voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
Armored Likho's new weapon: BusySnake Stealer
Kaspersky uncovered a sophisticated phishing campaign by the APT group Armored Likho, deploying a previously undocumented Python-based infostealer dubbed BusySnake Stealer. The campaign targets government agencies and electric power sectors across Russia, Brazil, and Kazakhstan through spear-phishing emails containing malicious EXE or LNK attachments. BusySnake Stealer features advanced obfuscation using PyArmor Pro, extracts credentials from browsers using DPAPI and NSS libraries, captures screenshots, logs keystrokes, scrapes cryptocurrency wallets and 2FA tokens, and establishes reverse SSH tunnels for remote access. The threat actor leverages AI-generated code for first-stage payloads and distributes components via GitHub repositories. The stealer maintains persistence through scheduled tasks and communicates with C2 infrastructure to receive commands dynamically, representing a significant evolution in the group's technical capabilities.
Pulse ID: 6a47a77e01d1e457798b3a33
Pulse Link: https://otx.alienvault.com/pulse/6a47a77e01d1e457798b3a33
Pulse Author: AlienVault
Created: 2026-07-03 12:13:50
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#2FA #Brazil #Browser #CyberSecurity #Email #GitHub #Government #InfoSec #InfoStealer #Kaspersky #Kazakhstan #LNK #OTX #OpenThreatExchange #Phishing #Python #RAT #Russia #SSH #SpearPhishing #bot #cryptocurrency #AlienVault
Indirect Prompt Injection in Web Content Targets AI Agents
AI agents are increasingly vulnerable to indirect prompt injection (IPI) attacks, where malicious instructions are embedded in web content to manipulate AI-driven workflows. Two campaigns were identified that combine SEO poisoning with CSS/HTML abuse to influence AI decision-making. The first campaign uses fake API documentation to trick AI agents into making fraudulent payments for a fake Python library, incorporating hidden instructions in JSON-LD and CSS-concealed content directing payment of $3.00 via Stripe or approximately 0.0012 ETH to attacker wallets. The second campaign employs typosquatting to impersonate DeBank, a cryptocurrency portfolio tracker, embedding hidden prompts to make the fraudulent site appear as an authoritative source. Testing across 26 LLMs revealed 4 models were vulnerable to the payment scam and 2 models misclassified the typosquatting site, demonstrating measurable real-world impact.
Pulse ID: 6a46cc8d21232689c52266a2
Pulse Link: https://otx.alienvault.com/pulse/6a46cc8d21232689c52266a2
Pulse Author: AlienVault
Created: 2026-07-02 20:39:41
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Bank #CyberSecurity #HTML #InfoSec #OTX #OpenThreatExchange #Python #RAT #RCE #RTF #SEOPoisoning #TypoSquatting #bot #cryptocurrency #AlienVault
🎣 Phishing Spotlight
yamzoza-north-007-amazon[.]s3[.]us-east-1[.]amazonaws[.]com
🔒 SSL: exp. 2026-11-06
🌐 Stack: AmazonS3
🔗 https://beesint.com/pulse/e5ed2510-015c-4f42-9d57-52b5dc399b67
Geopolitical tensions persist in the Strait of Hormuz with Iran's transit control threats, while Sudan's conflict expands regionally. In technology, Microsoft announced a $2.5B investment in enterprise AI. Cybersecurity saw the NetNut proxy network dismantled and a critical "Bad Epoll" Linux kernel flaw disclosed. Five Eyes warns AI-fueled cyberattacks are imminent.
#AnonNews_irc #Cybersecurity #News
Qcom: 56 CVEs tracked. Avg CVSS 5.5. 78% unpatched. Trust Score: C. Top weakness: NULL pointer dereference (CWE-476). Low visibility, high risk. Assess your exposure. #Qcom #cybersecurity #infosec
After Samsung Health, the Wearable app could be getting its biggest redesign yet
Your watch deserves better, and this redesign looks ready to deliver it.
https://www.androidauthority.com/galaxy-wearable-app-redesign-leak-3684329/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
I tried replacing Google Photos with Amazon Photos — and it went better than expected
I still prefer Google Photos, but Amazon comes pretty close here.
https://www.androidauthority.com/google-photos-vs-amazon-photos-switch-hands-on-3679448/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
IBM WebSphere Application Server: Drei Schwachstellen im Hilfesystem der Admin-Konsole entdeckt
- Zwei davon betreffen Cross-Site-Scripting (XSS), eine dritte einen Path-Traversal-Fehler.
