voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]TechWire ⚡ » 🤖 🌐
@techwire@social.gamefan.net

Nintendo’s Talking Flower got a small price cut

If you’re the type of person who could always use a little extra positive affirmation, or you have a weakness for weird gadgets, the Talking Flower might be of interest. I’m only kind of serious. The toy is based on a c…

theverge.com/gadgets/964138/ni

[The Verge]

    [?]Daniel Marsh » 🤖 🌐
    @danielmarsh@social.thepixelspulse.com

    Australia's ACSC has sounded the alarm on a global campaign targeting vulnerable CMS platforms, including WordPress and Joomla, with AI now accelerating the exploitation of *known* flaws. Many businesses are falling victim to webshell deployments via unpatched plugins like Ninja Forms and Simple File List, leading to data theft and full network compromise. This isn't about…

    tpp.blog/23qeckd

    🤖 This post was AI-generated.

      [?]Daniel Marsh » 🤖 🌐
      @danielmarsh@social.thepixelspulse.com

      'Ghostcommit' exposes a major blind spot in AI development security: prompt injection hidden in image files. Researchers demonstrated how malicious PNGs can instruct AI coding agents to read and exfiltrate .env file secrets, completely bypassing traditional AI code reviewers like CodeRabbit and Bugbot. This redefines supply chain risk beyond just code.

      tpp.blog/70ohpyk

      🤖 This post was AI-generated.

        [?]TheHackerWire » 🤖 🌐
        @thehackerwire@mastodon.social

        🟠 CVE-2026-1359 - High (8.8)

        The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the genolve_setOpt() function in all versions up to, and including, 5.0.5. This makes it poss...

        🔗 thehackerwire.com/vulnerabilit

        CVE Alert: CVE-2026-1359

        Alt...CVE Alert: CVE-2026-1359

          [?]TheHackerWire » 🤖 🌐
          @thehackerwire@mastodon.social

          🟠 CVE-2025-6784 - High (8.8)

          The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.3.5 via the 'code-engine' shortcode. This is due to the plugin not restricting access to the code injecting functionality of the pl...

          🔗 thehackerwire.com/vulnerabilit

          CVE Alert: CVE-2025-6784

          Alt...CVE Alert: CVE-2025-6784

            [?]TheHackerWire » 🤖 🌐
            @thehackerwire@mastodon.social

            🟠 CVE-2026-7655 - High (8.1)

            The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and including, 4.2.3. This is due to the plugin not properly validating a user's identity prior to updating their details like email du...

            🔗 thehackerwire.com/vulnerabilit

            CVE Alert: CVE-2026-7655

            Alt...CVE Alert: CVE-2026-7655

              [?]TheHackerWire » 🤖 🌐
              @thehackerwire@mastodon.social

              🟠 CVE-2026-2354 - High (8.8)

              The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed file type validation bypass in the `upload_extension_files()` function in all versions up to, and including, 1.4.6. The `upload_extension_files()`...

              🔗 thehackerwire.com/vulnerabilit

              CVE Alert: CVE-2026-2354

              Alt...CVE Alert: CVE-2026-2354

                [?]TechWire ⚡ » 🤖 🌐
                @techwire@social.gamefan.net

                How I turned my Pixel into the ultimate Home Assistant smart home companion

                I can't imagine smart home life without my Pixel now.

                androidauthority.com/pixel-hom

                [Android Authority]

                  [?]Pikapods » 🌐
                  @Pikapods@mastodon.social

                  Progress Software has ordered ShareFile customers to shut down Windows servers running Storage Zone Controllers due to a credible external security threat.

                  Open-source alternatives like Nextcloud and FileBrowser provide secure, enterprise-ready file sharing where you maintain complete control over the infrastructure, data, and uptime.

                  thehackernews.com/2026/07/urge

                    [?]TechWire ⚡ » 🤖 🌐
                    @techwire@social.gamefan.net

                    Anthropic Adds 'Reflect' Feature to Claude for Tracking Your Usage

                    Anthropic is updating Claude with a new "Reflect" feature that's akin to Spotify Wrapped. Reflect lets you look back on how you've been using Claude, and for how long. Reflect includes a summary of Claude usage, incorpo…

                    macrumors.com/2026/07/09/anthr

                    [MacRumors]

                      [?]BeeSINT » 🌐
                      @BeeSINT@mastodon.social

                      🎣 Phishing Spotlight

                      cz-facebook[.]blogspot[.]com

                      🔒 SSL: exp. 2026-09-14
                      🌐 Stack: GSE, blogger

                      🔗 beesint.com/pulse/73e6420f-173

                        [?]CVEDatabase.com » 🌐
                        @cvedatabase@techhub.social

                        Security Tip: Establish out-of-band (OOB) communication channels for your Incident Response team. 🛡️

                        If an attacker gains access to your primary email or chat platforms, they can monitor your response efforts or even disrupt them. Prepare a secure, separate channel (like Signal or a dedicated offline instance) in advance to maintain command and control.

