voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]EUVD Bot » 🤖 🌐
@EUVD_Bot@mastodon.social

🚨 EUVD-2026-46146

📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Hospital Management System
🏢 Vendor: itsourcecode
📅 Updated: 2026-07-21

📝 A vulnerability was identified in itsourcecode Hospital Management System 1.0. This vulnerability affects unknown code of the file /prescriptionorder.php. Such manipulation of the argument editid leads to sql injection. The attack can...

🔗 euvd.enisa.europa.eu/vulnerabi

    [?]EUVD Bot » 🤖 🌐
    @EUVD_Bot@mastodon.social

    🚨 EUVD-2026-46145

    📊 Score: 7.2/10 (CVSS v3.1)
    📦 Product: AX7501-B1 firmware
    🏢 Vendor: Zyxel
    📅 Updated: 2026-07-21

    📝 A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 could allow an authenticated attacker with administrator privileges to execute OS co...

    🔗 euvd.enisa.europa.eu/vulnerabi

      [?]EUVD Bot » 🤖 🌐
      @EUVD_Bot@mastodon.social

      🚨 EUVD-2026-46144

      📊 Score: 6.8/10 (CVSS v3.1)
      📦 Product: TeX Live, TeX Live
      🏢 Vendor: TeX Live
      📅 Updated: 2026-07-21

      📝 The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers to crash applications or potentially execute arbitrary code b...

      🔗 euvd.enisa.europa.eu/vulnerabi

        [?]EUVD Bot » 🤖 🌐
        @EUVD_Bot@mastodon.social

        🚨 EUVD-2026-46143

        📊 Score: 6.9/10 (CVSS v3.1)
        📦 Product: DNS-320
        🏢 Vendor: D-Link
        📅 Updated: 2026-07-21

        📝 A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata[] results in unrestricted upload. The attack is possible to be carried out remo...

        🔗 euvd.enisa.europa.eu/vulnerabi

          [?]EUVD Bot » 🤖 🌐
          @EUVD_Bot@mastodon.social

          🚨 EUVD-2026-46140

          📊 Score: n/a
          📅 Updated: 2026-07-21

          📝 FlareSolverr before version 3.4.7 contains a server-side request forgery (SSRF) vulnerability in the /v1 API endpoint. This allows a remote attacker to obtain sensitive information

          🔗 euvd.enisa.europa.eu/vulnerabi

            [?]EUVD Bot » 🤖 🌐
            @EUVD_Bot@mastodon.social

            🚨 EUVD-2026-46142

            📊 Score: n/a
            📅 Updated: 2026-07-21

            📝 An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and before allows an attacker to execute arbitrary code via a crafted FEX file

            🔗 euvd.enisa.europa.eu/vulnerabi

              [?]EUVD Bot » 🤖 🌐
              @EUVD_Bot@mastodon.social

              🚨 EUVD-2026-46141

              📊 Score: 6.9/10 (CVSS v3.1)
              📅 Updated: 2026-07-21

              📝 An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a remote attacker to execute arbitrary code via the validate_url, safe_fetch, _build_opener, _fetch_html and _download_binary functions.

              🔗 euvd.enisa.europa.eu/vulnerabi

                [?]EUVD Bot » 🤖 🌐
                @EUVD_Bot@mastodon.social

                🚨 EUVD-2026-46139

                📊 Score: n/a
                📅 Updated: 2026-07-21

                📝 Cross Site Scripting vulnerability in fuint Member Marketing System <=v1.0 allows a remote attacker to execute arbitrary code via the ClientMessageController.java file

                🔗 euvd.enisa.europa.eu/vulnerabi

                  [?]EUVD Bot » 🤖 🌐
                  @EUVD_Bot@mastodon.social

                  🚨 EUVD-2024-55692

                  📊 Score: n/a
                  📅 Updated: 2026-07-21

                  📝 The Tenda TX9 V22.03.02.20 firmware has a denial of service vulnerability in the update_dev_name function of the file /goform/SetOnlineDevName

                  🔗 euvd.enisa.europa.eu/vulnerabi

                    [?]EUVD Bot » 🤖 🌐
                    @EUVD_Bot@mastodon.social

                    🚨 EUVD-2024-55690

                    📊 Score: n/a
                    📅 Updated: 2026-07-21

                    📝 The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_424CE0 function of the file /goform/setMacFilterCfg.

                    🔗 euvd.enisa.europa.eu/vulnerabi

                      [?]EUVD Bot » 🤖 🌐
                      @EUVD_Bot@mastodon.social

                      🚨 EUVD-2024-55691

                      📊 Score: n/a
                      📅 Updated: 2026-07-21

                      📝 The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_425964 function of the file /goform/SetOnlineDevName

                      🔗 euvd.enisa.europa.eu/vulnerabi

                        [?]EUVD Bot » 🤖 🌐
                        @EUVD_Bot@mastodon.social

                        🚨 EUVD-2024-55688

                        📊 Score: n/a
                        📅 Updated: 2026-07-21

                        📝 The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EEE0 function of the file /goform/SetStaticRouteCfg.

                        🔗 euvd.enisa.europa.eu/vulnerabi

                          [?]ThreatNoir » 🌐
                          @threatnoir@infosec.exchange

                          ⚠️ CRITICAL: Hackers abuse ViPNet software to target Russian govt agencies

                          Advanced threat actor HelloNet is actively exploiting ViPNet's update mechanism to compromise Russian government and critical infrastructure targets since May 2026. The attack chain uses DLL sideloading to deploy persistent backdoors and additional malware modules. This represents a supply chain co…

                          threatnoir.com/focus

                            [?]linuxwebzine » 🌐
                            @linuxwebzine@mstdn.ro

                            🛡️⏱️ GNOME scurtează termenul de dezvăluire publică a vulnerabilităților de la 90 la 30 de zileProiectul GNOME a adoptat o schimbare majoră în politica sa de securitate cibernetică (Responsible Disclosure Policy), reducând drastic fereastra în care bug-urile de securitate raportate sunt păstrate confidențiale: de la 90 de zile la doar 30 de zile.Această măsură urmărește să accelereze ritmul în care patch-urile de securitate ajung la utilizatorii finali și să oblige menținătorii de pachete să reacționeze cu o mai mare celeritate în fața amenințărilor.Iată detaliile cheie legate de această nouă politică adoptată de GNOME:🔹 De la standardul industriei (90 zile) la un ritm alert (30 zile)Tradițional, corporațiile mari de tehnologie și proiectele open-source majore (precum Google Project Zero) folosesc o fereastră de 90 de zile de la raportarea unei vulnerabilități până la publicarea detaliilor tehnice ale acesteia. Scopul este de a oferi dezvoltatorilor timp suficient să creeze, să testeze și să distribuie un patch fără a expune utilizatorii la atacuri cibernetice.GNOME a decis că 30 de zile sunt mai mult decât suficiente în ecosistemul lor actual, argumentând că:Ecosistemul se mișcă mai rapid: În prezent, pachetele Flatpak și integrările moderne din distribuții permit lansarea patch-urilor într-un timp mult mai scurt decât în urmă cu un deceniu.Prevenirea stagnării: O fereastră lungă de 90 de zile ducea deseori la amânarea rezolvării problemelor critice până în ultimele săptămâni înainte de expirarea termenului-limită.🔹 Ce se întâmplă dacă o vulnerabilitate nu este reparată în 30 de zile?Conform noilor reguli, odată ce un cercetător de securitate raportează confidențial o vulnerabilitate către echipa GNOME, după 30 de zile detaliile tehnice ale bug-ului pot fi făcute publice, indiferent dacă problema a fost complet remediată sau nu.Această practică crește presiunea publică asupra menținătorilor de module pentru a prioritiza rezolvarea breșelor de securitate înainte ca atacatorii să le poată exploata în masă.🔹 Excepții și flexibilitateEchipa de securitate GNOME a menționat că pot exista situații excepționale (de exemplu, vulnerabilități extrem de complexe care afectează mai multe componente ale sistemului de operare sau ale kernel-ului Linux), în care termenul poate fi extins temporar prin acord reciproc, însă regula de bază rămâne de 30 de zile.Prin această strategie agresivă, GNOME transmite un semnal clar comunității și industriei: securitatea desktop-ului Linux este o prioritate critică ce nu suportă amânări.

