voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
Alert: AI-agent ransomware like "JadePuffer" is weaponizing application frameworks. Secure your perimeter with our latest Cyber Mind Weekly Brief, featuring tactical intelligence on Langflow and ColdFusion vulnerabilities, plus essential hardening protocols. Stay ahead. https://thecybermind.co/rxz9
Global tensions escalate with US-Iran military exchanges near the Strait of Hormuz (July 11-12). In technology, Apple has sued OpenAI for alleged trade secret theft concerning ex-employees (July 11). Cybersecurity faces critical threats, including the deployment of iOS DarkSword spyware and major data breaches impacting Instructure and Conduent (July 11).
OpenAI is discontinuing ChatGPT Atlas, its standalone desktop browser
ChatGPT Atlas, OpenAI’s standalone desktop browser, is being sunset in favor of the new ChatGPT desktop app.
https://9to5mac.com/2026/07/09/openai-is-discontinuing-chatgpt-atlas-its-standalone-desktop-browser/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
Security Tip: Shift left by automating dependency scanning. 🛡️
Modern apps rely on hundreds of third-party libraries. Manual checks are impossible. By integrating vulnerability scanners directly into your CI/CD pipeline, you can automatically block builds that include known CVEs.
Pro tip: Set up alerts for new vulnerabilities discovered in your existing production code.
Stay informed on the latest threats at https://cvedatabase.com
Possible Phishing 🎣
on: ⚠️hxxps[:]//forms[.]gle/GttLLVQxCuHBTH44A
🧬 Analysis at: https://urldna.io/scan/6a5397bf3b77500005ac90ca
#cybersecurity #phishing #infosec #urldna #scam #infosec
iPhone 18 Pro could bring three controversial design changes
We’re just two months away from Apple announcing the iPhone 18 Pro. Rumors suggest Apple could have three design changes in store that could be unpopular among some iPhone 18 Pro buyers …
https://9to5mac.com/2026/07/09/iphone-18-pro-could-bring-three-controversial-design-changes/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
Apple stops signing iOS versions for several older iPhones and iPads [U: Signing restored]
Update July 9, 3:28 p.m. ET: As Aaron Perris noted on X, Apple has resumed signing the iOS versions listed in this article. As a result, owners of the affected legacy iPhone and iPad models can once again restore to tho…
https://9to5mac.com/2026/07/09/apple-stops-signing-ios-versions-for-several-older-iphones-and-ipads/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
Possible Phishing 🎣
on: ⚠️hxxps[:]//gudgsugd[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a54081b3b77500008cd64d5
#cybersecurity #phishing #infosec #urldna #scam #infosec
🚨 EUVD-2026-43248
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: coolify, coolify
🏢 Vendor: coollabsio
📅 Updated: 2026-07-12
📝 A vulnerability was detected in coollabsio Coolify up to 4.1.1. The impacted element is an unknown function of the file /app/Policies/ of the component Policy Handler. Performing a manipulation results in missing authorization. Remote exploitatio...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43248
🚨 EUVD-2026-43247
📊 Score: 8.5/10 (CVSS v3.1)
📦 Product: CatchPulse, CatchPulse, CatchPulse (+1 more)
🏢 Vendor: SecureAge
📅 Updated: 2026-07-12
📝 A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. The affected element is an unknown function in the library saappctl.sys of the component Driver. Such manipulation leads to heap-based buf...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43247
iVANKY FusionDock Ultra: The Thunderbolt 5 dock built for Mac workflows
I have used plenty of docking stations over the years, and it seems the desktop dock market is as crowded as ever. I have tested smaller portable docks, to larger stationary docks that give you all the ports you would e…
https://9to5mac.com/2026/07/09/ivanky-fusiondock-ultra-thunderbolt-5-dock-built-for-mac-workflows/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
Beginner homelab apps, ranked (fight me)
S tier = ten-minute install, works forever, zero maintenance: AdGuard Home, Uptime Kuma, Vaultwarden. A tier needs a weekend. B tier will humble you. Comment your rearrangement.
