voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
🚨 EUVD-2026-46146
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Hospital Management System
🏢 Vendor: itsourcecode
📅 Updated: 2026-07-21
📝 A vulnerability was identified in itsourcecode Hospital Management System 1.0. This vulnerability affects unknown code of the file /prescriptionorder.php. Such manipulation of the argument editid leads to sql injection. The attack can...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46146
🚨 EUVD-2026-46145
📊 Score: 7.2/10 (CVSS v3.1)
📦 Product: AX7501-B1 firmware
🏢 Vendor: Zyxel
📅 Updated: 2026-07-21
📝 A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 could allow an authenticated attacker with administrator privileges to execute OS co...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46145
🚨 EUVD-2026-46144
📊 Score: 6.8/10 (CVSS v3.1)
📦 Product: TeX Live, TeX Live
🏢 Vendor: TeX Live
📅 Updated: 2026-07-21
📝 The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers to crash applications or potentially execute arbitrary code b...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46144
🚨 EUVD-2026-46143
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: DNS-320
🏢 Vendor: D-Link
📅 Updated: 2026-07-21
📝 A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata[] results in unrestricted upload. The attack is possible to be carried out remo...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46143
🚨 EUVD-2026-46140
📊 Score: n/a
📅 Updated: 2026-07-21
📝 FlareSolverr before version 3.4.7 contains a server-side request forgery (SSRF) vulnerability in the /v1 API endpoint. This allows a remote attacker to obtain sensitive information
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46140
🚨 EUVD-2026-46142
📊 Score: n/a
📅 Updated: 2026-07-21
📝 An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and before allows an attacker to execute arbitrary code via a crafted FEX file
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46142
🚨 EUVD-2026-46141
📊 Score: 6.9/10 (CVSS v3.1)
📅 Updated: 2026-07-21
📝 An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a remote attacker to execute arbitrary code via the validate_url, safe_fetch, _build_opener, _fetch_html and _download_binary functions.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46141
🚨 EUVD-2026-46139
📊 Score: n/a
📅 Updated: 2026-07-21
📝 Cross Site Scripting vulnerability in fuint Member Marketing System <=v1.0 allows a remote attacker to execute arbitrary code via the ClientMessageController.java file
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46139
🚨 EUVD-2024-55692
📊 Score: n/a
📅 Updated: 2026-07-21
📝 The Tenda TX9 V22.03.02.20 firmware has a denial of service vulnerability in the update_dev_name function of the file /goform/SetOnlineDevName
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-55692
🚨 EUVD-2024-55690
📊 Score: n/a
📅 Updated: 2026-07-21
📝 The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_424CE0 function of the file /goform/setMacFilterCfg.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-55690
🚨 EUVD-2024-55691
📊 Score: n/a
📅 Updated: 2026-07-21
📝 The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_425964 function of the file /goform/SetOnlineDevName
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-55691
🚨 EUVD-2024-55688
📊 Score: n/a
📅 Updated: 2026-07-21
📝 The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EEE0 function of the file /goform/SetStaticRouteCfg.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-55688
⚠️ CRITICAL: Hackers abuse ViPNet software to target Russian govt agencies
Advanced threat actor HelloNet is actively exploiting ViPNet's update mechanism to compromise Russian government and critical infrastructure targets since May 2026. The attack chain uses DLL sideloading to deploy persistent backdoors and additional malware modules. This represents a supply chain co…