                              [?]Marin Ivezic » 🌐
                              @infosec@defcon.social

                              "Europe chose CV-QKD for its quantum networks." I keep seeing this in quantum coverage. It's wrong, and the real picture is more interesting, and more relevant to infosec practitioners than it first appears.

                              EuroQCI, the EU's quantum communication infrastructure programme, funds six parallel industrial projects across three QKD modalities. eCAUSIS is explicitly building DV-QKD systems and a European DV-QKD supply chain. MDI-QUEEN is developing measurement-device-independent QKD. QUARTERNEXT (launched July 6, €10M, coordinated by Luxquanta) is one of several CV-QKD tracks, alongside QKISS and SEQRET.

                              Europe didn't pick a protocol winner. It's building a portfolio.

                              So why does CV-QKD get disproportionate strategic attention? Supply chain.

                              DV-QKD's highest-performance detectors are superconducting nanowire single-photon detectors (SNSPDs) - cryogenic, specialised, thin supplier base. ID Quantique in Geneva was Europe's flagship SNSPD manufacturer. Then IonQ acquired a controlling stake (announced Feb 2025, completed May 2025). Europe's most prominent single-photon detector company is now a US subsidiary.

                              Single Quantum in Delft is EU-owned but small. Pixel Photonics in Münster (€13.5M raised April 2026) is a newer entrant. Beyond that: Photec (China), Scontel (Russia), Photon Spot and Quantum Opus (US).

                              CV-QKD sidesteps this dependency. Its detection hardware: homodyne receivers, InGaAs photodiodes, balanced detectors; uses telecom-derived components that European industry manufactures at scale. Not off-the-shelf telecom gear (a secure CV-QKD receiver requires tight shot-noise calibration, excess-noise estimation, and security-specific DSP), but the manufacturing base is European.

                              QUARTERNEXT's alignment with PIXEurope (the EU's ~€400M photonic chip pilot line) makes the industrial logic explicit.

                              Now here's what makes it more complicated than a clean sovereignty narrative.

                              China's 10,000+ km quantum network (described in a 2025 npj Quantum Information paper) is hybrid. Four decoy-state BB84 systems on the backbone, two Gaussian-modulated CV-QKD systems in metro networks. They use InGaAs/InP avalanche detectors and upconversion detectors on the backbone - not SNSPDs. The "China chose DV, Europe chose CV" framing is wrong when you look at deployment evidence.

                              Both ecosystems are converging on multi-modality. The question isn't which protocol wins. It's who controls the component stack.

                              The security proof angle matters for the infosec crowd too. DV-QKD (decoy-state BB84) has two decades of finite-key, coherent-attack security proofs. CV-QKD's proof literature is younger and more active: composable security for Gaussian modulation established in 2022, coherent-attack proofs for discrete modulation improved substantially in Feb 2025. The photon-number cutoff assumption in CV-QKD proofs (infinite-dimensional Hilbert spaces require truncation for numerical analysis) is an active research area.

                              This matters because the EU's Nostradamus certification lab at JRC Ispra will need to evaluate CV-QKD products against these proofs. If the proofs carry unresolved assumptions, the certification carries them too. The pipeline from proof theory to certified product to procurement framework is where CV-QKD's practical future lives or dies.

                              For practitioners: PQC migration is still the action item. The regulatory deadlines are set. QKD is a specialised additional control for specific use cases with specific risk profiles. If you're in EU-regulated critical infrastructure, track the Nostradamus certification pipeline as it will shape procurement requirements. Insist on modality-neutral key management interfaces (ETSI GS QKD 004/014). Don't lock into one vendor or one QKD flavour.

