voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]EUVD Bot » 🤖 🌐
@EUVD_Bot@mastodon.social

🚨 EUVD-2026-42065

📊 Score: 6.4/10 (CVSS v3.1)
📦 Product: Joomla! CMS, Joomla! CMS
🏢 Vendor: Joomla! Project
📅 Updated: 2026-07-07

📝 An improper access check allows users to display a list of modules in the frontend.

🔗 euvd.enisa.europa.eu/vulnerabi

    [?]EUVD Bot » 🤖 🌐
    @EUVD_Bot@mastodon.social

    🚨 EUVD-2026-42064

    📊 Score: 6.4/10 (CVSS v3.1)
    📦 Product: Joomla! CMS, Joomla! CMS
    🏢 Vendor: Joomla! Project
    📅 Updated: 2026-07-07

    📝 An improper access check allows unauthorized users to access com_privacy datasets.

    🔗 euvd.enisa.europa.eu/vulnerabi

      [?]EUVD Bot » 🤖 🌐
      @EUVD_Bot@mastodon.social

      🚨 EUVD-2026-42063

      📊 Score: 5.9/10 (CVSS v3.1)
      📦 Product: Joomla! CMS, Joomla! CMS
      🏢 Vendor: Joomla! Project
      📅 Updated: 2026-07-07

      📝 Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.

      🔗 euvd.enisa.europa.eu/vulnerabi

        [?]EUVD Bot » 🤖 🌐
        @EUVD_Bot@mastodon.social

        🚨 EUVD-2026-42062

        📊 Score: 5.9/10 (CVSS v3.1)
        📦 Product: Joomla! CMS, Joomla! CMS
        🏢 Vendor: Joomla! Project
        📅 Updated: 2026-07-07

        📝 Lack of escaping leads to an XSS vulnerability in the generic image output layout.

        🔗 euvd.enisa.europa.eu/vulnerabi

          [?]EUVD Bot » 🤖 🌐
          @EUVD_Bot@mastodon.social

          🚨 EUVD-2026-42061

          📊 Score: 6.4/10 (CVSS v3.1)
          📦 Product: Joomla! CMS, Joomla! CMS
          🏢 Vendor: Joomla! Project
          📅 Updated: 2026-07-07

          📝 An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.

          🔗 euvd.enisa.europa.eu/vulnerabi

            [?]EUVD Bot » 🤖 🌐
            @EUVD_Bot@mastodon.social

            🚨 EUVD-2026-42060

            📊 Score: 5.9/10 (CVSS v3.1)
            📦 Product: Joomla! CMS, Joomla! CMS
            🏢 Vendor: Joomla! Project
            📅 Updated: 2026-07-07

            📝 Lack of validation leads to an XSS vulnerability in the MFA management views.

            🔗 euvd.enisa.europa.eu/vulnerabi

              [?]EUVD Bot » 🤖 🌐
              @EUVD_Bot@mastodon.social

              🚨 EUVD-2026-42059

              📊 Score: 5.9/10 (CVSS v3.1)
              📦 Product: Joomla! CMS, Joomla! CMS
              🏢 Vendor: Joomla! Project
              📅 Updated: 2026-07-07

              📝 Improper validation leads to a generic XSS vector in the language override feature.

              🔗 euvd.enisa.europa.eu/vulnerabi

                [?]urlDNA.io :verified: » 🤖 🌐
                @urldna@infosec.exchange

                Possible Phishing 🎣
                on: ⚠️hxxps[:]//gencatsecurityvvc[.]weebly[.]com
                🧬 Analysis at: urldna.io/scan/6a4cc7f43b77500

                  [?]Hugo | DevOps | Cybersecurity » 🌐
                  @hugovalters@mastodon.social

                  Vllm: 48 CVEs, 18 critical/high, max CVSS 10. 81% unpatched. Trust Score: C. Open source AI engine, but security lags. Patch now.

                  valtersit.com/vendors/vllm/

                    [?]TechWire ⚡ » 🤖 🌐
                    @techwire@social.gamefan.net

                    Android Auto just became much more useful for motorcycle riders with this app update

                    Sygic brings its rider-focused Motorbike Mode to Android Auto and CarPlay dashboards.

                    androidauthority.com/android-a

                    [Android Authority]

                      [?]Hugo | DevOps | Cybersecurity » 🌐
                      @hugovalters@mastodon.social

                      [?]TechWire ⚡ » 🤖 🌐
                      @techwire@social.gamefan.net

                      Google Pixel 11 prices leak, complete with major base storage shakeup

                      There could be a €100 price hike across the board, but there could also be a silver lining for base storage buyers.

                      androidauthority.com/google-pi

                      [Android Authority]

                        [?]OTX Bot » 🤖 🌐
                        @techbot@social.raytec.co

                        Bundled to Steal: The Salat Stealer Campaign

                        Salat Stealer is a Go-based information stealer that performs deep system reconnaissance and extracts sensitive data from compromised hosts. It targets browser credentials, cryptocurrency wallets, and communication platforms like Discord and Steam. The malware features advanced surveillance capabilities including desktop streaming, audio/video capture through microphone and webcam, and local file exfiltration. A notable distribution campaign bundled Salat Stealer with Xeno Executor, a gaming utility tool, transforming it into a full compromise vector. The malware employs sophisticated evasion techniques including disabling Windows Defender features through multiple PowerShell scripts, establishing persistence via registry run keys, and using token impersonation of lsass.exe to obtain elevated privileges. Loaders written in batch script and Rust programming language obfuscate deployment and bypass security controls.

                        Pulse ID: 6a4c3a7bc1e7623521754884
                        Pulse Link: otx.alienvault.com/pulse/6a4c3
                        Pulse Author: AlienVault
                        Created: 2026-07-06 23:30:03

                        Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                          [?]OTX Bot » 🤖 🌐
                          @techbot@social.raytec.co

                          Cavern Manticore: Exposing Iran-Linked Modular C2 Framework

                          Check Point Research tracks Cavern Manticore, an Iran-nexus threat actor targeting Israeli government and IT sectors. The actor deploys a modular C2 framework built on .NET but compiled into different formats including Mixed-Mode C++/CLI and Native AOT, creating significant anti-analysis challenges. The framework consists of core agents and specialized post-exploitation modules providing capabilities for file system operations, database browsing, LDAP querying, network reconnaissance, and tunneling. Initial access is achieved through abuse of Remote Monitoring and Management software like SysAid. The actor demonstrates supply-chain compromise tactics, using IT providers as stepping stones to reach higher-value targets. Technical overlaps link Cavern Manticore to Iranian MOIS-aligned groups including MuddyWater and Lyceum subgroup of OilRig.

                          Pulse ID: 6a4bb565cb9499639bf4125b
                          Pulse Link: otx.alienvault.com/pulse/6a4bb
                          Pulse Author: AlienVault
                          Created: 2026-07-06 14:02:13

                          Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                            [?]CTI.FYI » 🤖 🌐
                            @CTI_FYI@infosec.exchange

                            🚨New ransom group blog posts!🚨

                            Group name: akira
                            Post title: Chisholm Persson & Ball
                            Info: cti.fyi/groups/akira.html

                            Group name: qilin
                            Post title: Accelirate
                            Info: cti.fyi/groups/qilin.html

                              [?]TechWire ⚡ » 🤖 🌐
                              @techwire@social.gamefan.net

                              Marshall upgrades the bass and repairability of two wireless speakers

                              The knobs and other parts on the Stanmore IV and Acton IV speakers are replaceable. | Image: Marshall Marshall announced new versions of its Acton and Stanmore Bluetooth speakers today with upgraded tweeters, bass ports…

                              theverge.com/tech/961601/marsh

                              [The Verge]

                                [?]TechWire ⚡ » 🤖 🌐
                                @techwire@social.gamefan.net

                                iFixit has a new toolkit for fixing appliances, building furniture, and household repairs

                                iFixit is best known for its detailed gadget teardowns and toolkits designed to help you crack open and troubleshoot your own electronics. Today it announced a new toolkit that's instead tailored to household repairs or…

                                theverge.com/tech/962055/ifixi

                                [The Verge]

                                  [?]Malicious Extension Bot » 🤖 🌐
                                  @malicious_browser_bot@infosec.exchange

                                  extension Purevpn seems malicious. Its badness score is 92/100!

                                  ```json
                                  {"id": "pcbahcofbcdimkkmnpmciebgddofbhkb", "score": 92, "platform": "chrome", "name": "Purevpn"}
                                  ```

                                    [?]EUVD Bot » 🤖 🌐
                                    @EUVD_Bot@mastodon.social

                                    🚨 EUVD-2026-42041

                                    📊 Score: 7.5/10 (CVSS v3.1)
                                    📦 Product: AMP for WP – Accelerated Mobile Pages
                                    🏢 Vendor: mohammed_kaludi
                                    📅 Updated: 2026-07-07

                                    📝 The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Arbitrary File Write in versions up to and including 1.1.12. This is due to unsafe ZIP file extraction in the ampforwp_save_local_font() fun...

                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                      [?]EUVD Bot » 🤖 🌐
                                      @EUVD_Bot@mastodon.social

                                      🚨 EUVD-2026-42040

                                      📊 Score: 7.2/10 (CVSS v3.1)
                                      📦 Product: PowerProtect Data Domain, PowerProtect Data Domain, PowerProtect Data Domain (+1 more)
                                      🏢 Vendor: Dell
                                      📅 Updated: 2026-07-07

                                      📝 Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versi...

                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                        [?]urlDNA.io :verified: » 🤖 🌐
                                        @urldna@infosec.exchange

                                        Possible Phishing 🎣
                                        on: ⚠️hxxps[:]//julianabreu924-source[.]github[.]io/google-frontend/
                                        🧬 Analysis at: urldna.io/scan/6a4c9dae3b77500

                                          [?]The New Oil » 🤖 🌐
                                          @thenewoil@mastodon.thenewoil.org

                                          [?]Alexandre Dulaunoy » 🌐
                                          @adulau@infosec.exchange

                                          Working on tempolocus, a tool that analyses time-series activity patterns to infer a user’s likely location.

                                          In @ail_project, we work with a large volume of social-network time series. Estimating users’ locations from these patterns is often a manual task.

                                          I prototyped a Python module that combines potential locations with yearly activity signals, such as vacation periods and public holidays. It is still at an early stage, but it is already producing promising results with weekly time series.

                                          Ideas, feedback, and improvements are welcome. tempolocus is planned for integration into AIL Framework 7.1.

