voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
🚨 EUVD-2026-43154
📊 Score: 6.4/10 (CVSS v3.1)
📦 Product: fresh Podcaster
🏢 Vendor: freshlabs
📅 Updated: 2026-07-11
📝 The fresh Podcaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'freshpodcaster' shortcode in all versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping on user supplied attribu...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43154
🚨 EUVD-2025-210456
📊 Score: 4.9/10 (CVSS v3.1)
📦 Product: Catalyst Connect Zoho CRM Client Portal
🏢 Vendor: catalyst2020
📅 Updated: 2026-07-11
📝 The Catalyst Connect Zoho CRM Client Portal plugin for WordPress is vulnerable to time-based SQL Injection via the ‘uid’ parameter in all versions up to, and including, 2.2.0 due to insufficient escaping on the user sup...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-210456
Possible Phishing 🎣
on: ⚠️hxxps[:]//espace-compte-disneyplus[.]com
🧬 Analysis at: https://urldna.io/scan/6a514f463b775000020828cf
#cybersecurity #phishing #infosec #urldna #scam #infosec
🚨 EUVD-2026-43153
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Context Blog
🏢 Vendor: postmagthemes
📅 Updated: 2026-07-11
📝 The Context Blog theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.5 via the context_blog_modal_popup. This makes it possible for unauthenticated attackers to extract the content of passw...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43153
🚨 EUVD-2026-43152
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Cost Calculator Builder
🏢 Vendor: stylemix
📅 Updated: 2026-07-11
📝 The Cost Calculator Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.11 via the (template body). This makes it possible for unauthenticated attackers to extract the plaint...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43152
🚨 EUVD-2026-43151
📊 Score: 4.3/10 (CVSS v3.1)
📦 Product: WP Easy Pay – Payment and Donation form Builder for Square
🏢 Vendor: saadiqbal
📅 Updated: 2026-07-11
📝 The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0. This is due to the plugin not properly...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43151
🚨 EUVD-2026-43150
📊 Score: 4.4/10 (CVSS v3.1)
📦 Product: White Label CMS
🏢 Vendor: videousermanuals
📅 Updated: 2026-07-11
📝 The White Label CMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.7.12 due to insufficient input sanitization and output escaping. This makes it possible for auth...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43150
🚨 EUVD-2026-43149
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: WP Hotel Booking
🏢 Vendor: thimpress
📅 Updated: 2026-07-11
📝 The WP Hotel Booking plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 2.3.1. This is due to the `web_hook_process_paypal_standard()` IPN handler selecting its PayPal validat...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43149
🚨 EUVD-2025-210455
📊 Score: 8.8/10 (CVSS v3.1)
📦 Product: Code Engine – PHP Snippets, AI Functions & Automation for WordPress
🏢 Vendor: tigroumeow
📅 Updated: 2026-07-11
📝 The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.3.5 via the 'code-engine' shortcode. This is due to the plugin not restrictin...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-210455
🚨 EUVD-2026-43148
📊 Score: 8.1/10 (CVSS v3.1)
📦 Product: SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments
🏢 Vendor: SureCart
📅 Updated: 2026-07-11
📝 The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and including, 4.2.3. This is due t...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43148
🚨 EUVD-2026-43147
📊 Score: 7.2/10 (CVSS v3.1)
📦 Product: Form Vibes – Save Contact Form 7 & Elementor Form Entries to Database
🏢 Vendor: WPVibes
📅 Updated: 2026-07-11
📝 The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 Form Field in all versions up to, and including, 1.5.2 due to insuf...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43147
Campcodes: 536 CVEs, 99% unpatched. 170 high-severity flaws, avg CVSS 6.12. Top weaknesses: Injection (CWE-74, CWE-89) & XSS (CWE-79). Trust Score: C. Small vendor, big risk. #Campcodes #cybersecurity #infosec
Are you filthy enough for a $700 portable shower?
