voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]EUVD Bot » 🤖 🌐
@EUVD_Bot@mastodon.social

🚨 EUVD-2026-42865

📊 Score: 3.9/10 (CVSS v3.1)
📅 Updated: 2026-07-10

📝 A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successful exploitation c...

🔗 euvd.enisa.europa.eu/vulnerabi

    [?]EUVD Bot » 🤖 🌐
    @EUVD_Bot@mastodon.social

    🚨 EUVD-2026-42864

    📊 Score: 5.3/10 (CVSS v3.1)
    📦 Product: KiviCare – Clinic & Patient Management System (EHR)
    🏢 Vendor: iqonicdesign
    📅 Updated: 2026-07-10

    📝 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.4.0. This is due to the plugin not properly verifying ...

    🔗 euvd.enisa.europa.eu/vulnerabi

      [?]EUVD Bot » 🤖 🌐
      @EUVD_Bot@mastodon.social

      🚨 EUVD-2026-42863

      📊 Score: 6.4/10 (CVSS v3.1)
      📦 Product: Logo Slider WP – Responsive Logo Carousel, Logo Gallery & Logo Showcase
      🏢 Vendor: LogicHunt
      📅 Updated: 2026-07-10

      📝 The Logo Slider – Logo Carousel, Client Logo Slider & Brand Showcase for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lgx_tooltip_position' parameter in...

      🔗 euvd.enisa.europa.eu/vulnerabi

        [?]EUVD Bot » 🤖 🌐
        @EUVD_Bot@mastodon.social

        🚨 EUVD-2026-42862

        📊 Score: 4.9/10 (CVSS v3.1)
        📦 Product: Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails
        🏢 Vendor: getwpfunnels
        📅 Updated: 2026-07-10

        📝 The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to generic SQL Injection via the 'recipients' parameter in all v...

        🔗 euvd.enisa.europa.eu/vulnerabi

          [?]EUVD Bot » 🤖 🌐
          @EUVD_Bot@mastodon.social

          🚨 EUVD-2026-42861

          📊 Score: 6.4/10 (CVSS v3.1)
          📦 Product: Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress
          🏢 Vendor: jegtheme
          📅 Updated: 2026-07-10

          📝 The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Box...

          🔗 euvd.enisa.europa.eu/vulnerabi

            [?]EUVD Bot » 🤖 🌐
            @EUVD_Bot@mastodon.social

            🚨 EUVD-2026-42860

            📊 Score: 6.5/10 (CVSS v3.1)
            📦 Product: JoomSport – for Sports: Team & League, Football, Hockey & more
            🏢 Vendor: beardev
            📅 Updated: 2026-07-10

            📝 The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL Injection via 'event' Shortcode Attribute in all versions up to, and including, 5.7...

            🔗 euvd.enisa.europa.eu/vulnerabi

              [?]EUVD Bot » 🤖 🌐
              @EUVD_Bot@mastodon.social

              🚨 EUVD-2026-42859

              📊 Score: 4.3/10 (CVSS v3.1)
              📦 Product: Invoice123
              🏢 Vendor: saskaita123
              📅 Updated: 2026-07-10

              📝 The Invoice123 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.7.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenti...

              🔗 euvd.enisa.europa.eu/vulnerabi

                [?]EUVD Bot » 🤖 🌐
                @EUVD_Bot@mastodon.social

                🚨 EUVD-2026-42858

                📊 Score: 9.3/10 (CVSS v3.1)
                📅 Updated: 2026-07-10

                📝 A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition (XSD) string. This can lead to unauthorized access to sensitive information, includ...

                🔗 euvd.enisa.europa.eu/vulnerabi

                  [?]EUVD Bot » 🤖 🌐
                  @EUVD_Bot@mastodon.social

                  🚨 EUVD-2026-42857

                  📊 Score: 8.2/10 (CVSS v3.1)
                  📦 Product: DMS
                  🏢 Vendor: R-SOFT SERWIS
                  📅 Updated: 2026-07-10

                  📝 R-SOFT DMS stores superadmin credentials using a non-salted nested MD5 hash. This allows an attacker who obtain password hash to decode superadmin credentials. Critically, this password cannot be changed except by modifying the configuration file.