🛡️⏱️ GNOME scurtează termenul de dezvăluire publică a vulnerabilităților de la 90 la 30 de zileProiectul GNOME a adoptat o schimbare majoră în politica sa de securitate cibernetică (Responsible Disclosure Policy), reducând drastic fereastra în care bug-urile de securitate raportate sunt păstrate confidențiale: de la 90 de zile la doar 30 de zile.Această măsură urmărește să accelereze ritmul în care patch-urile de securitate ajung la utilizatorii finali și să oblige menținătorii de pachete să reacționeze cu o mai mare celeritate în fața amenințărilor.Iată detaliile cheie legate de această nouă politică adoptată de GNOME:🔹 De la standardul industriei (90 zile) la un ritm alert (30 zile)Tradițional, corporațiile mari de tehnologie și proiectele open-source majore (precum Google Project Zero) folosesc o fereastră de 90 de zile de la raportarea unei vulnerabilități până la publicarea detaliilor tehnice ale acesteia. Scopul este de a oferi dezvoltatorilor timp suficient să creeze, să testeze și să distribuie un patch fără a expune utilizatorii la atacuri cibernetice.GNOME a decis că 30 de zile sunt mai mult decât suficiente în ecosistemul lor actual, argumentând că:Ecosistemul se mișcă mai rapid: În prezent, pachetele Flatpak și integrările moderne din distribuții permit lansarea patch-urilor într-un timp mult mai scurt decât în urmă cu un deceniu.Prevenirea stagnării: O fereastră lungă de 90 de zile ducea deseori la amânarea rezolvării problemelor critice până în ultimele săptămâni înainte de expirarea termenului-limită.🔹 Ce se întâmplă dacă o vulnerabilitate nu este reparată în 30 de zile?Conform noilor reguli, odată ce un cercetător de securitate raportează confidențial o vulnerabilitate către echipa GNOME, după 30 de zile detaliile tehnice ale bug-ului pot fi făcute publice, indiferent dacă problema a fost complet remediată sau nu.Această practică crește presiunea publică asupra menținătorilor de module pentru a prioritiza rezolvarea breșelor de securitate înainte ca atacatorii să le poată exploata în masă.🔹 Excepții și flexibilitateEchipa de securitate GNOME a menționat că pot exista situații excepționale (de exemplu, vulnerabilități extrem de complexe care afectează mai multe componente ale sistemului de operare sau ale kernel-ului Linux), în care termenul poate fi extins temporar prin acord reciproc, însă regula de bază rămâne de 30 de zile.Prin această strategie agresivă, GNOME transmite un semnal clar comunității și industriei: securitatea desktop-ului Linux este o prioritate critică ce nu suportă amânări.#OpenSource #GNOME #Cybersecurity #InfoSec #LinuxSecurity #Vulnerabilities #TechNews #Linuxiac
"Europe chose CV-QKD for its quantum networks." I keep seeing this in quantum coverage. It's wrong, and the real picture is more interesting, and more relevant to infosec practitioners than it first appears.
EuroQCI, the EU's quantum communication infrastructure programme, funds six parallel industrial projects across three QKD modalities. eCAUSIS is explicitly building DV-QKD systems and a European DV-QKD supply chain. MDI-QUEEN is developing measurement-device-independent QKD. QUARTERNEXT (launched July 6, €10M, coordinated by Luxquanta) is one of several CV-QKD tracks, alongside QKISS and SEQRET.
Europe didn't pick a protocol winner. It's building a portfolio.
So why does CV-QKD get disproportionate strategic attention? Supply chain.
DV-QKD's highest-performance detectors are superconducting nanowire single-photon detectors (SNSPDs) - cryogenic, specialised, thin supplier base. ID Quantique in Geneva was Europe's flagship SNSPD manufacturer. Then IonQ acquired a controlling stake (announced Feb 2025, completed May 2025). Europe's most prominent single-photon detector company is now a US subsidiary.
Single Quantum in Delft is EU-owned but small. Pixel Photonics in Münster (€13.5M raised April 2026) is a newer entrant. Beyond that: Photec (China), Scontel (Russia), Photon Spot and Quantum Opus (US).
CV-QKD sidesteps this dependency. Its detection hardware: homodyne receivers, InGaAs photodiodes, balanced detectors; uses telecom-derived components that European industry manufactures at scale. Not off-the-shelf telecom gear (a secure CV-QKD receiver requires tight shot-noise calibration, excess-noise estimation, and security-specific DSP), but the manufacturing base is European.
QUARTERNEXT's alignment with PIXEurope (the EU's ~€400M photonic chip pilot line) makes the industrial logic explicit.
Now here's what makes it more complicated than a clean sovereignty narrative.
China's 10,000+ km quantum network (described in a 2025 npj Quantum Information paper) is hybrid. Four decoy-state BB84 systems on the backbone, two Gaussian-modulated CV-QKD systems in metro networks. They use InGaAs/InP avalanche detectors and upconversion detectors on the backbone - not SNSPDs. The "China chose DV, Europe chose CV" framing is wrong when you look at deployment evidence.
Both ecosystems are converging on multi-modality. The question isn't which protocol wins. It's who controls the component stack.
