voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]TheHackerWire » 🤖 🌐
@thehackerwire@mastodon.social

🟠 CVE-2026-6896 - High (8.7)

GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to exec...

🔗 thehackerwire.com/vulnerabilit

CVE Alert: CVE-2026-6896

Alt...CVE Alert: CVE-2026-6896

    [?]TheHackerWire » 🤖 🌐
    @thehackerwire@mastodon.social

    🟠 CVE-2026-58525 - High (8.2)

    Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

    🔗 thehackerwire.com/vulnerabilit

    CVE Alert: CVE-2026-58525

    Alt...CVE Alert: CVE-2026-58525

      [?]TheHackerWire » 🤖 🌐
      @thehackerwire@mastodon.social

      🟠 CVE-2026-60105 - High (8.6)

      Monsta FTP before 2.14.5 contains a server-side request forgery vulnerability in the fetchRemoteFile action caused by an incomplete IP blocklist check in the isBlockedIP() function, which fails to detect embedded IPv4 addresses within IPv4-mapped ...

      🔗 thehackerwire.com/vulnerabilit

      CVE Alert: CVE-2026-60105

      Alt...CVE Alert: CVE-2026-60105

        [?]TechWire ⚡ » 🤖 🌐
        @techwire@social.gamefan.net

        I tried DuckDuckGo's new video player, and it blocks YouTube ads for free

        Even as Chrome is killing ad blockers, DuckDuckGo's new video player now blocks ads by default on YouTube and elsewhere. Duck Player is available for MacOS, Windows, Android, and iOS.

        zdnet.com/article/duckduckgos-

        [ZDNet]

          [?]TechWire ⚡ » 🤖 🌐
          @techwire@social.gamefan.net

          Meta is reportedly working on smart glasses that would be recording all the time

          Meta might be the next company to make an always-on AI wearable. The company is working on prototype "super sensing" always-aware smart glasses that could continuously record audio and snap photos "every few seconds," a…

          theverge.com/tech/963138/meta-

          [The Verge]

            [?]TechWire ⚡ » 🤖 🌐
            @techwire@social.gamefan.net

            IBM and Red Hat launch Lightwell to defend open-source code from AI attacks

            Their plan to protect open-source projects from AI-discovered security holes has led to the launch of two commercial offerings: Lightwell Network and Lightwell Clearinghouse Premier.

            zdnet.com/article/ibm-and-red-

            [ZDNet]

              [?]EUVD Bot » 🤖 🌐
              @EUVD_Bot@mastodon.social

              🚨 EUVD-2026-42447

              📊 Score: 6.5/10 (CVSS v3.1)
              📦 Product: CoreWCF, CoreWCF
              🏢 Vendor: CoreWCF
              📅 Updated: 2026-07-08

              📝 CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF NetNamedPipe transport accepts attachment to a pre-existing named pipe instance, allowing local interception of NetNamedP...

              🔗 euvd.enisa.europa.eu/vulnerabi

                [?]EUVD Bot » 🤖 🌐
                @EUVD_Bot@mastodon.social

                🚨 EUVD-2026-42446

                📊 Score: 2.5/10 (CVSS v3.1)
                📦 Product: Wireshark, Wireshark
                🏢 Vendor: Wireshark Foundation
                📅 Updated: 2026-07-08

                📝 BLF file parser in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows possible information disclosure

                🔗 euvd.enisa.europa.eu/vulnerabi

                  [?]EUVD Bot » 🤖 🌐
                  @EUVD_Bot@mastodon.social

                  🚨 EUVD-2026-42445

                  📊 Score: 5.9/10 (CVSS v3.1)
                  📦 Product: Poly Edge E, Poly Trio C60, Poly CCX
                  🏢 Vendor: HP Inc.
                  📅 Updated: 2026-07-08

                  📝 The IP phone might use malicious input stored in configuration parameters and render it as content for the WebUI’s webpage.