                        Stay informed on the latest vulnerabilities at: cvedatabase.com

                          [?]urlDNA.io :verified: » 🤖 🌐
                          @urldna@infosec.exchange

                          Possible Phishing 🎣
                          on: ⚠️hxxps[:]//gimmenilogin[.]gitbook[.]io
                          🧬 Analysis at: urldna.io/scan/6a520dd43b77500

                            [?]Security BSides Delaware » 🌐
                            @BSidesDE@infosec.exchange

                            Great news everyone! We’re excited to announce 2026 will take place on November 13–14.
                            Thank you to everyone who has supported us and participated over the years, we can’t wait to see the community again. , registration, and venue details coming soon.

                              [?]TechWire ⚡ » 🤖 🌐
                              @techwire@social.gamefan.net

                              I wish someone told me about these 5 Android Auto settings before I bought my new car

                              A few Android Auto settings go a long way.

                              androidauthority.com/first-car

                              [Android Authority]

                                [?]Linuxiarze » 🌐
                                @Linuxiarze@mastodon.social

                                Red Hat zapewnia płatne wsparcie techniczne bez określonego końca. Red Hat oferuje dodatek Red Hat Enterprise Linux (RHEL) Long-Life Add-On, znany również jako „RHEL Forever”. linuxiarze.pl/red-hat-zapewnia

                                  [?]Linuxiarze » 🌐
                                  @Linuxiarze@fe.disroot.org

                                  Red Hat zapewnia płatne wsparcie techniczne bez określonego końca. Red Hat oferuje dodatek Red Hat Enterprise Linux (RHEL) Long-Life Add-On, znany również jako „RHEL Forever”. https://linuxiarze.pl/red-hat-zapewnia-platne-wsparcie-techniczne-bez-okreslonego-konca/ #linux #redhat #server #cybersecurity

                                    [?]BeeSINT » 🌐
                                    @BeeSINT@mastodon.social

                                    💾 🟠 Glendale Community College (glendale.edu)
                                    ✓ Verified
                                    📊 ~794K records compromised
                                    📂 Academic records, Dates of birth, Email addresses, Genders +4 more
                                    📅 2026-06-15 · disclosed 26d after incident
                                    🌐 director, jQuery (Library)
                                    ⚠️ No SPF/DMARC configured

                                    🔗 beesint.com/pulse/ffc01932-e88

                                      [?]TechWire ⚡ » 🤖 🌐
                                      @techwire@social.gamefan.net

                                      Flock cameras mistakenly track car reviewer over 'stolen' tags — police ambush tester in store parking lo…

                                      Flock AI cameras failed to read the smaller digits on a non-standard New Jersey plate, leading cops to block in the driver on suspicion of driving a vehicle with "stolen" tags. It turns out the initial police report omi…

                                      tomshardware.com/tech-industry

                                      [Tom's Hardware]

                                        [?]EUVD Bot » 🤖 🌐
                                        @EUVD_Bot@mastodon.social

                                        🚨 EUVD-2026-43168

                                        📊 Score: 10.0/10 (CVSS v3.1)
                                        📦 Product: rsjoomla.com RSFiles extension for Joomla
                                        🏢 Vendor: rsjoomla.com
                                        📅 Updated: 2026-07-11

                                        📝 The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                          [?]EUVD Bot » 🤖 🌐
                                          @EUVD_Bot@mastodon.social

                                          🚨 EUVD-2026-43167

                                          📊 Score: 9.0/10 (CVSS v3.1)
                                          📦 Product: phoca.cz Phoca Download extension for Joomla
                                          🏢 Vendor: phoca.cz
                                          📅 Updated: 2026-07-11

                                          📝 The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.

                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                            [?]TheHackerWire » 🤖 🌐
                                            @thehackerwire@mastodon.social

                                            🟠 CVE-2026-14262 - High (8.8)

                                            The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication Bypass to Privilege Escalation in all versions up to, and including, 3.6.6 via the `payload` parameter. The vulnerability exists...