The security proof angle matters for the infosec crowd too. DV-QKD (decoy-state BB84) has two decades of finite-key, coherent-attack security proofs. CV-QKD's proof literature is younger and more active: composable security for Gaussian modulation established in 2022, coherent-attack proofs for discrete modulation improved substantially in Feb 2025. The photon-number cutoff assumption in CV-QKD proofs (infinite-dimensional Hilbert spaces require truncation for numerical analysis) is an active research area.
This matters because the EU's Nostradamus certification lab at JRC Ispra will need to evaluate CV-QKD products against these proofs. If the proofs carry unresolved assumptions, the certification carries them too. The pipeline from proof theory to certified product to procurement framework is where CV-QKD's practical future lives or dies.
For practitioners: PQC migration is still the action item. The regulatory deadlines are set. QKD is a specialised additional control for specific use cases with specific risk profiles. If you're in EU-regulated critical infrastructure, track the Nostradamus certification pipeline as it will shape procurement requirements. Insist on modality-neutral key management interfaces (ETSI GS QKD 004/014). Don't lock into one vendor or one QKD flavour.
Full analysis: https://postquantum.com/post-quantum/europe-cv-qkd-industrialisation/
#infosec #cybersecurity #quantum #QKD #PQC #cryptography #postquantum #EuroQCI
Apple Releases macOS Golden Gate Beta 4
Apple today provided developers with the fourth beta of macOS Golden Gate, with the update coming two weeks after Apple seeded the third beta. Developers can download macOS Golden Gate by going to System Settings > Ge…
https://www.macrumors.com/2026/07/20/apple-releases-macos-27-beta-4/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #MacRumors [MacRumors]
The #Trump administration is reportedly considering measures to effectively #ban #ChineseAI models, including #sanctions, #securitywarnings, and #executiveorders. These measures, driven by concerns over #cybersecurity and #commercialinterests, aim to deter U.S. companies from using Chinese models without imposing a direct ban. https://the-decoder.com/trump-administration-reportedly-builds-a-slow-motion-ban-on-chinese-ai-models-through-sanctions-and-soft-pressure/?eicker.news #tech #media #news
🚀 IPFire 2.29 Core Update 203 aduce o schimbare majoră pe partea de DNS!
Distribuția firewall open-source IPFire renunță la vechiul resolver Unbound și trece la Knot Resolver, oferind mai multă flexibilitate, performanță și securitate avansată.
✨ Ce este nou în această versiune:
🔒 Redirecționare DNS-over-TLS (DoT) pentru interogări criptate
🛡️ DNS Firewall nou: blocare de malware, reclame și categorii de domenii la nivel de rețea
🔍 Forțare SafeSearch pe marile motoare de căutare și YouTube
⚡ Cache persistent care rezistă la reporniri și este partajat eficient între nucleele CPU
📶 Suport Wi-Fi 6E / Wi-Fi 7 (banda de 6 GHz) pentru modul Access Point
☁️ Suport IMDSv2 pentru instanțele din Amazon Web Services (AWS)
📦 Actualizări de securitate și pachete majore: Suricata, OpenVPN, BIND, microcod Intel și multe altele.
⚠️ Notă de compatibilitate: Zonele redirecționate (Forwarded zones) nu mai acceptă nume de domenii (FQDN), ci necesită adrese IP directe.
