voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]Open Security Conference » 🌐
@OSCo@infosec.exchange

Huge thanks to our silver sponsor from day 1: itRISKman and @jenshoffmann! 🩶 We're immensely grateful for their continued support over the years. They literally keep the Open Security Conference more affordable for everyone interested in cybersecurity.

Discover itRISKman: itriskman.de/

Learn more about all our sponsors: opensecurityconference.org/sup

[lisi]

    [?]BeeSINT » 🌐
    @BeeSINT@mastodon.social

    🎣 Phishing Spotlight

    docusign-verify-auth[.]eportalsecure[.]workers[.]dev

    🔒 SSL: exp. 2026-08-11
    🌐 Stack: cloudflare

    🔗 beesint.com/pulse/6bbc9ee8-6e6

      [?]urlDNA.io :verified: » 🤖 🌐
      @urldna@infosec.exchange

      Possible Phishing 🎣
      on: ⚠️hxxps[:]//webmailverityuions[.]weebly[.]com
      🧬 Analysis at: urldna.io/scan/6a4cc01c3b77500

        [?]CTI.FYI » 🤖 🌐
        @CTI_FYI@infosec.exchange

        🚨New ransom group blog post!🚨

        Group name: bravox
        Post title: PB Fiduciaire SA 🇨🇭
        Info: cti.fyi/groups/bravox.html

          [?]TechWire ⚡ » 🤖 🌐
          @techwire@social.gamefan.net

          After 10 months with the Pixel 10 Pro XL, I’m tired of the nonsense

          The noise is often louder than the problem.

          androidauthority.com/pixel-10-

          [Android Authority]

            [?]TechWire ⚡ » 🤖 🌐
            @techwire@social.gamefan.net

            Nothing Phone 4b launched: Unique design for all, big battery for some

            The Phone 4b still delivers impressive battery health and a decent update policy.

            androidauthority.com/nothing-p

            [Android Authority]

              [?]EUVD Bot » 🤖 🌐
              @EUVD_Bot@mastodon.social

              🚨 EUVD-2026-42032

              📊 Score: 8.4/10 (CVSS v3.1)
              📦 Product: PcVue
              🏢 Vendor: arcinfo
              📅 Updated: 2026-07-07

              📝 The encryption algorithm used to protect the configuration of user accounts, stored in the built-in user directory of PcVue projects, all versions prior to 17.0.0, is not strong enough for the level of protection required. A local attacker could alter the exis...

              🔗 euvd.enisa.europa.eu/vulnerabi

                [?]EUVD Bot » 🤖 🌐
                @EUVD_Bot@mastodon.social

                🚨 EUVD-2026-42031

                📊 Score: 6.8/10 (CVSS v3.1)
                📦 Product: PcVue
                🏢 Vendor: arcinfo
                📅 Updated: 2026-07-07

                📝 Credentials of built-in users are insecurely stored in the User directory of PcVue projects, all versions prior to 17.0.0. A local attacker could retrieve users’ credentials. 

                Active Directory accounts are not affected by this vulnerability.

                🔗 euvd.enisa.europa.eu/vulnerabi

                  [?]EUVD Bot » 🤖 🌐
                  @EUVD_Bot@mastodon.social

                  🚨 EUVD-2026-42030

                  📊 Score: n/a
                  📦 Product: Apache Airflow
                  🏢 Vendor: Apache Software Foundation
                  📅 Updated: 2026-07-07

                  📝 A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG author could embed a malicious trigger into a DAG to gain remote co...

                  🔗 euvd.enisa.europa.eu/vulnerabi

                    [?]EUVD Bot » 🤖 🌐
                    @EUVD_Bot@mastodon.social

                    🚨 EUVD-2026-42029

                    📊 Score: n/a
                    📦 Product: Apache Airflow
                    🏢 Vendor: Apache Software Foundation
                    📅 Updated: 2026-07-07

                    📝 In Apache Airflow before 3.3.0, the REST API task-instance detail and list
                    endpoints returned a deferred task's trigger kwargs without masking. When a
                    deferred operator passed a secret (for example a provider API key) into its
                    trigger, any authent...