                  🔗 euvd.enisa.europa.eu/vulnerabi

                    [?]EUVD Bot » 🤖 🌐
                    @EUVD_Bot@mastodon.social

                    🚨 EUVD-2026-42442

                    📊 Score: 6.0/10 (CVSS v3.1)
                    📦 Product: Poly Edge E, Poly Trio C60, Poly CCX
                    🏢 Vendor: HP Inc.
                    📅 Updated: 2026-07-08

                    📝 Malicious use of a stolen cookie might allow modifications to the contents of the IP phone’s webpage.

                    🔗 euvd.enisa.europa.eu/vulnerabi

                      [?]EUVD Bot » 🤖 🌐
                      @EUVD_Bot@mastodon.social

                      🚨 EUVD-2026-42444

                      📊 Score: 6.1/10 (CVSS v3.1)
                      📦 Product: ux, ux
                      🏢 Vendor: symfony
                      📅 Updated: 2026-07-08

                      📝 Symfony UX is a JavaScript ecosystem for Symfony. From 2.17.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux_icon() Twig function is marked is_safe=['html'] and Icon::toHtml() inlines SVG source verbatim, allowing unsanitized local SVG files or Iconify on-...

                      🔗 euvd.enisa.europa.eu/vulnerabi

                        [?]EUVD Bot » 🤖 🌐
                        @EUVD_Bot@mastodon.social

                        🚨 EUVD-2026-42443

                        📊 Score: 7.8/10 (CVSS v3.1)
                        📦 Product: ux, ux
                        🏢 Vendor: symfony
                        📅 Updated: 2026-07-08

                        📝 Symfony UX is a JavaScript ecosystem for Symfony. From 2.32.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux:install console command installs files from a recipe kit by copying paths listed in a copy-files map, and because Path::isRelative() accepts paths ...

                        🔗 euvd.enisa.europa.eu/vulnerabi

                          [?]EUVD Bot » 🤖 🌐
                          @EUVD_Bot@mastodon.social

                          🚨 EUVD-2026-42441

                          📊 Score: 8.7/10 (CVSS v3.1)
                          📦 Product: org.hl7.fhir.core
                          🏢 Vendor: hapifhir
                          📅 Updated: 2026-07-08

                          📝 HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10, org.hl7.fhir.utilities.XsltUtilities saxonTransform(...) overloads instantiated a bare net.sf.saxon.TransformerFactoryImpl() ...

                          🔗 euvd.enisa.europa.eu/vulnerabi

                            [?]EUVD Bot » 🤖 🌐
                            @EUVD_Bot@mastodon.social

                            🚨 EUVD-2026-42440

                            📊 Score: 7.5/10 (CVSS v3.1)
                            📦 Product: org.hl7.fhir.core
                            🏢 Vendor: hapifhir
                            📅 Updated: 2026-07-08

                            📝 HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10, the fix for CVE-2026-45367 incompletely patched the DSTU2 module, leaving FHIRPathEngine.matches() in org.hl7.fhir.dstu2/util...

                            🔗 euvd.enisa.europa.eu/vulnerabi

                              [?]urlDNA.io :verified: » 🤖 🌐
                              @urldna@infosec.exchange

                              Possible Phishing 🎣
                              on: ⚠️hxxp[:]//amnaakhtar1213[.]github[.]io/amazon-page-clone
                              🧬 Analysis at: urldna.io/scan/6a4e7bcb3b77500

                                [?]EUVD Bot » 🤖 🌐
                                @EUVD_Bot@mastodon.social

                                🚨 EUVD-2026-42439

                                📊 Score: 7.2/10 (CVSS v3.1)
                                📦 Product: Fluentd
                                🏢 Vendor: fluent
                                📅 Updated: 2026-07-08

                                📝 Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, the Fluentd out_http output plugin allows placeholders such as ${tag} in the endpoint configuration parameter, and if a pl...

                                🔗 euvd.enisa.europa.eu/vulnerabi

                                  [?]EUVD Bot » 🤖 🌐
                                  @EUVD_Bot@mastodon.social

                                  🚨 EUVD-2026-42438

                                  📊 Score: 7.5/10 (CVSS v3.1)
                                  📦 Product: Fluentd
                                  🏢 Vendor: fluent
                                  📅 Updated: 2026-07-08

                                  📝 Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd's in_http and in_forward plugins support gzip-compressed data but enforce limits only on compressed payloads throu...

