voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]TechWire ⚡ » 🤖 🌐
@techwire@social.gamefan.net

Would you host part of an AI data center in your home?

A solar and home energy storage company is expanding into AI data centers, but not by building one - instead, it's offering to pay its customers to put its compute units in their homes. Sunrun is launching a pilot progr…

theverge.com/ai-artificial-int

[The Verge]

    [?]TechWire ⚡ » 🤖 🌐
    @techwire@social.gamefan.net

    Samsung may finally fix Voice Recorder’s biggest transcription limitation

    Your Samsung phone could soon get much better at transcribing voice notes.

    androidauthority.com/samsung-v

    [Android Authority]

      [?]Negative PID SL » 🌐
      @negativepid@mastodon.social

      [?]EUVD Bot » 🤖 🌐
      @EUVD_Bot@mastodon.social

      🚨 EUVD-2026-42971

      📊 Score: 7.4/10 (CVSS v3.1)
      📦 Product: coTURN
      🏢 Vendor: coturn
      📅 Updated: 2026-07-10

      📝 Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, coturn rejects loopback peers by default unless allow-loopback-peers is enabled, but the default loopback guard can be bypassed by using the IPv4-mapped IPv6 peer address ::f...

      🔗 euvd.enisa.europa.eu/vulnerabi

        [?]EUVD Bot » 🤖 🌐
        @EUVD_Bot@mastodon.social

        🚨 EUVD-2026-42970

        📊 Score: 6.0/10 (CVSS v3.1)
        📦 Product: coTURN
        🏢 Vendor: coturn
        📅 Updated: 2026-07-10

        📝 Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, the psd print sessions dump CLI command in coturn takes a filename argument and directly passes it to fopen with no path validation. An authenticated admin with CLI access ca...

        🔗 euvd.enisa.europa.eu/vulnerabi

          [?]EUVD Bot » 🤖 🌐
          @EUVD_Bot@mastodon.social

          🚨 EUVD-2026-42962

          📊 Score: 4.2/10 (CVSS v3.1)
          📦 Product: zitadel, zitadel
          🏢 Vendor: zitadel
          📅 Updated: 2026-07-10

          📝 ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Provider validation in internal/idp/providers/jwt/session.go skips the maximum token age freshness check when an incoming token omits...

          🔗 euvd.enisa.europa.eu/vulnerabi

            [?]EUVD Bot » 🤖 🌐
            @EUVD_Bot@mastodon.social

            🚨 EUVD-2026-42969

            📊 Score: 7.2/10 (CVSS v3.1)
            📦 Product: coTURN
            🏢 Vendor: coturn
            📅 Updated: 2026-07-10

            📝 Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.12.0, the coturn HTTPS admin panel passes HTTP query parameters directly into SQL queries via snprintf string interpolation without sanitization. The is_secure_string filter that p...

            🔗 euvd.enisa.europa.eu/vulnerabi

              [?]EUVD Bot » 🤖 🌐
              @EUVD_Bot@mastodon.social

              🚨 EUVD-2025-210453

              📊 Score: 5.1/10 (CVSS v3.1)
              📦 Product: hestiacp
              🏢 Vendor: hestiacp
              📅 Updated: 2026-07-10

              📝 HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerability that allows authenticated low-privilege users to inject arbitrary HTML by creating a DNS record with a double-quote followed by a script payload in the value field. The applicatio...

              🔗 euvd.enisa.europa.eu/vulnerabi

                [?]EUVD Bot » 🤖 🌐
                @EUVD_Bot@mastodon.social

                🚨 EUVD-2025-210452

                📊 Score: 8.7/10 (CVSS v3.1)
                📦 Product: hestiacp
                🏢 Vendor: hestiacp
                📅 Updated: 2026-07-10

                📝 HestiaCP before 1.9.5 contains an authenticated OS command injection vulnerability that allows low-privilege authenticated users to execute arbitrary commands as root by injecting a single-quote character into unvalidated DNS record types. Attackers can ...

                🔗 euvd.enisa.europa.eu/vulnerabi

                  [?]EUVD Bot » 🤖 🌐
                  @EUVD_Bot@mastodon.social

                  🚨 EUVD-2026-42968

                  📊 Score: 9.6/10 (CVSS v3.1)
                  📦 Product: prowler
                  🏢 Vendor: prowler-cloud
                  📅 Updated: 2026-07-10

                  📝 Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML authentication flow trusted the email domain asserted in a SAMLResponse when deciding which tenant should receive the final token, and the ACS finish logic in api/src/backend/api/v1/...

