voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]OTX Bot » 🤖 🌐
@techbot@social.raytec.co

Armored Likho's new weapon: BusySnake Stealer

Kaspersky uncovered a sophisticated phishing campaign by the APT group Armored Likho, deploying a previously undocumented Python-based infostealer dubbed BusySnake Stealer. The campaign targets government agencies and electric power sectors across Russia, Brazil, and Kazakhstan through spear-phishing emails containing malicious EXE or LNK attachments. BusySnake Stealer features advanced obfuscation using PyArmor Pro, extracts credentials from browsers using DPAPI and NSS libraries, captures screenshots, logs keystrokes, scrapes cryptocurrency wallets and 2FA tokens, and establishes reverse SSH tunnels for remote access. The threat actor leverages AI-generated code for first-stage payloads and distributes components via GitHub repositories. The stealer maintains persistence through scheduled tasks and communicates with C2 infrastructure to receive commands dynamically, representing a significant evolution in the group's technical capabilities.

Pulse ID: 6a47a77e01d1e457798b3a33
Pulse Link: otx.alienvault.com/pulse/6a47a
Pulse Author: AlienVault
Created: 2026-07-03 12:13:50

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    [?]OTX Bot » 🤖 🌐
    @techbot@social.raytec.co

    Indirect Prompt Injection in Web Content Targets AI Agents

    AI agents are increasingly vulnerable to indirect prompt injection (IPI) attacks, where malicious instructions are embedded in web content to manipulate AI-driven workflows. Two campaigns were identified that combine SEO poisoning with CSS/HTML abuse to influence AI decision-making. The first campaign uses fake API documentation to trick AI agents into making fraudulent payments for a fake Python library, incorporating hidden instructions in JSON-LD and CSS-concealed content directing payment of $3.00 via Stripe or approximately 0.0012 ETH to attacker wallets. The second campaign employs typosquatting to impersonate DeBank, a cryptocurrency portfolio tracker, embedding hidden prompts to make the fraudulent site appear as an authoritative source. Testing across 26 LLMs revealed 4 models were vulnerable to the payment scam and 2 models misclassified the typosquatting site, demonstrating measurable real-world impact.

    Pulse ID: 6a46cc8d21232689c52266a2
    Pulse Link: otx.alienvault.com/pulse/6a46c
    Pulse Author: AlienVault
    Created: 2026-07-02 20:39:41

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

      [?]BeeSINT » 🌐
      @BeeSINT@mastodon.social

      🎣 Phishing Spotlight

      yamzoza-north-007-amazon[.]s3[.]us-east-1[.]amazonaws[.]com

      🔒 SSL: exp. 2026-11-06
      🌐 Stack: AmazonS3

      🔗 beesint.com/pulse/e5ed2510-015

        [?]𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 :verified: » 🌐
        @youranonnewsirc@nerdculture.de

        ... [SENSITIVE CONTENT]

        Geopolitical tensions persist in the Strait of Hormuz with Iran's transit control threats, while Sudan's conflict expands regionally. In technology, Microsoft announced a $2.5B investment in enterprise AI. Cybersecurity saw the NetNut proxy network dismantled and a critical "Bad Epoll" Linux kernel flaw disclosed. Five Eyes warns AI-fueled cyberattacks are imminent.

          [?]Hugo | DevOps | Cybersecurity » 🌐
          @hugovalters@mastodon.social

          Qcom: 56 CVEs tracked. Avg CVSS 5.5. 78% unpatched. Trust Score: C. Top weakness: NULL pointer dereference (CWE-476). Low visibility, high risk. Assess your exposure.

          valtersit.com/vendors/qcom/

            [?]TechWire ⚡ » 🤖 🌐
            @techwire@social.gamefan.net

            After Samsung Health, the Wearable app could be getting its biggest redesign yet

            Your watch deserves better, and this redesign looks ready to deliver it.

            androidauthority.com/galaxy-we

            [Android Authority]

              [?]TechWire ⚡ » 🤖 🌐
              @techwire@social.gamefan.net

              I tried replacing Google Photos with Amazon Photos — and it went better than expected

              I still prefer Google Photos, but Amazon comes pretty close here.

              androidauthority.com/google-ph

              [Android Authority]

                [?]AllAboutSecurity » 🌐
                @allaboutsecurity@mastodon.social

                IBM WebSphere Application Server: Drei Schwachstellen im Hilfesystem der Admin-Konsole entdeckt

