voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]TechWire ⚡ » 🤖 🌐
@techwire@social.gamefan.net

Samsung unveils Galaxy Z Fold 8 deal for $1,230 off ahead of July Unpacked - how to qualify

Samsung Unpacked will take place later this month in London, and all eyes are on the Galaxy Glasses.

zdnet.com/article/samsung-unve

[ZDNet]

    [?]urlDNA.io :verified: » 🤖 🌐
    @urldna@infosec.exchange

    Possible Phishing 🎣
    on: ⚠️hxxps[:]//attcomunicationsupport[.]weebly[.]com/
    🧬 Analysis at: urldna.io/scan/6a4d30d23b77500

      [?]TechWire ⚡ » 🤖 🌐
      @techwire@social.gamefan.net

      I spent a week with Sony's $3,500 Bravia TV - the True RGB display is the real deal

      Outfitted with Sony's new Micro RGB panels, the Bravia 9 II is well on its way to usurping its OLED cousin's supremacy.

      zdnet.com/article/sony-bravia-

      [ZDNet]

        [?]TechWire ⚡ » 🤖 🌐
        @techwire@social.gamefan.net

        Intel patent reveals new XBM memory architecture that ditches HBM's costly silicon interposer — backend-transistor DRAM stack uses UCIe links and built-in repair to …

        Intel’s XBM patent proposes an HBM alternative that uses backend-transistor DRAM, UCIe chiplet links, and repair logic to reduce packaging costs and complexity.

        tomshardware.com/tech-industry

        [Tom's Hardware]

          [?]EUVD Bot » 🤖 🌐
          @EUVD_Bot@mastodon.social

          🚨 EUVD-2026-42136

          📊 Score: 5.8/10 (CVSS v3.1)
          📦 Product: coder, coder, coder (+1 more)
          🏢 Vendor: coder
          📅 Updated: 2026-07-08

          📝 Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the workspace app proxy resolves the target app from `httpapi.RequestHost()` which prefers the `X...

          🔗 euvd.enisa.europa.eu/vulnerabi

            [?]urlDNA.io :verified: » 🤖 🌐
            @urldna@infosec.exchange

            Possible Phishing 🎣
            on: ⚠️hxxp[:]//365k13[.]com/register[.]html
            🧬 Analysis at: urldna.io/scan/6a4d00393b77500

              [?]Malicious Extension Bot » 🤖 🌐
              @malicious_browser_bot@infosec.exchange

              extension Adblock for Youtube seems malicious. Its badness score is 94/100!

              ```json
              {"id": "gclhifbbggfamoojmienffegbmmfnfll", "score": 94, "platform": "chrome", "name": "Adblock for Youtube"}
              ```

                [?]Malicious Extension Bot » 🤖 🌐
                @malicious_browser_bot@infosec.exchange

                extension fkkoeecbjckjpnmenebojblcljjgbpoj seems malicious. Its badness score is 97/100!

                ```json
                {"id": "fkkoeecbjckjpnmenebojblcljjgbpoj", "score": 97, "platform": "chrome", "name": "fkkoeecbjckjpnmenebojblcljjgbpoj"}
                ```

                  [?]Malicious Extension Bot » 🤖 🌐
                  @malicious_browser_bot@infosec.exchange

                  extension Summary with ChatGPT seems malicious. Its badness score is 93/100!

                  ```json
                  {"id": "dokiamnhbobapjfhhhcjlfplabeofamp", "score": 93, "platform": "chrome", "name": "Summary with ChatGPT"}
                  ```

                    [?]TechWire ⚡ » 🤖 🌐
                    @techwire@social.gamefan.net

                    Modder builds 8,192-core GPU at home out of RISC-V microcontrollers — full "graphics card" draws over 2,000 watts of power, requires a 3D printer to program

                    Well-known engineer Matthias Balwierz (aka Bitluni) designed and created an 8,192-core RISC-V GPU at home.

                    tomshardware.com/maker-stem/mo

                    [Tom's Hardware]

                      [?]jbz » 🌐
                      @jbz@indieweb.social

                      「 Parrot OS 7.3 is now available for download, with updated installation images for this Debian-based, security-focused Linux distribution designed for penetration testing, digital forensics, reverse engineering, privacy, and development 」
                      linuxiac.com/parrot-os-7-3-is-

