voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]The New Oil » 🤖 🌐
@thenewoil@mastodon.thenewoil.org

[?]urlDNA.io :verified: » 🤖 🌐
@urldna@infosec.exchange

Possible Phishing 🎣
on: ⚠️hxxps[:]//monacotelecomservice[.]weebly[.]com/
🧬 Analysis at: urldna.io/scan/6a51ea053b77500

    [?]TheHackerWire » 🤖 🌐
    @thehackerwire@mastodon.social

    🔴 CVE-2026-2397 - Critical (9.8)

    Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows SQL Injection.

    This issue affects MobilMen 20T: from v3 through 10072026. NOTE: The vendor was ...

    🔗 thehackerwire.com/vulnerabilit

    CVE Alert: CVE-2026-2397

    Alt...CVE Alert: CVE-2026-2397

      [?]TechWire ⚡ » 🤖 🌐
      @techwire@social.gamefan.net

      The MacRumors Show: Goodbye MacBook Pro? MacBook Ultra Is Coming

      On this week's episode of The MacRumors Show, we discuss the future of Apple's increasingly tangled high-end MacBook lineup, including the entry-level MacBook Pro and the rumored "MacBook Ultra." Subscribe to The MacRum…

      macrumors.com/2026/07/10/the-m

      [MacRumors]

        [?]Malicious Extension Bot » 🤖 🌐
        @malicious_browser_bot@infosec.exchange

        extension T‮gnidar‬v‮wei‬ A‮spp‬ seems malicious. Its badness score is 89/100!

        ```json
        {"id": "enhccgfadgcpinpjlndlaknnfibedafm", "score": 89, "platform": "chrome", "name": "T\u202egnidar\u202cv\u202ewei\u202c A\u202espp\u202c"}
        ```

          [?]TechWire ⚡ » 🤖 🌐
          @techwire@social.gamefan.net

          Apple Watch Accounts for 90% of AI Smartwatch Shipments

          Apple accounted for roughly 90% of all Edge AI-capable smartwatch shipments in the first quarter of 2026, according to new data from Counterpoint Research. That dominance came as Edge AI penetration across the broader s…

          macrumors.com/2026/07/10/apple

          [MacRumors]

            [?]urlDNA.io :verified: » 🤖 🌐
            @urldna@infosec.exchange

            Possible Phishing 🎣
            on: ⚠️hxxps[:]//evenementlesinfos[.]firebaseapp[.]com
            🧬 Analysis at: urldna.io/scan/6a5238133b77500

              [?]The New Oil » 🤖 🌐
              @thenewoil@mastodon.thenewoil.org

              [?]TechWire ⚡ » 🤖 🌐
              @techwire@social.gamefan.net

              Top Stories: 'iPhone Ultra' and Apple TV Rumors, iOS 27 Beta 3, and More

              Apple's annual iPhone event is just two months away, but we're still not quite clear on when and in what quantities the new foldable "iPhone Ultra" will be available. It sounds like we could end up in a situation simila…

              macrumors.com/2026/07/11/top-s

              [MacRumors]

                [?]TechWire ⚡ » 🤖 🌐
                @techwire@social.gamefan.net

                Oregon’s Attorney General withdraws effort to delay Paramount and Warner Bros. merger

                Oregon Attorney General Dan Rayfield had been seeking documents from Paramount related to its takeover of Warner Bros. Discovery. Rayfield also asked a state circuit court judge to delay the closing of the deal by 60 da…

                theverge.com/policy/964493/ore

                [The Verge]

                  [?]TheHackerWire » 🤖 🌐
                  @thehackerwire@mastodon.social

                  🟠 CVE-2026-56675 - High (8.3)

                  9Router is an AI router & token saver. Prior to 0.5.2, 9router treats loopback requests as trusted and allows /v1/* access without an API key, so a same-host reverse proxy that forwards public traffic to the backend through 127.0.0.1 causes src/da...

                  🔗 thehackerwire.com/vulnerabilit

                  CVE Alert: CVE-2026-56675

                  Alt...CVE Alert: CVE-2026-56675

                    [?]The New Oil » 🤖 🌐
                    @thenewoil@mastodon.thenewoil.org

                    [?]TheHackerWire » 🤖 🌐
                    @thehackerwire@mastodon.social

                    🟠 CVE-2026-55638 - High (8.6)

                    9Router is an AI router & token saver. Prior to 0.5.2, 9router protects /v1, /v1beta, /api/v1, and /api/v1beta in src/dashboardGuard.js but omits /codex before next.config.mjs rewrites /codex/* to /api/v1/responses. A remote unauthenticated attack...

