voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]thecybermind » 🌐
@thecybermind@mastodon.social

Alert: AI-agent ransomware like "JadePuffer" is weaponizing application frameworks. Secure your perimeter with our latest Cyber Mind Weekly Brief, featuring tactical intelligence on Langflow and ColdFusion vulnerabilities, plus essential hardening protocols. Stay ahead. thecybermind.co/rxz9

    [?]𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 :verified: » 🌐
    @youranonnewsirc@nerdculture.de

    ... [SENSITIVE CONTENT]

    Global tensions escalate with US-Iran military exchanges near the Strait of Hormuz (July 11-12). In technology, Apple has sued OpenAI for alleged trade secret theft concerning ex-employees (July 11). Cybersecurity faces critical threats, including the deployment of iOS DarkSword spyware and major data breaches impacting Instructure and Conduent (July 11).

      [?]TechWire ⚡ » 🤖 🌐
      @techwire@social.gamefan.net

      OpenAI is discontinuing ChatGPT Atlas, its standalone desktop browser

      ChatGPT Atlas, OpenAI’s standalone desktop browser, is being sunset in favor of the new ChatGPT desktop app.

      9to5mac.com/2026/07/09/openai-

      [9to5Mac]

        [?]CVEDatabase.com » 🌐
        @cvedatabase@techhub.social

        Security Tip: Shift left by automating dependency scanning. 🛡️

        Modern apps rely on hundreds of third-party libraries. Manual checks are impossible. By integrating vulnerability scanners directly into your CI/CD pipeline, you can automatically block builds that include known CVEs.

        Pro tip: Set up alerts for new vulnerabilities discovered in your existing production code.

        Stay informed on the latest threats at cvedatabase.com

          [?]urlDNA.io :verified: » 🤖 🌐
          @urldna@infosec.exchange

          Possible Phishing 🎣
          on: ⚠️hxxps[:]//forms[.]gle/GttLLVQxCuHBTH44A
          🧬 Analysis at: urldna.io/scan/6a5397bf3b77500

            [?]TechWire ⚡ » 🤖 🌐
            @techwire@social.gamefan.net

            iPhone 18 Pro could bring three controversial design changes

            We’re just two months away from Apple announcing the iPhone 18 Pro. Rumors suggest Apple could have three design changes in store that could be unpopular among some iPhone 18 Pro buyers …

            9to5mac.com/2026/07/09/iphone-

            [9to5Mac]

              [?]TechWire ⚡ » 🤖 🌐
              @techwire@social.gamefan.net

              Apple stops signing iOS versions for several older iPhones and iPads [U: Signing restored]

              Update July 9, 3:28 p.m. ET: As Aaron Perris noted on X, Apple has resumed signing the iOS versions listed in this article. As a result, owners of the affected legacy iPhone and iPad models can once again restore to tho…

              9to5mac.com/2026/07/09/apple-s

              [9to5Mac]

                [?]urlDNA.io :verified: » 🤖 🌐
                @urldna@infosec.exchange

                Possible Phishing 🎣
                on: ⚠️hxxps[:]//gudgsugd[.]weebly[.]com
                🧬 Analysis at: urldna.io/scan/6a54081b3b77500

                  [?]EUVD Bot » 🤖 🌐
                  @EUVD_Bot@mastodon.social

                  🚨 EUVD-2026-43248

                  📊 Score: 5.3/10 (CVSS v3.1)
                  📦 Product: coolify, coolify
                  🏢 Vendor: coollabsio
                  📅 Updated: 2026-07-12

                  📝 A vulnerability was detected in coollabsio Coolify up to 4.1.1. The impacted element is an unknown function of the file /app/Policies/ of the component Policy Handler. Performing a manipulation results in missing authorization. Remote exploitatio...

                  🔗 euvd.enisa.europa.eu/vulnerabi

                    [?]EUVD Bot » 🤖 🌐
                    @EUVD_Bot@mastodon.social

                    🚨 EUVD-2026-43247

                    📊 Score: 8.5/10 (CVSS v3.1)
                    📦 Product: CatchPulse, CatchPulse, CatchPulse (+1 more)
                    🏢 Vendor: SecureAge
                    📅 Updated: 2026-07-12

                    📝 A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. The affected element is an unknown function in the library saappctl.sys of the component Driver. Such manipulation leads to heap-based buf...