                  This is...

                  🔗 euvd.enisa.europa.eu/vulnerabi

                    [?]EUVD Bot » 🤖 🌐
                    @EUVD_Bot@mastodon.social

                    🚨 EUVD-2026-42856

                    📊 Score: 7.1/10 (CVSS v3.1)
                    📦 Product: DMS, DMS
                    🏢 Vendor: R-SOFT SERWIS
                    📅 Updated: 2026-07-10

                    📝 R-SOFT DMS is vulnerable to Insecure Direct Object Reference (IDOR) attack in multiple file download endpoints. The application fetches files from the database by ID and serves them to whoever requests them, relying only on session authentication, mea...

                    🔗 euvd.enisa.europa.eu/vulnerabi

                      [?]EUVD Bot » 🤖 🌐
                      @EUVD_Bot@mastodon.social

                      🚨 EUVD-2026-42855

                      📊 Score: 9.0/10 (CVSS v3.1)
                      📦 Product: DMS, DMS
                      🏢 Vendor: R-SOFT SERWIS
                      📅 Updated: 2026-07-10

                      📝 R-SOFT DMS is vulnerable to OS Command Injection in the Optical Character Recognition (OCR) module. Multiple command execution functions accept user-controllable file paths without proper sanitization before passing them to the system shell via SSH. I...

                      🔗 euvd.enisa.europa.eu/vulnerabi

                        [?]EUVD Bot » 🤖 🌐
                        @EUVD_Bot@mastodon.social

                        🚨 EUVD-2026-42854

                        📊 Score: 5.1/10 (CVSS v3.1)
                        📦 Product: DMS, DMS
                        🏢 Vendor: R-SOFT SERWIS
                        📅 Updated: 2026-07-10

                        📝 R-SOFT DMS is vulnerable to Stored XSS in file upload functionality. Authenticated attacker can inject arbitrary HTML and JS into the name of the file being uploaded, which will be executed when visiting file list or upload status by other users.

                        Thi...

                        🔗 euvd.enisa.europa.eu/vulnerabi

                          [?]EUVD Bot » 🤖 🌐
                          @EUVD_Bot@mastodon.social

                          🚨 EUVD-2026-42853

                          📊 Score: 8.7/10 (CVSS v3.1)
                          📦 Product: DMS, DMS
                          🏢 Vendor: R-SOFT SERWIS
                          📅 Updated: 2026-07-10

                          📝 R-SOFT DMS is vulnerable to OS Command Injection in konwertujAction() function. The document converter executes shell commands using unsanitized file paths and format parameters. This allows an authenticated attacker to execute arbitrary system comman...

                          🔗 euvd.enisa.europa.eu/vulnerabi

                            [?]urlDNA.io :verified: » 🤖 🌐
                            @urldna@infosec.exchange

                            Possible Phishing 🎣
                            on: ⚠️hxxp[:]//0283659[.]com/index[.]html
                            🧬 Analysis at: urldna.io/scan/6a5076183b77500

                              [?]BeyondMachines :verified: » 🤖 🌐
                              @beyondmachines1@infosec.exchange

                              Microsoft Patches RoguePlanet Zero-Day in Defender Engine

                              Microsoft fixed a zero-day vulnerability in the Malware Protection Engine known as RoguePlanet that allowed local attackers to gain SYSTEM privileges.

                              **Check that your Microsoft Malware Protection Engine version is 1.1.26060.3008 or higher (look in Windows Security settings). Most devices update automatically, but exploit code is already public, so verify now. If you run isolated or offline networks, manually apply the latest engine update, since those systems won't get it automatically and remain vulnerable even if the antivirus is disabled.**

                              beyondmachines.net/event_detai

                                [?]deafnews » 🤖 🌐
                                @deafnews@infosec.exchange

                                [?]TechWire ⚡ » 🤖 🌐
                                @techwire@social.gamefan.net

                                Still screenshotting your videos? Google Photos could make life easier for you

                                A useful Google Photos feature could soon become easier to find.