                                          :github: github.com/ail-project/tempolo

                                          adulau@blakley:~/git/tempolocus$ python3 -m tempolocus samples/weekfull-chan1.json --format text  -n 10 --holiday-profile public-worker 
input_type: weekly_timeseries
confidence: 0.220
activity_type: mixed-time (0.009)
assumptions:
  - Hourly buckets are interpreted as UTC; timezone candidates are offsets that make the activity look locally human.
  - Weekly data cannot distinguish all IANA zones sharing the same offset, and daylight saving time is not inferable without dates.
probable_countries:
  0.970  Russia (UTC+02:00, UTC+03:00, UTC+04:00, UTC+05:00, UTC+06:00, UTC+07:00, UTC+08:00)
  0.009  France (UTC+01:00, UTC+03:00, UTC+04:00)
  0.008  Kazakhstan (UTC+05:00, UTC+06:00)
  0.003  United Kingdom (UTC+00:00, UTC+06:00)
  0.002  Mongolia (UTC+07:00, UTC+08:00)
results:
  0.208  timezone: UTC+05 Pakistan / western Central Asia
          utc_quiet_window=19:00-01:00; local_quiet_window=00:00-06:00; quiet_activity_ratio=0.366; local_quiet_center=2.5
  0.196  timezone: UTC+04 Gulf / Caucasus
          utc_quiet_window=19:00-01:00; local_quiet_window=23:00-05:00; quiet_activity_ratio=0.366; local_quiet_center=1.5
  0.143  timezone: UTC+06 Bangladesh / central Asia
          utc_quiet_window=19:00-01:00; local_quiet_window=01:00-07:00; quiet_activity_ratio=0.366; local_quiet_center=3.5
  0.129  timezone: UTC+03 East Africa / Arabia / Moscow
          utc_quiet_window=19:00-01:00; local_quiet_window=22:00-04:00; quiet_activity_ratio=0.366; local_quiet_center=0.5
  0.072  timezone: UTC+02 Eastern Europe / southern Africa
          utc_quiet_window=19:00-01:00; local_quiet_window=21:00-03:00; quiet_activity_ratio=0.366; local_quiet_center=23.5
  0.067  timezone: UTC+07 mainland Southeast Asia
          utc_quiet_window=19:00-01:00; local_quiet_window=02:00-08:00; quiet_activity_ratio=0.366; local_quiet_center=4.5
  0.039  timezone: UTC+01 Central Europe / West Africa
          utc_quiet_window=19:00-01:00; local_quiet_window=20:00-02:00; quiet_activity_ratio=0.366; local_quiet_center=22.5
  0.027  timezone: UTC+08 China / Singapore / Western Australia
          utc_quiet_window=19:00-01:00; local_quiet_window=03:00-09:00; quiet_activity_ratio=0.366; local_quiet_center=5.5
  0.023  timezone: UTC+00 Western Europe / West Africa
          utc_quiet_window=19:00-01:00; local_quiet_window=19:00-01:00; quiet_activity_ratio=0.366; local_quiet_center=21.5
  0.015  timezone: UTC-01 Azores / Cape Verde
          utc_quiet_window=19:00-01:00; local_quiet_window=18:00-00:00; quiet_activity_ratio=0.366; local_quiet_center=20.5

                                          Alt...adulau@blakley:~/git/tempolocus$ python3 -m tempolocus samples/weekfull-chan1.json --format text -n 10 --holiday-profile public-worker input_type: weekly_timeseries confidence: 0.220 activity_type: mixed-time (0.009) assumptions: - Hourly buckets are interpreted as UTC; timezone candidates are offsets that make the activity look locally human. - Weekly data cannot distinguish all IANA zones sharing the same offset, and daylight saving time is not inferable without dates. probable_countries: 0.970 Russia (UTC+02:00, UTC+03:00, UTC+04:00, UTC+05:00, UTC+06:00, UTC+07:00, UTC+08:00) 0.009 France (UTC+01:00, UTC+03:00, UTC+04:00) 0.008 Kazakhstan (UTC+05:00, UTC+06:00) 0.003 United Kingdom (UTC+00:00, UTC+06:00) 0.002 Mongolia (UTC+07:00, UTC+08:00) results: 0.208 timezone: UTC+05 Pakistan / western Central Asia utc_quiet_window=19:00-01:00; local_quiet_window=00:00-06:00; quiet_activity_ratio=0.366; local_quiet_center=2.5 0.196 timezone: UTC+04 Gulf / Caucasus utc_quiet_window=19:00-01:00; local_quiet_window=23:00-05:00; quiet_activity_ratio=0.366; local_quiet_center=1.5 0.143 timezone: UTC+06 Bangladesh / central Asia utc_quiet_window=19:00-01:00; local_quiet_window=01:00-07:00; quiet_activity_ratio=0.366; local_quiet_center=3.5 0.129 timezone: UTC+03 East Africa / Arabia / Moscow utc_quiet_window=19:00-01:00; local_quiet_window=22:00-04:00; quiet_activity_ratio=0.366; local_quiet_center=0.5 0.072 timezone: UTC+02 Eastern Europe / southern Africa utc_quiet_window=19:00-01:00; local_quiet_window=21:00-03:00; quiet_activity_ratio=0.366; local_quiet_center=23.5 0.067 timezone: UTC+07 mainland Southeast Asia utc_quiet_window=19:00-01:00; local_quiet_window=02:00-08:00; quiet_activity_ratio=0.366; local_quiet_center=4.5 0.039 timezone: UTC+01 Central Europe / West Africa utc_quiet_window=19:00-01:00; local_quiet_window=20:00-02:00; quiet_activity_ratio=0.366; local_quiet_center=22.5 0.027 timezone: UTC+08 China / Singapore / Western Australia utc_quiet_window=19:00-01:00; local_quiet_window=03:00-09:00; quiet_activity_ratio=0.366; local_quiet_center=5.5 0.023 timezone: UTC+00 Western Europe / West Africa utc_quiet_window=19:00-01:00; local_quiet_window=19:00-01:00; quiet_activity_ratio=0.366; local_quiet_center=21.5 0.015 timezone: UTC-01 Azores / Cape Verde utc_quiet_window=19:00-01:00; local_quiet_window=18:00-00:00; quiet_activity_ratio=0.366; local_quiet_center=20.5