                  🔗 euvd.enisa.europa.eu/vulnerabi

                    [?]The New Oil » 🤖 🌐
                    @thenewoil@mastodon.thenewoil.org

                    What are the worst apps — and how do you spot them?

                    proton.me/blog/spyware-apps

                      [?]EUVD Bot » 🤖 🌐
                      @EUVD_Bot@mastodon.social

                      🚨 EUVD-2026-42967

                      📊 Score: 8.1/10 (CVSS v3.1)
                      📦 Product: zitadel
                      🏢 Vendor: zitadel
                      📅 Updated: 2026-07-10

                      📝 ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's OAuth2 Token Exchange endpoint for urn:ietf:params:oauth:grant-type:token-exchange does not verify that the subject token belongs to the requesting client or that requested sc...

                      🔗 euvd.enisa.europa.eu/vulnerabi

                        [?]EUVD Bot » 🤖 🌐
                        @EUVD_Bot@mastodon.social

                        🚨 EUVD-2026-42966

                        📊 Score: 4.8/10 (CVSS v3.1)
                        📦 Product: zitadel
                        🏢 Vendor: zitadel
                        📅 Updated: 2026-07-10

                        📝 ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's external identity provider handler checks that the local user's email is verified but does not verify that the external IdP confirmed ownership of the same email before auto-l...

                        🔗 euvd.enisa.europa.eu/vulnerabi

                          [?]EUVD Bot » 🤖 🌐
                          @EUVD_Bot@mastodon.social

                          🚨 EUVD-2026-42964

                          📊 Score: 7.3/10 (CVSS v3.1)
                          📦 Product: zitadel
                          🏢 Vendor: zitadel
                          📅 Updated: 2026-07-10

                          📝 ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL Login V2 OIDC and SAML FailedPrecondition error paths return loginSettings.defaultRedirectUri to router.push without applying the isSafeRedirectUri check, allowing an organizati...

                          🔗 euvd.enisa.europa.eu/vulnerabi

                            [?]EUVD Bot » 🤖 🌐
                            @EUVD_Bot@mastodon.social

                            🚨 EUVD-2026-42979

                            📊 Score: 7.4/10 (CVSS v3.1)
                            📦 Product: zitadel, zitadel
                            🏢 Vendor: zitadel
                            📅 Updated: 2026-07-10

                            📝 ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's OAuth2 and OIDC CodeExchange, RefreshToken, and device token flows fail to verify that the requesting client matches the client that initiated the authoriz...

                            🔗 euvd.enisa.europa.eu/vulnerabi

                              [?]EUVD Bot » 🤖 🌐
                              @EUVD_Bot@mastodon.social

                              🚨 EUVD-2026-42978

                              📊 Score: 2.3/10 (CVSS v3.1)
                              📦 Product: zitadel
                              🏢 Vendor: zitadel
                              📅 Updated: 2026-07-10

                              📝 ZITADEL is an open source identity management platform. From 4.0.0-rc.1 through 4.15.1, ZITADEL's HTTP notification channels, OIDC BackChannel Logout, and SAML metadata URL fetches do not consistently validate user-defined URLs against protected denylist han...

                              🔗 euvd.enisa.europa.eu/vulnerabi

                                [?]EUVD Bot » 🤖 🌐
                                @EUVD_Bot@mastodon.social

                                🚨 EUVD-2026-42977

                                📊 Score: 2.3/10 (CVSS v3.1)
                                📦 Product: zitadel
                                🏢 Vendor: zitadel
                                📅 Updated: 2026-07-10

                                📝 ZITADEL is an open source identity management platform. Prior to 4.15.1, ZITADEL's event store validation can retain the original resource owner for a deleted user identifier, causing a later user recreated with the same identifier in another organization to...

                                🔗 euvd.enisa.europa.eu/vulnerabi

                                  [?]EUVD Bot » 🤖 🌐
                                  @EUVD_Bot@mastodon.social

                                  🚨 EUVD-2026-42976

                                  📊 Score: 6.3/10 (CVSS v3.1)
                                  📦 Product: AI Assist for Customer
                                  🏢 Vendor: Deloitte
                                  📅 Updated: 2026-07-10

                                  📝 Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additional parameters to read from or inject content into the retrieval-augmented generation (RAG) corpus. On 2026-03-25, AI Assi...