                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                    [?]EUVD Bot » 🤖 🌐
                                    @EUVD_Bot@mastodon.social

                                    🚨 EUVD-2026-42437

                                    📊 Score: 7.5/10 (CVSS v3.1)
                                    📦 Product: Fluentd
                                    🏢 Vendor: fluent
                                    📅 Updated: 2026-07-08

                                    📝 Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd's Monitor Agent plugin in_monitor_agent exposes internal metrics and plugin information via a REST API, and respon...

                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                      [?]EUVD Bot » 🤖 🌐
                                      @EUVD_Bot@mastodon.social

                                      🚨 EUVD-2026-42436

                                      📊 Score: 9.8/10 (CVSS v3.1)
                                      📦 Product: Fluentd
                                      🏢 Vendor: fluent
                                      📅 Updated: 2026-07-08

                                      📝 Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd allows dynamically constructing file paths using the ${tag} placeholder, and insufficient validation of ${tag} in ...

                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                        [?]EUVD Bot » 🤖 🌐
                                        @EUVD_Bot@mastodon.social

                                        🚨 EUVD-2026-42435

                                        📊 Score: 8.8/10 (CVSS v3.1)
                                        📦 Product: Ubuntu, Ubuntu, Ubuntu (+1 more)
                                        🏢 Vendor: Canonical
                                        📅 Updated: 2026-07-08

                                        📝 A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files marked as executable when the mailcap package is installed. A compromised or malicio...

                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                          [?]EUVD Bot » 🤖 🌐
                                          @EUVD_Bot@mastodon.social

                                          🚨 EUVD-2026-42434

                                          📊 Score: 8.3/10 (CVSS v3.1)
                                          📦 Product: RestrictedPython
                                          🏢 Vendor: zopefoundation
                                          📅 Updated: 2026-07-08

                                          📝 RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide a program input into a trusted environment. Prior to 8.3, check_function_argument_names() rejected protected guard hook names for regular,...

                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                            [?]EUVD Bot » 🤖 🌐
                                            @EUVD_Bot@mastodon.social

                                            🚨 EUVD-2026-42433

                                            📊 Score: 4.9/10 (CVSS v3.1)
                                            📦 Product: snipe-it
                                            🏢 Vendor: grokability
                                            📅 Updated: 2026-07-08

                                            📝 Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, the GET /api/v1/{object}/selectlist API endpoint is missing an authorization check. Any user who can log into Snipe-IT - regardless of permissions - can retrieve a paginated list...

                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                              [?]deafnews » 🤖 🌐
                                              @deafnews@infosec.exchange

                                              [?]TechWire ⚡ » 🤖 🌐
                                              @techwire@social.gamefan.net

                                              Best Buy is selling the LG C5 OLED for nearly 50% off right now - and I highly recommend it

                                              It may be a generation behind, but the LG C5 OLED TV still offers plenty of reasons to pick one up, especially at this price.

                                              zdnet.com/article/lg-c5-65-inc

                                              [ZDNet]

                                                [?]The New Oil » 🤖 🌐
                                                @thenewoil@mastodon.thenewoil.org

                                                [?]TechWire ⚡ » 🤖 🌐
                                                @techwire@social.gamefan.net

                                                Twelve South’s AirFly Pro is a great travel companion, and it’s on sale for $40

                                                Twelve South’s AirFly Pro is just $5 more than the SE model. | Image: Twelve South If you’ve got a summer trip coming up, the last-gen Twelve South AirFly Pro is one of those gadgets that can make a long flight feel a l…

                                                theverge.com/gadgets/962910/tw

                                                [The Verge]

                                                  [?]urlDNA.io :verified: » 🤖 🌐
                                                  @urldna@infosec.exchange

                                                  Possible Phishing 🎣
                                                  on: ⚠️hxxps[:]//3115dh38[.]com/
                                                  🧬 Analysis at: urldna.io/scan/6a4e6dbd3b77500

                                                    [?]The New Oil » 🤖 🌐
                                                    @thenewoil@mastodon.thenewoil.org

                                                    [?]TechWire ⚡ » 🤖 🌐
                                                    @techwire@social.gamefan.net

                                                    Duolingo’s big course upgrade is making some learners feel lost

                                                    This wasn’t the Duolingo upgrade I had in mind.