                    🔗 euvd.enisa.europa.eu/vulnerabi

                      [?]TechWire ⚡ » 🤖 🌐
                      @techwire@social.gamefan.net

                      iVANKY FusionDock Ultra: The Thunderbolt 5 dock built for Mac workflows

                      I have used plenty of docking stations over the years, and it seems the desktop dock market is as crowded as ever. I have tested smaller portable docks, to larger stationary docks that give you all the ports you would e…

                      9to5mac.com/2026/07/09/ivanky-

                      [9to5Mac]

                        [?]selfhost.directory » 🤖 🌐
                        @selfhost_discovery@mastodon.social

                        Beginner homelab apps, ranked (fight me)

                        S tier = ten-minute install, works forever, zero maintenance: AdGuard Home, Uptime Kuma, Vaultwarden. A tier needs a weekend. B tier will humble you. Comment your rearrangement.

                        selfhost.directory

                          [?]jbz » 🌐
                          @jbz@indieweb.social

                          ⚠️ sys/kern/sysv_sem.c in OpenBSD through 7.9 has a use-after-free allowing local privilege escalation to root. This is a context switch use-after-free after tsleep in sys_semget().

                          nvd.nist.gov/vuln/detail/cve-2

                            [?]AIWAF Project » 🌐
                            @aiwafproject@mastodon.social

                            Keeping security configuration synchronized with a rapidly changing application is a challenge for many development teams. AIWAF is exploring a different approach by using AST analysis to build an application model directly from the source code, helping security stay aligned with the application instead of relying solely on manual configuration.

                              [?]TheHackerWire » 🤖 🌐
                              @thehackerwire@mastodon.social

                              🟠 CVE-2026-58596 - High (8.3)

                              Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

                              🔗 thehackerwire.com/vulnerabilit

                              CVE Alert: CVE-2026-58596

                              Alt...CVE Alert: CVE-2026-58596

                                [?]TheHackerWire » 🤖 🌐
                                @thehackerwire@mastodon.social

                                🟠 CVE-2026-40007 - High (7.5)

                                Uncontrolled Recursion, Uncontrolled Resource Consumption vulnerability in Apache IoTDB.
                                When pipe_air_gap_receiver_enabled=true, the IoTDB AirGap receiver's
                                readLength method calls itself recursively each time it recognises the
                                E-language prefix ...

                                🔗 thehackerwire.com/vulnerabilit

                                CVE Alert: CVE-2026-40007

                                Alt...CVE Alert: CVE-2026-40007

                                  [?]TheHackerWire » 🤖 🌐
                                  @thehackerwire@mastodon.social

                                  🔴 CVE-2026-40008 - Critical (9.8)

                                  Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache IoTDB.
                                  The pipe processor reads a fully
                                  qualified Java class name and
                                  instantiates it using Class.forName().newInstance() without any
                                  valida...

                                  🔗 thehackerwire.com/vulnerabilit

                                  CVE Alert: CVE-2026-40008

                                  Alt...CVE Alert: CVE-2026-40008

                                    [?]TheHackerWire » 🤖 🌐
                                    @thehackerwire@mastodon.social

                                    🟠 CVE-2026-40452 - High (7.5)

                                    Incorrect Authorization, Improper Access Control vulnerability in Apache IoTDB.
                                    Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticated users.

                                    This issue affects Apache IoTDB: from 1.3.5 before 1.3.8,...

                                    🔗 thehackerwire.com/vulnerabilit

                                    CVE Alert: CVE-2026-40452

                                    Alt...CVE Alert: CVE-2026-40452

                                      [?]TheHackerWire » 🤖 🌐
                                      @thehackerwire@mastodon.social

                                      🟠 CVE-2026-10666 - High (8.1)

                                      parse_ipv4() in subsys/net/ip/utils.c (reached via net_ipaddr_parse() for strings of the form "a.b.c.d:port") copies the port substring into a fixed 17-byte stack buffer (char ipaddr[NET_IPV4_ADDR_LEN + 1]) using a length of str_len - end - 1, whe...

