voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]The New Oil » 🤖 🌐
@thenewoil@mastodon.thenewoil.org

[?]TechWire ⚡ » 🤖 🌐
@techwire@social.gamefan.net

Duolingo’s big course upgrade is making some learners feel lost

This wasn’t the Duolingo upgrade I had in mind.

androidauthority.com/duolingo-

[Android Authority]

    [?]Black Cat White Hat Security » 🌐
    @BCWHQuiz@defcon.social

    NIST SP 800-171 is a cybersecurity framework developed by the National Institute of Standards and Technology (NIST) that defines the security requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems and organizations.



    Link: blackcatwhitehatsecurity.com

    NIST SP 800-171 is a cybersecurity framework developed by the National Institute of Standards and Technology (NIST) that defines the security requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems and organizations.

    Alt...NIST SP 800-171 is a cybersecurity framework developed by the National Institute of Standards and Technology (NIST) that defines the security requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems and organizations.

      [?]TechWire ⚡ » 🤖 🌐
      @techwire@social.gamefan.net

      If Microsoft sold off Xbox, who would even buy it?

      This week, Microsoft took a huge ax to its Xbox business. The company announced that it would be laying off 1,600 workers now, 1,600 more over the next fiscal year, and that it would be shedding four studios. Xbox CEO A…

      theverge.com/games/962837/micr

      [The Verge]

        [?]EUVD Bot » 🤖 🌐
        @EUVD_Bot@mastodon.social

        🚨 EUVD-2026-42344

        📊 Score: 6.9/10 (CVSS v3.1)
        📦 Product: pypdf
        🏢 Vendor: py-pdf
        📅 Updated: 2026-07-08

        📝 pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with repeated malformed cross-reference streams that cause pypdf to spend long runtimes recovering broken cross-reference table entries. This issue is fixed in...

        🔗 euvd.enisa.europa.eu/vulnerabi

          [?]EUVD Bot » 🤖 🌐
          @EUVD_Bot@mastodon.social

          🚨 EUVD-2026-42343

          📊 Score: 6.9/10 (CVSS v3.1)
          📦 Product: pypdf
          🏢 Vendor: py-pdf
          📅 Updated: 2026-07-08

          📝 pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with declared image size values that are much too large compared to the actual data, causing large memory usage in pypdf image parsing. This issue is fixed in ...

          🔗 euvd.enisa.europa.eu/vulnerabi

            [?]EUVD Bot » 🤖 🌐
            @EUVD_Bot@mastodon.social

            🚨 EUVD-2026-42342

            📊 Score: 4.9/10 (CVSS v3.1)
            📦 Product: Shared library
            🏢 Vendor: Hashicorp
            📅 Updated: 2026-07-08

            📝 HashiCorp memberlist before version 0.6.0 is vulnerable to a denial-of-service issue in its push/pull state handling that may allow an attacker with network access to the gossip port to exhaust memory on a receiving node and cause the process to ter...

            🔗 euvd.enisa.europa.eu/vulnerabi

              [?]urlDNA.io :verified: » 🤖 🌐
              @urldna@infosec.exchange

              Possible Phishing 🎣
              on: ⚠️hxxps[:]//kilhail[.]weebly[.]com
              🧬 Analysis at: urldna.io/scan/6a4e580b3b77500

                [?]OTX Bot » 🤖 🌐
                @techbot@social.raytec.co

                Aerospace Phishing Campaign Leveraging AnyDesk and Blat SMTP for Data Exfiltration

                Pulse ID: 6a4e9983359b19f10b66d843
                Pulse Link: otx.alienvault.com/pulse/6a4e9
                Pulse Author: cryptocti
                Created: 2026-07-08 18:40:03

                Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                  [?]Hugo | DevOps | Cybersecurity » 🌐
                  @hugovalters@mastodon.social

                  Moodle: 61 CVEs, 1 high severity, avg CVSS 6.43. 91% unpatched. Trust Score: C. Top weakness: Missing Authorization (CWE-862). Open-source LMS, but patching lags. Secure your e-learning platform now.

                  valtersit.com/vendors/moodle/

                    [?]deafnews » 🤖 🌐
                    @deafnews@infosec.exchange

                    [?]Hackread.com » 🌐
                    @Hackread@mstdn.social

                    has added built-in YouTube ad blocking to its browser, no extensions required.

                    Listen/Read: hackread.com/duckduckgo-blocks

                      [?]TechWire ⚡ » 🤖 🌐
                      @techwire@social.gamefan.net

                      Google Play Store will look a little different the next time you open it

                      Google is given these two tabs a redesign.

                      androidauthority.com/google-pl

                      [Android Authority]

                        [?]BrianKrebs » 🌐
                        @briankrebs@infosec.exchange

                        New, by me: Felons, Fraudsters Flog Offensive Cybersecurity Startup

                        A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names.

                        krebsonsecurity.com/2026/07/fe

                        A screenshot of two Twitter/X posts from the IRIS C2 account. One features a still shot from a video of a Dallas Cowboy cheerleader standing on a green field waving pom-poms and looking to the left. The caption reads: POV: You stopped screwing around with vendor bug bounties and make a lucrative living selling to Western exploit brokers instead. The post below that says, "Mom, how did we get so rich?" The reply: "Your father stopped d*cking around with bug bounty programs and sold his exploits to western governments."

                        Alt...A screenshot of two Twitter/X posts from the IRIS C2 account. One features a still shot from a video of a Dallas Cowboy cheerleader standing on a green field waving pom-poms and looking to the left. The caption reads: POV: You stopped screwing around with vendor bug bounties and make a lucrative living selling to Western exploit brokers instead. The post below that says, "Mom, how did we get so rich?" The reply: "Your father stopped d*cking around with bug bounty programs and sold his exploits to western governments."

                        A photo of Burkman (left) and Wohl) outside his Arlington, Va. in a 2020 press conference where they made up sexual assault allegations against public figures. Burkman is and standing at a podium in a blue suit. Wohl, also in a blue suit and tie, stands to the right of Burkman, looking down.

                        Alt...A photo of Burkman (left) and Wohl) outside his Arlington, Va. in a 2020 press conference where they made up sexual assault allegations against public figures. Burkman is and standing at a podium in a blue suit. Wohl, also in a blue suit and tie, stands to the right of Burkman, looking down.

                          [?]TechWire ⚡ » 🤖 🌐
                          @techwire@social.gamefan.net

                          Gaming laptops are too expensive right now, but this one’s a good value

                          It’s not a great time to shop for a gaming laptop. The unprecedented rise in cost for RAM (and storage to a slightly lesser extent) has made laptops with low-to-midrange specs cost much more than they should. Recent dea…

                          theverge.com/gadgets/962754/ms

                          [The Verge]

                            [?]Alexandre Dulaunoy » 🌐
                            @adulau@infosec.exchange

                            We are exploring some ambitious ideas around reducing external dependencies and relying more on our own libraries across MISP and related tooling. Over the past year, we have been working on a replacement network graph library for the new MISP interface and things are getting really interesting. Pivotick is already used in around ten open-source tools, including CTI Transmute, AIL Project, and Rulezet. It has also recently been integrated into the new MISP UI, OverMind. The library is, of course, open source and comes with extensive documentation, including AI-parseable documentation to make integration easier. We have just released Pivotick v1.2.0.

                            pivotick.github.io/Pivotick/

                            github.com/Pivotick/Pivotick

                            pivotick screenshot

                            Alt...pivotick screenshot

                              [?]Negative PID SL » 🌐
                              @negativepid@mastodon.social

                              [?]The New Oil » 🤖 🌐
                              @thenewoil@mastodon.thenewoil.org

                              [?]EUVD Bot » 🤖 🌐
                              @EUVD_Bot@mastodon.social

                              🚨 EUVD-2026-42245

                              📊 Score: 7.5/10 (CVSS v3.1)
                              📦 Product: Tanium Server, Tanium Server, Tanium Server
                              🏢 Vendor: Tanium
                              📅 Updated: 2026-07-08

                              📝 Tanium addressed a denial of service vulnerability in Tanium Server.

                              🔗 euvd.enisa.europa.eu/vulnerabi

                                [?]EUVD Bot » 🤖 🌐
                                @EUVD_Bot@mastodon.social

                                🚨 EUVD-2026-42244

                                📊 Score: 2.7/10 (CVSS v3.1)
                                📦 Product: PowerProtect Data Domain, PowerProtect Data Domain, PowerProtect Data Domain (+1 more)
                                🏢 Vendor: Dell
                                📅 Updated: 2026-07-08

                                📝 Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versi...

                                🔗 euvd.enisa.europa.eu/vulnerabi

                                  [?]EUVD Bot » 🤖 🌐
                                  @EUVD_Bot@mastodon.social

                                  🚨 EUVD-2026-42233

                                  📊 Score: 9.2/10 (CVSS v3.1)
                                  📦 Product: Blocksy Companion, Blocksy Companion
                                  🏢 Vendor: Creative Themes
                                  📅 Updated: 2026-07-08

                                  📝 Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validation in the save_attac...

