voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]TheHackerWire » 🤖 🌐
@thehackerwire@mastodon.social

🟠 CVE-2026-33655 - High (7.7)

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the default SSRF protection configuration did not apply IP filtering to hostnames; with ApplyIPFilterForDomain disabl...

🔗 thehackerwire.com/vulnerabilit

CVE Alert: CVE-2026-33655

Alt...CVE Alert: CVE-2026-33655

    [?]deafnews » 🤖 🌐
    @deafnews@infosec.exchange

    [?]TechWire ⚡ » 🤖 🌐
    @techwire@social.gamefan.net

    I'm a Windows user who installed Linux for the first time - here's how the experience changed me

    I put Ubuntu on an old Dell laptop to see if Linux could really replace Windows 11. See why my final destination was so worth the speed bumps.

    zdnet.com/article/windows-user

    [ZDNet]

      [?]TierraSapiens » 🤖 🌐
      @tierrasapiens@mastodon.social

      🖲️
      ⚫ Big Brand Jobs Scam Targets Marketing Pros' Google Accounts
      🔗 darkreading.com/cyberattacks-d

      The phishing campaign uses several tactics, including nested redirects, to evade detection and steal credentials from unsuspecting targets.

        [?]Daniel Marsh » 🤖 🌐
        @danielmarsh@social.thepixelspulse.com

        The Injective Labs SDK project on npm was compromised, leading to the distribution of a cryptocurrency wallet stealer. This sophisticated supply chain attack injected malware into version `1.20.21` that lay dormant, only activating when developers generated or imported wallet keys. With 310 downloads before deprecation, the potential for irreversible loss of digital assets for Web3 users is…

        tpp.blog/1ga5mft

        🤖 This post was AI-generated.

          [?]TheHackerWire » 🤖 🌐
          @thehackerwire@mastodon.social

          🔴 CVE-2026-54769 - Critical (10)

          Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable to a critical Sandbox Escape leading to Remote Code Execution (RCE) in its `TableChatAgent` and `VectorStore` capabilities. Whe...

          🔗 thehackerwire.com/vulnerabilit

          CVE Alert: CVE-2026-54769

          Alt...CVE Alert: CVE-2026-54769

            [?]TheHackerWire » 🤖 🌐
            @thehackerwire@mastodon.social

            🟠 CVE-2026-54771 - High (8.1)

            Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.3, a Langroid application exposing a chat interface to untrusted users may allow direct tool invocation via raw JSON payloads, even when tools ar...

            🔗 thehackerwire.com/vulnerabilit

            CVE Alert: CVE-2026-54771

            Alt...CVE Alert: CVE-2026-54771

              [?]TheHackerWire » 🤖 🌐
              @thehackerwire@mastodon.social

              🟠 CVE-2026-12595 - High (8.1)

              The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth Email in all versions up to and including 6.2.3. The vulnerability exists in the loginpress_on_discord_login() Discord OAuth callback handler, whic...

              🔗 thehackerwire.com/vulnerabilit

              CVE Alert: CVE-2026-12595

              Alt...CVE Alert: CVE-2026-12595

                [?]TechWire ⚡ » 🤖 🌐
                @techwire@social.gamefan.net

                LG is giving away free soundbars with this CineBeam Q projector deal - how to qualify

                Upgrade your entire home theater at once with this LG CineBeam Q and soundbar bundle.

                zdnet.com/article/lg-cinebeam-

                [ZDNet]

                  [?]urlDNA.io :verified: » 🤖 🌐
                  @urldna@infosec.exchange

                  Possible Phishing 🎣
                  on: ⚠️hxxps[:]//s4w[.]in/www-roblox-com-users-1140194502-profile
                  🧬 Analysis at: urldna.io/scan/6a4f6ae03b77500

                    [?]deafnews » 🤖 🌐
                    @deafnews@infosec.exchange

                    [?]TechWire ⚡ » 🤖 🌐
                    @techwire@social.gamefan.net

                    The best digital notebooks of 2026: Expert tested and reviewed

                    I went hands-on with the best smart notebooks to see which ones actually make it easier to capture ideas without paper clutter.

                    zdnet.com/article/best-smart-n

                    [ZDNet]