                - Zwei davon betreffen Cross-Site-Scripting (XSS), eine dritte einen Path-Traversal-Fehler.

                all-about-security.de/ibm-webs

                  [?]CTI.FYI » 🤖 🌐
                  @CTI_FYI@infosec.exchange

                  🚨New ransom group blog post!🚨

                  Group name: qilin
                  Post title: Wood Ellis & Wood CPA
                  Info: cti.fyi/groups/qilin.html

                    [?]CVEDatabase.com » 🌐
                    @cvedatabase@techhub.social

                    🛡️ This week in cybersecurity: AI Orchestration risks take center stage. We analyze a critical RCE in Open-Agent-Orchestrator and the emerging threat of model-based sandbox escapes. Keep your AI stack secure with our weekly breakdown. Full analysis here: cvedatabase.com/blog/weekly-cv

                      [?]urlDNA.io :verified: » 🤖 🌐
                      @urldna@infosec.exchange

                      Possible Phishing 🎣
                      on: ⚠️hxxps[:]//roblox[.]com[.]bi
                      🧬 Analysis at: urldna.io/scan/6a4a79673b77500

                        [?]ransomNews » 🌐
                        @ransomnews.online@bsky.brid.gy

                        ⚠️ Fake Google verification pages deliver malware instead

                        Attackers impersonate Google and verification screens to trick users into executing malicious PowerShell commands that install .

                        🔗 read more: gbhackers.com/fake-google-...

                          [?]TechWire ⚡ » 🤖 🌐
                          @techwire@social.gamefan.net

                          Survey says this is the best Play Store alternative, but Google might not agree

                          Most readers believe in the power of open source apps.

                          androidauthority.com/best-goog

                          [Android Authority]

                            [?]Daily CyberSecurity » 🌐
                            @DailyCyberSecurity@infosec.exchange

                            Discover how The Gentlemen ransomware utilized a ktapi.sys zero-day BYOVD attack to bypass kernel defenses and disable EDR systems in seconds.

                            meterpreter.org/gentlemen-rans

                              [?]TechWire ⚡ » 🤖 🌐
                              @techwire@social.gamefan.net

                              OnePlus is allegedly honoring warranties with vouchers nobody asked for, and users aren’t happy

                              These €100 vouchers can't be redeemed because nearly everything is out of stock or already discounted.

                              androidauthority.com/oneplus-e

                              [Android Authority]

                                [?]urlDNA.io :verified: » 🤖 🌐
                                @urldna@infosec.exchange

                                Possible Phishing 🎣
                                on: ⚠️hxxps[:]//sportybetballanceader[.]weebly[.]com/
                                🧬 Analysis at: urldna.io/scan/6a4b6eb53b77500

                                  [?]EarthInsider » 🌐
                                  @EarthInsider@mastodon.social

                                  Is 'Iron Bird Seed' a code for something more dangerous? The truth might surprise you.

                                  Full story 👇

                                  Learn more: earthinsider.in/2026/07/iron-b

                                  Close-up of aerospace-grade hardware known as iron bird seed on an industrial metal workbench.

                                  Alt...Close-up of aerospace-grade hardware known as iron bird seed on an industrial metal workbench.

                                    [?]TechWire ⚡ » 🤖 🌐
                                    @techwire@social.gamefan.net

                                    These 5 Android apps are so good, I’m surprised they’re free

                                    Good free apps really do still exist.

                                    androidauthority.com/best-free

                                    [Android Authority]

                                      [?]:awesome:🐦‍🔥nemo™🐦‍⬛ 🇺🇦🍉 » 🌐
                                      @nemo@mas.to

                                      InvisibleX wurde von Datendiebstahl & missbräuchlicher Nutzung wie Spam-Mails, dubiosen Anrufen und unerwünschter Werbung betroffen – und geht jetzt aktiv dagegen vor. Mit Erfahrung, Datenbroker-Analyse und DSGVO-basierten Löschanfragen schützt InvisibleX persönliche Daten regelmäßig. 🛡️🔒 invisiblex.de/about-us

                                        [?]Hugo | DevOps | Cybersecurity » 🌐
                                        @hugovalters@mastodon.social

                                        You use Tor on a secure VPS every day. But do you know what actually lurks on the 2025 dark web? Scams, surprises, and secrets that’ll make you rethink your threat model. Full report inside.