                    🔗 euvd.enisa.europa.eu/vulnerabi

                      [?]urlDNA.io :verified: » 🤖 🌐
                      @urldna@infosec.exchange

                      Possible Phishing 🎣
                      on: ⚠️hxxps[:]//swiftcargogh[.]com/bouygues-construction[.]com
                      🧬 Analysis at: urldna.io/scan/6a4c17783b77500

                        [?]EUVD Bot » 🤖 🌐
                        @EUVD_Bot@mastodon.social

                        🚨 EUVD-2026-42028

                        📊 Score: n/a
                        📦 Product: Apache Airflow
                        🏢 Vendor: Apache Software Foundation
                        📅 Updated: 2026-07-07

                        📝 The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key names like `*_password` / `*_token` / `*_secret`) could not ...

                        🔗 euvd.enisa.europa.eu/vulnerabi

                          [?]EUVD Bot » 🤖 🌐
                          @EUVD_Bot@mastodon.social

                          🚨 EUVD-2026-42027

                          📊 Score: n/a
                          📦 Product: Apache Airflow
                          🏢 Vendor: Apache Software Foundation
                          📅 Updated: 2026-07-07

                          📝 Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file. `GET /api/v2/dagSources/{dag_id}` — and the equivalent Dag-source view in the UI — returned the entire sourc...

                          🔗 euvd.enisa.europa.eu/vulnerabi

                            [?]EUVD Bot » 🤖 🌐
                            @EUVD_Bot@mastodon.social

                            🚨 EUVD-2026-42026

                            📊 Score: 8.8/10 (CVSS v3.1)
                            📅 Updated: 2026-07-07

                            📝 A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server
                            (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0),
                            an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet
                            that is copied into a 512-byte heap receive bu...

                            🔗 euvd.enisa.europa.eu/vulnerabi

                              [?]EUVD Bot » 🤖 🌐
                              @EUVD_Bot@mastodon.social

                              🚨 EUVD-2026-42025

                              📊 Score: n/a
                              📦 Product: Apache Airflow
                              🏢 Vendor: Apache Software Foundation
                              📅 Updated: 2026-07-07

                              📝 A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's readable-Dag filter to the top-level serialized Dag key but still emitted referenced Dag IDs through the `dep.source` and `dep.target` fields of trigger / ...

                              🔗 euvd.enisa.europa.eu/vulnerabi

                                [?]EUVD Bot » 🤖 🌐
                                @EUVD_Bot@mastodon.social

                                🚨 EUVD-2026-42024

                                📊 Score: n/a
                                📦 Product: Apache Airflow
                                🏢 Vendor: Apache Software Foundation
                                📅 Updated: 2026-07-07

                                📝 The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` and `AIRFLOW__WORKERS__SECRETS_BACKEND_KWARG__SECRET_ID`) as synthetic config options whose option...

                                🔗 euvd.enisa.europa.eu/vulnerabi

                                  [?]EUVD Bot » 🤖 🌐
                                  @EUVD_Bot@mastodon.social

                                  🚨 EUVD-2026-42023

                                  📊 Score: 8.0/10 (CVSS v3.1)
                                  📅 Updated: 2026-07-07

                                  📝 A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root. On default RHEL...

                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                    [?]EUVD Bot » 🤖 🌐
                                    @EUVD_Bot@mastodon.social

                                    🚨 EUVD-2026-42022

                                    📊 Score: 8.8/10 (CVSS v3.1)
                                    📅 Updated: 2026-07-07

                                    📝 A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo ...

                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                      [?]BeyondMachines :verified: » 🤖 🌐
                                      @beyondmachines1@infosec.exchange

                                      Moody Bible Institute Data Breach Exposes 2.3 Million Records via PeopleSoft Zero-Day

                                      Moody Bible Institute suffered a large-scale data breach after the ShinyHunters group exploited a zero-day vulnerability in Oracle PeopleSoft to exfiltrate 23 gigabytes of sensitive records. The incident exposed the personal information of 2.3 million individuals after the institute did not respond to extortion demands.