                    🔗 thehackerwire.com/vulnerabilit

                    CVE Alert: CVE-2026-55638

                    Alt...CVE Alert: CVE-2026-55638

                      [?]urlDNA.io :verified: » 🤖 🌐
                      @urldna@infosec.exchange

                      Possible Phishing 🎣
                      on: ⚠️hxxps[:]//cryptoagent[.]vercel[.]app
                      🧬 Analysis at: urldna.io/scan/6a5222493b77500

                        [?]TheHackerWire » 🤖 🌐
                        @thehackerwire@mastodon.social

                        🟠 CVE-2026-55641 - High (8.2)

                        9Router is an AI router & token saver. Prior to 0.5.2, 9router determines whether a /v1 LLM proxy request is local by reading the client-controlled Host header, allowing a remote unauthenticated attacker to send Host: localhost and bypass API-key ...

                        🔗 thehackerwire.com/vulnerabilit

                        CVE Alert: CVE-2026-55641

                        Alt...CVE Alert: CVE-2026-55641

                          [?]Hugo | DevOps | Cybersecurity » 🌐
                          @hugovalters@mastodon.social

                          Draytek: 95 CVEs, 1 CISA KEV exploited. 100% unpatched. Trust Score: C. Avg CVSS 4.7. Patch now or risk branch office breach.

                          valtersit.com/vendors/draytek/

                            [?]N_{Dario Fadda} » 🌐
                            @nuke@poliversity.it

                            ✨ CISA aggiunge Langflow e Joomla al catalogo KEV: una IDOR ruba le chiavi degli agenti AI, uno zero-day PHP infetta i siti in un solo POST

                            insicurezzadigitale.com/cisa-a

                            @informatica

                              [?]TechWire ⚡ » 🤖 🌐
                              @techwire@social.gamefan.net

                              Apple Sues OpenAI for Stealing Trade Secrets to Build AI Hardware

                              Apple today accused OpenAI of stealing Apple trade secrets and intellectual property in its effort to develop an AI hardware device. In a lawsuit filed with the Northern District of California, Apple said it uncovered e…

                              macrumors.com/2026/07/10/apple

                              [MacRumors]

                                [?]hackers-arise.official » 🌐
                                @hackers_arise@mastodon.social

                                Allow access only where necessary and to those who need it

                                  [?]TheHackerWire » 🤖 🌐
                                  @thehackerwire@mastodon.social

                                  🟠 CVE-2026-52747 - High (8.6)

                                  ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to 3.0.16, the multipart/form-data request body parser in libmodsecurity silently removes embedded line breaks from non-file form-...

                                  🔗 thehackerwire.com/vulnerabilit

                                  CVE Alert: CVE-2026-52747

                                  Alt...CVE Alert: CVE-2026-52747

                                    [?]TheHackerWire » 🤖 🌐
                                    @thehackerwire@mastodon.social

                                    🟠 CVE-2026-44795 - High (8.8)

                                    Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe YAML processing bypasses safe deserialization when using CloudFormation deployments or CloudFoundry baking. The use ...

                                    🔗 thehackerwire.com/vulnerabilit

                                    CVE Alert: CVE-2026-44795

                                    Alt...CVE Alert: CVE-2026-44795

                                      [?]TheHackerWire » 🤖 🌐
                                      @thehackerwire@mastodon.social

                                      🟠 CVE-2026-55229 - High (7.5)

                                      Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.34.0, Gotenberg's /forms/libreoffice/convert endpoint allows a specially crafted document to cause LibreOffice to automatically retrieve external HTTP(S) resources and local fil...

                                      🔗 thehackerwire.com/vulnerabilit

                                      CVE Alert: CVE-2026-55229

                                      Alt...CVE Alert: CVE-2026-55229

                                        [?]TheHackerWire » 🤖 🌐
                                        @thehackerwire@mastodon.social

                                        🟠 CVE-2026-55233 - High (7.5)

                                        OpenResty is a high performance web platform. From 1.29.2.1 to before 1.29.2.5, an out-of-bounds write vulnerability exists in the upstream PROXY protocol v2 implementation. When OpenResty is configured to send PROXY protocol version 2 headers to ...

                                        🔗 thehackerwire.com/vulnerabilit

                                        CVE Alert: CVE-2026-55233

                                        Alt...CVE Alert: CVE-2026-55233

                                          [?]TheHackerWire » 🤖 🌐
                                          @thehackerwire@mastodon.social

                                          🟠 CVE-2026-55405 - High (7.6)

                                          LangChain4j is a Java library for building LLM-powered applications on the JVM. Prior to 1.2.1-beta8, 1.5.1-beta11, 1.11.8-beta19, and 1.16.3-beta26, the MariaDB and pgvector embedding stores build metadata-filter SQL by string-concatenating filt...

                                          🔗 thehackerwire.com/vulnerabilit

                                          CVE Alert: CVE-2026-55405

                                          Alt...CVE Alert: CVE-2026-55405

                                            [?]TheHackerWire » 🤖 🌐
                                            @thehackerwire@mastodon.social

                                            🔴 CVE-2026-12761 - Critical (9.8)

                                            The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass leading to account takeover in versions up to and including 7.7.0. This is due to the Profile Completion flow...

                                            🔗 thehackerwire.com/vulnerabilit

                                            CVE Alert: CVE-2026-12761

                                            Alt...CVE Alert: CVE-2026-12761

                                              [?]TheHackerWire » 🤖 🌐
                                              @thehackerwire@mastodon.social

                                              🟠 CVE-2026-55377 - High (8.1)

                                              Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's Account Center step-up check accepted any active verification record that belonged to the current user and had isVerified === true. A WebAuthn regi...

                                              🔗 thehackerwire.com/vulnerabilit

                                              CVE Alert: CVE-2026-55377

                                              Alt...CVE Alert: CVE-2026-55377

                                                [?]TheHackerWire » 🤖 🌐
                                                @thehackerwire@mastodon.social

                                                🔴 CVE-2026-61445 - Critical (9.9)

                                                PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. Attackers can inject malicious prompts through the chat...

                                                🔗 thehackerwire.com/vulnerabilit

                                                CVE Alert: CVE-2026-61445

                                                Alt...CVE Alert: CVE-2026-61445

                                                  [?]The New Oil » 🤖 🌐
                                                  @thenewoil@mastodon.thenewoil.org

                                                  [?]TechWire ⚡ » 🤖 🌐
                                                  @techwire@social.gamefan.net

                                                  White House taps the guy who keeps crying ‘aliens’ to run UFO group

                                                  Harvard astrophysicist Avi Loeb will head the UAP Science Advisory Council established by the White House, the Pentagon, the Office of the Director of National Intelligence, the FBI, and "the intelligence community." Th…

                                                  theverge.com/science/964478/wh

                                                  [The Verge]

                                                    [?]TechWire ⚡ » 🤖 🌐
                                                    @techwire@social.gamefan.net

                                                    AMD RX 9070 GRE collapses to $499 to save 1440p gaming — RDNA 4 price slips 9% to steal a piece of Nvidia's mid-range pie

                                                    AMD's Radeon RX 9070 GRE has received its first price cut since launching outside China, making the 1440p-focused RDNA 4 graphics card a more compelling alternative to Nvidia's RTX 5060 Ti 16GB.

                                                    tomshardware.com/pc-components

                                                    [Tom's Hardware]

                                                      [?]TechWire ⚡ » 🤖 🌐
                                                      @techwire@social.gamefan.net

                                                      Bambu Lab collabs with Insta360 for epic design contest — win thousands in 3D printers, Luna Ultra cameras, and gift cards

                                                      Your design concept could win a next-gen camera and 3D printer.

                                                      tomshardware.com/3d-printing/b

                                                      [Tom's Hardware]

                                                        [?]Negative PID SL » 🌐
                                                        @negativepid@mastodon.social

                                                        [?]EUVD Bot » 🤖 🌐
                                                        @EUVD_Bot@mastodon.social

                                                        🚨 EUVD-2026-43178

                                                        📊 Score: 8.4/10 (CVSS v3.1)
                                                        📦 Product: PraisonAI
                                                        🏢 Vendor: mervinpraison
                                                        📅 Updated: 2026-07-11

                                                        📝 PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend that allows attackers to bypass SSRF validation by exploiting DNS rebinding and HTTP redirects. Attackers can craft URLs that resolv...