                                                    androidauthority.com/duolingo-

                                                    [Android Authority]

                                                      [?]Black Cat White Hat Security » 🌐
                                                      @BCWHQuiz@defcon.social

                                                      NIST SP 800-171 is a cybersecurity framework developed by the National Institute of Standards and Technology (NIST) that defines the security requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems and organizations.



                                                      Link: blackcatwhitehatsecurity.com

                                                      NIST SP 800-171 is a cybersecurity framework developed by the National Institute of Standards and Technology (NIST) that defines the security requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems and organizations.

                                                      Alt...NIST SP 800-171 is a cybersecurity framework developed by the National Institute of Standards and Technology (NIST) that defines the security requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems and organizations.

                                                        [?]TechWire ⚡ » 🤖 🌐
                                                        @techwire@social.gamefan.net

                                                        If Microsoft sold off Xbox, who would even buy it?

                                                        This week, Microsoft took a huge ax to its Xbox business. The company announced that it would be laying off 1,600 workers now, 1,600 more over the next fiscal year, and that it would be shedding four studios. Xbox CEO A…

                                                        theverge.com/games/962837/micr

                                                        [The Verge]

                                                          [?]EUVD Bot » 🤖 🌐
                                                          @EUVD_Bot@mastodon.social

                                                          🚨 EUVD-2026-42344

                                                          📊 Score: 6.9/10 (CVSS v3.1)
                                                          📦 Product: pypdf
                                                          🏢 Vendor: py-pdf
                                                          📅 Updated: 2026-07-08

                                                          📝 pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with repeated malformed cross-reference streams that cause pypdf to spend long runtimes recovering broken cross-reference table entries. This issue is fixed in...

                                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                                            [?]EUVD Bot » 🤖 🌐
                                                            @EUVD_Bot@mastodon.social

                                                            🚨 EUVD-2026-42343

                                                            📊 Score: 6.9/10 (CVSS v3.1)
                                                            📦 Product: pypdf
                                                            🏢 Vendor: py-pdf
                                                            📅 Updated: 2026-07-08

                                                            📝 pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with declared image size values that are much too large compared to the actual data, causing large memory usage in pypdf image parsing. This issue is fixed in ...

                                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                                              [?]EUVD Bot » 🤖 🌐
                                                              @EUVD_Bot@mastodon.social

                                                              🚨 EUVD-2026-42342

                                                              📊 Score: 4.9/10 (CVSS v3.1)
                                                              📦 Product: Shared library
                                                              🏢 Vendor: Hashicorp
                                                              📅 Updated: 2026-07-08

                                                              📝 HashiCorp memberlist before version 0.6.0 is vulnerable to a denial-of-service issue in its push/pull state handling that may allow an attacker with network access to the gossip port to exhaust memory on a receiving node and cause the process to ter...

                                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                                [?]urlDNA.io :verified: » 🤖 🌐
                                                                @urldna@infosec.exchange

                                                                Possible Phishing 🎣
                                                                on: ⚠️hxxps[:]//kilhail[.]weebly[.]com
                                                                🧬 Analysis at: urldna.io/scan/6a4e580b3b77500

                                                                  [?]OTX Bot » 🤖 🌐
                                                                  @techbot@social.raytec.co

                                                                  Aerospace Phishing Campaign Leveraging AnyDesk and Blat SMTP for Data Exfiltration

                                                                  Pulse ID: 6a4e9983359b19f10b66d843
                                                                  Pulse Link: otx.alienvault.com/pulse/6a4e9
                                                                  Pulse Author: cryptocti
                                                                  Created: 2026-07-08 18:40:03

                                                                  Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                                                    [?]Hugo | DevOps | Cybersecurity » 🌐
                                                                    @hugovalters@mastodon.social

                                                                    Moodle: 61 CVEs, 1 high severity, avg CVSS 6.43. 91% unpatched. Trust Score: C. Top weakness: Missing Authorization (CWE-862). Open-source LMS, but patching lags. Secure your e-learning platform now.

