voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
Operation Capsule Vault: RokRAT Attack Chain Analysis Using EMBED_PAYLOAD_v2
A sophisticated spear-phishing campaign targeted individuals in research, policy, and academic fields through emails disguised as materials from an actual academic conference. The attack leveraged a cloud storage link delivering a malicious ISO file containing a PIF executable disguised as a PDF document. The multi-stage loader used EMBED_PAYLOAD_v2 structure to embed both legitimate documents and malicious payloads, which were sequentially extracted and executed in memory. Shellcode injection into explorer.exe ultimately deployed a RokRAT variant communicating with cloud-based C2 infrastructure via pCloud, Dropbox, and Yandex Cloud. The campaign demonstrated advanced social engineering by exploiting information from a real event, combined with sophisticated evasion techniques including process injection and cloud-based command-and-control operations. Attribution analysis linked the activity to APT37 based on infrastructure overlap, code similarities, and operational patterns.
Pulse ID: 6a5414fab18f9d7456d7eda8
Pulse Link: https://otx.alienvault.com/pulse/6a5414fab18f9d7456d7eda8
Pulse Author: AlienVault
Created: 2026-07-12 22:28:10
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APT37 #Cloud #CodeInjection #CyberSecurity #Dropbox #Email #InfoSec #OTX #OpenThreatExchange #PDF #Phishing #RAT #ShellCode #SocialEngineering #SpearPhishing #bot #pCloud #AlienVault
Sign here… and install an unwanted RMM
A sophisticated phishing campaign impersonates DocuSign's branding to compromise victims through malicious JavaScript embedded in fraudulent webpages. The attack leverages social engineering to trick users into downloading MSI installers disguised as legitimate DocuSign updates or documents. These payloads establish remote access through legitimate Remote Monitoring and Management tools from Atera Network Ltd and ConnectWise/ScreenConnect. Investigation revealed extensive attacker infrastructure spanning hundreds of domains, with tracking mechanisms via Telegram bots collecting detailed victim telemetry including IP addresses, geolocation, ISP information, and user-agent strings. The campaign targets both Windows and macOS systems, utilizing deployment kits across multiple infrastructures with similar URL patterns and JavaScript mechanisms.
Pulse ID: 6a512b20f12a5adf6bf2c1b3
Pulse Link: https://otx.alienvault.com/pulse/6a512b20f12a5adf6bf2c1b3
Pulse Author: AlienVault
Created: 2026-07-10 17:25:52
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ConnectWise #CyberSecurity #InfoSec #Java #JavaScript #Mac #MacOS #OTX #OpenThreatExchange #Phishing #SMS #ScreenConnect #SocialEngineering #Telegram #Windows #bot #AlienVault
How WP-SHELLSTORM Exposed 1.4M WordPress Sites
A financially motivated cybercrime group operating as WP-SHELLSTORM was exposed when their Python SimpleHTTPServer remained open for 22 days, revealing toolkits, logs, and target lists. The operation targeted over 1.4 million domains using 27 weaponized CVEs and deployed more than 5,700 active webshells across WordPress and Joomla platforms. A parallel campaign targeted Apache Nacos, XXL-Job, and Spring Boot infrastructure, exfiltrating 613 configuration files from 11 victims across nine organizations in May 2026, compromising cloud credentials, database passwords, and payment system keys. The Chinese-linked actor utilized sophisticated obfuscated webshells, botnet infrastructure, and implants designed to evade detection by mimicking legitimate system processes.
Pulse ID: 6a54b716f22fd928cabf4eb8
Pulse Link: https://otx.alienvault.com/pulse/6a54b716f22fd928cabf4eb8
Pulse Author: AlienVault
Created: 2026-07-13 09:59:50
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APAC #Apache #Chinese #Cloud #CyberCrime #CyberSecurity #HTTP #HTTPS #InfoSec #Mimic #OTX #OpenThreatExchange #Password #Passwords #Python #RAT #RDP #Word #Wordpress #bot #botnet #AlienVault
Survey suggests readers treat their core Android apps like a comfy couch
Almost 9 in every 10 readers prefer to stick with what they know.
https://www.androidauthority.com/switch-android-apps-poll-results-3686761/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Microsoft leverages advanced AI agents like MDASH to accelerate Windows vulnerability management and secure codebases.