                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                          [?]EUVD Bot » 🤖 🌐
                                                          @EUVD_Bot@mastodon.social

                                                          🚨 EUVD-2026-43177

                                                          📊 Score: 6.9/10 (CVSS v3.1)
                                                          📦 Product: PraisonAI
                                                          🏢 Vendor: mervinpraison
                                                          📅 Updated: 2026-07-11

                                                          📝 PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing unauthenticated attackers to inject messages with spoofed sender addresses. Attackers can POST crafted message.received events to the webhook endpoint to...

                                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                                            [?]EUVD Bot » 🤖 🌐
                                                            @EUVD_Bot@mastodon.social

                                                            🚨 EUVD-2026-43176

                                                            📊 Score: 8.8/10 (CVSS v3.1)
                                                            📦 Product: PraisonAI
                                                            🏢 Vendor: mervinpraison
                                                            📅 Updated: 2026-07-11

                                                            📝 PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS. Unauthenticated attackers can call GET /api/agents to read agent instructions and system prompts, or POST /a...

                                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                                              [?]EUVD Bot » 🤖 🌐
                                                              @EUVD_Bot@mastodon.social

                                                              🚨 EUVD-2026-43175

                                                              📊 Score: 9.3/10 (CVSS v3.1)
                                                              📦 Product: PraisonAI
                                                              🏢 Vendor: mervinpraison
                                                              📅 Updated: 2026-07-11

                                                              📝 PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends. Although schema, keyspace, and collection-name identifiers are validated, the dimension val...

                                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                                [?]EUVD Bot » 🤖 🌐
                                                                @EUVD_Bot@mastodon.social

                                                                🚨 EUVD-2026-43174

                                                                📊 Score: 6.8/10 (CVSS v3.1)
                                                                📦 Product: PraisonAI
                                                                🏢 Vendor: mervinpraison
                                                                📅 Updated: 2026-07-11

                                                                📝 PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing attackers to read files outside the workspace. Attackers can include path traversal sequences like @../outside_secret.txt or absolute paths in projec...

                                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                                  [?]EUVD Bot » 🤖 🌐
                                                                  @EUVD_Bot@mastodon.social

                                                                  🚨 EUVD-2026-43173

                                                                  📊 Score: 6.3/10 (CVSS v3.1)
                                                                  📦 Product: hono
                                                                  🏢 Vendor: Hono
                                                                  📅 Updated: 2026-07-11

                                                                  📝 Hono before 4.12.7 allows __proto__ key in parseBody with dot option enabled, permitting specially crafted form field names to create objects with __proto__ properties. When parsed results are merged into regular JavaScript objects using unsafe merge patterns, att...

                                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                                    [?]EUVD Bot » 🤖 🌐
                                                                    @EUVD_Bot@mastodon.social

                                                                    🚨 EUVD-2026-43172

                                                                    📊 Score: 4.8/10 (CVSS v3.1)
                                                                    📦 Product: ImageMagick
                                                                    🏢 Vendor: ImageMagick
                                                                    📅 Updated: 2026-07-11

                                                                    📝 ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory. An unrecognized magnify:method value triggers an out of bounds read, potentially exposing sensitive...

                                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                                      [?]TheHackerWire » 🤖 🌐
                                                                      @thehackerwire@mastodon.social

                                                                      🔴 CVE-2026-61447 - Critical (10)

                                                                      PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output t...

                                                                      🔗 thehackerwire.com/vulnerabilit

                                                                      CVE Alert: CVE-2026-61447

                                                                      Alt...CVE Alert: CVE-2026-61447

                                                                        [?]EUVD Bot » 🤖 🌐
                                                                        @EUVD_Bot@mastodon.social

                                                                        🚨 EUVD-2026-43171

                                                                        📊 Score: 8.7/10 (CVSS v3.1)
                                                                        📦 Product: capgo
                                                                        🏢 Vendor: Capgo
                                                                        📅 Updated: 2026-07-11

                                                                        📝 Capgo before 12.128.2 contains an information disclosure vulnerability in the find_apikey_by_value PostgreSQL function marked SECURITY DEFINER and executable by the anon role. Unauthenticated attackers can call this function via the /rest/v1/rpc/find_apikey_by_v...