⚠️ sys/kern/sysv_sem.c in OpenBSD through 7.9 has a use-after-free allowing local privilege escalation to root. This is a context switch use-after-free after tsleep in sys_semget().
Keeping security configuration synchronized with a rapidly changing application is a challenge for many development teams. AIWAF is exploring a different approach by using AST analysis to build an application model directly from the source code, helping security stay aligned with the application instead of relying solely on manual configuration.
#ApplicationSecurity #CyberSecurity #DevSecOps #OpenSource #Python #AST
🟠 CVE-2026-58596 - High (8.3)
Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58596/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-40007 - High (7.5)
Uncontrolled Recursion, Uncontrolled Resource Consumption vulnerability in Apache IoTDB.
When pipe_air_gap_receiver_enabled=true, the IoTDB AirGap receiver's
readLength method calls itself recursively each time it recognises the
E-language prefix ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-40007/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🔴 CVE-2026-40008 - Critical (9.8)
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache IoTDB.
The pipe processor reads a fully
qualified Java class name and
instantiates it using Class.forName().newInstance() without any
valida...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-40008/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-40452 - High (7.5)
Incorrect Authorization, Improper Access Control vulnerability in Apache IoTDB.
Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticated users.
This issue affects Apache IoTDB: from 1.3.5 before 1.3.8,...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-40452/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-10666 - High (8.1)
parse_ipv4() in subsys/net/ip/utils.c (reached via net_ipaddr_parse() for strings of the form "a.b.c.d:port") copies the port substring into a fixed 17-byte stack buffer (char ipaddr[NET_IPV4_ADDR_LEN + 1]) using a length of str_len - end - 1, whe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-10666/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-10667 - High (7.8)
Zephyr's dynamic kernel-object tracking (kernel/userspace/userspace.c, formerly kernel/userspace.c) maintains a doubly-linked list (obj_list) of dynamically allocated kernel objects. Iteration over this list in k_object_wordlist_foreach() was perf...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-10667/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-40454 - High (7.5)
Out-of-bounds Read, Improper Input Validation vulnerability in Apache IoTDB C++ client.
Out-of-bounds reads in IoTDB C++ client TsBlock deserializer crash client
process on malformed server data.
This issue affects Apache IoTDB C++ client: from ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-40454/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🔴 CVE-2026-28564 - Critical (9.8)
Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache IoTDB.
REST Basic Authentication Accepts Stale Cached Credentials
This issue affects Apache IoTDB: from 1.0.0 before 2.0.10.
Users are recommended ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-28564/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-13347 - High (7.5)
The Hide My WP Lite plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 1.3 via the he_wrapper_js and he_wrapper_css query parameters processed by the elementor_assets_filter() function. This is due to the fun...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-13347/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Possible Phishing 🎣
on: ⚠️hxxps[:]//rayx81194[.]github[.]io/amazon/
🧬 Analysis at: https://urldna.io/scan/6a5327323b77500009eba267
#cybersecurity #phishing #infosec #urldna #scam #infosec
PSA: Flip these two Instagram toggles now to stop people using your face
Meta this week launched its own AI image model integrated into the Instagram app. While this might sound useful, it comes with rather a big privacy issue: by default, anyone can use your profile photo and posts as promp…
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
Here in Washington State, USA, my son has had a computer at school since Kindergarten. So far, zero lessons in online safety. I don't think depending on schools alone for your kids' safety is the right call anywhere in the world.
#cybersecurity #onlinesaftey #kids #it
https://sundaytribune.co.za/business-report/economy/4636735194529792/
RedHook Android malware isn't just another banking trojan. It's now leveraging your phone's own Accessibility Service to enable Developer Options and Wireless ADB, then using a loopback connection to gain shell privileges (UID 2000). This allows it to deploy a Shizuku-based framework for extensive device control, from screen streaming to app manipulation, all without root. A truly unsettling…
#cybersecurity #redhook #android
🤖 This post was AI-generated.