                                androidauthority.com/google-ph

                                [Android Authority]

                                  [?]Negative PID SL » 🌐
                                  @negativepid@mastodon.social

                                  [?]TheHackerWire » 🤖 🌐
                                  @thehackerwire@mastodon.social

                                  🟠 CVE-2026-57023 - High (7.5)

                                  An Improper Validation of Specified Quantity in Input vulnerability in the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an unauthenticated, network-based attacker to cause a complete Denial of Service...

                                  🔗 thehackerwire.com/vulnerabilit

                                  CVE Alert: CVE-2026-57023

                                  Alt...CVE Alert: CVE-2026-57023

                                    [?]TheHackerWire » 🤖 🌐
                                    @thehackerwire@mastodon.social

                                    🟠 CVE-2026-57026 - High (7.5)

                                    An Improper Validation of Syntactic Correctness of Input vulnerability in the SIP plugin of Juniper Networks Junos OS on MX Series with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).If the...

                                    🔗 thehackerwire.com/vulnerabilit

                                    CVE Alert: CVE-2026-57026

                                    Alt...CVE Alert: CVE-2026-57026

                                      [?]TheHackerWire » 🤖 🌐
                                      @thehackerwire@mastodon.social

                                      🟠 CVE-2026-55604 - High (8.6)

                                      DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.7.0, the process-global `SessionStore` accepts caller-supplied `session_id` values without binding them to any authenticated principal or transp...

                                      🔗 thehackerwire.com/vulnerabilit

                                      CVE Alert: CVE-2026-55604

                                      Alt...CVE Alert: CVE-2026-55604

                                        [?]Negative PID SL » 🌐
                                        @negativepid@mastodon.social

                                        [?]EUVD Bot » 🤖 🌐
                                        @EUVD_Bot@mastodon.social

                                        🚨 EUVD-2026-42788

                                        📊 Score: 6.9/10 (CVSS v3.1)
                                        📦 Product: CowAgent, CowAgent
                                        🏢 Vendor: zhayujie
                                        📅 Updated: 2026-07-10

                                        📝 A vulnerability was determined in zhayujie CowAgent up to 2.1.1. Impacted is the function _build_image_content/_download_to_data_url of the file agent/tools/vision/vision.py of the component Vision Tool. Executing a manipulation of the argument i...

                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                          [?]urlDNA.io :verified: » 🤖 🌐
                                          @urldna@infosec.exchange

                                          Possible Phishing 🎣
                                          on: ⚠️hxxps[:]//bit[.]ly/480Y0ze
                                          🧬 Analysis at: urldna.io/scan/6a4fe9803b77500

                                            [?]Bobe'bot on security » 🤖 🌐
                                            @Bobe_bot@mastobot.ping.moi

                                            💭 Méditation du Firewall

                                            𝘜𝘯 𝘤𝘢𝘳𝘢𝘤𝘵è𝘳𝘦 𝘥𝘦 𝘥𝘪𝘧𝘧é𝘳𝘦𝘯𝘤𝘦 𝘥𝘢𝘯𝘴 𝘶𝘯𝘦 𝘜𝘙𝘓, 𝘦𝘵 𝘤'𝘦𝘴𝘵 𝘷𝘰𝘵𝘳𝘦 𝘯𝘶𝘮é𝘳𝘰 𝘥𝘦 𝘤𝘢𝘳𝘵𝘦 𝘲𝘶𝘪 𝘱𝘳𝘦𝘯𝘥 𝘥𝘦𝘴 𝘷𝘢𝘤𝘢𝘯𝘤𝘦𝘴 — 𝘴𝘢𝘯𝘴 𝘷𝘰𝘶𝘴.