                              Full analysis: postquantum.com/post-quantum/e

                                [?]TechWire ⚡ » 🤖 🌐
                                @techwire@social.gamefan.net

                                Apple Releases macOS Golden Gate Beta 4

                                Apple today provided developers with the fourth beta of macOS Golden Gate, with the update coming two weeks after Apple seeded the third beta. Developers can download ‌macOS Golden Gate‌ by going to System Settings > Ge…

                                macrumors.com/2026/07/20/apple

                                [MacRumors]

                                  [?]tech news ᳇ eicker.news » 🌐
                                  @technews@eicker.news

                                  The administration is reportedly considering measures to effectively models, including , , and . These measures, driven by concerns over and , aim to deter U.S. companies from using Chinese models without imposing a direct ban. the-decoder.com/trump-administ

                                    [?]linuxwebzine » 🌐
                                    @linuxwebzine@mstdn.ro

                                    🚀 IPFire 2.29 Core Update 203 aduce o schimbare majoră pe partea de DNS!

                                    Distribuția firewall open-source IPFire renunță la vechiul resolver Unbound și trece la Knot Resolver, oferind mai multă flexibilitate, performanță și securitate avansată.

                                    ✨ Ce este nou în această versiune:
                                    🔒 Redirecționare DNS-over-TLS (DoT) pentru interogări criptate
                                    🛡️ DNS Firewall nou: blocare de malware, reclame și categorii de domenii la nivel de rețea
                                    🔍 Forțare SafeSearch pe marile motoare de căutare și YouTube
                                    ⚡ Cache persistent care rezistă la reporniri și este partajat eficient între nucleele CPU
                                    📶 Suport Wi-Fi 6E / Wi-Fi 7 (banda de 6 GHz) pentru modul Access Point
                                    ☁️ Suport IMDSv2 pentru instanțele din Amazon Web Services (AWS)
                                    📦 Actualizări de securitate și pachete majore: Suricata, OpenVPN, BIND, microcod Intel și multe altele.

                                    ⚠️ Notă de compatibilitate: Zonele redirecționate (Forwarded zones) nu mai acceptă nume de domenii (FQDN), ci necesită adrese IP directe.

                                      [?]TechWire ⚡ » 🤖 🌐
                                      @techwire@social.gamefan.net

                                      Apple Seeds Fourth iOS 27 and iPadOS 27 Betas to Developers

                                      Apple today seeded the fourth betas of iOS 27 and iPadOS 27 to developers for testing purposes, with the update coming two weeks after Apple released the third betas. Registered developers can download the betas from th…

                                      macrumors.com/2026/07/20/apple

                                      [MacRumors]

                                        [?]ChiefGyk3D » 🌐
                                        @chiefgyk3d@social.chiefgyk3d.com

                                        Thanks for hanging out and diving into new tools, cybersecurity chats, and some Linux gaming! Appreciate you joining the hacker summer camp prep. 🤓💻

                                          [?]TechWire ⚡ » 🤖 🌐
                                          @techwire@social.gamefan.net

                                          Apple Sports App Updated With Additional Soccer Leagues Following 2026 FIFA World Cup

                                          Apple Sports was updated today with support for additional soccer leagues in Asia and Europe, plus the ability to see formations across most soccer leagues. The update arrives just one day after the 2026 FIFA World Cup …

                                          macrumors.com/2026/07/20/apple

                                          [MacRumors]

                                            [?]urlDNA.io :verified: » 🤖 🌐
                                            @urldna@infosec.exchange

                                            Possible Phishing 🎣
                                            on: ⚠️hxxps[:]//nidnaver5651373693[.]weebly[.]com
                                            🧬 Analysis at: urldna.io/scan/6a5e31bd3b77500

                                              [?]TechWire ⚡ » 🤖 🌐
                                              @techwire@social.gamefan.net

                                              Four Apple Stores in the U.S. Are Moving This Month

                                              Four of Apple's retail stores in the U.S. are moving this month, although all of them will only be a short distance from their existing locations. Apple Queens Center in Elmhurst, New York already moved to a temporary l…

                                              macrumors.com/2026/07/20/four-

                                              [MacRumors]

                                                [?]Negative PID SL » 🌐
                                                @negativepid@mastodon.social

                                                [?]TechWire ⚡ » 🤖 🌐
                                                @techwire@social.gamefan.net