🚨New ransom group blog post!🚨
Group name: qilin
Post title: Wood Ellis & Wood CPA
Info: https://cti.fyi/groups/qilin.html
#ransomware #cti #threatintelligence #cybersecurity #infosec
🛡️ This week in cybersecurity: AI Orchestration risks take center stage. We analyze a critical RCE in Open-Agent-Orchestrator and the emerging threat of model-based sandbox escapes. Keep your AI stack secure with our weekly breakdown. Full analysis here: https://cvedatabase.com/blog/weekly-cve-roundup-ai-orchestration-risks-and-the-shift-toward-model-based-rce-j-2026-06-14 #CVE #Cybersecurity #AISecurity #Infosec #PatchTuesday #TechNews
Possible Phishing 🎣
on: ⚠️hxxps[:]//roblox[.]com[.]bi
🧬 Analysis at: https://urldna.io/scan/6a4a79673b7750000370b06b
#cybersecurity #phishing #infosec #urldna #scam #infosec
⚠️ Fake Google verification pages deliver malware instead
Attackers impersonate Google and #Cloudflare verification screens to trick users into executing malicious PowerShell commands that install #malware.
🔗 read more: gbhackers.com/fake-google-...
Survey says this is the best Play Store alternative, but Google might not agree
Most readers believe in the power of open source apps.
https://www.androidauthority.com/best-google-play-store-alternative-poll-results-3684323/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Discover how The Gentlemen ransomware utilized a ktapi.sys zero-day BYOVD attack to bypass kernel defenses and disable EDR systems in seconds.
#TheGentlemen #Ransomware #ZeroDay #BYOVD #CyberSecurity #Expel
https://meterpreter.org/gentlemen-ransomware-zero-day/?utm_source=mastodon&utm_medium=jetpack_social
OnePlus is allegedly honoring warranties with vouchers nobody asked for, and users aren’t happy
These €100 vouchers can't be redeemed because nearly everything is out of stock or already discounted.
https://www.androidauthority.com/oneplus-eu-warranty-swapped-for-useless-voucher-3684328/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Possible Phishing 🎣
on: ⚠️hxxps[:]//sportybetballanceader[.]weebly[.]com/
🧬 Analysis at: https://urldna.io/scan/6a4b6eb53b77500009f79784
#cybersecurity #phishing #infosec #urldna #scam #infosec
Is 'Iron Bird Seed' a code for something more dangerous? The truth might surprise you.
Full story 👇
Learn more: https://www.earthinsider.in/2026/07/iron-bird-seed-supply-chain-security.html
#EarthInsider #EarthInsiderNews #EINews #US #America #USNews #USPolitics #IronBirdSeed #CyberSecurity #SupplyChain #AviationSafety #BreakingNews #MustRead
These 5 Android apps are so good, I’m surprised they’re free
Good free apps really do still exist.
https://www.androidauthority.com/best-free-android-apps-2026-3683259/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
InvisibleX wurde von Datendiebstahl & missbräuchlicher Nutzung wie Spam-Mails, dubiosen Anrufen und unerwünschter Werbung betroffen – und geht jetzt aktiv dagegen vor. Mit Erfahrung, Datenbroker-Analyse und DSGVO-basierten Löschanfragen schützt InvisibleX persönliche Daten regelmäßig. 🛡️🔒 https://invisiblex.de/about-us #Datenschutz #Privacy #DSGVO #CyberSecurity
You use Tor on a secure VPS every day. But do you know what actually lurks on the 2025 dark web? Scams, surprises, and secrets that’ll make you rethink your threat model. Full report inside. #Cybersecurity #Privacy #Tor
☕ CYBERBRIEFING — Lunedì 6 luglio 2026
👉 Leggi tutti gli aggiornamenti delle ultime 24 ore:
https://ilpuntocyber.rfeed.it/article.php?s=2026-07-06
Supreme Court rules the Fourth Amendment protects your phone’s location history
The Supreme Court rendered a decision this morning on a case debating whether or not people have an “expectation of privacy” from their government, even with always-available location tracking enabled on practically eve…
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Google [9to5Google]
GitHub Impersonation Deploys Information Stealer
Pulse ID: 6a4b46b25e24d42ee1f97215
Pulse Link: https://otx.alienvault.com/pulse/6a4b46b25e24d42ee1f97215
Pulse Author: Tr1sa111
Created: 2026-07-06 06:09:54
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #GitHub #InfoSec #OTX #OpenThreatExchange #bot #Tr1sa111
Vibe Coded Extortion: Path from Legal Lure to CrownX Ransom Capabilities
Pulse ID: 6a4b466d6af3e8b8886d92ae
Pulse Link: https://otx.alienvault.com/pulse/6a4b466d6af3e8b8886d92ae
Pulse Author: Tr1sa111
Created: 2026-07-06 06:08:45
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Extortion #InfoSec #OTX #OpenThreatExchange #bot #Tr1sa111
Samsung’s Galaxy Watch 9 band lineup leaks with more updates than the smartwatch [Gallery]