                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                    [?]urlDNA.io :verified: » 🤖 🌐
                                    @urldna@infosec.exchange

                                    Possible Phishing 🎣
                                    on: ⚠️hxxps[:]//217651[.]8b[.]io
                                    🧬 Analysis at: urldna.io/scan/6a51333d3b77500

                                      [?]EUVD Bot » 🤖 🌐
                                      @EUVD_Bot@mastodon.social

                                      🚨 EUVD-2026-42975

                                      📊 Score: 6.9/10 (CVSS v3.1)
                                      📦 Product: AI Assist for Customer
                                      🏢 Vendor: Deloitte
                                      📅 Updated: 2026-07-10

                                      📝 Deloitte AI Assist for Customer accepted unauthenticated POST requests through public-facing API endpoints that allowed a remote attacker to make limited additions to the configuration. These additions were not used by the system. On 2026-03-...

                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                        [?]EUVD Bot » 🤖 🌐
                                        @EUVD_Bot@mastodon.social

                                        🚨 EUVD-2026-42974

                                        📊 Score: 6.9/10 (CVSS v3.1)
                                        📦 Product: AI Assist for Customer
                                        🏢 Vendor: Deloitte
                                        📅 Updated: 2026-07-10

                                        📝 Deloitte AI Assist for Customer disclosed some configuration information through public-facing API endpoints that accepted unauthenticated requests. This information could reduce an attacker’s reconnaissance effort. On 2026-03-25, AI Assist f...

                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                          [?]Hugo | DevOps | Cybersecurity » 🌐
                                          @hugovalters@mastodon.social

                                          Radare2: 24 CVEs tracked, 87% unpatched. 0 CISA KEV exploited, but avg CVSS 6.67. Trust Score: C. Open source reverse engineering tool needs patching vigilance.

                                          valtersit.com/vendors/radare2/

                                            [?]TechWire ⚡ » 🤖 🌐
                                            @techwire@social.gamefan.net

                                            [?]TechWire ⚡ » 🤖 🌐
                                            @techwire@social.gamefan.net

                                            Spotify is tweaking one of Discover Weekly’s best features

                                            Spotify is testing revised filters for some playlists, while also announcing brand-new controls for Release Radar.

                                            androidauthority.com/spotify-d

                                            [Android Authority]

                                              [?]The New Oil » 🤖 🌐
                                              @thenewoil@mastodon.thenewoil.org

                                              [?]TechWire ⚡ » 🤖 🌐
                                              @techwire@social.gamefan.net

                                              Polestar owners left ‘holding the bag’ after EV brand pulls out of the US

                                              Last month, Polestar shocked the auto industry when it announced that it was pulling out of the US. The EV company's decision came after the federal government denied its authorization to continue selling its cars despi…

                                              theverge.com/transportation/96

                                              [The Verge]

                                                [?]TechWire ⚡ » 🤖 🌐
                                                @techwire@social.gamefan.net

                                                Doom’s new expansion shows just what makes id Software special

                                                This week should have been a celebration for Doom developer id Software. The studio just launched Revelations, a meaty expansion for Doom: The Dark Ages that adds a powerful new weapon and more demonic levels to blast t…

                                                theverge.com/games/963515/doom

                                                [The Verge]

                                                  [?]Hacker News » 🤖 🌐
                                                  @h4ckernews@mastodon.social

                                                  [?]N-gated Hacker News » 🤖 🌐
                                                  @ngate@mastodon.social

                                                  Ah, the glorious of creating a digital Fort Knox to keep out the riff-raff, only to lock yourself out—Bravo! 🎉🔒 Turns out, when you build a spam fortress, sometimes you end up being the dragon it guards against. 🐉🔥 Maybe next time, try asking the emails nicely? 📧💌
                                                  benjamin.piouffle.com/blog/bur

                                                    [?]EUVD Bot » 🤖 🌐
                                                    @EUVD_Bot@mastodon.social

                                                    🚨 EUVD-2026-42878

                                                    📊 Score: 7.2/10 (CVSS v3.1)
                                                    📦 Product: flaskbb, flaskbb
                                                    🏢 Vendor: flaskbb
                                                    📅 Updated: 2026-07-10

                                                    📝 FlaskBB through 2.2.0, fixed in commit acc88cf, contains an authorization bypass vulnerability that allows authenticated moderators to perform unauthorized actions on topics in forums they do not control by submitting crafted topic ID lists. Attacke...