                        [?]TierraSapiens » 🤖 🌐
                        @tierrasapiens@mastodon.social


                        🟣 La devastación de los terremotos no es la única emergencia humanitaria en Venezuela
                        🔗 es.wired.com/articulos/la-deva

                        Un informe contempla la situación de los pueblos indígenas debido al avance de la minería ilegal, así como los derechos ambientales de la población, cuya crisis

                          [?]TechWire ⚡ » 🤖 🌐
                          @techwire@social.gamefan.net

                          Of course viewers are giving up on Netflix shows

                          Even though Netflix is the world's most popular paid streaming service, the company has been struggling to keep viewers watching its series after their first seasons. Beef - the streamer's anthology about people locked …

                          theverge.com/entertainment/962

                          [The Verge]

                            [?]TechWire ⚡ » 🤖 🌐
                            @techwire@social.gamefan.net

                            This portable keyboard is the ultimate productivity tool - especially for Mac and PC users

                            The Asus ProArt KD300 keyboard is sleek and compact, with excellent multipoint connectivity.

                            zdnet.com/article/asus-proart-

                            [ZDNet]

                              [?]TechWire ⚡ » 🤖 🌐
                              @techwire@social.gamefan.net

                              How to run Linux GUI apps on Android (when it actually works)

                              Android is oh-so-close to being a full-blown Linux desktop. There's just one problem with the feature.

                              zdnet.com/article/how-to-run-l

                              [ZDNet]

                                [?]EUVD Bot » 🤖 🌐
                                @EUVD_Bot@mastodon.social

                                🚨 EUVD-2026-42118

                                📊 Score: 6.0/10 (CVSS v3.1)
                                📦 Product: graphql-engine, graphql-engine
                                🏢 Vendor: hasura
                                📅 Updated: 2026-07-07

                                📝 Hasura is an open-source product that provides users GraphQL or REST APIs. Prior to 2.49.2 and 2.45.5, a user can use a where clause on a table computed field (returning SETOF some_table) to infer row values that ought to be filtered fo...

                                🔗 euvd.enisa.europa.eu/vulnerabi

                                  [?]urlDNA.io :verified: » 🤖 🌐
                                  @urldna@infosec.exchange

                                  Possible Phishing 🎣
                                  on: ⚠️hxxps[:]//tga[.]dev
                                  🧬 Analysis at: urldna.io/scan/6a4d14773b77500

                                    [?]EUVD Bot » 🤖 🌐
                                    @EUVD_Bot@mastodon.social

                                    🚨 EUVD-2026-42117

                                    📊 Score: 7.1/10 (CVSS v3.1)
                                    📦 Product: FastGPT
                                    🏢 Vendor: labring
                                    📅 Updated: 2026-07-07

                                    📝 FastGPT is a knowledge-based AI application platform. Prior to 4.15.0, GET /api/core/ai/record/getRecord authenticates the caller but loads LLM request and response traces only by requestId without team scoping, allowing any authenticated user to read anothe...

                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                      [?]EUVD Bot » 🤖 🌐
                                      @EUVD_Bot@mastodon.social

                                      🚨 EUVD-2026-42116

                                      📊 Score: 7.7/10 (CVSS v3.1)
                                      📦 Product: FastGPT
                                      🏢 Vendor: labring
                                      📅 Updated: 2026-07-07

                                      📝 FastGPT is a knowledge-based AI application platform. Prior to 4.15.0-beta4, the HTTP-tool OpenAPI schema importer validates only the top-level URL before passing it to SwaggerParser.bundle, whose remote reference resolver fetches $ref URLs without FastGPT's...

                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                        [?]EUVD Bot » 🤖 🌐
                                        @EUVD_Bot@mastodon.social

                                        🚨 EUVD-2026-42115

                                        📊 Score: 8.6/10 (CVSS v3.1)
                                        📦 Product: FastGPT
                                        🏢 Vendor: labring
                                        📅 Updated: 2026-07-07

                                        📝 FastGPT is an open source AI knowledge base platform. Prior to v4.15.0-beta5, two FastGPT file handlers authorize an unrelated resource and then sign or read an S3 object using a key taken directly from the request, without checking that the key belongs to t...

                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                          [?]EUVD Bot » 🤖 🌐
                                          @EUVD_Bot@mastodon.social

                                          🚨 EUVD-2026-42114

                                          📊 Score: 6.3/10 (CVSS v3.1)
                                          📦 Product: FastGPT
                                          🏢 Vendor: labring
                                          📅 Updated: 2026-07-07

                                          📝 FastGPT is an open source AI knowledge base platform. From 4.14.17 to before 4.15.0-beta4, FastGPT allows an authenticated tenant user to call POST /api/core/dataset/collection/create/reTrainingCollection in a way that persists a server-owned datasetId value...

                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                            [?]EUVD Bot » 🤖 🌐
                                            @EUVD_Bot@mastodon.social

                                            🚨 EUVD-2026-42113

                                            📊 Score: 6.5/10 (CVSS v3.1)
                                            📦 Product: Anki
                                            🏢 Vendor: Ankitects
                                            📅 Updated: 2026-07-07

                                            📝 Anki is a program for creating and reviewing flashcards. Prior to 25.09.4, Anki's webview-based pages communicate with the Rust backend using an internal localhost API, and user scripts included via iframes in the editor can access this API despite protection...

                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                              [?]EUVD Bot » 🤖 🌐
                                              @EUVD_Bot@mastodon.social

                                              🚨 EUVD-2026-42112

                                              📊 Score: 2.1/10 (CVSS v3.1)
                                              📦 Product: Anki
                                              🏢 Vendor: Ankitects
                                              📅 Updated: 2026-07-07

                                              📝 Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, Anki launches a local HTTP server to serve media files and web pages for parts of its interface, but requests from other origins were not sufficiently blocked. A malicious website coul...

                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                [?]EUVD Bot » 🤖 🌐
                                                @EUVD_Bot@mastodon.social

                                                🚨 EUVD-2026-42111

                                                📊 Score: 9.1/10 (CVSS v3.1)
                                                📦 Product: coder, coder, coder (+3 more)
                                                🏢 Vendor: coder
                                                📅 Updated: 2026-07-07

                                                📝 Coder allows organizations to provision remote development environments via Terraform. In versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3, `azureidentity.Validate()` verifies that the PKCS#7 signer certificate chain...

                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                  [?]EUVD Bot » 🤖 🌐
                                                  @EUVD_Bot@mastodon.social

                                                  🚨 EUVD-2026-42110

                                                  📊 Score: 6.5/10 (CVSS v3.1)
                                                  📦 Product: OpenWRT
                                                  🏢 Vendor: OpenWRT
                                                  📅 Updated: 2026-07-07

                                                  📝 OpenWrt is a Linux operating system targeting embedded devices. Before v25.12.5, an integer underflow in handle_send_a() of the Emergency Access Daemon allows any unauthenticated attacker on the local network to crash the daemon by sending a single crafted U...

                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                    [?]EUVD Bot » 🤖 🌐
                                                    @EUVD_Bot@mastodon.social

                                                    🚨 EUVD-2026-42109

                                                    📊 Score: 3.1/10 (CVSS v3.1)
                                                    📦 Product: Grafana OSS, Grafana Enterprise, Grafana OSS (+7 more)
                                                    🏢 Vendor: Grafana
                                                    📅 Updated: 2026-07-07

                                                    📝 The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target...

                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                      [?]EUVD Bot » 🤖 🌐
                                                      @EUVD_Bot@mastodon.social

                                                      🚨 EUVD-2026-42108

                                                      📊 Score: 6.5/10 (CVSS v3.1)
                                                      📦 Product: coder, coder, coder (+3 more)
                                                      🏢 Vendor: coder
                                                      📅 Updated: 2026-07-07

                                                      📝 Coder allows organizations to provision remote development environments via Terraform. Versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3 are vulnerable to unauthenticated semi-blind Server-Side Request Forgery (SSRF) ...

                                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                                        [?]EUVD Bot » 🤖 🌐
                                                        @EUVD_Bot@mastodon.social

                                                        🚨 EUVD-2026-42107

                                                        📊 Score: 8.4/10 (CVSS v3.1)
                                                        📦 Product: koodo-reader
                                                        🏢 Vendor: koodo-reader
                                                        📅 Updated: 2026-07-07

                                                        📝 Koodo Reader is an ebook reader. In version 2.3.0 and earlier, Koodo Reader is vulnerable to remote code execution through malicious EPUB files because the open-book IPC handler enables nodeIntegrationInSubFrames and EPUB chapter content is rendere...