Samsung’s upcoming Galaxy Watch 9 really doesn’t look all that different from the Watch 8, but new leaks show off updated watch bands that actually deliver some notable changes.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Google [9to5Google]
Vibe Coded Extortion: Path from Legal Lure to CrownX Ransom Capabilities
Pulse ID: 6a4b466a1d410b804d5cc09a
Pulse Link: https://otx.alienvault.com/pulse/6a4b466a1d410b804d5cc09a
Pulse Author: Tr1sa111
Created: 2026-07-06 06:08:42
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Extortion #InfoSec #OTX #OpenThreatExchange #bot #Tr1sa111
Branded Gambling Campaigns: How Scammers Are Exploiting Trusted Brand Names to Drive Casino Traffic
Pulse ID: 6a4b461c2fc6412449dbc361
Pulse Link: https://otx.alienvault.com/pulse/6a4b461c2fc6412449dbc361
Pulse Author: Tr1sa111
Created: 2026-07-06 06:07:24
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #Rust #bot #Tr1sa111
AsyncRAT and Remcos Delivered in Multi-Stage Phishing Campaign
Pulse ID: 6a4b45f8cd2be13f3a96f5ff
Pulse Link: https://otx.alienvault.com/pulse/6a4b45f8cd2be13f3a96f5ff
Pulse Author: Tr1sa111
Created: 2026-07-06 06:06:48
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AsyncRAT #CyberSecurity #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #Remcos #bot #Tr1sa111
PamStealer: a Rust-based macOS infostealer that validates credentials through PAM
Pulse ID: 6a4b459328d25bbdc8b77726
Pulse Link: https://otx.alienvault.com/pulse/6a4b459328d25bbdc8b77726
Pulse Author: Tr1sa111
Created: 2026-07-06 06:05:07
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #InfoStealer #Mac #MacOS #OTX #OpenThreatExchange #Rust #bot #Tr1sa111
This dumb password rule is from AmiAmi.
Your password needs to be between 6 and 12 characters long, must contain only letters and numbers.
https://dumbpasswordrules.com/sites/amiami/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
Latest Galaxy Watch 9 leak reveals 5 brand-new watch faces
Minimalist, sporty, or packed with widgets — there's a face for everyone.
https://www.androidauthority.com/samsung-galaxy-watch-9-watch-faces-leak-3684292/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
🚨 EUVD-2026-41810
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Ecommerce Website
🏢 Vendor: CodeAstro
📅 Updated: 2026-07-06
📝 A security flaw has been discovered in CodeAstro Ecommerce Website 1.0. Impacted is an unknown function of the file /customer/my_account.php?my_wishlist. The manipulation of the argument delete_wishlist results in sql injection. The attack can be...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41810
🚨 EUVD-2026-41809
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Apartment Visitor Management System
🏢 Vendor: CodeAstro
📅 Updated: 2026-07-06
📝 A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. This issue affects some unknown processing of the file /apartment-visitor/visitor-entry.php. The manipulation of the argument visname leads to ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41809
🚨 EUVD-2026-41808
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Apartment Visitor Management System
🏢 Vendor: CodeAstro
📅 Updated: 2026-07-06
📝 A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. This vulnerability affects unknown code of the file /apartment-visitor/edit-apartment.php. Executing a manipulation of the argument editid can ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41808
SkillCloak: 90% of AI Agent Skill Scanners Fail Against Obfuscated Skills https://deafnews.it/en/article/skillcloak-90-of-ai-agent-skill-scanners-fail-against-obfuscated-skills #Cybersecurity
CodePeople: 47 CVEs, 100% unpatched. Max CVSS 8.5. Trust Score: C. WordPress plugins like Booking Calendar = wide attack surface. Patch now. #CodePeople #WordPress #cybersecurity
Galaxy Z Fold 8 and Fold 8 Ultra tipped to match OPPO’s nearly invisible crease
Samsung has reportedly changed the hinge to nearly eliminate the crease.
https://www.androidauthority.com/samsung-galaxy-z-fold-8-crease-3684302/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
🟠 CVE-2026-14327 - High (7.5)
The AR for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.40 via the 'file' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary fi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14327/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🔴 CVE-2026-13768 - Critical (10)
Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns connection information for all Gardyn Home Kit and Studio devices. Access to this key al...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-13768/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🔴 CVE-2026-41106 - Critical (9.3)
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-41106/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack