voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]TechWire ⚡ » 🤖 🌐
@techwire@social.gamefan.net

The 'learn to code' era is over - and employers are on the hook for reskilling now

AI's ushered in a new era of reskilling. Here's what the industry can learn from the last decade's drive to put people in tech jobs.

zdnet.com/article/learn-to-cod

[ZDNet]

    [?]Hacker News » 🤖 🌐
    @h4ckernews@mastodon.social

    [?]TechWire ⚡ » 🤖 🌐
    @techwire@social.gamefan.net

    I ditched Google Drive for my own self-hosted storage - and I wish I'd done it sooner

    Nextcloud is a free and open-source storage option that offers several advantages. Here's how it works.

    zdnet.com/article/i-ditched-go

    [ZDNet]

      [?]urlDNA.io :verified: » 🤖 🌐
      @urldna@infosec.exchange

      Possible Phishing 🎣
      on: ⚠️hxxps[:]//barclays-banking[.]net/landing/form/56ef60af-8857-46f5-acdb-2e0a0b56a105
      🧬 Analysis at: urldna.io/scan/6a5165353b77500

        [?]TechWire ⚡ » 🤖 🌐
        @techwire@social.gamefan.net

        Sony 1000X The Collexion vs. Bowers & Wilkins Px8 S2: Both wow, but one is comfier

        Sony's and Bowers & Wilkins' premium headphones deliver an elevated experience, but choosing the right pair isn't as cut-and-dry as you'd think.

        zdnet.com/article/sony-1000x-t

        [ZDNet]

          [?]TechWire ⚡ » 🤖 🌐
          @techwire@social.gamefan.net

          SpaceX wants to launch 100,000 more Starlink satellites - for 100x the bandwidth

          It could mean faster internet for rural customers, but not everyone is happy.

          zdnet.com/article/spacex-wants

          [ZDNet]

            [?]EUVD Bot » 🤖 🌐
            @EUVD_Bot@mastodon.social

            🚨 EUVD-2026-43118

            📊 Score: 8.8/10 (CVSS v3.1)
            📦 Product: WP Grid Builder
            🏢 Vendor: WP Grid Builder
            📅 Updated: 2026-07-11

            📝 The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3.3. This is due to missing authorization and meta key validation in the `update()` handler for the `/wp-json/wpgb/v2/metad...

            🔗 euvd.enisa.europa.eu/vulnerabi

              [?]EUVD Bot » 🤖 🌐
              @EUVD_Bot@mastodon.social

              🚨 EUVD-2026-43117

              📊 Score: 6.5/10 (CVSS v3.1)
              📦 Product: Under Construction Page (Pro)
              🏢 Vendor: webfactory
              📅 Updated: 2026-07-11

              📝 The UnderConstructionPage PRO plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.76. This is due to the plugin accepting arbitrary local file paths in the template_thumbnail parameter an...

              🔗 euvd.enisa.europa.eu/vulnerabi

                [?]urlDNA.io :verified: » 🤖 🌐
                @urldna@infosec.exchange

                Possible Phishing 🎣
                on: ⚠️hxxps[:]//cs491-backend-2026[.]web[.]app
                🧬 Analysis at: urldna.io/scan/6a51253b3b77500

                  [?]/G|T|R|O|N|I|X\ :python: :emacs: :nix: :linux: » 🌐
                  @gtronix@infosec.exchange

                  "US cybersecurity agency CISA had to build its incident playbook during the incident, agency reveals"

                  ""

                  techcrunch.com/2026/07/10/us-c

                    [?]TechWire ⚡ » 🤖 🌐
                    @techwire@social.gamefan.net

                    Red Hat will support your RHEL forever now - for a price

                    Red Hat's new Long-Life Add-On extends support on a specific release for as long as you're willing to pay for it.

                    zdnet.com/article/red-hat-ente

                    [ZDNet]

                      [?]TheHackerWire » 🤖 🌐
                      @thehackerwire@mastodon.social

                      🟠 CVE-2026-58499 - High (8.2)

                      EverOS is a memory runtime for agents. Prior to 1.0.1, EverOS is vulnerable to path traversal in the POST /api/v1/memory/add ingestion endpoint because the per-message sender_id field was not validated as a path-safe identifier, unlike app_id and ...

                      🔗 thehackerwire.com/vulnerabilit

                      CVE Alert: CVE-2026-58499

                      Alt...CVE Alert: CVE-2026-58499

                        [?]TheHackerWire » 🤖 🌐
                        @thehackerwire@mastodon.social

                        🟠 CVE-2026-57220 - High (7.5)

                        RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, the RabbitMQ stream listener does not enforce the configured stream frame-size limit while assembling frames during authentication and before Tune negotiation, allowing an unauthenticat...