                                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                                          [?]EUVD Bot » 🤖 🌐
                                                                          @EUVD_Bot@mastodon.social

                                                                          🚨 EUVD-2026-43170

                                                                          📊 Score: 6.9/10 (CVSS v3.1)
                                                                          📦 Product: capgo
                                                                          🏢 Vendor: Cap-go
                                                                          📅 Updated: 2026-07-11

                                                                          📝 Cap-go before 12.128.2 contains an information disclosure vulnerability in the public.transfer_app RPC function that returns distinct error messages for existing versus non-existing app IDs. Unauthenticated attackers can enumerate valid app IDs by observing err...

                                                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                                                            [?]EUVD Bot » 🤖 🌐
                                                                            @EUVD_Bot@mastodon.social

                                                                            🚨 EUVD-2026-43169

                                                                            📊 Score: 5.3/10 (CVSS v3.1)
                                                                            📦 Product: capgo
                                                                            🏢 Vendor: Capgo
                                                                            📅 Updated: 2026-07-11

                                                                            📝 Capgo before 12.128.12 contains a billing authorization bypass vulnerability in the plan_valid calculation that allows organizations with exhausted or expired usage credit grants to bypass billing gates. Attackers can exploit the divergence between the plugin ho...

                                                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                                                              [?]TheHackerWire » 🤖 🌐
                                                                              @thehackerwire@mastodon.social

                                                                              🔴 CVE-2026-60090 - Critical (9.8)

                                                                              PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends. Although schema, keyspace, and collection-name identifiers are validated, the dimension ...

                                                                              🔗 thehackerwire.com/vulnerabilit

                                                                              CVE Alert: CVE-2026-60090

                                                                              Alt...CVE Alert: CVE-2026-60090

                                                                                [?]TheHackerWire » 🤖 🌐
                                                                                @thehackerwire@mastodon.social

                                                                                🟠 CVE-2026-61426 - High (8.6)

                                                                                PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS. Unauthenticated attackers can call GET /api/agents to read agent instructions and system prompts, or POST...

                                                                                🔗 thehackerwire.com/vulnerabilit

                                                                                CVE Alert: CVE-2026-61426

                                                                                Alt...CVE Alert: CVE-2026-61426

                                                                                  [?]TheHackerWire » 🤖 🌐
                                                                                  @thehackerwire@mastodon.social

                                                                                  🟠 CVE-2026-61429 - High (8.5)

                                                                                  PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend that allows attackers to bypass SSRF validation by exploiting DNS rebinding and HTTP redirects. Attackers can craft URLs that res...

                                                                                  🔗 thehackerwire.com/vulnerabilit

                                                                                  CVE Alert: CVE-2026-61429

                                                                                  Alt...CVE Alert: CVE-2026-61429

                                                                                    [?]BeyondMachines :verified: » 🤖 🌐
                                                                                    @beyondmachines1@infosec.exchange

                                                                                    Samsung Patches Critical Image-Parsing Flaws in Galaxy Z Fold 7 and Flip 7

                                                                                    Samsung's July 2026 update fixes 57 vulnerabilities, including critical remote code execution flaws in image-parsing libraries. These vulnerabilities mirror those used in previous spyware campaigns to target Galaxy users via malicious files.

                                                                                    **If you have a Galaxy Z Fold 7 or Z Flip 7, time to update. Go to Settings > Software Update > Download and Install to patch. There are several flaws that can be exploited just by sending you a malicious image. If the update isn't available in your region yet, keep Google Play Protect on, don't install apps from outside the Play Store, and be careful opening images or media from unknown senders until you're patched.**

                                                                                    beyondmachines.net/event_detai

                                                                                      [?]TheHackerWire » 🤖 🌐
                                                                                      @thehackerwire@mastodon.social

                                                                                      🟠 CVE-2026-61439 - High (7.5)

                                                                                      PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults to CRITICAL severity, allowing HIGH-level threats to pass through unblocked. Attackers can submit single-vector prompt injectio...

                                                                                      🔗 thehackerwire.com/vulnerabilit

                                                                                      CVE Alert: CVE-2026-61439

                                                                                      Alt...CVE Alert: CVE-2026-61439

                                                                                        Back to top - More...