voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
🟠 CVE-2026-33655 - High (7.7)
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the default SSRF protection configuration did not apply IP filtering to hostnames; with ApplyIPFilterForDomain disabl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-33655/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Microsoft: AI Will Make Patch Tuesday Permanently More Demanding https://deafnews.it/en/article/microsoft-ai-will-make-patch-tuesday-permanently-more-demanding #Cybersecurity
I'm a Windows user who installed Linux for the first time - here's how the experience changed me
I put Ubuntu on an old Dell laptop to see if Linux could really replace Windows 11. See why my final destination was so worth the speed bumps.
https://www.zdnet.com/article/windows-user-installed-linux-for-the-first-time/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
🖲️ #Cybersecurity #Ciberseguridad #Ciberseguranca #Security #Seguridad #Seguranca #News #Noticia #Noticias #Tecnologia #Technology
⚫ Big Brand Jobs Scam Targets Marketing Pros' Google Accounts
🔗 https://www.darkreading.com/cyberattacks-data-breaches/big-brand-jobs-scam-marketing-pros-google-accounts
The phishing campaign uses several tactics, including nested redirects, to evade detection and steal credentials from unsuspecting targets.
The Injective Labs SDK project on npm was compromised, leading to the distribution of a cryptocurrency wallet stealer. This sophisticated supply chain attack injected malware into version `1.20.21` that lay dormant, only activating when developers generated or imported wallet keys. With 310 downloads before deprecation, the potential for irreversible loss of digital assets for Web3 users is…
#cybersecurity #injectivesdk #npm
🤖 This post was AI-generated.
🔴 CVE-2026-54769 - Critical (10)
Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable to a critical Sandbox Escape leading to Remote Code Execution (RCE) in its `TableChatAgent` and `VectorStore` capabilities. Whe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54769/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-54771 - High (8.1)
Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.3, a Langroid application exposing a chat interface to untrusted users may allow direct tool invocation via raw JSON payloads, even when tools ar...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54771/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-12595 - High (8.1)
The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth Email in all versions up to and including 6.2.3. The vulnerability exists in the loginpress_on_discord_login() Discord OAuth callback handler, whic...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12595/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
LG is giving away free soundbars with this CineBeam Q projector deal - how to qualify
Upgrade your entire home theater at once with this LG CineBeam Q and soundbar bundle.
https://www.zdnet.com/article/lg-cinebeam-q-soundbar-bundle-deal/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
Possible Phishing 🎣
on: ⚠️hxxps[:]//s4w[.]in/www-roblox-com-users-1140194502-profile
🧬 Analysis at: https://urldna.io/scan/6a4f6ae03b77500007c3572c
#cybersecurity #phishing #infosec #urldna #scam #infosec
Ex-DigitalMint Negotiator Gets 70 Months for Feeding Clients to BlackCat https://deafnews.it/en/article/ex-digitalmint-negotiator-gets-70-months-for-feeding-clients-to-blackcat #Cybersecurity
The best digital notebooks of 2026: Expert tested and reviewed
I went hands-on with the best smart notebooks to see which ones actually make it easier to capture ideas without paper clutter.
https://www.zdnet.com/article/best-smart-notebook/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
Microsoft goes all in on new AI-powered Windows security strategy - what it means for you
An elite security team at Microsoft has built an AI-powered pipeline to find vulnerabilities in Windows and get them to engineers to build fixes.
https://www.zdnet.com/article/microsoft-windows-ai-security-vulnerability-analysis/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
Possible Phishing 🎣
on: ⚠️hxxps[:]//bbxcavrbbwxpynpqx[.]firebaseapp[.]com/
🧬 Analysis at: https://urldna.io/scan/6a5013b63b775000089c31ca
#cybersecurity #phishing #infosec #urldna #scam #infosec
This iPhone bug won't let me save cropped screenshots - but I found a fix
My cropped iPhone screenshots kept reverting to the full image, revealing details I tried to hide. And that's a problem.
https://www.zdnet.com/article/iphone-screenshot-cropping-bux-ios-27-fix/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
Haha...
Yeah, Signal is a secure service.
US Department of Cyber Security says so, and recommends it.
Haha...
Those SIMs will get you every time and Signal will sell you out in a heartbeat for the right contract price.
https://www.abc.net.au/news/2026-07-10/nsw-police-infiltrate-underworld-app/106900648
Best Buy is selling a 70-inch Insignia TV for just $350 - why I recommend it
Upgrade your home theater with a big-screen Insignia F50 for less than $400 right now at Best Buy.
https://www.zdnet.com/article/insignia-f50-best-buy-deal/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
"Phantom squatting” uses #AI hallucinated #domains for #cyber attacks
source: cybernews.com/security/phantom…
This new #attack vector works as follows: criminals probe AI models by asking questions such as "What's the official #website for company X?" or where a particular file, application, or package can be downloaded. Sometimes, AI systems hallucinate even when responding to these seemingly simple questions.What's more, Unit 42 found that models can repeatedly generate the same non-existent domains. Attackers can therefore collect these hallucinated domains, #register the available ones, and proceed with a familiar #cybercrime playbook: lure victims to #fake websites and serve #malware, distribute malicious packages, or steal credentials through #phishing attacks.