                                      ****

                                      beyondmachines.net/event_detai

                                        [?]TechWire ⚡ » 🤖 🌐
                                        @techwire@social.gamefan.net

                                        Nothing Ear 3a launched with built-in audio recording, AI transcripts, and stronger ANC

                                        Plus, they come in some snazzy colors!

                                        androidauthority.com/nothing-e

                                        [Android Authority]

                                          [?]TheHackerWire » 🤖 🌐
                                          @thehackerwire@mastodon.social

                                          🟠 CVE-2026-34158 - High (8.8)

                                          Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, the executeInDocker() helper wraps user-controlled commands in single quotes without escaping embedded single quotes. Atta...

                                          🔗 thehackerwire.com/vulnerabilit

                                          CVE Alert: CVE-2026-34158

                                          Alt...CVE Alert: CVE-2026-34158

                                            [?]TheHackerWire » 🤖 🌐
                                            @thehackerwire@mastodon.social

                                            🟠 CVE-2026-42200 - High (8.8)

                                            Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, PostgreSQL initialization script (generate_init_scripts() method in app/Actions/Database/StartPostgresql.php) filename han...

                                            🔗 thehackerwire.com/vulnerabilit

                                            CVE Alert: CVE-2026-42200

                                            Alt...CVE Alert: CVE-2026-42200

                                              [?]TheHackerWire » 🤖 🌐
                                              @thehackerwire@mastodon.social

                                              🟠 CVE-2026-42143 - High (8.8)

                                              Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, user-controlled persistent volume names are interpolated into shell commands executed on managed servers without escaping ...

                                              🔗 thehackerwire.com/vulnerabilit

                                              CVE Alert: CVE-2026-42143

                                              Alt...CVE Alert: CVE-2026-42143

                                                [?]AmmarSpaces » 🌐
                                                @AmmarSpaces@infosec.exchange

                                                [?]TechWire ⚡ » 🤖 🌐
                                                @techwire@social.gamefan.net

                                                Nintendo reveals launch timeline for the Switch 2 with a replaceable battery

                                                An extra 10g of weight seems like a small trade-off for a battery that can be replaced at home.

                                                androidauthority.com/switch-2-

                                                [Android Authority]

                                                  [?]TechWire ⚡ » 🤖 🌐
                                                  @techwire@social.gamefan.net

                                                  9to5Mac Overtime 071: A weird time for Apple

                                                  Fernando and Jeff discuss CarPlay on iOS 27, experience with the Rivian R1S on a road trip, why you might consider buying an iPhone 17 Pro right now instead of waiting for the iPhone 18 Pro, Apple Wallet and Amex Member…

                                                  9to5mac.com/2026/07/06/9to5mac

                                                  [9to5Mac]

                                                    [?]TechWire ⚡ » 🤖 🌐
                                                    @techwire@social.gamefan.net

                                                    You can now track your loved ones without opening Samsung Find

                                                    Tracking the location of your loved one just got easier, thanks to Samsung.

                                                    androidauthority.com/samsung-f

                                                    [Android Authority]

                                                      [?]Negative PID SL » 🌐
                                                      @negativepid@mastodon.social

                                                      [?]EUVD Bot » 🤖 🌐
                                                      @EUVD_Bot@mastodon.social

                                                      🚨 EUVD-2026-42013

                                                      📊 Score: n/a
                                                      📦 Product: wp2epub, DoLeads Integrator
                                                      🏢 Vendor: Unknown
                                                      📅 Updated: 2026-07-07

                                                      📝 The DoLeads Integrator WordPress plugin through 0.65, wp2epub WordPress plugin through 0.65 have been seen to be used to achieve RCE, once they are added adding to a blog, for example using a vulnerability where unclosed extensions from wordpress.org ca...