                        🔗 thehackerwire.com/vulnerabilit

                        CVE Alert: CVE-2026-57220

                        Alt...CVE Alert: CVE-2026-57220

                          [?]TheHackerWire » 🤖 🌐
                          @thehackerwire@mastodon.social

                          🔴 CVE-2026-57807 - Critical (9.8)

                          Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth Client) allows Password Recovery Exploitation.

                          This issue affects OAuth Single Sign On - SSO (OAuth ...

                          🔗 thehackerwire.com/vulnerabilit

                          CVE Alert: CVE-2026-57807

                          Alt...CVE Alert: CVE-2026-57807

                            [?]TheHackerWire » 🤖 🌐
                            @thehackerwire@mastodon.social

                            🔴 CVE-2026-55879 - Critical (9.3)

                            OpenReplay is a self-hosted session replay suite. From 1.24.0 before 1.25.0, the OpenReplay tracking SDK accepts custom event names and captured page URLs from any visitor using a public project key, stores them in ClickHouse without output encodi...

                            🔗 thehackerwire.com/vulnerabilit

                            CVE Alert: CVE-2026-55879

                            Alt...CVE Alert: CVE-2026-55879

                              [?]TheHackerWire » 🤖 🌐
                              @thehackerwire@mastodon.social

                              🟠 CVE-2026-55659 - High (7.7)

                              Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, several server-rendered Grist pages embedded user-controlled values into the page and into inline scripts without fully escaping them, allowing cross-site scripti...

                              🔗 thehackerwire.com/vulnerabilit

                              CVE Alert: CVE-2026-55659

                              Alt...CVE Alert: CVE-2026-55659

                                [?]TheHackerWire » 🤖 🌐
                                @thehackerwire@mastodon.social

                                🟠 CVE-2026-55213 - High (7.5)

                                h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit edd7a120bfc4af11ac0cbebce2a43cc1f93f9af1, when h2o processes a QPACK instruction sent from the peer over HTTP/3, lib/http3/qpack.c might allocate an on-stack buffe...

                                🔗 thehackerwire.com/vulnerabilit

                                CVE Alert: CVE-2026-55213

                                Alt...CVE Alert: CVE-2026-55213

                                  [?]TechWire ⚡ » 🤖 🌐
                                  @techwire@social.gamefan.net

                                  Pixel 11 Pro Fold FCC listing adds support for a big Tensor G6 shake-up

                                  This could be the first Tensor chip ever to not use a Samsung Exynos modem.

                                  androidauthority.com/tensor-g6

                                  [Android Authority]

                                    [?]TechWire ⚡ » 🤖 🌐
                                    @techwire@social.gamefan.net

                                    Disney Plus is reportedly looking into a free streaming tier

                                    Disney Plus is considering making some of its content free to watch, according to a report from Business Insider. A source tells the outlet that Adam Smith, Disney's chief product and technology officer, mentioned a fre…

                                    theverge.com/streaming/964056/

                                    [The Verge]

                                      [?]TechWire ⚡ » 🤖 🌐
                                      @techwire@social.gamefan.net

                                      Netflix is turning into YouTube

                                      Netflix has shows and movies. And video games. And live sports. And podcasts. And also, apparently, YouTube videos? For a company that used to seem like the next big thing in TV, it all feels a little frenetic, and mayb…

                                      theverge.com/podcast/964082/ne

                                      [The Verge]

                                        [?]TechWire ⚡ » 🤖 🌐
                                        @techwire@social.gamefan.net

                                        Spotify will let you fine-tune your weekly Release Radar playlist

                                        Spotify is giving listeners control to fine-tune what gets surfaced for them in Release Radar - one of its most popular weekly playlists. The new options allow you to narrow the playlist to a specific genre, focus on ar…

                                        theverge.com/entertainment/964

                                        [The Verge]

                                          [?]EUVD Bot » 🤖 🌐
                                          @EUVD_Bot@mastodon.social

                                          🚨 EUVD-2026-43105

                                          📊 Score: 7.1/10 (CVSS v3.1)
                                          📦 Product: frappe
                                          🏢 Vendor: frappe
                                          📅 Updated: 2026-07-10

                                          📝 Frappe is a full-stack web application framework. Prior to 16.19.0, authorization bypass was possible via the update_page endpoint in Workspace because public workspaces did not receive the required Workspace Manager edit check. This issue is fixed in version ...