A luxurious hot shower anywhere you go. Hot showers, like electricity, are a luxury that's easy to take for granted. That all changes after a few nights camping at a music festival, a week toiling at a backcountry job s…
https://www.theverge.com/reviews/963814/joolca-hottap-portable-shower-review
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
🟠 CVE-2026-42952 - High (7.5)
Previously, there was no throttling on repeated authentication attempts
to the charging station backend, which could allow an attacker to
execute a denial-of-service attack.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-42952/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-44383 - High (7.5)
Multiple connections to the backend using the same charging station ID
are allowed, which could allow an attacker to deploy multiple instances
of malicious OCPP clients to overwhelm the backend.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44383/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-55175 - High (7.5)
Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4 on their respective release lines, Kustomize bake operations allow unsafe YAML tag processing in rosco manifests. T...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55175/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Les comparto un video que grabé para una capacitación en seguridad y protección de la información:
"No dejes tus servidores expuestos: Principios fundamentales de Hardening y Seguridad"
Es bastante conceptual, como punto de partida para mostrar diferentes herramientas para cubrir cada aspecto.
Espero que les guste y les sirva!
#ciberseguridad #cybersecurity #privacy #encryption #cryptography #criptografía #infosec #juncotic
The best VPS hosting services for 2026: Expert tested and reviewed
If you need more power than shared hosting services can provide, the top VPS hosting providers can give you the dedicated resources and scalability needed to push your project to the next level.
https://www.zdnet.com/article/best-vps-hosting-service/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
Possible Phishing 🎣
on: ⚠️hxxps[:]//metatrextch[.]gitbook[.]io
🧬 Analysis at: https://urldna.io/scan/6a511ec33b775000020822d7
#cybersecurity #phishing #infosec #urldna #scam #infosec
Best wireless chargers of 2026: Expert tested
We tested the top wireless chargers from brands like Anker and Nomad to find the ones that make powering your devices easier than ever.
https://www.zdnet.com/article/best-wireless-charger/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
Viernes noche en Buenos Aires 🌃
Código, café y pensando en lo que se viene. 27 días para DEF CON 34, el hype está al máximo.
¿Qué están hackeando, leyendo o rompiendo este finde? 🔥🛡️
You're using 3M Command strips all wrong
3M Command strips are incredibly useful, if you use them right. These tips can turn 'it fell off the wall' into 'it's still there' years later.
https://www.zdnet.com/article/youre-using-3m-command-strips-all-wrong/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
Possible Phishing 🎣
on: ⚠️hxxps[:]//v0-seu-chopp-gelado[.]vercel[.]app
🧬 Analysis at: https://urldna.io/scan/6a51253c3b7750000208240b
#cybersecurity #phishing #infosec #urldna #scam #infosec
Metasploit Arms FlowiseAI and macOS: Two Exploits Land in the Framework https://deafnews.it/en/article/metasploit-arms-flowiseai-and-macos-two-exploits-land-in-the-framework #Cybersecurity
The 'learn to code' era is over - and employers are on the hook for reskilling now
AI's ushered in a new era of reskilling. Here's what the industry can learn from the last decade's drive to put people in tech jobs.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
The footgun of right-to-left decorative characters
https://blog.alexbeals.com/posts/the-footgun-of-right-to-left-decorative-characters
Comments: https://news.ycombinator.com/item?id=48813246
#HackerNews #footgun #righttoleft #decorativecharacters #cybersecurity #techblog
I ditched Google Drive for my own self-hosted storage - and I wish I'd done it sooner
Nextcloud is a free and open-source storage option that offers several advantages. Here's how it works.
https://www.zdnet.com/article/i-ditched-google-drive-for-self-hosted-storage-nextcloud/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
Possible Phishing 🎣
on: ⚠️hxxps[:]//barclays-banking[.]net/landing/form/56ef60af-8857-46f5-acdb-2e0a0b56a105
🧬 Analysis at: https://urldna.io/scan/6a5165353b77500002082b38
#cybersecurity #phishing #infosec #urldna #scam #infosec
Sony 1000X The Collexion vs. Bowers & Wilkins Px8 S2: Both wow, but one is comfier
Sony's and Bowers & Wilkins' premium headphones deliver an elevated experience, but choosing the right pair isn't as cut-and-dry as you'd think.
https://www.zdnet.com/article/sony-1000x-the-collexion-vs-bowers-wilkins-px8-s2/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
SpaceX wants to launch 100,000 more Starlink satellites - for 100x the bandwidth
It could mean faster internet for rural customers, but not everyone is happy.