                                              [?]Linuxiarze » 🌐
                                              @Linuxiarze@mastodon.social

                                              Google NotebookLM zapisuje Twoje notatki do formatu wideo. Google NotebookLM (LM = Language Model) to internetowe narzędzie do badań i robienia notatek opracowane przez Google Labs, które wykorzystuje sztuczną inteligencję... linuxiarze.pl/google-notebookl

                                                [?]Linuxiarze » 🌐
                                                @Linuxiarze@fe.disroot.org

                                                Google NotebookLM zapisuje Twoje notatki do formatu wideo. Google NotebookLM (LM = Language Model) to internetowe narzędzie do badań i robienia notatek opracowane przez Google Labs, które wykorzystuje sztuczną inteligencję... https://linuxiarze.pl/google-notebooklm-zapisuje-twoje-notatki-do-formatu-wideo/ #cybersecurity #sztucznainteligencja #notatki

                                                  [?]TechWire ⚡ » 🤖 🌐
                                                  @techwire@social.gamefan.net

                                                  Galaxy Z Fold 8, Fold 8 Ultra prices leak for US, and there might be bad news

                                                  It looks like a price hike is on the cards once again.

                                                  androidauthority.com/samsung-g

                                                  [Android Authority]

                                                    [?]Daily CyberSecurity » 🌐
                                                    @DailyCyberSecurity@infosec.exchange

                                                    Sysdig documented JADEPUFFER, the first agentic ransomware run end-to-end by an AI agent. It breached Langflow via CVE-2025-3248 and extorted a database.

                                                    securityonline.info/jadepuffer

                                                      [?]TechWire ⚡ » 🤖 🌐
                                                      @techwire@social.gamefan.net

                                                      Professor suspected AI-powered cheating on take-home midterms, makes finals in-person — only two students…

                                                      A Brown University professor suspected that almost his entire class cheated on take-home mid-term exams using AI tools after they scored unusually high. In-person final exams showed that only two students scored within …

                                                      tomshardware.com/tech-industry

                                                      [Tom's Hardware]

                                                        [?]Dumb Password Rules » 🤖 🌐
                                                        @dumbpasswordrules@infosec.exchange

                                                        This dumb password rule is from Rediff.

                                                        A maximum password length of 12. The hidden requirements are:
                                                        - at least 1 uppercase letter
                                                        - at least 1 lowercase letter
                                                        - at least 1 numeric character
                                                        - at least 1 special symbol (which can not be ^, %)

                                                        dumbpasswordrules.com/sites/re

                                                          [?]urlDNA.io :verified: » 🤖 🌐
                                                          @urldna@infosec.exchange

                                                          Possible Phishing 🎣
                                                          on: ⚠️hxxps[:]//mekucoinlogiin[.]gitbook[.]io
                                                          🧬 Analysis at: urldna.io/scan/6a5036123b77500

                                                            [?]TechWire ⚡ » 🤖 🌐
                                                            @techwire@social.gamefan.net

                                                            Nvidia shows off GeForce Trading Cards Series 1 — collectible cards show off games, GPUs, and tech demos, and will be available for free at upcoming events

                                                            Nvidia is creating a set of collectible trading cards that will be given away for free during live events and giveaways this summer.

                                                            tomshardware.com/pc-components

                                                            [Tom's Hardware]

                                                              [?]TechWire ⚡ » 🤖 🌐
                                                              @techwire@social.gamefan.net

                                                              Intel preps 28-core Nova Lake-S CPUs for Dunlow workstation platform — Entry-level Xeon chip features LGA1954 socket

                                                              Intel readies Xeon 'Dunlow' platform with 28 cores in LGA1954 packaging for entry-level servers and workstations.

                                                              tomshardware.com/pc-components

                                                              [Tom's Hardware]

                                                                [?]urlDNA.io :verified: » 🤖 🌐
                                                                @urldna@infosec.exchange

                                                                Possible Phishing 🎣
                                                                on: ⚠️hxxps[:]//creditiperhabbogratissicuro100[.]blogspot[.]it
                                                                🧬 Analysis at: urldna.io/scan/6a50605a3b77500

                                                                  [?]Hugo | DevOps | Cybersecurity » 🌐
                                                                  @hugovalters@mastodon.social

                                                                  Revive Adserver: 25 CVEs, 8 high-severity, avg CVSS 6.17. 100% unpatched. Trust Score: C. Open-source ad server, but 100% unpatched is risky.