                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                            [?]EUVD Bot » 🤖 🌐
                                            @EUVD_Bot@mastodon.social

                                            🚨 EUVD-2026-43104

                                            📊 Score: 5.3/10 (CVSS v3.1)
                                            📦 Product: frappe, frappe
                                            🏢 Vendor: frappe
                                            📅 Updated: 2026-07-10

                                            📝 Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.110.0, users without write access could attach files to any doctype through file-handling API endpoints such as add_attachments. This issue is fixed in versions 16.20.0 and 15.11...

                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                              [?]EUVD Bot » 🤖 🌐
                                              @EUVD_Bot@mastodon.social

                                              🚨 EUVD-2026-43104

                                              📊 Score: 5.3/10 (CVSS v3.1)
                                              📦 Product: frappe, frappe
                                              🏢 Vendor: frappe
                                              📅 Updated: 2026-07-10

                                              📝 Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.110.0, users without write access could attach files to any doctype through file-handling API endpoints such as add_attachments. This issue is fixed in versions 16.20.0 and 15.11...

                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                [?]EUVD Bot » 🤖 🌐
                                                @EUVD_Bot@mastodon.social

                                                🚨 EUVD-2026-43103

                                                📊 Score: 7.1/10 (CVSS v3.1)
                                                📦 Product: frappe
                                                🏢 Vendor: frappe
                                                📅 Updated: 2026-07-10

                                                📝 Frappe is a full-stack web application framework. Prior to 16.18.3, possible path traversal and local file inclusion were possible through secure local resource access in the Chrome PDF Generator. This issue is fixed in version 16.18.3.

                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                  [?]EUVD Bot » 🤖 🌐
                                                  @EUVD_Bot@mastodon.social

                                                  🚨 EUVD-2026-43103

                                                  📊 Score: 7.1/10 (CVSS v3.1)
                                                  📦 Product: frappe
                                                  🏢 Vendor: frappe
                                                  📅 Updated: 2026-07-10

                                                  📝 Frappe is a full-stack web application framework. Prior to 16.18.3, possible path traversal and local file inclusion were possible through secure local resource access in the Chrome PDF Generator. This issue is fixed in version 16.18.3.

                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                    [?]EUVD Bot » 🤖 🌐
                                                    @EUVD_Bot@mastodon.social

                                                    🚨 EUVD-2026-43102

                                                    📊 Score: 6.3/10 (CVSS v3.1)
                                                    📦 Product: Apache Log4j API, Apache Log4j API, Apache Log4j API
                                                    🏢 Vendor: Apache Software Foundation
                                                    📅 Updated: 2026-07-10

                                                    📝 Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API version...

                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                      [?]EUVD Bot » 🤖 🌐
                                                      @EUVD_Bot@mastodon.social

                                                      🚨 EUVD-2026-43102

                                                      📊 Score: 6.3/10 (CVSS v3.1)
                                                      📦 Product: Apache Log4j API, Apache Log4j API, Apache Log4j API
                                                      🏢 Vendor: Apache Software Foundation
                                                      📅 Updated: 2026-07-10

                                                      📝 Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API version...

                                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                                        [?]EUVD Bot » 🤖 🌐
                                                        @EUVD_Bot@mastodon.social

                                                        🚨 EUVD-2026-43101

                                                        📊 Score: 2.3/10 (CVSS v3.1)
                                                        📦 Product: frappe, frappe
                                                        🏢 Vendor: frappe
                                                        📅 Updated: 2026-07-10

                                                        📝 Frappe is a full-stack web application framework. Prior to 16.18.3 and 15.108.0, check_safe_sql_query permitted SELECT INTO OUTFILE queries, which could potentially work on self-hosted sites if database permissions are not well aligned and MySQL FILE p...

                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                          [?]EUVD Bot » 🤖 🌐
                                                          @EUVD_Bot@mastodon.social

                                                          🚨 EUVD-2026-43101

                                                          📊 Score: 2.3/10 (CVSS v3.1)
                                                          📦 Product: frappe, frappe
                                                          🏢 Vendor: frappe
                                                          📅 Updated: 2026-07-10

                                                          📝 Frappe is a full-stack web application framework. Prior to 16.18.3 and 15.108.0, check_safe_sql_query permitted SELECT INTO OUTFILE queries, which could potentially work on self-hosted sites if database permissions are not well aligned and MySQL FILE p...

