voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
🚨 EUVD-2026-42065
📊 Score: 6.4/10 (CVSS v3.1)
📦 Product: Joomla! CMS, Joomla! CMS
🏢 Vendor: Joomla! Project
📅 Updated: 2026-07-07
📝 An improper access check allows users to display a list of modules in the frontend.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42065
🚨 EUVD-2026-42064
📊 Score: 6.4/10 (CVSS v3.1)
📦 Product: Joomla! CMS, Joomla! CMS
🏢 Vendor: Joomla! Project
📅 Updated: 2026-07-07
📝 An improper access check allows unauthorized users to access com_privacy datasets.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42064
🚨 EUVD-2026-42063
📊 Score: 5.9/10 (CVSS v3.1)
📦 Product: Joomla! CMS, Joomla! CMS
🏢 Vendor: Joomla! Project
📅 Updated: 2026-07-07
📝 Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42063
🚨 EUVD-2026-42062
📊 Score: 5.9/10 (CVSS v3.1)
📦 Product: Joomla! CMS, Joomla! CMS
🏢 Vendor: Joomla! Project
📅 Updated: 2026-07-07
📝 Lack of escaping leads to an XSS vulnerability in the generic image output layout.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42062
🚨 EUVD-2026-42061
📊 Score: 6.4/10 (CVSS v3.1)
📦 Product: Joomla! CMS, Joomla! CMS
🏢 Vendor: Joomla! Project
📅 Updated: 2026-07-07
📝 An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42061
🚨 EUVD-2026-42060
📊 Score: 5.9/10 (CVSS v3.1)
📦 Product: Joomla! CMS, Joomla! CMS
🏢 Vendor: Joomla! Project
📅 Updated: 2026-07-07
📝 Lack of validation leads to an XSS vulnerability in the MFA management views.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42060
🚨 EUVD-2026-42059
📊 Score: 5.9/10 (CVSS v3.1)
📦 Product: Joomla! CMS, Joomla! CMS
🏢 Vendor: Joomla! Project
📅 Updated: 2026-07-07
📝 Improper validation leads to a generic XSS vector in the language override feature.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42059
Possible Phishing 🎣
on: ⚠️hxxps[:]//gencatsecurityvvc[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a4cc7f43b775000091e2aea
#cybersecurity #phishing #infosec #urldna #scam #infosec
Vllm: 48 CVEs, 18 critical/high, max CVSS 10. 81% unpatched. Trust Score: C. Open source AI engine, but security lags. Patch now. #Vllm #infosec #cybersecurity
Android Auto just became much more useful for motorcycle riders with this app update
Sygic brings its rider-focused Motorbike Mode to Android Auto and CarPlay dashboards.
https://www.androidauthority.com/android-auto-sygic-motorbike-mode-rollout-3684971/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
RE: https://mastodon.social/@0daybeats/116878113311694696
Great album form #music lovers #devops #devsecops #developers #sysadmin #linux users #cybersecurity #infosec #git #github #gitlab experts and also my favorite #python lovers
Google Pixel 11 prices leak, complete with major base storage shakeup
There could be a €100 price hike across the board, but there could also be a silver lining for base storage buyers.
https://www.androidauthority.com/google-pixel-11-storage-colors-price-leak-3684868/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Bundled to Steal: The Salat Stealer Campaign
Salat Stealer is a Go-based information stealer that performs deep system reconnaissance and extracts sensitive data from compromised hosts. It targets browser credentials, cryptocurrency wallets, and communication platforms like Discord and Steam. The malware features advanced surveillance capabilities including desktop streaming, audio/video capture through microphone and webcam, and local file exfiltration. A notable distribution campaign bundled Salat Stealer with Xeno Executor, a gaming utility tool, transforming it into a full compromise vector. The malware employs sophisticated evasion techniques including disabling Windows Defender features through multiple PowerShell scripts, establishing persistence via registry run keys, and using token impersonation of lsass.exe to obtain elevated privileges. Loaders written in batch script and Rust programming language obfuscate deployment and bypass security controls.
Pulse ID: 6a4c3a7bc1e7623521754884
Pulse Link: https://otx.alienvault.com/pulse/6a4c3a7bc1e7623521754884
Pulse Author: AlienVault
Created: 2026-07-06 23:30:03
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #Discord #InfoSec #Malware #OTX #OpenThreatExchange #PowerShell #RAT #Rust #Steam #Windows #bot #cryptocurrency #AlienVault
Cavern Manticore: Exposing Iran-Linked Modular C2 Framework
Check Point Research tracks Cavern Manticore, an Iran-nexus threat actor targeting Israeli government and IT sectors. The actor deploys a modular C2 framework built on .NET but compiled into different formats including Mixed-Mode C++/CLI and Native AOT, creating significant anti-analysis challenges. The framework consists of core agents and specialized post-exploitation modules providing capabilities for file system operations, database browsing, LDAP querying, network reconnaissance, and tunneling. Initial access is achieved through abuse of Remote Monitoring and Management software like SysAid. The actor demonstrates supply-chain compromise tactics, using IT providers as stepping stones to reach higher-value targets. Technical overlaps link Cavern Manticore to Iranian MOIS-aligned groups including MuddyWater and Lyceum subgroup of OilRig.
Pulse ID: 6a4bb565cb9499639bf4125b
Pulse Link: https://otx.alienvault.com/pulse/6a4bb565cb9499639bf4125b
Pulse Author: AlienVault
Created: 2026-07-06 14:02:13
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CheckPoint #CyberSecurity #Government #ICS #InfoSec #Iran #Israel #MuddyWater #NET #OTX #OilRig #OpenThreatExchange #RAT #SysAid #bot #AlienVault
🚨New ransom group blog posts!🚨
Group name: akira
Post title: Chisholm Persson & Ball
Info: https://cti.fyi/groups/akira.html
Group name: qilin
Post title: Accelirate
Info: https://cti.fyi/groups/qilin.html
#ransomware #cti #threatintelligence #cybersecurity #infosec
Marshall upgrades the bass and repairability of two wireless speakers
The knobs and other parts on the Stanmore IV and Acton IV speakers are replaceable. | Image: Marshall Marshall announced new versions of its Acton and Stanmore Bluetooth speakers today with upgraded tweeters, bass ports…
https://www.theverge.com/tech/961601/marshall-acton-stanmore-iv-bluetooth-wireless-speakers-repair
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
iFixit has a new toolkit for fixing appliances, building furniture, and household repairs
iFixit is best known for its detailed gadget teardowns and toolkits designed to help you crack open and troubleshoot your own electronics. Today it announced a new toolkit that's instead tailored to household repairs or…
https://www.theverge.com/tech/962055/ifixit-megalodon-tool-kit-household-appliance-repairs
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
#chrome extension Purevpn seems malicious. Its #cybersecurity badness score is 92/100!
```json
{"id": "pcbahcofbcdimkkmnpmciebgddofbhkb", "score": 92, "platform": "chrome", "name": "Purevpn"}
```
🚨 EUVD-2026-42041
📊 Score: 7.5/10 (CVSS v3.1)
📦 Product: AMP for WP – Accelerated Mobile Pages
🏢 Vendor: mohammed_kaludi
📅 Updated: 2026-07-07
📝 The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Arbitrary File Write in versions up to and including 1.1.12. This is due to unsafe ZIP file extraction in the ampforwp_save_local_font() fun...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42041
🚨 EUVD-2026-42040
📊 Score: 7.2/10 (CVSS v3.1)
📦 Product: PowerProtect Data Domain, PowerProtect Data Domain, PowerProtect Data Domain (+1 more)
🏢 Vendor: Dell
📅 Updated: 2026-07-07
📝 Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versi...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42040
Possible Phishing 🎣
on: ⚠️hxxps[:]//julianabreu924-source[.]github[.]io/google-frontend/
🧬 Analysis at: https://urldna.io/scan/6a4c9dae3b775000045eed1b
#cybersecurity #phishing #infosec #urldna #scam #infosec
#Windows11 identifier code used to track #ScatteredSpider perp after #Microsoft shared info with FBI
Working on tempolocus, a tool that analyses time-series activity patterns to infer a user’s likely location.
In @ail_project, we work with a large volume of social-network time series. Estimating users’ locations from these patterns is often a manual task.
I prototyped a Python module that combines potential locations with yearly activity signals, such as vacation periods and public holidays. It is still at an early stage, but it is already producing promising results with weekly time series.
Ideas, feedback, and improvements are welcome. tempolocus is planned for integration into AIL Framework 7.1.
🖲️ #Cybersecurity #Ciberseguridad #Ciberseguranca #Security #Seguridad #Seguranca #News #Noticia #Noticias #Tecnologia #Technology
⚫ JadePuffer: The First Complete LLM-Driven Ransomware Attack
🔗 https://www.darkreading.com/cyberattacks-data-breaches/jadepuffer-first-complete-llm-driven-ransomware-attack
An "agentic threat actor" successfully exploited a Langflow flaw to steal data from a production database server and encrypt other systems.