                                                                    valtersit.com/vendors/moodle/

                                                                      [?]deafnews » 🤖 🌐
                                                                      @deafnews@infosec.exchange

                                                                      [?]Hackread.com » 🌐
                                                                      @Hackread@mstdn.social

                                                                      has added built-in YouTube ad blocking to its browser, no extensions required.

                                                                      Listen/Read: hackread.com/duckduckgo-blocks

                                                                        [?]TechWire ⚡ » 🤖 🌐
                                                                        @techwire@social.gamefan.net

                                                                        Google Play Store will look a little different the next time you open it

                                                                        Google is given these two tabs a redesign.

                                                                        androidauthority.com/google-pl

                                                                        [Android Authority]

                                                                          [?]BrianKrebs » 🌐
                                                                          @briankrebs@infosec.exchange

                                                                          New, by me: Felons, Fraudsters Flog Offensive Cybersecurity Startup

                                                                          A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names.

                                                                          krebsonsecurity.com/2026/07/fe

                                                                          A screenshot of two Twitter/X posts from the IRIS C2 account. One features a still shot from a video of a Dallas Cowboy cheerleader standing on a green field waving pom-poms and looking to the left. The caption reads: POV: You stopped screwing around with vendor bug bounties and make a lucrative living selling to Western exploit brokers instead. The post below that says, "Mom, how did we get so rich?" The reply: "Your father stopped d*cking around with bug bounty programs and sold his exploits to western governments."

                                                                          Alt...A screenshot of two Twitter/X posts from the IRIS C2 account. One features a still shot from a video of a Dallas Cowboy cheerleader standing on a green field waving pom-poms and looking to the left. The caption reads: POV: You stopped screwing around with vendor bug bounties and make a lucrative living selling to Western exploit brokers instead. The post below that says, "Mom, how did we get so rich?" The reply: "Your father stopped d*cking around with bug bounty programs and sold his exploits to western governments."

                                                                          A photo of Burkman (left) and Wohl) outside his Arlington, Va. in a 2020 press conference where they made up sexual assault allegations against public figures. Burkman is and standing at a podium in a blue suit. Wohl, also in a blue suit and tie, stands to the right of Burkman, looking down.

                                                                          Alt...A photo of Burkman (left) and Wohl) outside his Arlington, Va. in a 2020 press conference where they made up sexual assault allegations against public figures. Burkman is and standing at a podium in a blue suit. Wohl, also in a blue suit and tie, stands to the right of Burkman, looking down.

                                                                            [?]TechWire ⚡ » 🤖 🌐
                                                                            @techwire@social.gamefan.net

                                                                            Gaming laptops are too expensive right now, but this one’s a good value

                                                                            It’s not a great time to shop for a gaming laptop. The unprecedented rise in cost for RAM (and storage to a slightly lesser extent) has made laptops with low-to-midrange specs cost much more than they should. Recent dea…

                                                                            theverge.com/gadgets/962754/ms

                                                                            [The Verge]

                                                                              [?]Alexandre Dulaunoy » 🌐
                                                                              @adulau@infosec.exchange

                                                                              We are exploring some ambitious ideas around reducing external dependencies and relying more on our own libraries across MISP and related tooling. Over the past year, we have been working on a replacement network graph library for the new MISP interface and things are getting really interesting. Pivotick is already used in around ten open-source tools, including CTI Transmute, AIL Project, and Rulezet. It has also recently been integrated into the new MISP UI, OverMind. The library is, of course, open source and comes with extensive documentation, including AI-parseable documentation to make integration easier. We have just released Pivotick v1.2.0.

                                                                              pivotick.github.io/Pivotick/

                                                                              github.com/Pivotick/Pivotick

                                                                              pivotick screenshot

                                                                              Alt...pivotick screenshot

                                                                                Back to top - More...