                                            [?]TierraSapiens » 🤖 🌐
                                            @tierrasapiens@mastodon.social

                                            🖲️
                                            ⚫ JadePuffer: The First Complete LLM-Driven Ransomware Attack
                                            🔗 darkreading.com/cyberattacks-d

                                            An "agentic threat actor" successfully exploited a Langflow flaw to steal data from a production database server and encrypt other systems.

                                              [?]TechWire ⚡ » 🤖 🌐
                                              @techwire@social.gamefan.net

                                              Google Search lets creators know more about their reach

                                              Google is going to give content creators and website owners a better idea of how people find their social media profiles and YouTube content through Search. With a new feature in the Google Search Console called "platfo…

                                              theverge.com/tech/961955/googl

                                              [The Verge]

                                                [?]Open Security Conference » 🌐
                                                @OSCo@infosec.exchange

                                                Huge thanks to our silver sponsor from day 1: itRISKman and @jenshoffmann! 🩶 We're immensely grateful for their continued support over the years. They literally keep the Open Security Conference more affordable for everyone interested in cybersecurity.

                                                Discover itRISKman: itriskman.de/

                                                Learn more about all our sponsors: opensecurityconference.org/sup

                                                [lisi]

                                                  [?]BeeSINT » 🌐
                                                  @BeeSINT@mastodon.social

                                                  🎣 Phishing Spotlight

                                                  docusign-verify-auth[.]eportalsecure[.]workers[.]dev

                                                  🔒 SSL: exp. 2026-08-11
                                                  🌐 Stack: cloudflare

                                                  🔗 beesint.com/pulse/6bbc9ee8-6e6

                                                    [?]urlDNA.io :verified: » 🤖 🌐
                                                    @urldna@infosec.exchange

                                                    Possible Phishing 🎣
                                                    on: ⚠️hxxps[:]//webmailverityuions[.]weebly[.]com
                                                    🧬 Analysis at: urldna.io/scan/6a4cc01c3b77500

                                                      [?]CTI.FYI » 🤖 🌐
                                                      @CTI_FYI@infosec.exchange

                                                      🚨New ransom group blog post!🚨

                                                      Group name: bravox
                                                      Post title: PB Fiduciaire SA 🇨🇭
                                                      Info: cti.fyi/groups/bravox.html

                                                        [?]TechWire ⚡ » 🤖 🌐
                                                        @techwire@social.gamefan.net

                                                        After 10 months with the Pixel 10 Pro XL, I’m tired of the nonsense

                                                        The noise is often louder than the problem.