                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                      [?]EUVD Bot » 🤖 🌐
                                                      @EUVD_Bot@mastodon.social

                                                      🚨 EUVD-2026-42877

                                                      📊 Score: 8.6/10 (CVSS v3.1)
                                                      📦 Product: flaskbb, flaskbb
                                                      🏢 Vendor: flaskbb
                                                      📅 Updated: 2026-07-10

                                                      📝 FlaskBB through 2.2.0, fixed in commit a5da9a5, contains a logic flaw vulnerability that allows authenticated administrators to delete all built-in authorization groups by exploiting a type mismatch in the bulk delete protection check. The bulk AJAX...

                                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                                        [?]urlDNA.io :verified: » 🤖 🌐
                                                        @urldna@infosec.exchange

                                                        Possible Phishing 🎣
                                                        on: ⚠️hxxps[:]//chillisinpatulas[.]weebly[.]com/
                                                        🧬 Analysis at: urldna.io/scan/6a50ca833b77500

                                                          [?]Daily CyberSecurity » 🌐
                                                          @DailyCyberSecurity@infosec.exchange

                                                          Iranian hackers deploy the Cavern Manticore modular framework to infiltrate Israeli networks. Discover how they exploit IT supply chains for cyberespionage.

                                                          meterpreter.org/cavern-mantico

                                                            [?]deafnews » 🤖 🌐
                                                            @deafnews@infosec.exchange

                                                            [?]TechWire ⚡ » 🤖 🌐
                                                            @techwire@social.gamefan.net

                                                            Miss the YotaPhone? This upstart brand just made the dual-screen phone for you.

                                                            And it's already destroyed its Kickstarter goal within minutes of going live.

                                                            androidauthority.com/bigme-hib

                                                            [Android Authority]

                                                              [?]shellsharks » 🌐
                                                              @shellsharks@infosec.pub

                                                              Off-Topic Friday

                                                              Wanna chat about something non-infosec amongst those of us who frequent /c/cybersecurity? Here’s your chance! (Keep things civil & respectful please)

                                                              (https://infosec.pub/c/cybersecurity)

                                                              [?]The New Oil » 🤖 🌐
                                                              @thenewoil@mastodon.thenewoil.org

                                                              [?]TechWire ⚡ » 🤖 🌐
                                                              @techwire@social.gamefan.net

                                                              Android’s local document backup tool is almost ready for prime time

                                                              The latest Google Play services beta comes with the long-awaited Documents folder for backing up local documents.

                                                              androidauthority.com/google-do

                                                              [Android Authority]

                                                                [?]TechWire ⚡ » 🤖 🌐
                                                                @techwire@social.gamefan.net

                                                                Netflix free trials return after six years, but some of you will miss out

                                                                You can get 30 days of 4K HDR playback free, unless you're in the US or the UK.

                                                                androidauthority.com/netflix-3

                                                                [Android Authority]

                                                                  [?]BeeSINT » 🌐
                                                                  @BeeSINT@mastodon.social

                                                                  🎣 Phishing Spotlight

                                                                  facebook-video-share[.]blogspot[.]com

                                                                  🔒 SSL: exp. 2026-09-14
                                                                  🌐 Stack: GSE

                                                                  🔗 beesint.com/pulse/45b2e99f-f55

                                                                    [?]Technical Master » 🌐
                                                                    @technicalmaster@mastodon.social

                                                                    For anyone tracking mobile privacy: A deep dive into modern iOS security. While Apple's Secure Enclave and App Sandboxing mitigate traditional self-replicating code, configuration profile hijacking and zero-click exploits remain a real vector for targeted spyware.

                                                                    Learn how to audit your iPhone's local data metrics, network configurations, and profile certificates for viruses without third-party tools.

                                                                    thetechnicalmaster.com/can-iph

                                                                      [?]ResearchBuzz: Firehose » 🌐
                                                                      @researchbuzz_firehose@rbfirehose.com

                                                                      TechCrunch: Another massive data breach exposed millions of driver’s license numbers. “U.S. insurance provider AssuranceAmerica has confirmed a data breach affecting the personal information and driver’s license numbers of 6.9 million people, making it the largest known spill of Americans’ driver’s license information this year.”

                                                                      https://rbfirehose.com/2026/07/10/techcrunch-another-massive-data-breach-exposed-millions-of-drivers-license-numbers/

                                                                      Back to top - More...