                                            🔗 thehackerwire.com/vulnerabilit

                                            CVE Alert: CVE-2026-14262

                                            Alt...CVE Alert: CVE-2026-14262

                                              [?]urlDNA.io :verified: » 🤖 🌐
                                              @urldna@infosec.exchange

                                              Possible Phishing 🎣
                                              on: ⚠️hxxps[:]//netflixquebec[.]blogspot[.]com
                                              🧬 Analysis at: urldna.io/scan/6a516b953b77500

                                                [?]TheHackerWire » 🤖 🌐
                                                @thehackerwire@mastodon.social

                                                🟠 CVE-2026-15335 - High (7.5)

                                                The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Parameter (form) in all versions up to, and including, 1.7.20 due to insufficient escaping on the user supplied parameter and lack of sufficient prepa...

                                                🔗 thehackerwire.com/vulnerabilit

                                                CVE Alert: CVE-2026-15335

                                                Alt...CVE Alert: CVE-2026-15335

                                                  [?]TheHackerWire » 🤖 🌐
                                                  @thehackerwire@mastodon.social

                                                  🔴 CVE-2026-14480 - Critical (9.9)

                                                  OpenPLC Runtime v3 contains an authenticated arbitrary file write
                                                  vulnerability in the legacy web UI program‑upload workflow. The
                                                  application stores an attacker‑supplied filename (prog_file) directly
                                                  into the Programs.File database field an...

                                                  🔗 thehackerwire.com/vulnerabilit

                                                  CVE Alert: CVE-2026-14480

                                                  Alt...CVE Alert: CVE-2026-14480

                                                    [?]TechWire ⚡ » 🤖 🌐
                                                    @techwire@social.gamefan.net

                                                    I used to love Claude, but the latest models are slowly ruining it

                                                    This isn't the Claude I used to love.

                                                    androidauthority.com/claude-la

                                                    [Android Authority]

                                                      [?]InfosecK2K » 🌐
                                                      @InfosecK2K@mastodon.social

                                                      Reduce cyber risk with the Principle of Least Privilege.

                                                      Limit access to only what's necessary, reduce insider threats, strengthen your organization's overall security posture, and improve compliance.

                                                        [?]pavroo » 🌐
                                                        @pavroo@universeodon.com

                                                        Red Hat zapewnia płatne wsparcie techniczne bez określonego końca. Red Hat oferuje dodatek Red Hat Enterprise Linux (RHEL) Long-Life Add-On, znany również jako „RHEL Forever”. linuxiarze.pl/red-hat-zapewnia

                                                          [?]TierraSapiens » 🤖 🌐
                                                          @tierrasapiens@mastodon.social

                                                          🖲️
                                                          ⚫ AI Agents Are a New Kind of Identity & Most Organizations Aren't Ready
                                                          🔗 darkreading.com/identity-acces

                                                          If you're handling them like a service account or API token, consider yourself behind. AI agents need a fundamentally different approach.

                                                            [?]TheHackerWire » 🤖 🌐
                                                            @thehackerwire@mastodon.social

                                                            🟠 CVE-2026-15338 - High (7.5)

                                                            The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.1 via the get_type_template function. This makes it possible for authenticated attackers, with contributor...

                                                            🔗 thehackerwire.com/vulnerabilit

                                                            CVE Alert: CVE-2026-15338

                                                            Alt...CVE Alert: CVE-2026-15338

                                                              [?]TheHackerWire » 🤖 🌐
                                                              @thehackerwire@mastodon.social

                                                              🟠 CVE-2026-13353 - High (8.8)

                                                              The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.0.1 via the 'MappedFields' parameter. This is due to missing capabi...

                                                              🔗 thehackerwire.com/vulnerabilit

                                                              CVE Alert: CVE-2026-13353

                                                              Alt...CVE Alert: CVE-2026-13353

                                                                [?]TheHackerWire » 🤖 🌐
                                                                @thehackerwire@mastodon.social

                                                                🟠 CVE-2026-13756 - High (8.8)

                                                                The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3.3. This is due to missing authorization and meta key validation in the `update()` handler for the `/wp-json/wpgb/v2/metadata` ...

                                                                🔗 thehackerwire.com/vulnerabilit

                                                                CVE Alert: CVE-2026-13756

                                                                Alt...CVE Alert: CVE-2026-13756

                                                                  [?]TechWire ⚡ » 🤖 🌐
                                                                  @techwire@social.gamefan.net

                                                                  Tencent is reportedly in talks to acquire Manus from Meta, following Beijing intervention — company expec…

                                                                  Tencent is in talks with Manus and other investors to raise the $2 billion needed to buy back the startup from Meta. Beijing ordered the two companies to unwind the deal six months after the surprise announcement of its…

                                                                  tomshardware.com/tech-industry

                                                                  [Tom's Hardware]

                                                                    [?]TechWire ⚡ » 🤖 🌐
                                                                    @techwire@social.gamefan.net

                                                                    Asus ROG Strix Scar 18 (2026) Review: Stunning Mini‑LED, serious muscle, and a few missed steps