#IPFire #Linux #OpenSource #CyberSecurity #DNS #KnotResolver #Networking #SysAdmin #TechNews #Firewall
Apple Seeds Fourth iOS 27 and iPadOS 27 Betas to Developers
Apple today seeded the fourth betas of iOS 27 and iPadOS 27 to developers for testing purposes, with the update coming two weeks after Apple released the third betas. Registered developers can download the betas from th…
https://www.macrumors.com/2026/07/20/apple-seeds-ios-27-beta-4/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #MacRumors [MacRumors]
Thanks for hanging out and diving into new tools, cybersecurity chats, and some Linux gaming! Appreciate you joining the hacker summer camp prep. 🤓💻 #Cybersecurity #Linux
Apple Sports App Updated With Additional Soccer Leagues Following 2026 FIFA World Cup
Apple Sports was updated today with support for additional soccer leagues in Asia and Europe, plus the ability to see formations across most soccer leagues. The update arrives just one day after the 2026 FIFA World Cup …
https://www.macrumors.com/2026/07/20/apple-sports-app-gets-more-soccer-leagues/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #MacRumors [MacRumors]
Possible Phishing 🎣
on: ⚠️hxxps[:]//nidnaver5651373693[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a5e31bd3b7750000794a645
#cybersecurity #phishing #infosec #urldna #scam #infosec
Four Apple Stores in the U.S. Are Moving This Month
Four of Apple's retail stores in the U.S. are moving this month, although all of them will only be a short distance from their existing locations. Apple Queens Center in Elmhurst, New York already moved to a temporary l…
https://www.macrumors.com/2026/07/20/four-apple-stores-moving-this-month/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #MacRumors [MacRumors]
Apple Seeds watchOS 26.6, tvOS 26.6 and visionOS 26.6 Release Candidates
Apple today provided developers with the release candidate versions of upcoming watchOS 26.6, tvOS 26.6, and visionOS 26.6 betas for testing purposes. The software comes a week after Apple seeded the fifth betas. The RC…
https://www.macrumors.com/2026/07/20/watchos-26-6-rc/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #MacRumors [MacRumors]
Possible Phishing 🎣
on: ⚠️hxxps[:]//www[.]sertras[.]com/v3/gndi-login/
🧬 Analysis at: https://urldna.io/scan/6a5eda6a3b775000082198aa
#cybersecurity #phishing #infosec #urldna #scam #infosec
#MalwareDB slides from #Hobocon are available from https://github.com/rjzak/malwaredb_hobocon_2026/releases/download/v1/Zak-MalwareDB-Hobocon2.pdf. It was a great conference and many thanks to the organizers #SecKC, #Amtrak for having us! #Cybersecurity #Trains
Estée Lauder has finally disclosed a significant data breach impacting current and former employees, stemming from a Clop ransomware attack on their Oracle E-Business Suite HR environment. The breach, which exposed highly sensitive data including Social Security numbers, passport details, and health information, highlights the critical impact of zero-day vulnerabilities like…
#cybersecurity #esteelauder #oracleebusinesssuite
🤖 This post was AI-generated.
Apple Seeds tvOS 27 Beta 4 to Developers
Apple today seeded the fourth beta of tvOS 27 to developers for testing purposes, with the update coming two weeks after Apple released the third beta. The beta can be downloaded and installed through the Settings app o…
https://www.macrumors.com/2026/07/20/apple-seeds-tvos-27-beta-4/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #MacRumors [MacRumors]
What is #Hobocon? It's a #CyberSecurity #conference aboard an #Amtrak train between Kansas City and Chicago, for a total of 22 inescapable hours with some fun, talented, and friendly hackers. Check it out! https://www.hobocon.com/
"A pull request that steals a repository's secrets by hiding the malicious instruction inside a PNG that AI code reviewers never open has been built."
This takes advantage of the fact that AI models are "multimodal" and see images -- and read text in images.
Rumänien: Cyberkrimineller löscht die gesamte Grundbuchdatenbank des Landes
Ein Angreifer löscht die gesamte rumänische Grundbuchdatenbank, nachdem eine Erpressung gescheitert war, und bringt damit den Immobilienmarkt zum Stillstand.
Apple Seeds macOS Tahoe 26.6 Release Candidate
Apple today provided the release candidate version of an upcoming macOS Tahoe 26.6 update to developers for testing purposes, with the update coming a week after Apple seeded the fifth beta. The release candidate marks …
https://www.macrumors.com/2026/07/20/apple-seeds-macos-tahoe-26-6-beta-6/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #MacRumors [MacRumors]
Possible Phishing 🎣
on: ⚠️hxxps[:]//webmail-erty5[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a5e461b3b77500004c970f2
#cybersecurity #phishing #infosec #urldna #scam #infosec
The White House launched the GOLD EAGLE initiative for faster vulnerability coordination across U.S. critical infrastructure, using AI to patch flaws.
#GOLDEAGLE #Cybersecurity #VulnerabilityCoordination #CriticalInfrastructure #AI #CISA
Apple Seeds iOS 26.6 and iPadOS 26.6 Release Candidates
Apple today seeded the release candidate versions of upcoming iOS 26.6 and iPadOS 26.6 updates to developers for testing purposes, with the software coming a week after Apple seeded the fifth betas. The RCs represent th…
https://www.macrumors.com/2026/07/20/apple-seeds-ios-26-6-beta-6/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #MacRumors [MacRumors]
📰 Prompt Injection Attacks are thwarting AI hacking agents by tricking them into shutting down before they can cause harm.