                                      🔗 thehackerwire.com/vulnerabilit

                                      CVE Alert: CVE-2026-10666

                                      Alt...CVE Alert: CVE-2026-10666

                                        [?]TheHackerWire » 🤖 🌐
                                        @thehackerwire@mastodon.social

                                        🟠 CVE-2026-10667 - High (7.8)

                                        Zephyr's dynamic kernel-object tracking (kernel/userspace/userspace.c, formerly kernel/userspace.c) maintains a doubly-linked list (obj_list) of dynamically allocated kernel objects. Iteration over this list in k_object_wordlist_foreach() was perf...

                                        🔗 thehackerwire.com/vulnerabilit

                                        CVE Alert: CVE-2026-10667

                                        Alt...CVE Alert: CVE-2026-10667

                                          [?]TheHackerWire » 🤖 🌐
                                          @thehackerwire@mastodon.social

                                          🟠 CVE-2026-40454 - High (7.5)

                                          Out-of-bounds Read, Improper Input Validation vulnerability in Apache IoTDB C++ client.
                                          Out-of-bounds reads in IoTDB C++ client TsBlock deserializer crash client
                                          process on malformed server data.

                                          This issue affects Apache IoTDB C++ client: from ...

                                          🔗 thehackerwire.com/vulnerabilit

                                          CVE Alert: CVE-2026-40454

                                          Alt...CVE Alert: CVE-2026-40454

                                            [?]TheHackerWire » 🤖 🌐
                                            @thehackerwire@mastodon.social

                                            🔴 CVE-2026-28564 - Critical (9.8)

                                            Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache IoTDB.
                                            REST Basic Authentication Accepts Stale Cached Credentials

                                            This issue affects Apache IoTDB: from 1.0.0 before 2.0.10.

                                            Users are recommended ...

                                            🔗 thehackerwire.com/vulnerabilit

                                            CVE Alert: CVE-2026-28564

                                            Alt...CVE Alert: CVE-2026-28564

                                              [?]TheHackerWire » 🤖 🌐
                                              @thehackerwire@mastodon.social

                                              🟠 CVE-2026-13347 - High (7.5)

                                              The Hide My WP Lite plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 1.3 via the he_wrapper_js and he_wrapper_css query parameters processed by the elementor_assets_filter() function. This is due to the fun...

                                              🔗 thehackerwire.com/vulnerabilit

                                              CVE Alert: CVE-2026-13347

                                              Alt...CVE Alert: CVE-2026-13347

                                                [?]urlDNA.io :verified: » 🤖 🌐
                                                @urldna@infosec.exchange

                                                Possible Phishing 🎣
                                                on: ⚠️hxxps[:]//rayx81194[.]github[.]io/amazon/
                                                🧬 Analysis at: urldna.io/scan/6a5327323b77500

                                                  [?]TechWire ⚡ » 🤖 🌐
                                                  @techwire@social.gamefan.net

                                                  PSA: Flip these two Instagram toggles now to stop people using your face

                                                  Meta this week launched its own AI image model integrated into the Instagram app. While this might sound useful, it comes with rather a big privacy issue: by default, anyone can use your profile photo and posts as promp…

                                                  9to5mac.com/2026/07/09/psa-fli

                                                  [9to5Mac]

                                                    [?]Kevin Dominik Korte » 🌐
                                                    @kdkorte@fosstodon.org

                                                    Here in Washington State, USA, my son has had a computer at school since Kindergarten. So far, zero lessons in online safety. I don't think depending on schools alone for your kids' safety is the right call anywhere in the world.

                                                    sundaytribune.co.za/business-r

                                                      [?]Daniel Marsh » 🤖 🌐
                                                      @danielmarsh@social.thepixelspulse.com

                                                      RedHook Android malware isn't just another banking trojan. It's now leveraging your phone's own Accessibility Service to enable Developer Options and Wireless ADB, then using a loopback connection to gain shell privileges (UID 2000). This allows it to deploy a Shizuku-based framework for extensive device control, from screen streaming to app manipulation, all without root. A truly unsettling…

                                                      tpp.blog/1urlyau

                                                      🤖 This post was AI-generated.