https://www.zdnet.com/article/spacex-wants-to-launch-100000-more-starlink-satellites/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
🚨 EUVD-2026-43118
📊 Score: 8.8/10 (CVSS v3.1)
📦 Product: WP Grid Builder
🏢 Vendor: WP Grid Builder
📅 Updated: 2026-07-11
📝 The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3.3. This is due to missing authorization and meta key validation in the `update()` handler for the `/wp-json/wpgb/v2/metad...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43118
🚨 EUVD-2026-43117
📊 Score: 6.5/10 (CVSS v3.1)
📦 Product: Under Construction Page (Pro)
🏢 Vendor: webfactory
📅 Updated: 2026-07-11
📝 The UnderConstructionPage PRO plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.76. This is due to the plugin accepting arbitrary local file paths in the template_thumbnail parameter an...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43117
Possible Phishing 🎣
on: ⚠️hxxps[:]//cs491-backend-2026[.]web[.]app
🧬 Analysis at: https://urldna.io/scan/6a51253b3b77500002082408
#cybersecurity #phishing #infosec #urldna #scam #infosec
"US cybersecurity agency CISA had to build its incident playbook during the incident, agency reveals"
""
Red Hat will support your RHEL forever now - for a price
Red Hat's new Long-Life Add-On extends support on a specific release for as long as you're willing to pay for it.
https://www.zdnet.com/article/red-hat-enterprise-linux-forever-support/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
🟠 CVE-2026-58499 - High (8.2)
EverOS is a memory runtime for agents. Prior to 1.0.1, EverOS is vulnerable to path traversal in the POST /api/v1/memory/add ingestion endpoint because the per-message sender_id field was not validated as a path-safe identifier, unlike app_id and ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58499/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-57220 - High (7.5)
RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, the RabbitMQ stream listener does not enforce the configured stream frame-size limit while assembling frames during authentication and before Tune negotiation, allowing an unauthenticat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-57220/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🔴 CVE-2026-57807 - Critical (9.8)
Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth Client) allows Password Recovery Exploitation.
This issue affects OAuth Single Sign On - SSO (OAuth ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-57807/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🔴 CVE-2026-55879 - Critical (9.3)
OpenReplay is a self-hosted session replay suite. From 1.24.0 before 1.25.0, the OpenReplay tracking SDK accepts custom event names and captured page URLs from any visitor using a public project key, stores them in ClickHouse without output encodi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55879/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-55659 - High (7.7)
Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, several server-rendered Grist pages embedded user-controlled values into the page and into inline scripts without fully escaping them, allowing cross-site scripti...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55659/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-55213 - High (7.5)
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit edd7a120bfc4af11ac0cbebce2a43cc1f93f9af1, when h2o processes a QPACK instruction sent from the peer over HTTP/3, lib/http3/qpack.c might allocate an on-stack buffe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55213/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Pixel 11 Pro Fold FCC listing adds support for a big Tensor G6 shake-up
This could be the first Tensor chip ever to not use a Samsung Exynos modem.
https://www.androidauthority.com/tensor-g6-mediatek-modem-2-3686559/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Disney Plus is reportedly looking into a free streaming tier
Disney Plus is considering making some of its content free to watch, according to a report from Business Insider. A source tells the outlet that Adam Smith, Disney's chief product and technology officer, mentioned a fre…
https://www.theverge.com/streaming/964056/disney-plus-free-tier-report
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Netflix is turning into YouTube
Netflix has shows and movies. And video games. And live sports. And podcasts. And also, apparently, YouTube videos? For a company that used to seem like the next big thing in TV, it all feels a little frenetic, and mayb…
https://www.theverge.com/podcast/964082/netflix-youtube-smart-glasses-vergecast
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Spotify will let you fine-tune your weekly Release Radar playlist
Spotify is giving listeners control to fine-tune what gets surfaced for them in Release Radar - one of its most popular weekly playlists. The new options allow you to narrow the playlist to a specific genre, focus on ar…
https://www.theverge.com/entertainment/964021/spotify-release-radar-algorithm-controls
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]