                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                          [?]EUVD Bot » 🤖 🌐
                                                          @EUVD_Bot@mastodon.social

                                                          🚨 EUVD-2026-42106

                                                          📊 Score: 9.2/10 (CVSS v3.1)
                                                          📦 Product: mem0
                                                          🏢 Vendor: mem0
                                                          📅 Updated: 2026-07-07

                                                          📝 mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request forgery via attacker-controlled ollama_base_url parameter. Unauthenticated attackers can retrieve stored secrets like OpenAI API keys via GET /ap...

                                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                                            [?]Malicious Extension Bot » 🤖 🌐
                                                            @malicious_browser_bot@infosec.exchange

                                                            extension ZLibrary Searcher seems malicious. Its badness score is 98/100!

                                                            ```json
                                                            {"id": "ffedaeoanbhgmanhhecfjodpopcjnhkc", "score": 98, "platform": "chrome", "name": "ZLibrary Searcher"}
                                                            ```

                                                              [?]Malicious Extension Bot » 🤖 🌐
                                                              @malicious_browser_bot@infosec.exchange

                                                              extension Natural Reader Text to Speech seems malicious. Its badness score is 86/100!

                                                              ```json
                                                              {"id": "eopjamlpanhfkcbnoeofcnmdfdiogfgl", "score": 86, "platform": "chrome", "name": "Natural Reader Text to Speech"}
                                                              ```

                                                                [?]Malicious Extension Bot » 🤖 🌐
                                                                @malicious_browser_bot@infosec.exchange

                                                                extension Live Start Page - Living Wallpapers seems malicious. Its badness score is 85/100!

                                                                ```json
                                                                {"id": "egbkgelnkodaldbpkgjmhcekjakkcpnk", "score": 85, "platform": "chrome", "name": "Live Start Page - Living Wallpapers"}
                                                                ```

                                                                  [?]Malicious Extension Bot » 🤖 🌐
                                                                  @malicious_browser_bot@infosec.exchange

                                                                  extension Simple mass downloader seems malicious. Its badness score is 89/100!

                                                                  ```json
                                                                  {"id": "dbhdfkiddhdhmcikjdgblfjbenjfjlfh", "score": 89, "platform": "chrome", "name": "Simple mass downloader"}
                                                                  ```

                                                                    [?]deafnews » 🤖 🌐
                                                                    @deafnews@infosec.exchange

                                                                    Accenture Confirms Data Breach: 35 GB of Data Up for Sale by Threat Actor '888' deafnews.it/en/article/accentu

                                                                      [?]TechWire ⚡ » 🤖 🌐
                                                                      @techwire@social.gamefan.net

                                                                      Samsung confirms Unpacked event for later this month — mark your calendars!

                                                                      We've got two weeks to go before we officially meet Samsung's latest mobile hardware.

                                                                      androidauthority.com/samsung-g

                                                                      [Android Authority]

                                                                        [?]TierraSapiens » 🤖 🌐
                                                                        @tierrasapiens@mastodon.social

                                                                        🖲️
                                                                        ⚫ 'GitLost' Flaw Leaks Private Data From GitHub's Agentic Workflows
                                                                        🔗 darkreading.com/cyber-risk/git

                                                                        The flaw allows an unauthenticated attacker to craft a GitHub Issue in an org's public repository and then silently pull data from its private repos, too.

                                                                          [?]TechWire ⚡ » 🤖 🌐
                                                                          @techwire@social.gamefan.net

                                                                          Google announces Pixel 11 launch event in August

                                                                          Google is hosting its next Made by Google launch event for Pixel hardware on August 12th in New York City, according to an invitation sent by Google to The Verge. Unusually, the event is taking place in the evening: It'…

                                                                          theverge.com/tech/962313/made-

                                                                          [The Verge]

                                                                            [?]/G|T|R|O|N|I|X\ :python: :emacs: :nix: :linux: » 🌐
                                                                            @gtronix@infosec.exchange

                                                                            "Help EFF Cut the AI Hype"

                                                                            "It's just the opposite for EFF. In the global race to build and dominate the AI industry, it can sure seem like the interests of ordinary people sit last on the agenda."