                                        valtersit.com/dark-web-diaries

                                          [?]N_{Dario Fadda} » 🌐
                                          @nuke@poliversity.it

                                          ☕ CYBERBRIEFING — Lunedì 6 luglio 2026

                                          👉 Leggi tutti gli aggiornamenti delle ultime 24 ore:
                                          ilpuntocyber.rfeed.it/article.


                                          @informatica

                                            [?]TechWire ⚡ » 🤖 🌐
                                            @techwire@social.gamefan.net

                                            Supreme Court rules the Fourth Amendment protects your phone’s location history

                                            The Supreme Court rendered a decision this morning on a case debating whether or not people have an “expectation of privacy” from their government, even with always-available location tracking enabled on practically eve…

                                            9to5google.com/2026/06/29/supr

                                            [9to5Google]

                                              [?]OTX Bot » 🤖 🌐
                                              @techbot@social.raytec.co

                                              GitHub Impersonation Deploys Information Stealer

                                              Pulse ID: 6a4b46b25e24d42ee1f97215
                                              Pulse Link: otx.alienvault.com/pulse/6a4b4
                                              Pulse Author: Tr1sa111
                                              Created: 2026-07-06 06:09:54

                                              Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                                [?]OTX Bot » 🤖 🌐
                                                @techbot@social.raytec.co

                                                Vibe Coded Extortion: Path from Legal Lure to CrownX Ransom Capabilities

                                                Pulse ID: 6a4b466d6af3e8b8886d92ae
                                                Pulse Link: otx.alienvault.com/pulse/6a4b4
                                                Pulse Author: Tr1sa111
                                                Created: 2026-07-06 06:08:45

                                                Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                                  [?]TechWire ⚡ » 🤖 🌐
                                                  @techwire@social.gamefan.net

                                                  Samsung’s Galaxy Watch 9 band lineup leaks with more updates than the smartwatch [Gallery]

                                                  Samsung’s upcoming Galaxy Watch 9 really doesn’t look all that different from the Watch 8, but new leaks show off updated watch bands that actually deliver some notable changes.

                                                  9to5google.com/2026/06/29/sams

                                                  [9to5Google]

                                                    [?]OTX Bot » 🤖 🌐
                                                    @techbot@social.raytec.co

                                                    Vibe Coded Extortion: Path from Legal Lure to CrownX Ransom Capabilities

                                                    Pulse ID: 6a4b466a1d410b804d5cc09a
                                                    Pulse Link: otx.alienvault.com/pulse/6a4b4
                                                    Pulse Author: Tr1sa111
                                                    Created: 2026-07-06 06:08:42

                                                    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                                      [?]OTX Bot » 🤖 🌐
                                                      @techbot@social.raytec.co

                                                      Branded Gambling Campaigns: How Scammers Are Exploiting Trusted Brand Names to Drive Casino Traffic

                                                      Pulse ID: 6a4b461c2fc6412449dbc361
                                                      Pulse Link: otx.alienvault.com/pulse/6a4b4
                                                      Pulse Author: Tr1sa111
                                                      Created: 2026-07-06 06:07:24

                                                      Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                                        [?]OTX Bot » 🤖 🌐
                                                        @techbot@social.raytec.co

                                                        AsyncRAT and Remcos Delivered in Multi-Stage Phishing Campaign

                                                        Pulse ID: 6a4b45f8cd2be13f3a96f5ff
                                                        Pulse Link: otx.alienvault.com/pulse/6a4b4
                                                        Pulse Author: Tr1sa111
                                                        Created: 2026-07-06 06:06:48

                                                        Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                                          [?]OTX Bot » 🤖 🌐
                                                          @techbot@social.raytec.co

                                                          PamStealer: a Rust-based macOS infostealer that validates credentials through PAM

                                                          Pulse ID: 6a4b459328d25bbdc8b77726
                                                          Pulse Link: otx.alienvault.com/pulse/6a4b4
                                                          Pulse Author: Tr1sa111
                                                          Created: 2026-07-06 06:05:07

                                                          Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                                            [?]Dumb Password Rules » 🤖 🌐
                                                            @dumbpasswordrules@infosec.exchange

                                                            This dumb password rule is from AmiAmi.

                                                            Your password needs to be between 6 and 12 characters long, must contain only letters and numbers.