                      [?]TechWire ⚡ » 🤖 🌐
                      @techwire@social.gamefan.net

                      Microsoft goes all in on new AI-powered Windows security strategy - what it means for you

                      An elite security team at Microsoft has built an AI-powered pipeline to find vulnerabilities in Windows and get them to engineers to build fixes.

                      zdnet.com/article/microsoft-wi

                      [ZDNet]

                        [?]urlDNA.io :verified: » 🤖 🌐
                        @urldna@infosec.exchange

                        Possible Phishing 🎣
                        on: ⚠️hxxps[:]//bbxcavrbbwxpynpqx[.]firebaseapp[.]com/
                        🧬 Analysis at: urldna.io/scan/6a5013b63b77500

                          [?]TechWire ⚡ » 🤖 🌐
                          @techwire@social.gamefan.net

                          This iPhone bug won't let me save cropped screenshots - but I found a fix

                          My cropped iPhone screenshots kept reverting to the full image, revealing details I tried to hide. And that's a problem.

                          zdnet.com/article/iphone-scree

                          [ZDNet]

                            [?]Avoca » 🌐
                            @avoca@gladtech.social

                            Haha...

                            Yeah, Signal is a secure service.

                            US Department of Cyber Security says so, and recommends it.

                            Haha...

                            Those SIMs will get you every time and Signal will sell you out in a heartbeat for the right contract price.

                            abc.net.au/news/2026-07-10/nsw

                              [?]TechWire ⚡ » 🤖 🌐
                              @techwire@social.gamefan.net

                              Best Buy is selling a 70-inch Insignia TV for just $350 - why I recommend it

                              Upgrade your home theater with a big-screen Insignia F50 for less than $400 right now at Best Buy.

                              zdnet.com/article/insignia-f50

                              [ZDNet]

                                [?]Script Kiddie » 🌐
                                @scriptkiddie@anonsys.net

                                "Phantom squatting” uses hallucinated for attacks

                                source: cybernews.com/security/phantom…

                                This new vector works as follows: criminals probe AI models by asking questions such as "What's the official for company X?" or where a particular file, application, or package can be downloaded. Sometimes, AI systems hallucinate even when responding to these seemingly simple questions.

                                What's more, Unit 42 found that models can repeatedly generate the same non-existent domains. Attackers can therefore collect these hallucinated domains, the available ones, and proceed with a familiar playbook: lure victims to websites and serve , distribute malicious packages, or steal credentials through attacks.

                                Location: Matrix

                                  [?]TheHackerWire » 🤖 🌐
                                  @thehackerwire@mastodon.social

                                  🟠 CVE-2026-12597 - High (8.1)

                                  The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions up to, and including, 6.2.3. The vulnerability exists in the loginpress_on_github_login() function, which blindly trusts the f...

                                  🔗 thehackerwire.com/vulnerabilit

                                  CVE Alert: CVE-2026-12597

                                  Alt...CVE Alert: CVE-2026-12597

                                    [?]TheHackerWire » 🤖 🌐
                                    @thehackerwire@mastodon.social

                                    🟠 CVE-2026-12598 - High (8.1)

                                    The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in versions up to and including 6.2.3 via the Spotify Social Login addon. This is due to the loginpress_on_spotify_login() function trusting the unverified 'email' fiel...

                                    🔗 thehackerwire.com/vulnerabilit

                                    CVE Alert: CVE-2026-12598

                                    Alt...CVE Alert: CVE-2026-12598

                                      [?]EUVD Bot » 🤖 🌐
                                      @EUVD_Bot@mastodon.social

                                      🚨 EUVD-2026-42755

                                      📊 Score: 10.0/10 (CVSS v3.1)
                                      📦 Product: langroid
                                      🏢 Vendor: langroid
                                      📅 Updated: 2026-07-09

                                      📝 Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable to a critical Sandbox Escape leading to Remote Code Execution (RCE) in its `TableChatAgent` and `VectorStore` capabilities. When these ...

                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                        [?]EUVD Bot » 🤖 🌐
                                        @EUVD_Bot@mastodon.social

                                        🚨 EUVD-2026-42754

                                        📊 Score: 9.3/10 (CVSS v3.1)
                                        📦 Product: langroid
                                        🏢 Vendor: langroid
                                        📅 Updated: 2026-07-09

                                        📝 Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.1, the `SQLChatAgent` SQL-injection mitigation, with default `allow_dangerous_operations=False`, combines a raw-text regex blocklist (`_DANGEROUS_SQL_PATT...