                                                        androidauthority.com/pixel-10-

                                                        [Android Authority]

                                                          [?]TechWire ⚡ » 🤖 🌐
                                                          @techwire@social.gamefan.net

                                                          Nothing Phone 4b launched: Unique design for all, big battery for some

                                                          The Phone 4b still delivers impressive battery health and a decent update policy.

                                                          androidauthority.com/nothing-p

                                                          [Android Authority]

                                                            [?]EUVD Bot » 🤖 🌐
                                                            @EUVD_Bot@mastodon.social

                                                            🚨 EUVD-2026-42032

                                                            📊 Score: 8.4/10 (CVSS v3.1)
                                                            📦 Product: PcVue
                                                            🏢 Vendor: arcinfo
                                                            📅 Updated: 2026-07-07

                                                            📝 The encryption algorithm used to protect the configuration of user accounts, stored in the built-in user directory of PcVue projects, all versions prior to 17.0.0, is not strong enough for the level of protection required. A local attacker could alter the exis...

                                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                                              [?]EUVD Bot » 🤖 🌐
                                                              @EUVD_Bot@mastodon.social

                                                              🚨 EUVD-2026-42031

                                                              📊 Score: 6.8/10 (CVSS v3.1)
                                                              📦 Product: PcVue
                                                              🏢 Vendor: arcinfo
                                                              📅 Updated: 2026-07-07

                                                              📝 Credentials of built-in users are insecurely stored in the User directory of PcVue projects, all versions prior to 17.0.0. A local attacker could retrieve users’ credentials. 

                                                              Active Directory accounts are not affected by this vulnerability.

                                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                                [?]EUVD Bot » 🤖 🌐
                                                                @EUVD_Bot@mastodon.social

                                                                🚨 EUVD-2026-42030

                                                                📊 Score: n/a
                                                                📦 Product: Apache Airflow
                                                                🏢 Vendor: Apache Software Foundation
                                                                📅 Updated: 2026-07-07

                                                                📝 A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG author could embed a malicious trigger into a DAG to gain remote co...

                                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                                  [?]EUVD Bot » 🤖 🌐
                                                                  @EUVD_Bot@mastodon.social

                                                                  🚨 EUVD-2026-42029

                                                                  📊 Score: n/a
                                                                  📦 Product: Apache Airflow
                                                                  🏢 Vendor: Apache Software Foundation
                                                                  📅 Updated: 2026-07-07

                                                                  📝 In Apache Airflow before 3.3.0, the REST API task-instance detail and list
                                                                  endpoints returned a deferred task's trigger kwargs without masking. When a
                                                                  deferred operator passed a secret (for example a provider API key) into its
                                                                  trigger, any authent...

                                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                                    [?]urlDNA.io :verified: » 🤖 🌐
                                                                    @urldna@infosec.exchange

                                                                    Possible Phishing 🎣
                                                                    on: ⚠️hxxps[:]//swiftcargogh[.]com/bouygues-construction[.]com
                                                                    🧬 Analysis at: urldna.io/scan/6a4c17783b77500

                                                                      [?]EUVD Bot » 🤖 🌐
                                                                      @EUVD_Bot@mastodon.social

                                                                      🚨 EUVD-2026-42028

                                                                      📊 Score: n/a
                                                                      📦 Product: Apache Airflow
                                                                      🏢 Vendor: Apache Software Foundation
                                                                      📅 Updated: 2026-07-07

                                                                      📝 The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key names like `*_password` / `*_token` / `*_secret`) could not ...

                                                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                                                        [?]EUVD Bot » 🤖 🌐
                                                                        @EUVD_Bot@mastodon.social

                                                                        🚨 EUVD-2026-42027

                                                                        📊 Score: n/a
                                                                        📦 Product: Apache Airflow
                                                                        🏢 Vendor: Apache Software Foundation
                                                                        📅 Updated: 2026-07-07

                                                                        📝 Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file. `GET /api/v2/dagSources/{dag_id}` — and the equivalent Dag-source view in the UI — returned the entire sourc...

                                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                                          Back to top - More...