorization vulnerability in WPXPO WowAddons product-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WowAddons: from n/a through <= 1.6.8.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43442
🚨 EUVD-2026-43451
📊 Score: 6.5/10 (CVSS v3.1)
📦 Product: Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More
🏢 Vendor: WPDeveloper
📅 Updated: 2026-07-13
📝 Improper Validation of Specified Quantity in Input vulnerability in WPDeveloper Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More better...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43451
🚨 EUVD-2026-43450
📊 Score: 7.1/10 (CVSS v3.1)
📦 Product: Jobmonster
🏢 Vendor: NooTheme
📅 Updated: 2026-07-13
📝 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobmonster noo-jobmonster allows Reflected XSS.This issue affects Jobmonster: from n/a through <= 4.8.5.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43450
🚨 EUVD-2026-43448
📊 Score: 7.2/10 (CVSS v3.1)
📦 Product: WPJAM Basic
🏢 Vendor: Denishua
📅 Updated: 2026-07-13
📝 Server-Side Request Forgery (SSRF) vulnerability in denishua WPJAM Basic wpjam-basic allows Server Side Request Forgery.This issue affects WPJAM Basic: from n/a through <= 7.0.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43448
🚨 EUVD-2026-43447
📊 Score: 8.8/10 (CVSS v3.1)
📦 Product: WPJAM Basic
🏢 Vendor: Denishua
📅 Updated: 2026-07-13
📝 Deserialization of Untrusted Data vulnerability in denishua WPJAM Basic wpjam-basic allows Object Injection.This issue affects WPJAM Basic: from n/a through <= 7.0.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43447
🚨 EUVD-2026-43446
📊 Score: 7.1/10 (CVSS v3.1)
📦 Product: Chatbot
🏢 Vendor: QuantumCloud
📅 Updated: 2026-07-13
📝 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatBot chatbot allows Stored XSS.This issue affects ChatBot: from n/a through <= 8.3.7.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43446
🚨 EUVD-2026-43445
📊 Score: 6.5/10 (CVSS v3.1)
📦 Product: reCAPTCHA (v2 & v3) for Asgaros Forum
🏢 Vendor: Hitesh Chandwani
📅 Updated: 2026-07-13
📝 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hitesh Chandwani reCAPTCHA (v2 & v3) for Asgaros Forum recaptcha-for-asgaros-forum allows DOM-Based XSS.This ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43445
🚨 EUVD-2026-43443
📊 Score: 7.1/10 (CVSS v3.1)
📦 Product: Themify Builder
🏢 Vendor: themifyme
📅 Updated: 2026-07-13
📝 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Builder themify-builder allows Reflected XSS.This issue affects Themify Builder: from n/a through <= 7.7.4.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43443
Gay & Lesbian Community Services Center Reported Data Breach Affecting Approximately 75,532 Individuals
The Gay & Lesbian Community Services Center of Orange County reported a data breach affecting 75,532 individuals after unauthorized access to its network between December 25 and December 26, 2025. The Inc Ransom group claimed responsibility, and the exposed data may include personal and medical information. The organization is offering complimentary identity protection services.
****
#cybersecurity #infosec #incident #databreach
https://beyondmachines.net/event_details/gay-lesbian-community-services-center-of-orange-county-discloses-data-breach-affecting-approximately-75532-individuals-z-q-o-0-j/gD2P6Ple2L
Nothing Phone 3 deal brings this standout phone back down to record low of $599
Save $200 on the Nothing Phone 3, dropping it to $599 with flagship specs, triple 50MP cameras, and a standout design.
https://www.androidauthority.com/nothing-phone-3-deal-2026-3686942/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Dutch intelligence agencies are facing fresh scrutiny after a watchdog found unauthorized access to bulk citizen datasets, excessive data retention, and weak audit logging.
Privacy advocates now fear some of that data could also be used in AI systems, raising questions about oversight, transparency, and whether agencies have learned from past failures.
Full breakdown:
https://thecybersecguru.com/news/aivd-mivd-ai-training-citizen-data/
#CyberSecurity #Privacy #AI #Infosec #DataProtection #Surveillance #Netherlands #GDPR
5 Android features I miss every time I switch to an iPhone
It's sad that iPhones still can't do these things in 2026.
https://www.androidauthority.com/5-android-features-i-miss-when-switching-iphone-3685743/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Insta360’s next 360° camera leaked with a smaller body, smoother 8K video
It's also ready to launch in the US.
https://www.androidauthority.com/insta360-x6-leak-3686738/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Organized cybercrime: the rise of cybercrime syndicates #negativepid #digitalInvestigations #OSINT #cybersecurity #AI #tech #onlineInvestigations #robotics #cyberpsychology #cybercrime https://negativepid.blog/organized-cybercrime-the-rise-of-cybercrime-syndicates/?utm_source=mastodon&utm_medium=social&utm_campaign=fedica-Negative-PID-Blog
secsolutionforum 2026: la CER comprende sicurezza cyber e fisica: Il 17 luglio 2026 il Governo adottera’ l’elenco delle entita’ critiche previsto dalla Direttiva CER, mentre dal 17 agosto le aziende designate avranno circa dieci...
#secsolutionforum #DirettivaCER #resilienza #sicurezzafisica #cybersecurity http://dlvr.it/TTVyzz
Security Tip: Effective patch management starts with visibility. 🛡️
You can't protect what you don't know exists. Maintain a continuous, automated asset inventory to identify "shadow IT" and legacy systems. Without a clear map of your attack surface, critical vulnerabilities will inevitably go unpatched.
Stay ahead of the threats with real-time intelligence: https://cvedatabase.com
#InfoSec #CyberSecurity #VulnerabilityManagement #CVE #SysAdmin
🛡️ New Security Analysis: Weekly CVE Roundup (June 28, 2026). This week, we analyze a critical authentication bypass in next-auth-pro and the persistent threat of race conditions in modern identity management. 📖 Read the full report: https://cvedatabase.com/blog/weekly-cve-roundup-tackling-authentication-logic-flaws-and-race-conditions-june--2026-06-28 #CyberSecurity #CVE #Infosec #WebDev #PatchManagement
Possible Phishing 🎣
on: ⚠️hxxps[:]//mxg-e63fe1[.]webflow[.]io
🧬 Analysis at: https://urldna.io/scan/6a5432413b77500008cd6880
#cybersecurity #phishing #infosec #urldna #scam #infosec