🔗 https://www.wired.com/story/prompt-injection-attacks-are-thwarting-ai-hacking-agents/
📰 Prompt Injection Attacks are thwarting AI hacking agents by tricking them into shutting down before they can cause harm.
🔗 https://www.wired.com/story/prompt-injection-attacks-are-thwarting-ai-hacking-agents/
Hello People.
This is my first fediverse post, featuring my first #assembly64 program in #linux. I am a #student who is just getting into #cybersecurity and love contributing to #infosec, #lowlevel stuffs and #linuxkernel.
I love to program in #c, and use #archlinux btw. Looking for people to connect. I installed LinkedIn a few days ago for connecting with people and figured out that it was a #scam in jobmarket, just data feed into companies. (No offense, just in my opinion).
I was suggested to start learning #assembly64 by a random reddit user when I asked some questions about #c programming and how to get better at it. Currently learning #syscalls in linux, and I guess assembly programming alongside with c programming is helpful - I can understand syscalls and registers (for some extent).
Looking forward for friends to connect. Follow me and I will follow you back - provided that we have same or similar interests. I am also interested in #russian arts, languages and techs - I am not a Russian btw.
I need suggestions \ #help on how to get started in fediverse, cybersecurity and low level stuffs. You can see my profile for more information.
🟠 CVE-2026-47255 - High (8.2)
AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness related to validation and and binding of inactive-agent hour filtering; storage...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47255/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🔴 CVE-2026-63767 - Critical (9.8)
ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands by sending crafted pickle payloads to the SchedulerServer ZMQ ROUTER ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63767/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-53591 - High (8.6)
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.223, an unauthenticated attacker can inject messages into any existing support conversation by sending a single email to the helpdesk's public ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53591/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Surveillance pricing is not just airline-style dynamic pricing!
It is personal data, location, shopping history, loyalty programs, and AI-driven targeting influencing the price or discount someone sees.
Watch this episode of @sharedsecurity on Youtube:
https://youtu.be/B9mxJXkerWA
Listen wherever you like to get your podcasts:
https://sharedsecurity.net/subscribe
https://sharedsecurity.net/2026/07/20/surveillance-pricing-when-your-data-sets-the-price/
New iPad Mini With OLED Display Will Also Have 'Major' Chip Upgrade
A new iPad mini coming by October will deliver a "major processor leap," according to Bloomberg's Mark Gurman. with an A19 Pro chip or an A20 Pro chip, up from the A17 Pro in the current 2024 model. Other rumored featur…
https://www.macrumors.com/2026/07/20/next-ipad-mini-major-chip-upgrade/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #MacRumors [MacRumors]
Possible Phishing 🎣
on: ⚠️hxxps[:]//rachy011[.]github[.]io/live-coding-test
🧬 Analysis at: https://urldna.io/scan/6a5e70623b775000080c5885
#cybersecurity #phishing #infosec #urldna #scam #infosec
🚨 EUVD-2026-46135
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: DNS-320
🏢 Vendor: D-Link
📅 Updated: 2026-07-20
📝 A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_file/upload.php. Executing a manipulation of the argument File can lead to unrestricted upload. The attack can be launched remotely. The ex...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46135
🚨 EUVD-2026-46134
📊 Score: 8.1/10 (CVSS v3.1)
📦 Product: gitleaks
🏢 Vendor: gitleaks
📅 Updated: 2026-07-20
📝 Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who can supply or influence report templates to read arbitrary environment variables and exfiltrate sensitive data by leveraging non-hermetic Sprig template function...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46134
🚨 EUVD-2026-46133
📊 Score: 7.5/10 (CVSS v3.1)
📦 Product: netty, netty
🏢 Vendor: netty
📅 Updated: 2026-07-20
📝 Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded `maxHe...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46133
🚨 EUVD-2026-46132
📊 Score: 7.5/10 (CVSS v3.1)
📦 Product: netty, netty
🏢 Vendor: netty
📅 Updated: 2026-07-20
📝 Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materiali...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46132
'ClickLock' Malware Coerces Mac Users Into Giving Up Passwords
Security firm Group-IB has identified a new piece of macOS malware in the wild that pressures users into surrendering their passwords via a barrage of fake system prompts. Dubbed "ClickLock Stealer," the malware needs n…
https://www.macrumors.com/2026/07/20/clicklock-malware-mac-users-giving-up-passwords/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #MacRumors [MacRumors]