                                                                            eff.org/deeplinks/2026/07/help

                                                                              [?]The New Oil » 🤖 🌐
                                                                              @thenewoil@mastodon.thenewoil.org

                                                                              [?]TechWire ⚡ » 🤖 🌐
                                                                              @techwire@social.gamefan.net

                                                                              Google throws Voice a lifeline with addition of two new personal paid tiers

                                                                              Voice quietly added two new personal paid plans — and nobody noticed.

                                                                              androidauthority.com/google-vo

                                                                              [Android Authority]

                                                                                [?]EUVD Bot » 🤖 🌐
                                                                                @EUVD_Bot@mastodon.social

                                                                                🚨 EUVD-2026-42072

                                                                                📊 Score: n/a
                                                                                📦 Product: HTTP::Tiny
                                                                                🏢 Vendor: HAARG
                                                                                📅 Updated: 2026-07-07

                                                                                📝 HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.

                                                                                When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into th...

                                                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                  [?]EUVD Bot » 🤖 🌐
                                                                                  @EUVD_Bot@mastodon.social

                                                                                  🚨 EUVD-2026-42071

                                                                                  📊 Score: 5.4/10 (CVSS v3.1)
                                                                                  📦 Product: coder, coder, coder
                                                                                  🏢 Vendor: coder
                                                                                  📅 Updated: 2026-07-07

                                                                                  📝 Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, AI Bridge proxy endpoints authenticate via `Server.IsAuthorized` in `coderd/aibridge...

                                                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                    [?]EUVD Bot » 🤖 🌐
                                                                                    @EUVD_Bot@mastodon.social

                                                                                    🚨 EUVD-2026-42070

                                                                                    📊 Score: 5.9/10 (CVSS v3.1)
                                                                                    📦 Product: Joomla! CMS, Joomla! CMS
                                                                                    🏢 Vendor: Joomla! Project
                                                                                    📅 Updated: 2026-07-07

                                                                                    📝 Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.

                                                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                      [?]EUVD Bot » 🤖 🌐
                                                                                      @EUVD_Bot@mastodon.social

                                                                                      🚨 EUVD-2026-42069

                                                                                      📊 Score: 6.4/10 (CVSS v3.1)
                                                                                      📦 Product: Joomla! CMS, Joomla! CMS
                                                                                      🏢 Vendor: Joomla! Project
                                                                                      📅 Updated: 2026-07-07

                                                                                      📝 An improper access check allows privileged users to overwrite media files without editing permissions.

                                                                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                        [?]EUVD Bot » 🤖 🌐
                                                                                        @EUVD_Bot@mastodon.social

                                                                                        🚨 EUVD-2026-42068

                                                                                        📊 Score: 6.4/10 (CVSS v3.1)
                                                                                        📦 Product: Joomla! CMS, Joomla! CMS
                                                                                        🏢 Vendor: Joomla! Project
                                                                                        📅 Updated: 2026-07-07

                                                                                        📝 An improper access check allows unauthorized users to create custom fields via webservices endpoints.

                                                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                          [?]EUVD Bot » 🤖 🌐
                                                                                          @EUVD_Bot@mastodon.social

                                                                                          🚨 EUVD-2026-42067

                                                                                          📊 Score: 5.9/10 (CVSS v3.1)
                                                                                          📦 Product: Joomla! CMS, Joomla! CMS
                                                                                          🏢 Vendor: Joomla! Project
                                                                                          📅 Updated: 2026-07-07

                                                                                          📝 Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.

                                                                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                            [?]EUVD Bot » 🤖 🌐
                                                                                            @EUVD_Bot@mastodon.social

                                                                                            🚨 EUVD-2026-42066

                                                                                            📊 Score: 6.4/10 (CVSS v3.1)
                                                                                            📦 Product: Joomla! CMS
                                                                                            🏢 Vendor: Joomla! Project
                                                                                            📅 Updated: 2026-07-07

                                                                                            📝 An improper access check allows unauthorized users to access workflow stage and transition information.

                                                                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                              Back to top - More...