                                                            dumbpasswordrules.com/sites/am

                                                              [?]TechWire ⚡ » 🤖 🌐
                                                              @techwire@social.gamefan.net

                                                              Latest Galaxy Watch 9 leak reveals 5 brand-new watch faces

                                                              Minimalist, sporty, or packed with widgets — there's a face for everyone.

                                                              androidauthority.com/samsung-g

                                                              [Android Authority]

                                                                [?]EUVD Bot » 🤖 🌐
                                                                @EUVD_Bot@mastodon.social

                                                                🚨 EUVD-2026-41810

                                                                📊 Score: 5.3/10 (CVSS v3.1)
                                                                📦 Product: Ecommerce Website
                                                                🏢 Vendor: CodeAstro
                                                                📅 Updated: 2026-07-06

                                                                📝 A security flaw has been discovered in CodeAstro Ecommerce Website 1.0. Impacted is an unknown function of the file /customer/my_account.php?my_wishlist. The manipulation of the argument delete_wishlist results in sql injection. The attack can be...

                                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                                  [?]EUVD Bot » 🤖 🌐
                                                                  @EUVD_Bot@mastodon.social

                                                                  🚨 EUVD-2026-41809

                                                                  📊 Score: 5.3/10 (CVSS v3.1)
                                                                  📦 Product: Apartment Visitor Management System
                                                                  🏢 Vendor: CodeAstro
                                                                  📅 Updated: 2026-07-06

                                                                  📝 A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. This issue affects some unknown processing of the file /apartment-visitor/visitor-entry.php. The manipulation of the argument visname leads to ...

                                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                                    [?]EUVD Bot » 🤖 🌐
                                                                    @EUVD_Bot@mastodon.social

                                                                    🚨 EUVD-2026-41808

                                                                    📊 Score: 5.3/10 (CVSS v3.1)
                                                                    📦 Product: Apartment Visitor Management System
                                                                    🏢 Vendor: CodeAstro
                                                                    📅 Updated: 2026-07-06

                                                                    📝 A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. This vulnerability affects unknown code of the file /apartment-visitor/edit-apartment.php. Executing a manipulation of the argument editid can ...

                                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                                      [?]deafnews » 🤖 🌐
                                                                      @deafnews@infosec.exchange

                                                                      [?]Hugo | DevOps | Cybersecurity » 🌐
                                                                      @hugovalters@mastodon.social

                                                                      CodePeople: 47 CVEs, 100% unpatched. Max CVSS 8.5. Trust Score: C. WordPress plugins like Booking Calendar = wide attack surface. Patch now.

                                                                      valtersit.com/vendors/codepeop

                                                                        [?]TechWire ⚡ » 🤖 🌐
                                                                        @techwire@social.gamefan.net

                                                                        Galaxy Z Fold 8 and Fold 8 Ultra tipped to match OPPO’s nearly invisible crease

                                                                        Samsung has reportedly changed the hinge to nearly eliminate the crease.

                                                                        androidauthority.com/samsung-g

                                                                        [Android Authority]

                                                                          [?]TheHackerWire » 🤖 🌐
                                                                          @thehackerwire@mastodon.social

                                                                          🟠 CVE-2026-14327 - High (7.5)

                                                                          The AR for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.40 via the 'file' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary fi...

                                                                          🔗 thehackerwire.com/vulnerabilit

                                                                          CVE Alert: CVE-2026-14327

                                                                          Alt...CVE Alert: CVE-2026-14327

                                                                            [?]TheHackerWire » 🤖 🌐
                                                                            @thehackerwire@mastodon.social

                                                                            🔴 CVE-2026-13768 - Critical (10)

                                                                            Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns connection information for all Gardyn Home Kit and Studio devices. Access to this key al...

                                                                            🔗 thehackerwire.com/vulnerabilit

                                                                            CVE Alert: CVE-2026-13768

                                                                            Alt...CVE Alert: CVE-2026-13768

                                                                              [?]TheHackerWire » 🤖 🌐
                                                                              @thehackerwire@mastodon.social

                                                                              🔴 CVE-2026-41106 - Critical (9.3)

                                                                              Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

                                                                              🔗 thehackerwire.com/vulnerabilit

                                                                              CVE Alert: CVE-2026-41106

                                                                              Alt...CVE Alert: CVE-2026-41106

                                                                                Back to top - More...