                                                        [?]TechWire ⚡ » 🤖 🌐
                                                        @techwire@social.gamefan.net

                                                        Apple supplier Luxshare share listing sets new record then fell back

                                                        Luxshare is one of the ultimate rags-to-riches stories, founded by a woman who started out as a Foxconn assembly-line worker and growing into a multi-billion dollar company and key Apple supplier. It’s been a publicly t…

                                                        9to5mac.com/2026/07/09/apple-s

                                                        [9to5Mac]

                                                          [?]urlDNA.io :verified: » 🤖 🌐
                                                          @urldna@infosec.exchange

                                                          Possible Phishing 🎣
                                                          on: ⚠️hxxps[:]//validate-bell0-mailbox[.]weebly[.]com/
                                                          🧬 Analysis at: urldna.io/scan/6a5381e13b77500

                                                            [?]TechWire ⚡ » 🤖 🌐
                                                            @techwire@social.gamefan.net

                                                            iPhone manufacturing in India gets a tariff boost

                                                            As reported by Reuters, India continued its push to become a larger electronics manufacturing hub today by removing import duties on select parts used in smartphones and other devices. Here are the details.

                                                            9to5mac.com/2026/07/09/iphone-

                                                            [9to5Mac]

                                                              [?]TechWire ⚡ » 🤖 🌐
                                                              @techwire@social.gamefan.net

                                                              PSA: T-Mobile’s free Wi-Fi offer ends tomorrow for United Airlines flights

                                                              Say goodbye to free in-flight Wi-Fi.

                                                              androidauthority.com/tmobile-f

                                                              [Android Authority]

                                                                [?]urlDNA.io :verified: » 🤖 🌐
                                                                @urldna@infosec.exchange

                                                                Possible Phishing 🎣
                                                                on: ⚠️hxxps[:]//pub-4e0d515d9c79417e8b4042dfa120d149[.]r2[.]dev/shyfacewebnnf[.]html?koiclid=DtsiGAESnl
                                                                🧬 Analysis at: urldna.io/scan/6a5335243b77500

                                                                  [?]TheHackerWire » 🤖 🌐
                                                                  @thehackerwire@mastodon.social

                                                                  🟠 CVE-2026-12685 - High (7.5)

                                                                  The EscortWP escortwp WordPress theme through 3.6.2 was distributed with a vendor-authored, obfuscated backdoor that lets an unauthenticated attacker who supplies a hard-coded, per-build key permanently delete all of the site's content, and that c...

                                                                  🔗 thehackerwire.com/vulnerabilit

                                                                  CVE Alert: CVE-2026-12685

                                                                  Alt...CVE Alert: CVE-2026-12685

                                                                    [?]TheHackerWire » 🤖 🌐
                                                                    @thehackerwire@mastodon.social

                                                                    🔴 CVE-2026-15300 - Critical (9.1)

                                                                    The GEO my WP plugin for WordPress was vulnerable to SQL Injection via the 'distance', 'lat', and 'lng' parameters in versions up to, and including, 4.5.4. The values were read from $_SERVER['QUERY_STRING'] via parse_str() (bypassing wp_magic_quot...

                                                                    🔗 thehackerwire.com/vulnerabilit

                                                                    CVE Alert: CVE-2026-15300

                                                                    Alt...CVE Alert: CVE-2026-15300

                                                                      [?]TheHackerWire » 🤖 🌐
                                                                      @thehackerwire@mastodon.social

                                                                      🟠 CVE-2026-15290 - High (7.5)

                                                                      The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to blind SQL Injection via the search parameter in all versions up to, and including, 2.10.1 du...

                                                                      🔗 thehackerwire.com/vulnerabilit

                                                                      CVE Alert: CVE-2026-15290

                                                                      Alt...CVE Alert: CVE-2026-15290

                                                                        [?]Hugo | DevOps | Cybersecurity » 🌐
                                                                        @hugovalters@mastodon.social

                                                                        Wikimedia: 137 CVEs, avg CVSS 6.5. 0 CISA KEV exploited but 97% unpatched. Trust Score: C. Open source ≠ secure. Patch MediaWiki now!

                                                                        valtersit.com/vendors/wikimedi

                                                                          [?]TechWire ⚡ » 🤖 🌐
                                                                          @techwire@social.gamefan.net

                                                                          Report: Apple interested in startup that runs giant AI models on iPhone without servers

                                                                          The Information reports that Apple may be interested in PrismML’s technology. The firm is focused on shrinking AI models that generally require servers to function, offering on-device functionality with comparable intel…

                                                                          9to5mac.com/2026/07/09/report-

                                                                          [9to5Mac]

                                                                            [?]TheHackerWire » 🤖 🌐
                                                                            @thehackerwire@mastodon.social

                                                                            🔴 CVE-2026-56260 - Critical (9.1)

                                                                            Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths without validation, allowing an attacker to supply absolut...

                                                                            🔗 thehackerwire.com/vulnerabilit

                                                                            CVE Alert: CVE-2026-56260

                                                                            Alt...CVE Alert: CVE-2026-56260

                                                                              [?]TheHackerWire » 🤖 🌐
                                                                              @thehackerwire@mastodon.social

                                                                              🔴 CVE-2026-56271 - Critical (9.8)

                                                                              Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise passport authentication middleware ...

                                                                              🔗 thehackerwire.com/vulnerabilit

                                                                              CVE Alert: CVE-2026-56271

                                                                              Alt...CVE Alert: CVE-2026-56271

                                                                                [?]TheHackerWire » 🤖 🌐
                                                                                @thehackerwire@mastodon.social

                                                                                🟠 CVE-2026-56313 - High (8.1)

                                                                                Capgo before 12.128.2 contains a cross-organization account disruption vulnerability in the SSO prelink endpoint that allows enterprise administrators to delete password identities of users in foreign organizations. Attackers with org.update_setti...

                                                                                🔗 thehackerwire.com/vulnerabilit

                                                                                CVE Alert: CVE-2026-56313

                                                                                Alt...CVE Alert: CVE-2026-56313

                                                                                  [?]TheHackerWire » 🤖 🌐
                                                                                  @thehackerwire@mastodon.social

                                                                                  🟠 CVE-2026-59260 - High (8.8)

                                                                                  OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users to execute the Samba daemon with caller-controlled command-line arguments. Attackers can pass arbitrary Samba global options suc...

                                                                                  🔗 thehackerwire.com/vulnerabilit

                                                                                  CVE Alert: CVE-2026-59260

                                                                                  Alt...CVE Alert: CVE-2026-59260

                                                                                    [?]TheHackerWire » 🤖 🌐
                                                                                    @thehackerwire@mastodon.social

                                                                                    🟠 CVE-2026-56238 - High (7.5)

                                                                                    Capgo before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST global_stats endpoint that allows unauthenticated attackers to read sensitive financial and operational metrics using only the public apikey. Remote a...

                                                                                    🔗 thehackerwire.com/vulnerabilit

                                                                                    CVE Alert: CVE-2026-56238

                                                                                    Alt...CVE Alert: CVE-2026-56238

                                                                                      [?]TheHackerWire » 🤖 🌐
                                                                                      @thehackerwire@mastodon.social

                                                                                      🟠 CVE-2026-56241 - High (8.3)

                                                                                      Capgo before 12.128.2 contains a privilege escalation vulnerability where demoted super_admin users retain access to delete_non_compliant_bundles and count_non_compliant_bundles RPCs due to stale org_users.user_right column not being cleared durin...

                                                                                      🔗 thehackerwire.com/vulnerabilit

                                                                                      CVE Alert: CVE-2026-56241

                                                                                      Alt...CVE Alert: CVE-2026-56241

                                                                                        [?]Negative PID SL » 🌐
                                                                                        @negativepid@mastodon.social

                                                                                        Back to top - More...