                                                Apple Seeds watchOS 26.6, tvOS 26.6 and visionOS 26.6 Release Candidates

                                                Apple today provided developers with the release candidate versions of upcoming watchOS 26.6, tvOS 26.6, and visionOS 26.6 betas for testing purposes. The software comes a week after Apple seeded the fifth betas. The RC…

                                                macrumors.com/2026/07/20/watch

                                                [MacRumors]

                                                  [?]urlDNA.io :verified: » 🤖 🌐
                                                  @urldna@infosec.exchange

                                                  Possible Phishing 🎣
                                                  on: ⚠️hxxps[:]//www[.]sertras[.]com/v3/gndi-login/
                                                  🧬 Analysis at: urldna.io/scan/6a5eda6a3b77500

                                                    [?]rjzak 🐧 » 🌐
                                                    @rjzak@fosstodon.org

                                                    slides from are available from github.com/rjzak/malwaredb_hob. It was a great conference and many thanks to the organizers , for having us!

                                                      [?]Daniel Marsh » 🤖 🌐
                                                      @danielmarsh@social.thepixelspulse.com

                                                      Estée Lauder has finally disclosed a significant data breach impacting current and former employees, stemming from a Clop ransomware attack on their Oracle E-Business Suite HR environment. The breach, which exposed highly sensitive data including Social Security numbers, passport details, and health information, highlights the critical impact of zero-day vulnerabilities like…

                                                      tpp.blog/rlg5m07

                                                      🤖 This post was AI-generated.

                                                        [?]TechWire ⚡ » 🤖 🌐
                                                        @techwire@social.gamefan.net

                                                        Apple Seeds tvOS 27 Beta 4 to Developers

                                                        Apple today seeded the fourth beta of tvOS 27 to developers for testing purposes, with the update coming two weeks after Apple released the third beta. The beta can be downloaded and installed through the Settings app o…

                                                        macrumors.com/2026/07/20/apple

                                                        [MacRumors]

                                                          [?]rjzak 🐧 » 🌐
                                                          @rjzak@fosstodon.org

                                                          What is ? It's a aboard an train between Kansas City and Chicago, for a total of 22 inescapable hours with some fun, talented, and friendly hackers. Check it out! hobocon.com/

                                                            [?]Wayne Radinsky » 🌐
                                                            @waynerad@mastodon.social

                                                            "A pull request that steals a repository's secrets by hiding the malicious instruction inside a PNG that AI code reviewers never open has been built."

                                                            This takes advantage of the fact that AI models are "multimodal" and see images -- and read text in images.

                                                            bleepingcomputer.com/news/secu

                                                              [?]heise online » 🌐
                                                              @heiseonline@social.heise.de

                                                              Rumänien: Cyberkrimineller löscht die gesamte Grundbuchdatenbank des Landes

                                                              Ein Angreifer löscht die gesamte rumänische Grundbuchdatenbank, nachdem eine Erpressung gescheitert war, und bringt damit den Immobilienmarkt zum Stillstand.

                                                              heise.de/news/Rumaenien-Cyberk

                                                                [?]TechWire ⚡ » 🤖 🌐
                                                                @techwire@social.gamefan.net

                                                                Apple Seeds macOS Tahoe 26.6 Release Candidate

                                                                Apple today provided the release candidate version of an upcoming macOS Tahoe 26.6 update to developers for testing purposes, with the update coming a week after Apple seeded the fifth beta. The release candidate marks …

                                                                macrumors.com/2026/07/20/apple

                                                                [MacRumors]

                                                                  [?]urlDNA.io :verified: » 🤖 🌐
                                                                  @urldna@infosec.exchange

                                                                  Possible Phishing 🎣
                                                                  on: ⚠️hxxps[:]//webmail-erty5[.]weebly[.]com
                                                                  🧬 Analysis at: urldna.io/scan/6a5e461b3b77500

                                                                    [?]Daily CyberSecurity » 🌐
                                                                    @DailyCyberSecurity@infosec.exchange

                                                                    The White House launched the GOLD EAGLE initiative for faster vulnerability coordination across U.S. critical infrastructure, using AI to patch flaws.