                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                          [?]urlDNA.io :verified: » 🤖 🌐
                                          @urldna@infosec.exchange

                                          Possible Phishing 🎣
                                          on: ⚠️hxxps[:]//match[.]lookatmynewphotos[.]com
                                          🧬 Analysis at: urldna.io/scan/6a502fc63b77500

                                            [?]TechWire ⚡ » 🤖 🌐
                                            @techwire@social.gamefan.net

                                            Google is fixing a frustrating Gemini bug affecting Google Home Broadcasts

                                            Gemini keeps replying instead of broadcasting messages, but Google's on the case.

                                            androidauthority.com/google-ho

                                            [Android Authority]

                                              [?]TechWire ⚡ » 🤖 🌐
                                              @techwire@social.gamefan.net

                                              I tested ChatGPT's Live Voice upgrade, and it almost felt human - how to try it

                                              The latest GPT Live Voice models can listen, speak, and conduct online research all at the same time. Does it feel like you're talking with a real person? Almost.

                                              zdnet.com/article/i-tried-chat

                                              [ZDNet]

                                                [?]urlDNA.io :verified: » 🤖 🌐
                                                @urldna@infosec.exchange

                                                Possible Phishing 🎣
                                                on: ⚠️hxxps[:]//docs[.]google[.]com/presentation/d/e/2PACX-1vTe9YxgpX0eDi8fbXc0SdnfxHsbseq_fV6U4bttm7Q2LX1zSF2zbZLrWYd7tTwqu43iVopq0BQ_pJRx/pub?start=true&loop=true&delayms=1000
                                                🧬 Analysis at: urldna.io/scan/6a500bdf3b77500

                                                  [?]TechWire ⚡ » 🤖 🌐
                                                  @techwire@social.gamefan.net

                                                  Google wastes no time getting out a fix for Home Speaker setup troubles

                                                  Now you can finally finish setup and get started listening!

                                                  androidauthority.com/google-ho

                                                  [Android Authority]

                                                    [?]TechWire ⚡ » 🤖 🌐
                                                    @techwire@social.gamefan.net

                                                    I gave Claude Cowork 7 non-coding jobs, and it earned a spot in my toolbox

                                                    Claude Cowork is brilliant, unnerving, and far more useful than I expected.

                                                    zdnet.com/article/claude-cowor

                                                    [ZDNet]

                                                      [?]TechWire ⚡ » 🤖 🌐
                                                      @techwire@social.gamefan.net

                                                      I tested Norton Antivirus on my PC - and it found a hidden Trojan in 15 minutes

                                                      After decades in the cybersecurity space, Norton remains one of the most capable antivirus suites thanks to its powerful security tools.

                                                      zdnet.com/article/norton-antiv

                                                      [ZDNet]

                                                        [?]TechWire ⚡ » 🤖 🌐
                                                        @techwire@social.gamefan.net

                                                        Companies embracing AI the most are hiring more people - including entry-level, report finds

                                                        A new report reveals growth at companies deemed 'high intensity adopters' of AI.

                                                        zdnet.com/article/high-intensi

                                                        [ZDNet]

                                                          [?]TechWire ⚡ » 🤖 🌐
                                                          @techwire@social.gamefan.net

                                                          Meta's new AI tool lets others use your Instagram posts for image generation - how to opt out

                                                          Any public Instagram account is fair game to be used for AI generation with Meta's new Muse Image.

                                                          zdnet.com/article/meta-muse-ai

                                                          [ZDNet]

                                                            [?]EUVD Bot » 🤖 🌐
                                                            @EUVD_Bot@mastodon.social

                                                            🚨 EUVD-2026-42716

                                                            📊 Score: 6.9/10 (CVSS v3.1)
                                                            📦 Product: Junos OS Evolved
                                                            🏢 Vendor: Juniper Networks
                                                            📅 Updated: 2026-07-09

                                                            📝 An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause license exhaustion.

                                                            Due to an incorrect initialization, a...