                                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                                            [?]EUVD Bot » 🤖 🌐
                                                            @EUVD_Bot@mastodon.social

                                                            🚨 EUVD-2026-43100

                                                            📊 Score: 6.9/10 (CVSS v3.1)
                                                            📦 Product: frappe, frappe
                                                            🏢 Vendor: frappe
                                                            📅 Updated: 2026-07-10

                                                            📝 Frappe is a full-stack web application framework. Prior to 16.16.0 and 15.106.0, user enumeration could be performed via the reset_password endpoint. This issue is fixed in versions 16.16.0 and 15.106.0.

                                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                                              [?]EUVD Bot » 🤖 🌐
                                                              @EUVD_Bot@mastodon.social

                                                              🚨 EUVD-2026-43100

                                                              📊 Score: 6.9/10 (CVSS v3.1)
                                                              📦 Product: frappe, frappe
                                                              🏢 Vendor: frappe
                                                              📅 Updated: 2026-07-10

                                                              📝 Frappe is a full-stack web application framework. Prior to 16.16.0 and 15.106.0, user enumeration could be performed via the reset_password endpoint. This issue is fixed in versions 16.16.0 and 15.106.0.

                                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                                [?]EUVD Bot » 🤖 🌐
                                                                @EUVD_Bot@mastodon.social

                                                                🚨 EUVD-2026-43099

                                                                📊 Score: 5.3/10 (CVSS v3.1)
                                                                📦 Product: frappe, frappe
                                                                🏢 Vendor: frappe
                                                                📅 Updated: 2026-07-10

                                                                📝 Frappe is a full-stack web application framework. Prior to 15.107.5 and 16.18.2, an endpoint in reportview lacked appropriate permission checks and that has since been fixed. This vulnerability is fixed in 15.107.5 and 16.18.2.

                                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                                  [?]EUVD Bot » 🤖 🌐
                                                                  @EUVD_Bot@mastodon.social

                                                                  🚨 EUVD-2026-43099

                                                                  📊 Score: 5.3/10 (CVSS v3.1)
                                                                  📦 Product: frappe, frappe
                                                                  🏢 Vendor: frappe
                                                                  📅 Updated: 2026-07-10

                                                                  📝 Frappe is a full-stack web application framework. Prior to 15.107.5 and 16.18.2, an endpoint in reportview lacked appropriate permission checks and that has since been fixed. This vulnerability is fixed in 15.107.5 and 16.18.2.

                                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                                    [?]EUVD Bot » 🤖 🌐
                                                                    @EUVD_Bot@mastodon.social

                                                                    🚨 EUVD-2026-43098

                                                                    📊 Score: 8.7/10 (CVSS v3.1)
                                                                    📦 Product: cphalcon
                                                                    🏢 Vendor: phalcon
                                                                    📅 Updated: 2026-07-10

                                                                    📝 Phalcon is a high-performance, full-stack PHP framework. Prior to 5.15.0, every Phalcon MVC application built with a default router registers a built-in route whose compiled PCRE pattern contains the nested quantifier (/.), and the same construct is produce...

                                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                                      [?]EUVD Bot » 🤖 🌐
                                                                      @EUVD_Bot@mastodon.social

                                                                      🚨 EUVD-2026-43098

                                                                      📊 Score: 8.7/10 (CVSS v3.1)
                                                                      📦 Product: cphalcon
                                                                      🏢 Vendor: phalcon
                                                                      📅 Updated: 2026-07-10

                                                                      📝 Phalcon is a high-performance, full-stack PHP framework. Prior to 5.15.0, every Phalcon MVC application built with a default router registers a built-in route whose compiled PCRE pattern contains the nested quantifier (/.), and the same construct is produce...

                                                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                                                        [?]EUVD Bot » 🤖 🌐
                                                                        @EUVD_Bot@mastodon.social

                                                                        🚨 EUVD-2026-43097

                                                                        📊 Score: 8.2/10 (CVSS v3.1)
                                                                        📦 Product: cphalcon
                                                                        🏢 Vendor: phalcon
                                                                        📅 Updated: 2026-07-10

                                                                        📝 Phalcon is a high-performance, full-stack PHP framework. Prior to 5.14.1, Phalcon\Encryption\Crypt::decrypt compares the attacker-supplied HMAC tag against the freshly computed HMAC using PHP/Zephir identity comparison, which lowers to a byte-wise compariso...

                                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                                          [?]EUVD Bot » 🤖 🌐
                                                                          @EUVD_Bot@mastodon.social

                                                                          🚨 EUVD-2026-43097

                                                                          📊 Score: 8.2/10 (CVSS v3.1)
                                                                          📦 Product: cphalcon
                                                                          🏢 Vendor: phalcon
                                                                          📅 Updated: 2026-07-10

                                                                          📝 Phalcon is a high-performance, full-stack PHP framework. Prior to 5.14.1, Phalcon\Encryption\Crypt::decrypt compares the attacker-supplied HMAC tag against the freshly computed HMAC using PHP/Zephir identity comparison, which lowers to a byte-wise compariso...

                                                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                                                            [?]deafnews » 🤖 🌐
                                                                            @deafnews@infosec.exchange

                                                                            [?]Brian Clark » 🌐
                                                                            @deepthoughts10@infosec.exchange

                                                                            @badsamurai cool! Didn’t know about this one:

                                                                            Block (or limit) access to the login at dash.cloudflare.com. Especially if you are not a Cloudflare customer. This is a low-regret technique to reduce shadow cloud and dev sprawl on Cloudflare.

                                                                              [?]TechWire ⚡ » 🤖 🌐
                                                                              @techwire@social.gamefan.net

                                                                              Nvidia’s biggest RAM supplier just had a trillion-dollar debut on Wall Street

                                                                              SK Hynix CEO Kwak Noh-Jung. | Image: Michael Nagle/Bloomberg via Getty Images As the AI boom boosts demand for RAM, SK Hynix - one of the world's biggest suppliers of memory chips - launched on Wall Street Friday. The S…

                                                                              theverge.com/tech/964121/sk-hy

                                                                              [The Verge]

                                                                                [?]jbz » 🌐
                                                                                @jbz@indieweb.social

                                                                                📄 A Final Return for OpenBSD Anti-Return-Oriented Programming Mitigations

                                                                                「 We bring this mitigation, originally developed for the custom OpenBSD implementation of the LLVM compiler suite, to GCC by way of a standalone utility that sits in between the compiler and the assembler and rewrites potential gadget instructions before assembly into object code 」

                                                                                papers.ssrn.com/sol3/papers.cf

                                                                                  [?]AIWAF Project » 🌐
                                                                                  @aiwafproject@mastodon.social

                                                                                  Your application already describes itself through its source code. AIWAF uses AST analysis to automatically discover routes, authentication, APIs, forms, and expected payloads, helping reduce manual security configuration as applications evolve.

                                                                                    [?]TheHackerWire » 🤖 🌐
                                                                                    @thehackerwire@mastodon.social

                                                                                    🔴 CVE-2026-55500 - Critical (9.9)

                                                                                    9Router is an AI router & token saver. Prior to 0.4.80, the /api/settings/database endpoint allows full database export (containing all credentials, API keys, OAuth tokens, and settings) and full database import (complete overwrite) without any au...

                                                                                    🔗 thehackerwire.com/vulnerabilit

                                                                                    CVE Alert: CVE-2026-55500

                                                                                    Alt...CVE Alert: CVE-2026-55500

                                                                                      [?]TheHackerWire » 🤖 🌐
                                                                                      @thehackerwire@mastodon.social

                                                                                      🟠 CVE-2026-54149 - High (8.8)

                                                                                      MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.0-lts, MaxKB tool import functionality in apps/tools/serializers/tool.py and MCP referencing mode in apps/application/chat_pipeline/step/chat_step/impl/base_chat_step.py do not con...

                                                                                      🔗 thehackerwire.com/vulnerabilit

                                                                                      CVE Alert: CVE-2026-54149

                                                                                      Alt...CVE Alert: CVE-2026-54149

                                                                                        [?]TheHackerWire » 🤖 🌐
                                                                                        @thehackerwire@mastodon.social

                                                                                        🟠 CVE-2026-33382 - High (7.5)

                                                                                        Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing...

                                                                                        🔗 thehackerwire.com/vulnerabilit

                                                                                        CVE Alert: CVE-2026-33382

                                                                                        Alt...CVE Alert: CVE-2026-33382

                                                                                          [?]TechWire ⚡ » 🤖 🌐
                                                                                          @techwire@social.gamefan.net

                                                                                          This Game Boy Micro-style console instantly sold out — but you get another chance to buy tonight

                                                                                          AYANEO Pocket Micro 2 sales return tonight, and you absolutely do not want to miss out.

                                                                                          androidauthority.com/pocket-mi

                                                                                          [Android Authority]

                                                                                            [?]TechWire ⚡ » 🤖 🌐
                                                                                            @techwire@social.gamefan.net

                                                                                            Google Pixel 11 Pro Fold appears at the FCC ahead of August launch

                                                                                            Pixel 11 Pro Fold's launch feels closer than ever.

                                                                                            androidauthority.com/pixel-11-

                                                                                            [Android Authority]

                                                                                              Back to top - More...