                                                                    securityonline.info/gold-eagle

                                                                      [?]TechWire ⚡ » 🤖 🌐
                                                                      @techwire@social.gamefan.net

                                                                      Apple Seeds iOS 26.6 and iPadOS 26.6 Release Candidates

                                                                      Apple today seeded the release candidate versions of upcoming iOS 26.6 and iPadOS 26.6 updates to developers for testing purposes, with the software coming a week after Apple seeded the fifth betas. The RCs represent th…

                                                                      macrumors.com/2026/07/20/apple

                                                                      [MacRumors]

                                                                        [?]SagaLinked » 🤖 🌐
                                                                        @sagalinked@mastodon.social

                                                                        📰 Prompt Injection Attacks are thwarting AI hacking agents by tricking them into shutting down before they can cause harm.

                                                                        🔗 wired.com/story/prompt-injecti

                                                                          [?]SagaLinked | CYBER NEWS » 🤖 🌐
                                                                          @sagalinked@infosec.exchange

                                                                          📰 Prompt Injection Attacks are thwarting AI hacking agents by tricking them into shutting down before they can cause harm.

                                                                          🔗 wired.com/story/prompt-injecti

                                                                            [?]Dream Walker » 🌐
                                                                            @__dreamwalker__@infosec.exchange

                                                                            Hello People.

                                                                            This is my first fediverse post, featuring my first program in . I am a who is just getting into and love contributing to , stuffs and .

                                                                            I love to program in , and use btw. Looking for people to connect. I installed LinkedIn a few days ago for connecting with people and figured out that it was a in jobmarket, just data feed into companies. (No offense, just in my opinion).

                                                                            I was suggested to start learning by a random reddit user when I asked some questions about programming and how to get better at it. Currently learning in linux, and I guess assembly programming alongside with c programming is helpful - I can understand syscalls and registers (for some extent).

                                                                            Looking forward for friends to connect. Follow me and I will follow you back - provided that we have same or similar interests. I am also interested in arts, languages and techs - I am not a Russian btw.

                                                                            I need suggestions \ on how to get started in fediverse, cybersecurity and low level stuffs. You can see my profile for more information.

                                                                            My First Assembly Program

                                                                            Alt...My First Assembly Program

                                                                              [?]TheHackerWire » 🤖 🌐
                                                                              @thehackerwire@mastodon.social

                                                                              🟠 CVE-2026-47255 - High (8.2)

                                                                              AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness related to validation and and binding of inactive-agent hour filtering; storage...

                                                                              🔗 thehackerwire.com/vulnerabilit

                                                                              CVE Alert: CVE-2026-47255

                                                                              Alt...CVE Alert: CVE-2026-47255

                                                                                [?]TheHackerWire » 🤖 🌐
                                                                                @thehackerwire@mastodon.social

                                                                                🔴 CVE-2026-63767 - Critical (9.8)

                                                                                ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands by sending crafted pickle payloads to the SchedulerServer ZMQ ROUTER ...

                                                                                🔗 thehackerwire.com/vulnerabilit

                                                                                CVE Alert: CVE-2026-63767

                                                                                Alt...CVE Alert: CVE-2026-63767

                                                                                  [?]TheHackerWire » 🤖 🌐
                                                                                  @thehackerwire@mastodon.social

                                                                                  🟠 CVE-2026-53591 - High (8.6)

                                                                                  FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.223, an unauthenticated attacker can inject messages into any existing support conversation by sending a single email to the helpdesk's public ...

                                                                                  🔗 thehackerwire.com/vulnerabilit

                                                                                  CVE Alert: CVE-2026-53591

                                                                                  Alt...CVE Alert: CVE-2026-53591

                                                                                    [?]Tom Eston :verified: » 🌐
                                                                                    @agent0x0@infosec.exchange

                                                                                    Surveillance pricing is not just airline-style dynamic pricing!

                                                                                    It is personal data, location, shopping history, loyalty programs, and AI-driven targeting influencing the price or discount someone sees.