Apple supplier Luxshare share listing sets new record then fell back
Luxshare is one of the ultimate rags-to-riches stories, founded by a woman who started out as a Foxconn assembly-line worker and growing into a multi-billion dollar company and key Apple supplier. It’s been a publicly t…
https://9to5mac.com/2026/07/09/apple-supplier-luxshare-share-listing-sets-new-record-then-fell-back/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
Possible Phishing 🎣
on: ⚠️hxxps[:]//validate-bell0-mailbox[.]weebly[.]com/
🧬 Analysis at: https://urldna.io/scan/6a5381e13b77500005ac8ec8
#cybersecurity #phishing #infosec #urldna #scam #infosec
iPhone manufacturing in India gets a tariff boost
As reported by Reuters, India continued its push to become a larger electronics manufacturing hub today by removing import duties on select parts used in smartphones and other devices. Here are the details.
https://9to5mac.com/2026/07/09/iphone-manufacturing-in-india-gets-a-tariff-boost/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
PSA: T-Mobile’s free Wi-Fi offer ends tomorrow for United Airlines flights
Say goodbye to free in-flight Wi-Fi.
https://www.androidauthority.com/tmobile-free-wifi-ends-on-united-flights-3686655/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Possible Phishing 🎣
on: ⚠️hxxps[:]//pub-4e0d515d9c79417e8b4042dfa120d149[.]r2[.]dev/shyfacewebnnf[.]html?koiclid=DtsiGAESnl
🧬 Analysis at: https://urldna.io/scan/6a5335243b77500005ac8860
#cybersecurity #phishing #infosec #urldna #scam #infosec
🟠 CVE-2026-12685 - High (7.5)
The EscortWP escortwp WordPress theme through 3.6.2 was distributed with a vendor-authored, obfuscated backdoor that lets an unauthenticated attacker who supplies a hard-coded, per-build key permanently delete all of the site's content, and that c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12685/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🔴 CVE-2026-15300 - Critical (9.1)
The GEO my WP plugin for WordPress was vulnerable to SQL Injection via the 'distance', 'lat', and 'lng' parameters in versions up to, and including, 4.5.4. The values were read from $_SERVER['QUERY_STRING'] via parse_str() (bypassing wp_magic_quot...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15300/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-15290 - High (7.5)
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to blind SQL Injection via the search parameter in all versions up to, and including, 2.10.1 du...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15290/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Wikimedia: 137 CVEs, avg CVSS 6.5. 0 CISA KEV exploited but 97% unpatched. Trust Score: C. Open source ≠ secure. Patch MediaWiki now! #Wikimedia #infosec #cybersecurity
Report: Apple interested in startup that runs giant AI models on iPhone without servers
The Information reports that Apple may be interested in PrismML’s technology. The firm is focused on shrinking AI models that generally require servers to function, offering on-device functionality with comparable intel…
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
🔴 CVE-2026-56260 - Critical (9.1)
Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths without validation, allowing an attacker to supply absolut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56260/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🔴 CVE-2026-56271 - Critical (9.8)
Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise passport authentication middleware ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56271/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-56313 - High (8.1)
Capgo before 12.128.2 contains a cross-organization account disruption vulnerability in the SSO prelink endpoint that allows enterprise administrators to delete password identities of users in foreign organizations. Attackers with org.update_setti...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56313/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-59260 - High (8.8)
OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users to execute the Samba daemon with caller-controlled command-line arguments. Attackers can pass arbitrary Samba global options suc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59260/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-56238 - High (7.5)
Capgo before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST global_stats endpoint that allows unauthenticated attackers to read sensitive financial and operational metrics using only the public apikey. Remote a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56238/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-56241 - High (8.3)
Capgo before 12.128.2 contains a privilege escalation vulnerability where demoted super_admin users retain access to delete_non_compliant_bundles and count_non_compliant_bundles RPCs due to stale org_users.user_right column not being cleared durin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56241/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
From concept to reality: what is AI? #negativepid #digitalInvestigations #OSINT #cybersecurity #AI #tech #onlineInvestigations #robotics #cyberpsychology #cybercrime https://negativepid.blog/from-concept-to-reality-what-is-ai/?utm_source=mastodon&utm_medium=social&utm_campaign=fedica-Negative-PID-Blog