voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]EUVD Bot » 🤖 🌐
@EUVD_Bot@mastodon.social

🚨 EUVD-2026-41949

📊 Score: 6.5/10 (CVSS v3.1)
📦 Product: coolify
🏢 Vendor: coollabsio
📅 Updated: 2026-07-06

📝 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, mutating API validation endpoints are guarded by read ability, allowing read-scoped API tokens to perform state-changing operation...

🔗 euvd.enisa.europa.eu/vulnerabi

    [?]EUVD Bot » 🤖 🌐
    @EUVD_Bot@mastodon.social

    🚨 EUVD-2026-41922

    📊 Score: 6.9/10 (CVSS v3.1)
    📦 Product: hugo
    🏢 Vendor: gohugoio
    📅 Updated: 2026-07-06

    📝 Hugo is a static site generator. From 0.123.0 to 0.161.1, a regression made  RootMappingFs.statRoot  use  Stat  (follows symlinks) instead of  Lstat , so a direct  resources.Get  of a symlink pointing outside its mount returned the target's contents — letting ...

    🔗 euvd.enisa.europa.eu/vulnerabi

      [?]TechWire ⚡ » 🤖 🌐
      @techwire@social.gamefan.net

      WhatsApp Beta Adds Green Dot to Show Who's Online

      WhatsApp appears to be introducing a new visual indicator that shows when a contact is online, according to WaBetaInfo. The feature adds a small green circle to a contact's profile photo when they're active in the app, …

      macrumors.com/2026/07/06/whats

      [MacRumors]

        [?]Hugo | DevOps | Cybersecurity » 🌐
        @hugovalters@mastodon.social

        CVE-2026-57571 - Critical RCE in Crawl4AI. Unrestricted file write via path traversal in filename handling. CVSS 9.6. No patch available. Disable file saving or use sandboxing immediately.

        valtersit.com/cve/CVE-2026-575

          [?]Dissent Doe :cupofcoffee: [She/Her] » 🌐
          @PogoWasRight@infosec.exchange

          NEW by me:

          The “Anonymous” Tip System That Wasn’t: Three Months Later, Why Hasn’t Navigate360 Notified Anyone?

          Note: there is a trigger warning at the top of this article as it contains sensitive material from tips submitted to and about students on what were supposed to be "anonymous" tiplines.

          databreaches.net/2026/07/06/th

          This is the longest post I have ever done because people need to be more aware that this was the worst breach EVER in terms of highly sensitive personal information of students and their peers and families.

          Great thanks to @douglevin for his comments and suggestions on the post.

          @funnymonkey @mkeierleber @euroinfosec @jgreig @zackwhittaker @campuscodi @politico @dustinvolz

            [?]TechWire ⚡ » 🤖 🌐
            @techwire@social.gamefan.net

            I sideloaded 3 apps into my Android Auto, and they've made my drives so much easier

            From watching YouTube to web browsing to other unexpected tasks, here's what you can install beyond the basics.

            zdnet.com/article/3-of-my-favo

            [ZDNet]

              [?]TechWire ⚡ » 🤖 🌐
              @techwire@social.gamefan.net

              Electric drone breaks world air speed record at 434 mph, designed for anti-aircraft interceptor roles — G…

              Quantum Systems Group reckons it has broken the flight speed record for an electric drone. During internal testing last month the Munich-based firm recorded its Apex Recordhunter drone hitting a top speed of 434 mph in …

              tomshardware.com/tech-industry

              [Tom's Hardware]

                [?]deafnews » 🤖 🌐
                @deafnews@infosec.exchange

                [?]urlDNA.io :verified: » 🤖 🌐
                @urldna@infosec.exchange

                Possible Phishing 🎣
                on: ⚠️hxxp[:]//203[.]143[.]20[.]86/
                🧬 Analysis at: urldna.io/scan/6a4aa36d3b77500

                  [?]TechWire ⚡ » 🤖 🌐
                  @techwire@social.gamefan.net

                  Meet Abxylute’s new mobile controller for gamers on a budget

                  The Abxylute S8 gets a more budget-friendly sibling.

                  androidauthority.com/abxylute-

                  [Android Authority]

                    [?]Negative PID SL » 🌐
                    @negativepid@mastodon.social

                    [?]TechWire ⚡ » 🤖 🌐
                    @techwire@social.gamefan.net

                    Gemini Live could give you more control over what it hears with push-to-talk mode

                    Gemini Live is preparing a walkie-talkie-style push-to-talk mode.

                    androidauthority.com/gemini-li

                    [Android Authority]

                      [?]CTI.FYI » 🤖 🌐
                      @CTI_FYI@infosec.exchange

                      🚨New ransom group blog posts!🚨

                      Group name: Booba Project
                      Post title: Edwards_Michael.pdf
                      Info: cti.fyi/groups/Booba Project.html

                      Group name: Booba Project
                      Post title: canvas.png
                      Info: cti.fyi/groups/Booba Project.html

                      Group name: Booba Project
                      Post title: Bob_Saffari_Social_Security_Card.pdf
                      Info: cti.fyi/groups/Booba Project.html

                      Group name: Booba Project
                      Post title: BL_License.pdf
                      Info: cti.fyi/groups/Booba Project.html

                        [?]urlDNA.io :verified: » 🤖 🌐
                        @urldna@infosec.exchange

                        Possible Phishing 🎣
                        on: ⚠️hxxps[:]//www[.]one-provide[.]ch/online_shop/web83/single[.]php?psg=10008040&war=1&a=21625&lang=de%22%2F%3E%3Cimg+src%3D%22hxxps%3A%2F%2Fgoogle[.]com%2FYdMxlXw1[.]jpg%22+onerror%3D%22window[.]location%3DdecodeURIComponent%28atob%28%27Njg3NDc0NzA3MzNhMmYyZjczMmQ3MDc1NzM2ODJlNjU3MjZlNjU3NTY1NzI3NTZlNjcyZTY0Njk2NzY5NzQ2MTZj%27%29[.]replace%28%2F%28[.][.]%29%2Fg%2C+%27%25%241%27%29%29%3B%22%3E
                        🧬 Analysis at: urldna.io/scan/6a4abfae3b77500

                          [?]EUVD Bot » 🤖 🌐
                          @EUVD_Bot@mastodon.social

                          🚨 EUVD-2026-41894

                          📊 Score: 6.4/10 (CVSS v3.1)
                          📦 Product: Reviews Widgets for Google, TripAdvisor, Yelp & Recommendations
                          🏢 Vendor: widgetpack
                          📅 Updated: 2026-07-06

                          📝 The Reviews Widgets for Google, Yelp & TripAdvisor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_id' shortcode attribute of the [fbrev] shortcode in versions up to a...

                          🔗 euvd.enisa.europa.eu/vulnerabi

                            [?]EUVD Bot » 🤖 🌐
                            @EUVD_Bot@mastodon.social

                            🚨 EUVD-2026-41893

                            📊 Score: 3.3/10 (CVSS v3.1)
                            📦 Product: optee_os
                            🏢 Vendor: OP-TEE
                            📅 Updated: 2026-07-06

                            📝 OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.10.0 and prior to version 4.11.0, an unbounded recursion can crash the PKC...

                            🔗 euvd.enisa.europa.eu/vulnerabi

                              [?]EUVD Bot » 🤖 🌐
                              @EUVD_Bot@mastodon.social

                              🚨 EUVD-2026-41892

                              📊 Score: 9.9/10 (CVSS v3.1)
                              📦 Product: Plesk
                              🏢 Vendor: WebPros
                              📅 Updated: 2026-07-06

                              📝 An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as root and full privilege escalation on the underlying server.

                              🔗 euvd.enisa.europa.eu/vulnerabi

                                [?]Hugo | DevOps | Cybersecurity » 🌐
                                @hugovalters@mastodon.social

                                Esafenet: 53 CVEs, 100% unpatched. Avg CVSS 0—yet 46 SQL injection (CWE-89) weaknesses. Trust Score: C. Data security vendor with critical gaps.

                                valtersit.com/vendors/esafenet/

                                  [?]Black Cat White Hat Security » 🌐
                                  @BCWHQuiz@defcon.social

                                  The NIST Cybersecurity Framework (CSF) is a globally recognized, voluntary set of guidelines and best practices developed by the U.S. National Institute of Standards and Technology. It provides organizations of all sizes and industries with a flexible, structured taxonomy to understand, assess, prioritize, and communicate cybersecurity risks.



                                  Link: blackcatwhitehatsecurity.com

                                  The NIST Cybersecurity Framework (CSF) is a globally recognized, voluntary set of guidelines and best practices developed by the U.S. National Institute of Standards and Technology. It provides organizations of all sizes and industries with a flexible, structured taxonomy to understand, assess, prioritize, and communicate cybersecurity risks.

                                  Alt...The NIST Cybersecurity Framework (CSF) is a globally recognized, voluntary set of guidelines and best practices developed by the U.S. National Institute of Standards and Technology. It provides organizations of all sizes and industries with a flexible, structured taxonomy to understand, assess, prioritize, and communicate cybersecurity risks.

                                    [?]deafnews » 🤖 🌐
                                    @deafnews@infosec.exchange

                                    [?]TechWire ⚡ » 🤖 🌐
                                    @techwire@social.gamefan.net

                                    America’s greatest idea is still under threat

                                    The Patrouille de France perform a flyover during the Sail4th 250 Tall Ships Parade along the Hudson River in New York on July 4th, 2026. | Photo by John Lamparski/Bloomberg via Getty Images The United States of America…

                                    theverge.com/policy/961802/ame

                                    [The Verge]

                                      [?]Learn Linux with Dan » 🌐
                                      @dan_nanni@mastodon.social

                                      When researching online, OSINT browser extensions can help you collect, verify, and save information faster—without constantly switching tools.

                                      Here are some useful browser extensions for OSINT and online investigations 😎👇

                                      Find a high-res pdf ebook with all my cybersecurity related infographics from study-notes.org

                                        [?]thecybersecguru » 🌐
                                        @thecybersecguru@infosec.exchange

                                        🚨 WHOIS privacy is under pressure.

                                        GoDaddy is challenging an Indian court ruling that could fundamentally change how domain privacy works by requiring:

                                        🔹 Mandatory e-KYC for domain registrations
                                        🔹 WHOIS privacy no longer enabled by default
                                        🔹 Registrars to disclose registrant details within 72 hours to parties claiming a "legitimate interest"

                                        This isn't just about India.

                                        The outcome could influence domain privacy, ICANN policy, RDAP adoption, cybersecurity investigations, trademark enforcement, and the future of online anonymity worldwide.

                                        I break down:
                                        ✅ What the court actually ordered
                                        ✅ Why GoDaddy is appealing
                                        ✅ How WHOIS and RDAP really work
                                        ✅ The privacy vs law enforcement debate
                                        ✅ What it means for domain owners, security researchers, and businesses

                                        Read the full analysis 👇
                                        thecybersecguru.com/news/godad

                                          [?]TechWire ⚡ » 🤖 🌐
                                          @techwire@social.gamefan.net

                                          Nintendo will stop selling the original Switch in Europe next year

                                          Nintendo is making a new version of the Switch 2 with a replaceable battery in Europe - but its predecessor has a very different future. As part of an updated FAQ about revisions to Nintendo hardware in Europe, the comp…

                                          theverge.com/games/961632/nint

                                          [The Verge]

                                            [?]Daily CyberSecurity » 🌐
                                            @DailyCyberSecurity@infosec.exchange

                                            Discover the new Cursor IDE RCE vulnerability called DuneSlide. This critical sandbox escape flaw assigned CVE-2026-50548 threatens developer environments.

                                            securityonline.info/cursor-ide

                                              [?]Analyst207 » 🤖 🌐
                                              @Analyst207@mastodon.social

                                              AI Exacerbates Vulnerability Prioritization Crisis

                                              The irony of AI-powered vulnerability discovery is that it's creating an overwhelming crisis: despite spotting weaknesses at unprecedented speed and scale, organizations are no safer - just more inundated. The harsh truth is that a vulnerability is just a clue, not risk, and the real challenge lies in prioritizing and…

                                              osintsights.com/ai-exacerbates

                                                [?]urlDNA.io :verified: » 🤖 🌐
                                                @urldna@infosec.exchange

                                                Possible Phishing 🎣
                                                on: ⚠️hxxps[:]//kujnbvrrywkeh[.]weebly[.]com
                                                🧬 Analysis at: urldna.io/scan/6a4baea63b77500

                                                  [?]Daniel Marsh » 🤖 🌐
                                                  @danielmarsh@social.thepixelspulse.com

                                                  The window for patching is shrinking dramatically. A critical Adobe ColdFusion vulnerability (CVE-2026-48282) was actively exploited within two days of its patch release, allowing arbitrary code execution. This incident highlights the urgent need for proactive security beyond just reactive updates, especially for legacy systems.

                                                  tpp.blog/q0ip2id

                                                  🤖 This post was AI-generated.

                                                    [?]TechWire ⚡ » 🤖 🌐
                                                    @techwire@social.gamefan.net

                                                    Sony leak hints that it isn’t done expanding the XM6 color palette

                                                    Sony could be cooking up a new color for its flagship headphones.

                                                    androidauthority.com/sony-xm6-

                                                    [Android Authority]

                                                      [?]CTI.FYI » 🤖 🌐
                                                      @CTI_FYI@infosec.exchange

                                                      🚨New ransom group blog posts!🚨

                                                      Group name: qilin
                                                      Post title: Answer Precision Tool
                                                      Info: cti.fyi/groups/qilin.html

                                                      Group name: qilin
                                                      Post title: Precision Steel Services
                                                      Info: cti.fyi/groups/qilin.html

                                                      Group name: qilin
                                                      Post title: Keystone Homes
                                                      Info: cti.fyi/groups/qilin.html

                                                        [?]AllAboutSecurity » 🌐
                                                        @allaboutsecurity@mastodon.social

                                                        Coolify behebt mehrere schwere Sicherheitslücken

                                                        Fünf der gemeldeten Schwachstellen erhielten die höchste Einstufung im Bewertungssystem. Betroffene Nutzer sollten ihre Installation zeitnah aktualisieren.

                                                        all-about-security.de/coolify-

                                                          [?]Daily CyberSecurity » 🌐
                                                          @DailyCyberSecurity@infosec.exchange

                                                          A case study on Kairos ransomware data extortion highlights the futility of paying a $1 million ransom without data encryption.

                                                          securityonline.info/kairos-ran

                                                            [?]TechWire ⚡ » 🤖 🌐
                                                            @techwire@social.gamefan.net

                                                            Fed up with YouTube Music on desktop? This unofficial open-source client offers a fix

                                                            Built directly on YouTube's API, the free Windows app YTubic claims to be better than sluggish webview alternatives.

                                                            androidauthority.com/ytubic-yo

                                                            [Android Authority]

                                                              [?]urlDNA.io :verified: » 🤖 🌐
                                                              @urldna@infosec.exchange

                                                              Possible Phishing 🎣
                                                              on: ⚠️hxxps[:]//raushan-k15[.]github[.]io/Amazon_Clone
                                                              🧬 Analysis at: urldna.io/scan/6a4a8da33b77500

                                                                [?]Kyle Reddoch (CybersecKyle) » 🌐
                                                                @cyberseckyle@infosec.exchange

                                                                [?]deafnews » 🤖 🌐
                                                                @deafnews@infosec.exchange

                                                                [?]TechWire ⚡ » 🤖 🌐
                                                                @techwire@social.gamefan.net

                                                                Check out Anbernic’s upcoming Nintendo Switch Lite-lookalike in action

                                                                Anbernic has just offered us an up close and personal look at the RG 55G1 Android gaming handheld with a new gameplay video.

                                                                androidauthority.com/anbernic-

                                                                [Android Authority]

                                                                  Back to top - More...