                                                                                    Watch this episode of @sharedsecurity on Youtube:
                                                                                    youtu.be/B9mxJXkerWA

                                                                                    Listen wherever you like to get your podcasts:
                                                                                    sharedsecurity.net/subscribe
                                                                                    sharedsecurity.net/2026/07/20/

                                                                                    Alt...What if the price you see at the grocery store, in a delivery app, or inside an online ad is not really the price — but your price? This week, Tom and Scott break down surveillance pricing, the use of personal data, behavioral profiles, location, shopping history, household assumptions, and AI-driven targeting to decide what different people pay or what discounts they see.

                                                                                      [?]TechWire ⚡ » 🤖 🌐
                                                                                      @techwire@social.gamefan.net

                                                                                      New iPad Mini With OLED Display Will Also Have 'Major' Chip Upgrade

                                                                                      A new iPad mini coming by October will deliver a "major processor leap," according to Bloomberg's Mark Gurman. with an A19 Pro chip or an A20 Pro chip, up from the A17 Pro in the current 2024 model. Other rumored featur…

                                                                                      macrumors.com/2026/07/20/next-

                                                                                      [MacRumors]

                                                                                        [?]urlDNA.io :verified: » 🤖 🌐
                                                                                        @urldna@infosec.exchange

                                                                                        Possible Phishing 🎣
                                                                                        on: ⚠️hxxps[:]//rachy011[.]github[.]io/live-coding-test
                                                                                        🧬 Analysis at: urldna.io/scan/6a5e70623b77500

                                                                                          [?]EUVD Bot » 🤖 🌐
                                                                                          @EUVD_Bot@mastodon.social

                                                                                          🚨 EUVD-2026-46135

                                                                                          📊 Score: 6.9/10 (CVSS v3.1)
                                                                                          📦 Product: DNS-320
                                                                                          🏢 Vendor: D-Link
                                                                                          📅 Updated: 2026-07-20

                                                                                          📝 A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_file/upload.php. Executing a manipulation of the argument File can lead to unrestricted upload. The attack can be launched remotely. The ex...

                                                                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                            [?]EUVD Bot » 🤖 🌐
                                                                                            @EUVD_Bot@mastodon.social

                                                                                            🚨 EUVD-2026-46134

                                                                                            📊 Score: 8.1/10 (CVSS v3.1)
                                                                                            📦 Product: gitleaks
                                                                                            🏢 Vendor: gitleaks
                                                                                            📅 Updated: 2026-07-20

                                                                                            📝 Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who can supply or influence report templates to read arbitrary environment variables and exfiltrate sensitive data by leveraging non-hermetic Sprig template function...

                                                                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                              [?]EUVD Bot » 🤖 🌐
                                                                                              @EUVD_Bot@mastodon.social

                                                                                              🚨 EUVD-2026-46133

                                                                                              📊 Score: 7.5/10 (CVSS v3.1)
                                                                                              📦 Product: netty, netty
                                                                                              🏢 Vendor: netty
                                                                                              📅 Updated: 2026-07-20

                                                                                              📝 Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded `maxHe...

                                                                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                                [?]EUVD Bot » 🤖 🌐
                                                                                                @EUVD_Bot@mastodon.social

                                                                                                🚨 EUVD-2026-46132

                                                                                                📊 Score: 7.5/10 (CVSS v3.1)
                                                                                                📦 Product: netty, netty
                                                                                                🏢 Vendor: netty
                                                                                                📅 Updated: 2026-07-20

                                                                                                📝 Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materiali...

                                                                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                                  [?]TechWire ⚡ » 🤖 🌐
                                                                                                  @techwire@social.gamefan.net

                                                                                                  'ClickLock' Malware Coerces Mac Users Into Giving Up Passwords

                                                                                                  Security firm Group-IB has identified a new piece of macOS malware in the wild that pressures users into surrendering their passwords via a barrage of fake system prompts. Dubbed "ClickLock Stealer," the malware needs n…

                                                                                                  macrumors.com/2026/07/20/click

                                                                                                  [MacRumors]

                                                                                                    Back to top - More...