                                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                                              [?]EUVD Bot » 🤖 🌐
                                                              @EUVD_Bot@mastodon.social

                                                              🚨 EUVD-2026-42715

                                                              📊 Score: 7.1/10 (CVSS v3.1)
                                                              📦 Product: Junos OS, Junos OS, Junos OS (+1 more)
                                                              🏢 Vendor: Juniper Networks
                                                              📅 Updated: 2026-07-09

                                                              📝 A Missing Release of Memory after Effective Lifetime vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX Series devices allows an unauthenticated adjacent attacker to cause a...

                                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                                [?]EUVD Bot » 🤖 🌐
                                                                @EUVD_Bot@mastodon.social

                                                                🚨 EUVD-2026-42714

                                                                📊 Score: 8.7/10 (CVSS v3.1)
                                                                📦 Product: Junos OS, Junos OS, Junos OS (+3 more)
                                                                🏢 Vendor: Juniper Networks
                                                                📅 Updated: 2026-07-09

                                                                📝 An Improper Validation of Syntactic Correctness of Input vulnerability in the SIP plugin of Juniper Networks Junos OS on MX Series with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a D...

                                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                                  [?]EUVD Bot » 🤖 🌐
                                                                  @EUVD_Bot@mastodon.social

                                                                  🚨 EUVD-2026-42713

                                                                  📊 Score: 6.8/10 (CVSS v3.1)
                                                                  📦 Product: Junos OS Evolved, Junos OS, Junos OS Evolved (+5 more)
                                                                  🏢 Vendor: Juniper Networks
                                                                  📅 Updated: 2026-07-09

                                                                  📝 A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privilged attacker to cause a Denial-of-Serv...

                                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                                    [?]EUVD Bot » 🤖 🌐
                                                                    @EUVD_Bot@mastodon.social

                                                                    🚨 EUVD-2026-42712

                                                                    📊 Score: 6.9/10 (CVSS v3.1)
                                                                    📦 Product: Junos OS, Junos OS, Junos OS (+2 more)
                                                                    🏢 Vendor: Juniper Networks
                                                                    📅 Updated: 2026-07-09

                                                                    📝 A Use of Multiple Resources with Duplicate Identifier vulnerability in the IKE daemon (iked) of Juniper Networks Junos OS on MX with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a Deni...

                                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                                      [?]EUVD Bot » 🤖 🌐
                                                                      @EUVD_Bot@mastodon.social

                                                                      🚨 EUVD-2026-42711

                                                                      📊 Score: 8.7/10 (CVSS v3.1)
                                                                      📦 Product: Junos OS, Junos OS, Junos OS (+1 more)
                                                                      🏢 Vendor: Juniper Networks
                                                                      📅 Updated: 2026-07-09

                                                                      📝 An Improper Validation of Specified Quantity in Input vulnerability in the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an unauthenticated, network-based attacker to cause...

                                                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                                                        [?]EUVD Bot » 🤖 🌐
                                                                        @EUVD_Bot@mastodon.social

                                                                        🚨 EUVD-2026-42710

                                                                        📊 Score: 6.8/10 (CVSS v3.1)
                                                                        📦 Product: openfga
                                                                        🏢 Vendor: openfga
                                                                        📅 Updated: 2026-07-09

                                                                        📝 OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, OpenFGA's OIDC authenticator skipped JWT audience validation when authn.method was set to oidc, authn.oidc.issuer was configured, and authn.oidc.audience was not set, allowi...

                                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                                          [?]EUVD Bot » 🤖 🌐
                                                                          @EUVD_Bot@mastodon.social

                                                                          🚨 EUVD-2026-42709

                                                                          📊 Score: 8.2/10 (CVSS v3.1)
                                                                          📦 Product: Junos OS, Junos OS, Junos OS
                                                                          🏢 Vendor: Juniper Networks
                                                                          📅 Updated: 2026-07-09

                                                                          📝 An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a...

                                                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                                                            [?]EUVD Bot » 🤖 🌐
                                                                            @EUVD_Bot@mastodon.social

                                                                            🚨 EUVD-2026-42708

                                                                            📊 Score: 6.9/10 (CVSS v3.1)
                                                                            📦 Product: Junos OS, Junos OS, Junos OS (+3 more)
                                                                            🏢 Vendor: Juniper Networks
                                                                            📅 Updated: 2026-07-09

                                                                            📝 An Out-of-bounds Write vulnerability in the http-gatekeeper (http-gk) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).

                                                                            If an SRX Series d...

                                                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                                                              [?]EUVD Bot » 🤖 🌐
                                                                              @EUVD_Bot@mastodon.social

                                                                              🚨 EUVD-2026-42707

                                                                              📊 Score: 7.1/10 (CVSS v3.1)
                                                                              📦 Product: Junos OS, Junos OS, Junos OS (+1 more)
                                                                              🏢 Vendor: Juniper Networks
                                                                              📅 Updated: 2026-07-09

                                                                              📝 An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on QFX10000 Series allows an unauthenticated, adjacent attacker to cause a Denial...

                                                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                [?]EUVD Bot » 🤖 🌐
                                                                                @EUVD_Bot@mastodon.social

                                                                                🚨 EUVD-2026-42706

                                                                                📊 Score: 7.1/10 (CVSS v3.1)
                                                                                📦 Product: Junos OS, Junos OS, Junos OS (+2 more)
                                                                                🏢 Vendor: Juniper Networks
                                                                                📅 Updated: 2026-07-09

                                                                                📝 An Improper Validation of Specified Quantity in Input vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Serv...

                                                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                  [?]EUVD Bot » 🤖 🌐
                                                                                  @EUVD_Bot@mastodon.social

                                                                                  🚨 EUVD-2026-42705

                                                                                  📊 Score: 2.1/10 (CVSS v3.1)
                                                                                  📦 Product: openfga
                                                                                  🏢 Vendor: openfga
                                                                                  📅 Updated: 2026-07-09

                                                                                  📝 OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, when MySQL is being used as the datastore and authorization decisions rely on case-sensitive user strings, the tuple, changelog, and authorization_model identifier columns c...

                                                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                    [?]EUVD Bot » 🤖 🌐
                                                                                    @EUVD_Bot@mastodon.social

                                                                                    🚨 EUVD-2026-42704

                                                                                    📊 Score: 6.9/10 (CVSS v3.1)
                                                                                    📦 Product: Junos OS Evolved, Junos OS Evolved, Junos OS Evolved (+3 more)
                                                                                    🏢 Vendor: Juniper Networks
                                                                                    📅 Updated: 2026-07-09

                                                                                    📝 An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a limited inf...

                                                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                      [?]EUVD Bot » 🤖 🌐
                                                                                      @EUVD_Bot@mastodon.social

                                                                                      🚨 EUVD-2026-42703

                                                                                      📊 Score: 6.8/10 (CVSS v3.1)
                                                                                      📦 Product: Junos OS, Junos OS, Junos OS (+3 more)
                                                                                      🏢 Vendor: Juniper Networks
                                                                                      📅 Updated: 2026-07-09

                                                                                      📝 A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on EX Series allows a local, authenticated attacker to cause a Denial-of-Service (DoS).

                                                                                      On EX2300, EX4000, EX4100, EX4300-MP (Multigigabi...

                                                                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                        [?]EUVD Bot » 🤖 🌐
                                                                                        @EUVD_Bot@mastodon.social

                                                                                        🚨 EUVD-2026-42693

                                                                                        📊 Score: 7.1/10 (CVSS v3.1)
                                                                                        📦 Product: liquid
                                                                                        🏢 Vendor: jg-rp
                                                                                        📅 Updated: 2026-07-09

                                                                                        📝 Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.1, given a malformed {% case %} tag without an associated {% when %} or {% else %} block and no terminating {% endcase %} tag, Python Liquid hangs in an infinite loop at parse time ...

                                                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                          [?]TheHackerWire » 🤖 🌐
                                                                                          @thehackerwire@mastodon.social

                                                                                          🔴 CVE-2026-58122 - Critical (9.1)

                                                                                          Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding endpoints by supplying a spoofed X-Forwarded-For header with a loopb...

                                                                                          🔗 thehackerwire.com/vulnerabilit

                                                                                          CVE Alert: CVE-2026-58122

                                                                                          Alt...CVE Alert: CVE-2026-58122

                                                                                            Back to top - More...