Google Search lets creators know more about their reach
Google is going to give content creators and website owners a better idea of how people find their social media profiles and YouTube content through Search. With a new feature in the Google Search Console called "platfo…
https://www.theverge.com/tech/961955/google-search-console-reach-platform-properties
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Huge thanks to our silver sponsor from day 1: itRISKman and @jenshoffmann! 🩶 We're immensely grateful for their continued support over the years. They literally keep the Open Security Conference more affordable for everyone interested in cybersecurity.
Discover itRISKman: https://www.itriskman.de/
Learn more about all our sponsors: https://opensecurityconference.org/support/sponsors/
#osco #osco26 #Security #CyberSecurity #InfoSec #AppSec #OTSecurity #OpenSpace [lisi]
🎣 Phishing Spotlight
docusign-verify-auth[.]eportalsecure[.]workers[.]dev
🔒 SSL: exp. 2026-08-11
🌐 Stack: cloudflare
🔗 https://beesint.com/pulse/6bbc9ee8-6e66-4591-9bb3-df90ea2fd250
Possible Phishing 🎣
on: ⚠️hxxps[:]//webmailverityuions[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a4cc01c3b775000045ef13d
#cybersecurity #phishing #infosec #urldna #scam #infosec
🚨New ransom group blog post!🚨
Group name: bravox
Post title: PB Fiduciaire SA 🇨🇭
Info: https://cti.fyi/groups/bravox.html
#ransomware #cti #threatintelligence #cybersecurity #infosec
After 10 months with the Pixel 10 Pro XL, I’m tired of the nonsense
The noise is often louder than the problem.
https://www.androidauthority.com/pixel-10-pro-xl-10-months-later-3683456/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Nothing Phone 4b launched: Unique design for all, big battery for some
The Phone 4b still delivers impressive battery health and a decent update policy.
https://www.androidauthority.com/nothing-phone-4b-3684722/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
🚨 EUVD-2026-42032
📊 Score: 8.4/10 (CVSS v3.1)
📦 Product: PcVue
🏢 Vendor: arcinfo
📅 Updated: 2026-07-07
📝 The encryption algorithm used to protect the configuration of user accounts, stored in the built-in user directory of PcVue projects, all versions prior to 17.0.0, is not strong enough for the level of protection required. A local attacker could alter the exis...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42032
🚨 EUVD-2026-42031
📊 Score: 6.8/10 (CVSS v3.1)
📦 Product: PcVue
🏢 Vendor: arcinfo
📅 Updated: 2026-07-07
📝 Credentials of built-in users are insecurely stored in the User directory of PcVue projects, all versions prior to 17.0.0. A local attacker could retrieve users’ credentials.
Active Directory accounts are not affected by this vulnerability.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42031
🚨 EUVD-2026-42030
📊 Score: n/a
📦 Product: Apache Airflow
🏢 Vendor: Apache Software Foundation
📅 Updated: 2026-07-07
📝 A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG author could embed a malicious trigger into a DAG to gain remote co...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42030
🚨 EUVD-2026-42029
📊 Score: n/a
📦 Product: Apache Airflow
🏢 Vendor: Apache Software Foundation
📅 Updated: 2026-07-07
📝 In Apache Airflow before 3.3.0, the REST API task-instance detail and list
endpoints returned a deferred task's trigger kwargs without masking. When a
deferred operator passed a secret (for example a provider API key) into its
trigger, any authent...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42029
Possible Phishing 🎣
on: ⚠️hxxps[:]//swiftcargogh[.]com/bouygues-construction[.]com
🧬 Analysis at: https://urldna.io/scan/6a4c17783b775000072f4bae
#cybersecurity #phishing #infosec #urldna #scam #infosec
🚨 EUVD-2026-42028
📊 Score: n/a
📦 Product: Apache Airflow
🏢 Vendor: Apache Software Foundation
📅 Updated: 2026-07-07
📝 The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key names like `*_password` / `*_token` / `*_secret`) could not ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42028
🚨 EUVD-2026-42027
📊 Score: n/a
📦 Product: Apache Airflow
🏢 Vendor: Apache Software Foundation
📅 Updated: 2026-07-07
📝 Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file. `GET /api/v2/dagSources/{dag_id}` — and the equivalent Dag-source view in the UI — returned the entire sourc...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42027