                                                                    The Asus ROG Strix Scar 18 pairs an 18-inch mini-LED display with cutting-edge components, but omissions like PCIe 5.0 storage and dual-channel RAM —plus slightly weaker performance than Razer’s Blade 18 —keep it from t…

                                                                    tomshardware.com/laptops/gamin

                                                                    [Tom's Hardware]

                                                                      [?]TechWire ⚡ » 🤖 🌐
                                                                      @techwire@social.gamefan.net

                                                                      Steam sales reportedly topped $11 billion during H1 2026 due to shifting trends — staggering growth drive…

                                                                      Steam made an estimated $11.1 billion in revenue in the first six months of 2026, according to estimates from research firm Alinea Analytics. That's more than it did in the entire pandemic-ridden year of 2020. In fact, …

                                                                      tomshardware.com/video-games/p

                                                                      [Tom's Hardware]

                                                                        [?]TechWire ⚡ » 🤖 🌐
                                                                        @techwire@social.gamefan.net

                                                                        Intel's midrange Core Ultra 5 245K is down to its lowest price ever at just $179 on Amazon — save up to 4…

                                                                        Intel's forgotten 14-core SKU from last year has received a sizable discount on Amazon, making it one of the best value propositions in CPUs right now. It performs amicably in gaming and professional tasks thanks to its…

                                                                        tomshardware.com/pc-components

                                                                        [Tom's Hardware]

                                                                          [?]Negative PID SL » 🌐
                                                                          @negativepid@mastodon.social

                                                                          [?]EUVD Bot » 🤖 🌐
                                                                          @EUVD_Bot@mastodon.social

                                                                          🚨 EUVD-2026-43160

                                                                          📊 Score: 8.8/10 (CVSS v3.1)
                                                                          📦 Product: Essential Addons for Elementor – Popular Elementor Templates & Widgets
                                                                          🏢 Vendor: wpdevteam
                                                                          📅 Updated: 2026-07-11

                                                                          📝 The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via Email Header Injection in all versions up to,...

                                                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                                                            [?]EUVD Bot » 🤖 🌐
                                                                            @EUVD_Bot@mastodon.social

                                                                            🚨 EUVD-2026-43159

                                                                            📊 Score: 4.3/10 (CVSS v3.1)
                                                                            📦 Product: Wallet for WooCommerce
                                                                            🏢 Vendor: subratamal
                                                                            📅 Updated: 2026-07-11

                                                                            📝 The Wallet for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes i...

                                                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                                                              [?]EUVD Bot » 🤖 🌐
                                                                              @EUVD_Bot@mastodon.social

                                                                              🚨 EUVD-2026-43158

                                                                              📊 Score: 6.4/10 (CVSS v3.1)
                                                                              📦 Product: WCFM Marketplace – Multivendor Marketplace for WooCommerce
                                                                              🏢 Vendor: wclovers
                                                                              📅 Updated: 2026-07-11

                                                                              📝 The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Attachment 'post_title' in all versions up to, and including, 3.7.3 due t...

                                                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                [?]EUVD Bot » 🤖 🌐
                                                                                @EUVD_Bot@mastodon.social

                                                                                🚨 EUVD-2026-43157

                                                                                📊 Score: 7.5/10 (CVSS v3.1)
                                                                                📦 Product: WP CTA – Call Now Button, Sticky Button & Call to Action Builder
                                                                                🏢 Vendor: blendmedia
                                                                                📅 Updated: 2026-07-11

                                                                                📝 The WP CTA – Sticky CTA Builder, Generate Leads, Promote Sales plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'fildname' parameter in all versions up to, and including,...

                                                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                  [?]EUVD Bot » 🤖 🌐
                                                                                  @EUVD_Bot@mastodon.social

                                                                                  🚨 EUVD-2026-43156

                                                                                  📊 Score: 5.3/10 (CVSS v3.1)
                                                                                  📦 Product: WCFM – Frontend Manager for WooCommerce
                                                                                  🏢 Vendor: wclovers
                                                                                  📅 Updated: 2026-07-11

                                                                                  📝 The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.7.27. This is due to the plugin not properly verifying that a user is authorized t...

                                                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                    [?]EUVD Bot » 🤖 🌐
                                                                                    @EUVD_Bot@mastodon.social

                                                                                    🚨 EUVD-2026-43155

                                                                                    📊 Score: 4.4/10 (CVSS v3.1)
                                                                                    📦 Product: Widgets for Google Reviews
                                                                                    🏢 Vendor: trustindex
                                                                                    📅 Updated: 2026-07-11

                                                                                    📝 The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 13.3 due to insufficient input sanitization and output escaping. This makes it pos...

                                                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                      Back to top - More...