                                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                                        [?]EUVD Bot » 🤖 🌐
                                                        @EUVD_Bot@mastodon.social

                                                        🚨 EUVD-2026-42012

                                                        📊 Score: n/a
                                                        📦 Product: uncanny-automator-pro
                                                        🏢 Vendor: Unknown
                                                        📅 Updated: 2026-07-07

                                                        📝 The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny-automator-pro WordPress plugin before 7.3.0.6 update/distribution infrastructure was compromised; the injected backdoor grants unauthentic...

                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                          [?]EUVD Bot » 🤖 🌐
                                                          @EUVD_Bot@mastodon.social

                                                          🚨 EUVD-2026-42011

                                                          📊 Score: n/a
                                                          📦 Product: Frontend File Manager Plugin
                                                          🏢 Vendor: Unknown
                                                          📅 Updated: 2026-07-07

                                                          📝 The Frontend File Manager Plugin WordPress plugin through 23.6 does not validate a file path derived from user input before deleting the referenced file, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php) whe...

                                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                                            [?]EUVD Bot » 🤖 🌐
                                                            @EUVD_Bot@mastodon.social

                                                            🚨 EUVD-2026-42010

                                                            📊 Score: n/a
                                                            📦 Product: WP Travel Engine
                                                            🏢 Vendor: Unknown
                                                            📅 Updated: 2026-07-07

                                                            📝 The WP Travel Engine WordPress plugin before 6.8.1 does not properly validate the source of a user-supplied profile image path before moving the file, allowing authenticated users with subscriber-level access and above to relocate arbitrary files within the WordP...

                                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                                              [?]EUVD Bot » 🤖 🌐
                                                              @EUVD_Bot@mastodon.social

                                                              🚨 EUVD-2026-42009

                                                              📊 Score: 9.8/10 (CVSS v3.1)
                                                              📦 Product: WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell
                                                              🏢 Vendor: getwpfunnels
                                                              📅 Updated: 2026-07-07

                                                              📝 The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.12.7 ...

                                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                                [?]EUVD Bot » 🤖 🌐
                                                                @EUVD_Bot@mastodon.social

                                                                🚨 EUVD-2026-42008

                                                                📊 Score: 7.1/10 (CVSS v3.1)
                                                                📦 Product: MicroRealEstate
                                                                🏢 Vendor: MicroRealEstate
                                                                📅 Updated: 2026-07-07

                                                                📝 Relative path traversal vulnerability in MicroRealEstate file upload functionality allows attackers to potentially overwrite system files.

                                                                This issue affects MicroRealEstate: through 1.0.0-alpha3.

                                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                                  [?]EUVD Bot » 🤖 🌐
                                                                  @EUVD_Bot@mastodon.social

                                                                  🚨 EUVD-2026-42007

                                                                  📊 Score: 5.1/10 (CVSS v3.1)
                                                                  📦 Product: Web Config
                                                                  🏢 Vendor: SEIKO EPSON CORPORATION
                                                                  📅 Updated: 2026-07-07

                                                                  📝 Cross-site request forgery vulnerability exists in SEIKO EPSON Web Config. If a user views a malicious page while logged into Web Config, unintended operations may be performed.

                                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                                    [?]EUVD Bot » 🤖 🌐
                                                                    @EUVD_Bot@mastodon.social

                                                                    🚨 EUVD-2026-42006

                                                                    📊 Score: 5.3/10 (CVSS v3.1)
                                                                    📦 Product: MicroRealEstate
                                                                    🏢 Vendor: MicroRealEstate
                                                                    📅 Updated: 2026-07-07

                                                                    📝 Broken object-level access control on the Template API in MicroRealEstate allows attackers to retrieve document templates used by other organizations without authorization.

                                                                    This issue affects MicroRealEstate: through 1.0.0-alpha3.