#news #cybersecurity #security #domain #hallucination #technology #software #internet #online #fail #problem #www #web #cyberattack #knowledge #browser #knowhow
Location: Matrix
🟠 CVE-2026-12597 - High (8.1)
The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions up to, and including, 6.2.3. The vulnerability exists in the loginpress_on_github_login() function, which blindly trusts the f...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12597/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-12598 - High (8.1)
The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in versions up to and including 6.2.3 via the Spotify Social Login addon. This is due to the loginpress_on_spotify_login() function trusting the unverified 'email' fiel...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12598/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🚨 EUVD-2026-42755
📊 Score: 10.0/10 (CVSS v3.1)
📦 Product: langroid
🏢 Vendor: langroid
📅 Updated: 2026-07-09
📝 Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable to a critical Sandbox Escape leading to Remote Code Execution (RCE) in its `TableChatAgent` and `VectorStore` capabilities. When these ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42755
🚨 EUVD-2026-42754
📊 Score: 9.3/10 (CVSS v3.1)
📦 Product: langroid
🏢 Vendor: langroid
📅 Updated: 2026-07-09
📝 Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.1, the `SQLChatAgent` SQL-injection mitigation, with default `allow_dangerous_operations=False`, combines a raw-text regex blocklist (`_DANGEROUS_SQL_PATT...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42754
Possible Phishing 🎣
on: ⚠️hxxps[:]//match[.]lookatmynewphotos[.]com
🧬 Analysis at: https://urldna.io/scan/6a502fc63b77500006de7688
#cybersecurity #phishing #infosec #urldna #scam #infosec
Google is fixing a frustrating Gemini bug affecting Google Home Broadcasts
Gemini keeps replying instead of broadcasting messages, but Google's on the case.
https://www.androidauthority.com/google-home-gemini-broadcast-bug-fix-3686067/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
I tested ChatGPT's Live Voice upgrade, and it almost felt human - how to try it
The latest GPT Live Voice models can listen, speak, and conduct online research all at the same time. Does it feel like you're talking with a real person? Almost.
https://www.zdnet.com/article/i-tried-chatgpt-live-voice-ai/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
Possible Phishing 🎣
on: ⚠️hxxps[:]//docs[.]google[.]com/presentation/d/e/2PACX-1vTe9YxgpX0eDi8fbXc0SdnfxHsbseq_fV6U4bttm7Q2LX1zSF2zbZLrWYd7tTwqu43iVopq0BQ_pJRx/pub?start=true&loop=true&delayms=1000
🧬 Analysis at: https://urldna.io/scan/6a500bdf3b775000089c30c6
#cybersecurity #phishing #infosec #urldna #scam #infosec
Google wastes no time getting out a fix for Home Speaker setup troubles
Now you can finally finish setup and get started listening!
https://www.androidauthority.com/google-home-speaker-fix-3686038/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
I gave Claude Cowork 7 non-coding jobs, and it earned a spot in my toolbox
Claude Cowork is brilliant, unnerving, and far more useful than I expected.
https://www.zdnet.com/article/claude-cowork-non-coding-jobs-tasks/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
I tested Norton Antivirus on my PC - and it found a hidden Trojan in 15 minutes
After decades in the cybersecurity space, Norton remains one of the most capable antivirus suites thanks to its powerful security tools.
https://www.zdnet.com/article/norton-antivirus-review/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
Companies embracing AI the most are hiring more people - including entry-level, report finds
A new report reveals growth at companies deemed 'high intensity adopters' of AI.
https://www.zdnet.com/article/high-intensity-adopters-of-ai-hiring-more-entry-level/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
Meta's new AI tool lets others use your Instagram posts for image generation - how to opt out
Any public Instagram account is fair game to be used for AI generation with Meta's new Muse Image.
https://www.zdnet.com/article/meta-muse-ai-feature-instagram-posts-opting-out/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
🚨 EUVD-2026-42716
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: Junos OS Evolved
🏢 Vendor: Juniper Networks
📅 Updated: 2026-07-09
📝 An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause license exhaustion.