#WindowsSecurity #AIVulnerabilityScanning #MicrosoftMDASH #CyberSecurity
What’s the point of foldable Pixel phones anymore?
Hardware wins foldable wars, and Google isn’t keeping up.
https://www.androidauthority.com/foldable-pixel-phones-whats-the-point-3684076/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Possible Phishing 🎣
on: ⚠️hxxps[:]//rauma-update[.]weebly[.]com/
🧬 Analysis at: https://urldna.io/scan/6a54a9173b77500004aefa4a
#cybersecurity #phishing #infosec #urldna #scam #infosec
"The hidden cybersecurity risk sitting in every SMB office"
"Printers remain cybersecurity’s overlooked weak link, putting sensitive SMB data at risk."
https://www.techradar.com/pro/the-hidden-cybersecurity-risk-sitting-in-every-smb-office
One Misconfigured Server, Three Active Campaigns: Full exposure of three AiTM Phishing Operators
A misconfigured Python HTTP server on a Budapest VPS exposed the complete operational infrastructure of three distinct phishing operators. The investigation uncovered codemado, an Egyptian threat actor operating since 2018, running a full AiTM platform with custom tools including MaDoO Blaster; saroula01, deploying OAuth Device Code Flow attacks that accumulated 218 victims across 12 countries over a year; and mail-argenta, a Nigerian operator identified through infostealer logs containing his own credentials. All three actors leveraged customized Evilginx forks and AI-assisted development to build MFA-bypass infrastructure from public GitHub repositories. The campaigns targeted Microsoft 365 accounts primarily, with codemado maintaining ties to RockyBelling's "The Quarry" cybercrime ecosystem. The exposed server contained phishing configurations, credential logs, RMM installers, combolists, and Telegram session files, revealing sustained operations from at least January 2025 through May 2026.
Pulse ID: 6a54bfc57c70fae743cb883e
Pulse Link: https://otx.alienvault.com/pulse/6a54bfc57c70fae743cb883e
Pulse Author: AlienVault
Created: 2026-07-13 10:36:53
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AitM #CyberCrime #CyberSecurity #GitHub #HTTP #InfoSec #InfoStealer #MFA #Microsoft #OTX #OpenThreatExchange #Phishing #Python #RAT #Telegram #bot #AlienVault
The details for our second keynote just dropped! 🤩 Jahmel Harris will share his insights on "Building a Penetration Testing Lab in 2026" and we're here for it.
Check out the full description here: https://opensecurityconference.org/conference/keynotes
You also don't want to miss this? Register now for #osco26: https://opensecurityconference.org/conference/registration
#osco #CyberSecurity #Security #InfoSec #AppSec [lisi]
This $185 pocket computer with a keyboard is a brilliant idea, and we’re hoping it ships
Finally, a gadget that won't tempt you into opening social media.
https://www.androidauthority.com/pocketmage-crowdfunded-computer-3686775/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
jscrambler npm Package Compromised in Supply Chain Attack
A malicious release of the jscrambler npm package (version 8.14.0) was published on July 11, 2026, introducing hidden native binaries that execute automatically during installation. The compromised package added an undocumented preinstall hook executing dist/setup.js, which deploys platform-specific binaries for Linux, macOS, and Windows embedded in an obfuscated CSI container. The payload is a Rust-built infostealer targeting cryptocurrency wallets, AI coding assistants, cloud credentials (AWS, GCP, Azure), browser data, and messaging applications. String obfuscation uses per-string ChaCha20-Poly1305 encryption. The threat actor published five malicious versions (8.14.0, 8.16.0, 8.17.0, 8.18.0, 8.20.0) over three hours, evolving delivery methods to evade detection. Version 8.22.0 is confirmed clean. The package receives approximately 15,800 weekly downloads, affecting developer workstations, CI systems, and build pipelines with access to credentials and secrets.
Pulse ID: 6a52d7f22883fcd1f11046c2
Pulse Link: https://otx.alienvault.com/pulse/6a52d7f22883fcd1f11046c2
Pulse Author: AlienVault
Created: 2026-07-11 23:55:30
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #Azure #Browser #ChaCha20 #Cloud #CyberSecurity #Encryption #InfoSec #InfoStealer #Linux #Mac #MacOS #NPM #OTX #OpenThreatExchange #Rust #SupplyChain #Windows #bot #cryptocurrency #AlienVault
GitHub: 107 CVEs tracked, avg CVSS 6.95, max 9.8. 92% unpatched. Trust Score: C. Code supply chain at risk—patch your repos. #GitHub #infosec #cybersecurity
Malicious Go Module Exposes GitHub Malware Lure Network Spanning 222 Repositories
Pulse ID: 6a546e3af140da650cba1b67
Pulse Link: https://otx.alienvault.com/pulse/6a546e3af140da650cba1b67
Pulse Author: Tr1sa111
Created: 2026-07-13 04:48:58
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #GitHub #InfoSec #Malware #OTX #OpenThreatExchange #bot #Tr1sa111
🟠 CVE-2026-7162 - High (7.8)
Successful
exploitation of the integer overflow vulnerability could allow an attacker to
achieve system-level access to the affected software.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-7162/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-9492 - High (7.8)
The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) developed by GIGABYTE Technology has an Improper Access Control vulnerability. Authenticated local attackers can send specific IOCTL commands through the driver MyPort...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9492/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
SANDISK Phone Drive for iPhone is a great solution to low storage
Each time we buy a phone, we have to decide which storage tier to go for, and that requires a judgment call – not just about how much storage we need today, but how much we are likely to need for however long we end up …
https://9to5mac.com/2026/07/11/sandisk-phone-drive-iphone-great-solution-to-low-storage/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
Indie App Spotlight: ‘Route 25’ is an all-in-one social app for Pokémon collectors
Welcome to Indie App Spotlight. This is a weekly 9to5Mac series where we showcase the latest apps in the indie app world. If you’re a developer and would like your app featured, get in contact. Many apps make it easy to…
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
Possible Phishing 🎣
on: ⚠️hxxp[:]//project[.]activeadvice[.]eu/wp-includes/br/
🧬 Analysis at: https://urldna.io/scan/6a53cfe43b77500008cd5e78
#cybersecurity #phishing #infosec #urldna #scam #infosec
Indirect prompt injection exploits AI agent vulnerabilities through malicious web content. Attackers manipulate language models using hidden instructions.
Samsung may delay the TriFold 2, but another wild phone could arrive first
We may see a slidable Samsung phone before the next TriFold comes into the picture.
https://www.androidauthority.com/samsung-galaxy-z-trifold-2-delay-leak-3686677/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
They've been quiet for a few weeks, but it looks like it was overly optimistic to hope that we'd heard the last of 2019 (the hacker, not the year).
But, no, here they are, with yet another Australian data breach impacting what looks like many thousands of Aussies.
Samsung’s HomeUp update is finally rolling out with powerful new gestures
It's getting more customization options as well.
https://www.androidauthority.com/samsung-homeup-new-gestures-customization-3686698/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
🚨 EUVD-2026-43280
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: self-rag
🏢 Vendor: AkariAsai
📅 Updated: 2026-07-13
📝 A vulnerability was determined in AkariAsai self-rag up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99. Affected by this issue is the function Indexer.deserialize_from of the file retrieval_lm/src/index.py of the component retrieval_lm. Executing a manipulat...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43280
🚨 EUVD-2026-43279
📊 Score: 5.1/10 (CVSS v3.1)
📦 Product: DeDeCMS
📅 Updated: 2026-07-13
📝 A security flaw has been discovered in DedeCMS 5.7.118. Impacted is an unknown function of the file /plus/search.php of the component Column Management. Performing a manipulation of the argument Column Name results in code injection. The attack is possible to be carried out r...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43279
🚨 EUVD-2026-43278
📊 Score: 4.8/10 (CVSS v3.1)
📦 Product: Online Book Store System
🏢 Vendor: SourceCodester
📅 Updated: 2026-07-13
📝 A vulnerability was identified in SourceCodester Online Book Store System 1.0. This issue affects some unknown processing of the component User Management Module. Such manipulation of the argument Name/Username leads to cross site scr...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43278
🚨 EUVD-2026-43277
📊 Score: 4.8/10 (CVSS v3.1)
📦 Product: HashNeRF-pytorch
🏢 Vendor: yashbhalgat
📅 Updated: 2026-07-13
📝 A vulnerability has been found in yashbhalgat HashNeRF-pytorch up to 82885e698295982504eb6a26d060a6b2473e3706. Affected by this issue is the function torch.load of the file run_nerf.py of the component Checkpoint File Handler. The manipulation o...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43277
🚨 EUVD-2026-43276
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: WuzhiCMS, WuzhiCMS
📅 Updated: 2026-07-13
📝 A flaw has been found in WuzhiCMS up to 4.1.0. Affected by this vulnerability is the function config/listimage of the file /index.php?m=attachment&f=index&v=upload of the component Attachment API. Executing a manipulation can lead to information disclosure. The att...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43276
Possible Phishing 🎣
on: ⚠️hxxps[:]//webmailupdatecompa[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a540e723b77500008cd6574
#cybersecurity #phishing #infosec #urldna #scam #infosec
CISA Adds Two Joomla Zero-Days to KEV Catalog: Deadline July 13 https://deafnews.it/en/article/cisa-adds-two-joomla-zero-days-to-kev-catalog-deadline-july-13 #Cybersecurity
F5: 128 CVEs, 100% unpatched. 2 CISA KEV exploited. Trust Score: D. 86 critical/high flaws. Patch now or risk exploitation. #F5 #cybersecurity #infosec
This strange Pixel bug keeps launching Circle to Search, and no one knows why
Circle to Search is making itself way too comfortable on some Pixels.
https://www.androidauthority.com/android-17-circle-to-search-bug-3686687/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Suspected Armored Likho APT hackers deploy the new BusySnake Stealer to target government agencies and electric power sectors globally.
#BusySnakeStealer #ArmoredLikho #CyberSecurity #Malware #APT
Run Kali Linux and isolated browsers on a $99 ZimaBoard 2 with zero lag. This Kasm setup turns your homelab into a cyber lab. #Homelab #Linux #Cybersecurity
https://www.valtersit.com/turn-your-zimaboard-2-into-an-ultimate-cyber-lab-with-kasm-2026-guide/
🔴 CVE-2026-15511 - Critical (9.8)
A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. Affected by this vulnerability is the function system_wl_upload_pic_file of the file /usr/bin/webmgnt of the component FastCGI Backend. This manipulation of the argument filena...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15511/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-15506 - High (7.8)
A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. The affected element is an unknown function in the library saappctl.sys of the component Driver. Such manipulation leads to heap-based buffer overflow. An attack has ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15506/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-15288 - High (7.5)
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 2.2.1. This is due to the plugin accepting the payment amount directly from user-contr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15288/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🔴 CVE-2026-15282 - Critical (9.8)
The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'insapp_upload_image_as_attachment' function in all versions up to, and including, 1.2. This makes it possible for unau...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15282/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
iPhone Ultra battery details allegedly revealed in new leak
As we approach the official announcement of Apple’s iPhone Ultra in September, more specs continue to leak. A new rumor today claims to reveal exactly how big the foldable iPhone’s battery will be.
https://9to5mac.com/2026/07/10/iphone-ultra-battery-details-allegedly-revealed-in-new-leak/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
With ChatGPT Atlas shutting down, here are the AI browsers people actually use
OpenAI is pulling the plug on its dedicated web browser, ChatGPT Atlas. Instead of investing in an AI browser with a small user base, the company is improving agentic web use features inside the new ChatGPT desktop app.…
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
These are my favorite new Messages features in iOS 27 [Video]
If you were to just look at the Messages app in iOS 27, you might not think much has changed, but that is far from the truth. Under the hood, Apple has completely revamped the Messages experience, making it faster, smar…
https://9to5mac.com/2026/07/10/these-are-my-favorite-new-messages-features-in-ios-27-video/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]