                                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                                      [?]EUVD Bot » 🤖 🌐
                                                                      @EUVD_Bot@mastodon.social

                                                                      🚨 EUVD-2026-42005

                                                                      📊 Score: 7.1/10 (CVSS v3.1)
                                                                      📦 Product: MicroRealEstate
                                                                      🏢 Vendor: MicroRealEstate
                                                                      📅 Updated: 2026-07-07

                                                                      📝 Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstate allows attackers to access documents uploaded by landlords or tenants without authorization.

                                                                      This issue affects MicroRe...

                                                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                                                        [?]EUVD Bot » 🤖 🌐
                                                                        @EUVD_Bot@mastodon.social

                                                                        🚨 EUVD-2026-42004

                                                                        📊 Score: 7.1/10 (CVSS v3.1)
                                                                        📦 Product: MicroRealEstate
                                                                        🏢 Vendor: MicroRealEstate
                                                                        📅 Updated: 2026-07-07

                                                                        📝 MicroRealEstate is affected by broken object-level access controls in PDF generator functionality.

                                                                        This issue affects MicroRealEstate: through 1.0.0-alpha3.

                                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                                          [?]TheHackerWire » 🤖 🌐
                                                                          @thehackerwire@mastodon.social

                                                                          🔴 CVE-2026-14345 - Critical (9.8)

                                                                          The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.12.7 via the 'postData' parameter parameter. This is due to unsan...

                                                                          🔗 thehackerwire.com/vulnerabilit

                                                                          CVE Alert: CVE-2026-14345

                                                                          Alt...CVE Alert: CVE-2026-14345

                                                                            [?]EUVD Bot » 🤖 🌐
                                                                            @EUVD_Bot@mastodon.social

                                                                            🚨 EUVD-2026-42003

                                                                            📊 Score: 8.8/10 (CVSS v3.1)
                                                                            📦 Product: MicroRealEstate
                                                                            🏢 Vendor: MicroRealEstate
                                                                            📅 Updated: 2026-07-07

                                                                            📝 MicroRealEstate allows adversaries to bypass authentication due to a lack of token state management. This would permit adversaries targeting MicroRealEstate deployments to brute-force One-Time Passwords (OTP) to log in as any user. This issue...

                                                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                                                              [?]urlDNA.io :verified: » 🤖 🌐
                                                                              @urldna@infosec.exchange

                                                                              Possible Phishing 🎣
                                                                              on: ⚠️hxxps[:]//wallet-exoduss-io[.]wasmer[.]app
                                                                              🧬 Analysis at: urldna.io/scan/6a4c49643b77500

                                                                                [?]TheHackerWire » 🤖 🌐
                                                                                @thehackerwire@mastodon.social

                                                                                🟠 CVE-2026-34152 - High (8.8)

                                                                                Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, pre-deployment and post-deployment commands are single-quote escaped but then sent through SSH heredoc transport that pres...

                                                                                🔗 thehackerwire.com/vulnerabilit

                                                                                CVE Alert: CVE-2026-34152

                                                                                Alt...CVE Alert: CVE-2026-34152

                                                                                  [?]TheHackerWire » 🤖 🌐
                                                                                  @thehackerwire@mastodon.social

                                                                                  🟠 CVE-2026-34168 - High (8.8)

                                                                                  Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the LocalPersistentVolume.name field is interpolated directly into docker volume shell commands without shell argument esc...

                                                                                  🔗 thehackerwire.com/vulnerabilit

                                                                                  CVE Alert: CVE-2026-34168

                                                                                  Alt...CVE Alert: CVE-2026-34168

                                                                                    [?]Hugo | DevOps | Cybersecurity » 🌐
                                                                                    @hugovalters@mastodon.social

                                                                                    LearnPress: 43 CVEs, 12 critical/high, max CVSS 10. 100% unpatched. Trust Score: D. Top flaws: Missing authorization (CWE-862) & XSS (CWE-79). E-learning platforms at risk. Patch now.

                                                                                    valtersit.com/vendors/learnpre

                                                                                      Back to top - More...