                                                                  valtersit.com/vendors/revive-a

                                                                    [?]TechWire ⚡ » 🤖 🌐
                                                                    @techwire@social.gamefan.net

                                                                    AMD revives aging Zen 2 processor for budget PCs — Ryzen 7 4700LE resurfaces in a new $800 RTX 3050 prebuilt

                                                                    AMD's quiet revival of older Ryzen processors continues, with the Ryzen 7 4700LE now appearing in a prebuilt gaming desktop priced at $799.99.

                                                                    tomshardware.com/pc-components

                                                                    [Tom's Hardware]

                                                                      [?]thecybersecguru » 🌐
                                                                      @thecybersecguru@infosec.exchange

                                                                      Everyone uses Wi-Fi. Very few understand what actually happens after clicking "Connect."

                                                                      I spent weeks putting together a deep technical guide to 802.11 that goes beyond the usual "run this command" tutorials.

                                                                      Inside you'll learn:
                                                                      • How Wi-Fi really works at the protocol level
                                                                      • WEP → WPA → WPA2 → WPA3 evolution
                                                                      • Monitor mode & packet capture
                                                                      • 802.11 frame anatomy explained
                                                                      • Wireshark filters that actually matter
                                                                      • PMKID, WPS, Evil Twin, and handshake concepts
                                                                      • Aircrack-ng workflow
                                                                      • Defensive mitigations and why some "best practices" fail

                                                                      If you're preparing for OSCP, Hack The Box, TryHackMe, wireless pentesting, or just want to truly understand Wi-Fi, this guide is for you.

                                                                      Read it here 👇
                                                                      thecybersecguru.com/networking

                                                                        [?]Negative PID SL » 🌐
                                                                        @negativepid@mastodon.social

                                                                        [?]TechWire ⚡ » 🤖 🌐
                                                                        @techwire@social.gamefan.net

                                                                        OpenAI's GPT-5.6 and ChatGPT Work aim to beat Anthropic on price, speed, and productivity

                                                                        OpenAI's latest announcement looks like a lot more than a model upgrade.

                                                                        zdnet.com/article/openais-gpt-

                                                                        [ZDNet]

                                                                          [?]EUVD Bot » 🤖 🌐
                                                                          @EUVD_Bot@mastodon.social

                                                                          🚨 EUVD-2026-42765

                                                                          📊 Score: 5.3/10 (CVSS v3.1)
                                                                          📦 Product: PicoClaw, PicoClaw, PicoClaw (+7 more)
                                                                          🏢 Vendor: Sipeed
                                                                          📅 Updated: 2026-07-10

                                                                          📝 A weakness has been identified in Sipeed PicoClaw up to 0.2.9. Affected by this issue is some unknown functionality of the file pkg/channels/mqtt/mqtt.go of the component MQTT Channel Handler. This manipulation of the argument c...

                                                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                                                            [?]urlDNA.io :verified: » 🤖 🌐
                                                                            @urldna@infosec.exchange

                                                                            Possible Phishing 🎣
                                                                            on: ⚠️hxxp[:]//netflix555-login[.]com
                                                                            🧬 Analysis at: urldna.io/scan/6a4f95233b77500

                                                                              [?]TheHackerWire » 🤖 🌐
                                                                              @thehackerwire@mastodon.social

                                                                              🟠 CVE-2026-59832 - High (7.7)

                                                                              SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /snippets/*filepath route handler serveSnippets in kernel/server/serve.go joins a single-decoded request path with the snippets directory without subpath containmen...

                                                                              🔗 thehackerwire.com/vulnerabilit

                                                                              CVE Alert: CVE-2026-59832

                                                                              Alt...CVE Alert: CVE-2026-59832

                                                                                [?]TheHackerWire » 🤖 🌐
                                                                                @thehackerwire@mastodon.social

                                                                                🟠 CVE-2026-59834 - High (7.5)

                                                                                SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the block search endpoint POST /api/search/fullTextSearchBlock concatenates attacker-controlled paths values into SQL predicates used by non-SQL search modes, allowing ...

                                                                                🔗 thehackerwire.com/vulnerabilit

                                                                                CVE Alert: CVE-2026-59834

                                                                                Alt...CVE Alert: CVE-2026-59834

                                                                                  Back to top - More...