                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                    [?]EUVD Bot » 🤖 🌐
                                    @EUVD_Bot@mastodon.social

                                    🚨 EUVD-2026-42243

                                    📊 Score: 7.5/10 (CVSS v3.1)
                                    📦 Product: PowerProtect Data Domain, PowerProtect Data Domain, PowerProtect Data Domain (+1 more)
                                    🏢 Vendor: Dell
                                    📅 Updated: 2026-07-08

                                    📝 Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versi...

                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                      [?]EUVD Bot » 🤖 🌐
                                      @EUVD_Bot@mastodon.social

                                      🚨 EUVD-2026-42242

                                      📊 Score: 7.8/10 (CVSS v3.1)
                                      📦 Product: Omnissa Workspace ONE® Tunnel for Windows
                                      🏢 Vendor: Omnissa
                                      📅 Updated: 2026-07-08

                                      📝 Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability.

                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                        [?]EUVD Bot » 🤖 🌐
                                        @EUVD_Bot@mastodon.social

                                        🚨 EUVD-2026-42241

                                        📊 Score: 5.3/10 (CVSS v3.1)
                                        📦 Product: MISP
                                        🏢 Vendor: MISP
                                        📅 Updated: 2026-07-08

                                        📝 MISP’s importModule() path used getEnabledModule() to resolve a single import module by name, but this lookup did not enforce the per-organisation module restriction checked by getEnabledModules(). As a result, an authenticated user from an organisation that was n...

                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                          [?]EUVD Bot » 🤖 🌐
                                          @EUVD_Bot@mastodon.social

                                          🚨 EUVD-2026-42240

                                          📊 Score: 8.8/10 (CVSS v3.1)
                                          📦 Product: PowerProtect Data Domain, PowerProtect Data Domain, PowerProtect Data Domain (+1 more)
                                          🏢 Vendor: Dell
                                          📅 Updated: 2026-07-08

                                          📝 Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versi...

                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                            [?]EUVD Bot » 🤖 🌐
                                            @EUVD_Bot@mastodon.social

                                            🚨 EUVD-2026-42239

                                            📊 Score: 5.3/10 (CVSS v3.1)
                                            📦 Product: MISP
                                            🏢 Vendor: MISP
                                            📅 Updated: 2026-07-08

                                            📝 An authorization bypass in MISP’s EventsController::importModule() allowed authenticated users or read-only API keys with event view access to persist data to events they were not allowed to modify. When an import module returned results in the misp_standard forma...

                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                              [?]EUVD Bot » 🤖 🌐
                                              @EUVD_Bot@mastodon.social

                                              🚨 EUVD-2026-42238

                                              📊 Score: 5.3/10 (CVSS v3.1)
                                              📦 Product: Flask-MonitoringDashboard, Flask-MonitoringDashboard, Flask-MonitoringDashboard
                                              🏢 Vendor: flask-dashboard
                                              📅 Updated: 2026-07-08

                                              📝 A vulnerability has been found in flask-dashboard Flask-MonitoringDashboard up to 5.0.2. Affected by this issue is some unknown functionality. Such manipulation leads to cross-si...

                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                [?]EUVD Bot » 🤖 🌐
                                                @EUVD_Bot@mastodon.social

                                                🚨 EUVD-2026-42237

                                                📊 Score: 7.5/10 (CVSS v3.1)
                                                📦 Product: dgraph
                                                🏢 Vendor: dgraph-io
                                                📅 Updated: 2026-07-08

                                                📝 Dgraph is an open source distributed GraphQL database. Prior to version 25.3.4, the `checkUserPassword` GraphQL query in Dgraph is vulnerable to DQL (Dgraph Query Language) injection. User-supplied password values are interpolated directly into a DQL `check...

                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                  [?]EUVD Bot » 🤖 🌐
                                                  @EUVD_Bot@mastodon.social

                                                  🚨 EUVD-2026-42235

                                                  📊 Score: 9.1/10 (CVSS v3.1)
                                                  📦 Product: dgraph
                                                  🏢 Vendor: dgraph-io
                                                  📅 Updated: 2026-07-08

                                                  📝 Dgraph is an open source distributed GraphQL database. Prior to version 25.3.5, Dgraph Alpha exposes the RPCs used for external snapshot import on the public gRPC port `:9080` without authentication or authorization. As a result, an unauthenticated network ...

                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                    [?]EUVD Bot » 🤖 🌐
                                                    @EUVD_Bot@mastodon.social

                                                    🚨 EUVD-2026-42236

                                                    📊 Score: 7.1/10 (CVSS v3.1)
                                                    📦 Product: PowerProtect Data Domain, PowerProtect Data Domain, PowerProtect Data Domain (+1 more)
                                                    🏢 Vendor: Dell
                                                    📅 Updated: 2026-07-08

                                                    📝 Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versi...

                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                      [?]EUVD Bot » 🤖 🌐
                                                      @EUVD_Bot@mastodon.social

                                                      🚨 EUVD-2026-42234

                                                      📊 Score: 5.3/10 (CVSS v3.1)
                                                      📦 Product: check-peer-dependencies, check-peer-dependencies, check-peer-dependencies (+2 more)
                                                      🏢 Vendor: christopherthielen
                                                      📅 Updated: 2026-07-08

                                                      📝 A flaw has been found in christopherthielen check-peer-dependencies up to 4.3.4. Affected by this vulnerability is the function shelljs.exec of the file dist/packageUtils....

                                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                                        [?]BeyondMachines :verified: » 🤖 🌐
                                                        @beyondmachines1@infosec.exchange

                                                        Accenture Confirms Security Breach After Hacker Claims 35 GB of Data Was Stolen

                                                        Accenture confirmed a data breach in July 2026 after a threat actor named "888" claimed to have stolen 35 GB of internal source code and other technical data from the company. The company stated the incident was isolated and remediated, with no impact on its global operations or service delivery.

                                                        ****

                                                        beyondmachines.net/event_detai

                                                          [?]TierraSapiens » 🤖 🌐
                                                          @tierrasapiens@mastodon.social

                                                          🖲️
                                                          ⚫ State IDs for AI Agents: Will Estonia Set a Precedent?
                                                          🔗 darkreading.com/cybersecurity-

                                                          The world's digital testing ground plans to help people use AI agents for government purposes.

                                                            [?]deafnews » 🤖 🌐
                                                            @deafnews@infosec.exchange

                                                            [?]TechWire ⚡ » 🤖 🌐
                                                            @techwire@social.gamefan.net

                                                            Gemini could make avatars even better by letting you share them with friends

                                                            Would you trust your friends to place your likeness in their AI video creations?

                                                            androidauthority.com/gemini-av

                                                            [Android Authority]

                                                              [?]Hackread.com » 🌐
                                                              @Hackread@mstdn.social

                                                              🚨 A newly identified APT dubbed is targeting government agencies and energy organizations with Stealer, a Python-based infostealer delivered through AI-generated loaders and spear-phishing campaigns.

                                                              The malware steals credentials, Telegram sessions, cryptocurrency wallets, and more, while built-in reverse SSH tunneling gives attackers long-term remote access.

                                                              Listen/Read: hackread.com/armored-likho-gov

                                                                [?]CyberNetsecIO » 🌐
                                                                @netsecio@mastodon.social

                                                                📰 New 'Bad Epoll' Linux Kernel Zero-Day (CVE-2026-46242) Grants Full Root Access

                                                                🚨 CRITICAL ZERO-DAY: 'Bad Epoll' (CVE-2026-46242) in Linux Kernel allows any local user to gain full root access. The use-after-free bug affects servers, desktops & Android. PoC exists. Patch immediately! 🐧💥

                                                                🌐 cyber[.]netsecops[.]io

                                                                🔗 cyber.netsecops.io/articles/ba

                                                                  [?]Hacker News » 🤖 🌐
                                                                  @h4ckernews@mastodon.social

                                                                  [?]BeeSINT » 🌐
                                                                  @BeeSINT@mastodon.social

                                                                  🎣 Phishing Spotlight

                                                                  rwqsssd[.]s3[.]ap-northeast-3[.]amazonaws[.]com

                                                                  🔒 SSL: exp. 2026-10-30
                                                                  🌐 Stack: AmazonS3

                                                                  🔗 beesint.com/pulse/64bf2f0e-fb7

                                                                    [?]Malicious Extension Bot » 🤖 🌐
                                                                    @malicious_browser_bot@infosec.exchange

                                                                    extension Bookmark Atlas seems malicious. Its badness score is 98/100!

                                                                    ```json
                                                                    {"id": "fdeijohdonbnikplckachfblcpbpkacp", "score": 98, "platform": "chrome", "name": "Bookmark Atlas"}
                                                                    ```

                                                                      Back to top - More...