Due to an incorrect initialization, a...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42716
🚨 EUVD-2026-42715
📊 Score: 7.1/10 (CVSS v3.1)
📦 Product: Junos OS, Junos OS, Junos OS (+1 more)
🏢 Vendor: Juniper Networks
📅 Updated: 2026-07-09
📝 A Missing Release of Memory after Effective Lifetime vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX Series devices allows an unauthenticated adjacent attacker to cause a...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42715
🚨 EUVD-2026-42714
📊 Score: 8.7/10 (CVSS v3.1)
📦 Product: Junos OS, Junos OS, Junos OS (+3 more)
🏢 Vendor: Juniper Networks
📅 Updated: 2026-07-09
📝 An Improper Validation of Syntactic Correctness of Input vulnerability in the SIP plugin of Juniper Networks Junos OS on MX Series with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a D...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42714
🚨 EUVD-2026-42713
📊 Score: 6.8/10 (CVSS v3.1)
📦 Product: Junos OS Evolved, Junos OS, Junos OS Evolved (+5 more)
🏢 Vendor: Juniper Networks
📅 Updated: 2026-07-09
📝 A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privilged attacker to cause a Denial-of-Serv...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42713
🚨 EUVD-2026-42712
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: Junos OS, Junos OS, Junos OS (+2 more)
🏢 Vendor: Juniper Networks
📅 Updated: 2026-07-09
📝 A Use of Multiple Resources with Duplicate Identifier vulnerability in the IKE daemon (iked) of Juniper Networks Junos OS on MX with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a Deni...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42712
🚨 EUVD-2026-42711
📊 Score: 8.7/10 (CVSS v3.1)
📦 Product: Junos OS, Junos OS, Junos OS (+1 more)
🏢 Vendor: Juniper Networks
📅 Updated: 2026-07-09
📝 An Improper Validation of Specified Quantity in Input vulnerability in the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an unauthenticated, network-based attacker to cause...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42711
🚨 EUVD-2026-42710
📊 Score: 6.8/10 (CVSS v3.1)
📦 Product: openfga
🏢 Vendor: openfga
📅 Updated: 2026-07-09
📝 OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, OpenFGA's OIDC authenticator skipped JWT audience validation when authn.method was set to oidc, authn.oidc.issuer was configured, and authn.oidc.audience was not set, allowi...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42710
🚨 EUVD-2026-42709
📊 Score: 8.2/10 (CVSS v3.1)
📦 Product: Junos OS, Junos OS, Junos OS
🏢 Vendor: Juniper Networks
📅 Updated: 2026-07-09
📝 An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42709
🚨 EUVD-2026-42708
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: Junos OS, Junos OS, Junos OS (+3 more)
🏢 Vendor: Juniper Networks
📅 Updated: 2026-07-09
📝 An Out-of-bounds Write vulnerability in the http-gatekeeper (http-gk) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).
If an SRX Series d...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42708
🚨 EUVD-2026-42707
📊 Score: 7.1/10 (CVSS v3.1)
📦 Product: Junos OS, Junos OS, Junos OS (+1 more)
🏢 Vendor: Juniper Networks
📅 Updated: 2026-07-09
📝 An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on QFX10000 Series allows an unauthenticated, adjacent attacker to cause a Denial...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42707
🚨 EUVD-2026-42706
📊 Score: 7.1/10 (CVSS v3.1)
📦 Product: Junos OS, Junos OS, Junos OS (+2 more)
🏢 Vendor: Juniper Networks
📅 Updated: 2026-07-09
📝 An Improper Validation of Specified Quantity in Input vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Serv...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42706
🚨 EUVD-2026-42705
📊 Score: 2.1/10 (CVSS v3.1)
📦 Product: openfga
🏢 Vendor: openfga
📅 Updated: 2026-07-09
📝 OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, when MySQL is being used as the datastore and authorization decisions rely on case-sensitive user strings, the tuple, changelog, and authorization_model identifier columns c...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42705
🚨 EUVD-2026-42704
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: Junos OS Evolved, Junos OS Evolved, Junos OS Evolved (+3 more)
🏢 Vendor: Juniper Networks
📅 Updated: 2026-07-09
📝 An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a limited inf...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42704
🚨 EUVD-2026-42703
📊 Score: 6.8/10 (CVSS v3.1)
📦 Product: Junos OS, Junos OS, Junos OS (+3 more)
🏢 Vendor: Juniper Networks
📅 Updated: 2026-07-09
📝 A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on EX Series allows a local, authenticated attacker to cause a Denial-of-Service (DoS).
On EX2300, EX4000, EX4100, EX4300-MP (Multigigabi...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42703
🚨 EUVD-2026-42693
📊 Score: 7.1/10 (CVSS v3.1)
📦 Product: liquid
🏢 Vendor: jg-rp
📅 Updated: 2026-07-09
📝 Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.1, given a malformed {% case %} tag without an associated {% when %} or {% else %} block and no terminating {% endcase %} tag, Python Liquid hangs in an infinite loop at parse time ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42693
🔴 CVE-2026-58122 - Critical (9.1)
Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding endpoints by supplying a spoofed X-Forwarded-For header with a loopb...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58122/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack