voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
🚨 EUVD-2026-41743
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: Smart Parking System
🏢 Vendor: code-projects
📅 Updated: 2026-07-05
📝 A vulnerability has been found in code-projects Smart Parking System 1.0. The affected element is an unknown function of the file /parkings/parkings.php. Such manipulation of the argument street/city/status leads to sql injection. The atta...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41743
🚨 EUVD-2026-41742
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: Class and Exam Timetabling System
🏢 Vendor: SourceCodester
📅 Updated: 2026-07-05
📝 A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the file /edit_product.php. This manipulation of the argument ID causes sql injection. Remote exploitation of t...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41742
Possible Phishing 🎣
on: ⚠️hxxps[:]//facebookloginaccount[.]blogspot[.]com/?m=1
🧬 Analysis at: https://urldna.io/scan/6a49de8d3b77500004856c71
#cybersecurity #phishing #infosec #urldna #scam #infosec
I tried a hidden Android Auto feature Google doesn’t want you to know about
Welcome to the world of sideloading Android Auto apps.
https://www.androidauthority.com/sideload-apps-android-auto-hidden-feature-3681820/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
🚨 EUVD-2026-41724
📊 Score: 4.8/10 (CVSS v3.1)
📦 Product: markdownify-mcp, markdownify-mcp
🏢 Vendor: zcaceres
📅 Updated: 2026-07-05
📝 A weakness has been identified in zcaceres markdownify-mcp up to 1.1.0. The affected element is the function assertPathAllowed of the file src/Markdownify.ts. Executing a manipulation can lead to symlink following. The attack can on...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41724
🚨 EUVD-2026-41723
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Syllabus-aligned Learning Management and Examination System
🏢 Vendor: SourceCodester
📅 Updated: 2026-07-05
📝 A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management and Examination System 1.0. Impacted is an unknown function of the file upload_files.php. Performing a manip...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41723
MacBook Pro models sharing the MacBook Ultra redesign is, and isn’t, surprising
We’ve been hearing for a long time now that a new high-end MacBook Ultra model with a touchscreen will get a significant redesign with a slimmer form factor. The new design appeared to be one of the things that would di…
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
This dumb password rule is from Nelnet (student loan servicer).
8 to 15 characters and no spaces? Why no spaces? Also limited to only these 6 special characters. That could mean that there is some process somewhere that puts this as part of a command line invocation.
https://dumbpasswordrules.com/sites/nelnet-student-loan-servicer/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
Malware found spreading through sponsored ad on X
Jamf Threat Labs, the company’s security research arm, recently shared details of a ClickFix-style attack it spotted running as a sponsored ad on the social media site X. Originating from a well-known verified account, …
https://9to5mac.com/2026/07/02/malware-found-spreading-through-sponsored-ads-on-x/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
That whole #JADEPUFFER feels like someone pointed a LLM based CTF toolkit against a (claimed) live target running an old unpatched langflow.
It's attacks were regurgitated stuff; like snippets from CTF and PoC writeups, down to the variables used.
The "ransomware" part is what I'll dub cyber-LARPing, where it destroyed MYSQL content by encrypting it with a random key, didn't store the key, didn't exfil any data, and dropped a bitcoin address in the ransomware note straight out of documentation.
I have no idea what to make of it, except I'm not at all surprised a cyber security company that has fully redPilled AI, creates hype around an LLM "autonomously" attacking a broken vibe-coded AI Agent deployment framework. But kudos for the "Agentic Threat Actor/ ATA" acronym.
May I suggest my own acronym for this? #TARP: Threat Actor Role Playing.
TLDR: It all feels... fake. But maybe the future of cyber attacks is LLMs destroying even more of the internet playing pretend?
https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion
Possible Phishing 🎣
on: ⚠️hxxp[:]//verificarmicuentaa-microsoft2o26[.]zya[.]me/?i=1
🧬 Analysis at: https://urldna.io/scan/6a49ec9c3b77500009f77f4a
#cybersecurity #phishing #infosec #urldna #scam #infosec
iOS 27 makes a very strong case for upgrading to a new iPhone
Most years, major iOS updates offer the same basic feature set on new iPhones and old ones. But with iOS 27 things are different, and anyone with an iPhone 15 or older will miss out on a lot of new features. Here’s why …
https://9to5mac.com/2026/07/02/ios-27-makes-a-very-strong-case-for-upgrading-to-a-new-iphone/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
Apple TV has five new movies premiering soon, here’s what’s coming
Apple TV has a strong lineup of shows about to debut, kicking off with tonight’s Silo season 3 premiere. But there are five new movies on the Apple TV schedule too, here’s what’s coming.
https://9to5mac.com/2026/07/02/apple-tv-has-five-new-movies-premiering-soon-heres-whats-coming/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
🚨 EUVD-2026-41730
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: GoClaw, GoClaw, GoClaw
🏢 Vendor: nextlevelbuilder
📅 Updated: 2026-07-05
📝 A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.13.0-beta.2. Impacted is the function MethodRouter.Handle of the file internal/gateway/router.go of the component WebSocket RPC Handler. Such manipulation l...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41730
🚨 EUVD-2026-41729
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: chatgpt-on-wechat CowAgent
🏢 Vendor: zhayujie
📅 Updated: 2026-07-05
📝 A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.1.0. This issue affects the function verify_server of the file channel/wechatmp/common.py of the component wx Endpoint. This manipulation of the argument wechatmp_tok...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41729
🚨 EUVD-2026-41728
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: Pizzafy E-Commerce System
🏢 Vendor: SourceCodester
📅 Updated: 2026-07-05
📝 A security flaw has been discovered in SourceCodester Pizzafy E-Commerce System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=confirm_order. The manipulation of the argument ID results in sql injecti...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41728
🚨 EUVD-2026-41727
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Online Examination
🏢 Vendor: code-projects
📅 Updated: 2026-07-05
📝 A vulnerability was identified in code-projects Online Examination 1.0. This affects an unknown part of the file /update.php?q=addquiz of the component Quiz Creation Feature. The manipulation of the argument name/total/right/wrong/time/tag/d...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41727
🚨 EUVD-2026-41726
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: Online Examination
🏢 Vendor: code-projects
📅 Updated: 2026-07-05
📝 A vulnerability was determined in code-projects Online Examination 1.0. Affected by this issue is some unknown functionality of the file head.php. Executing a manipulation of the argument uname/password can lead to sql injection. It is possi...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41726
Possible Phishing 🎣
on: ⚠️hxxps[:]//kineticwebmaill[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a497c2b3b7750000964f475
#cybersecurity #phishing #infosec #urldna #scam #infosec
🚨 EUVD-2026-41725
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: bluebox, bluebox, bluebox (+10 more)
🏢 Vendor: stephen-kruger
📅 Updated: 2026-07-05
📝 A vulnerability was found in stephen-kruger bluebox up to 4.5.12. Affected by this vulnerability is an unknown functionality. Performing a manipulation of the argument code results in cross site scripting. It is possible t...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41725
Deals: AirPods 4 nearly 25% off, M5 iPad Pro $350 off, M4 iPad Air, Apple accessories from $15, more
Alongside the ongoing all-time low on the 4-pack of Apple’s latest AirTag 2, today’s 9to5Toys Lunch Break is headlined by Amazon still offering Apple’s AirPods 4 at nearly 25% off ahead of July 4th and the pre-price hik…
https://9to5mac.com/2026/07/02/deals-airpods-4-m5-ipad-pro-m4-ipad-air-airtag-2/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
🚨 An AI found one Linux kernel bug... but completely missed its sibling.
That missed flaw became Bad Epoll (CVE-2026-46242).
A tiny race condition in Linux's `epoll` subsystem can let an ordinary local user become root with a 99% reliable exploit. It affects Linux systems and can even be chained in Android attack scenarios.
In my latest deep dive, I break down:
🔍 Why the vulnerability stayed hidden
⚡ How a 10-instruction race window was weaponized
🧠 Why AI detected one bug but missed this one
💥 The exploit chain from race condition to root shell
🛡️ Detection, mitigation, and patch guidance
📖 Full article:
https://thecybersecguru.com/exploits/cve-2026-46242-bad-epoll-linux-vulnerability/
🔁 Repost to help more Linux users and security professionals stay informed.
#Linux #CyberSecurity #InfoSec #LinuxKernel #CVE #BadEpoll #ExploitDevelopment #PrivilegeEscalation #Kernel #RedTeam #BlueTeam #EthicalHacking #AndroidSecurity #SecurityResearch
Vim: 54 CVEs, 81% unpatched, avg CVSS 5.1. Max CVSS 9.2. Trust Score: C. Top weaknesses: buffer overflows & injection. Open-source editors need vigilance. #Vim #infosec #cybersecurity
iOS 27 breaks 15 years of muscle memory on iPhone and iPad
Since iOS 5 in 2011, the iPhone and iPad have included Notification Center, a central place to find alerts from various apps in chronological order. Starting with iOS 27, Apple is making a major change to how users open…
https://9to5mac.com/2026/07/01/ios-27-just-broke-15-years-of-muscle-memory-on-iphone-and-ipad/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
MLB app gives baseball fans a new iPhone and iPad real-time scores widget
Baseball season is well underway, and the MLB app just gave fans a new way to keep up with real-time scores and more.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
Apple TV teases major new sci-fi series: Neuromancer
Apple TV has no shortage of excellent sci-fi series (including Silo, which returns tomorrow), and it just shared a teaser for what could be its next big hit: Neuromancer.
https://9to5mac.com/2026/07/01/apple-tv-teases-major-new-sci-fi-series-neuromancer/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
Apple launches ‘How Did We Lose This World?’ site for Silo season 3
Silo season 3 premieres Thursday night, and Apple has just launched a new website to promote the show. It’s called ‘How Did We Lose This World?’ and contains exclusive clips, cryptic images, and more.
https://9to5mac.com/2026/07/01/apple-launches-how-did-we-lose-this-world-site-for-silo-season-3/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
Musk denies SpaceX developing AI hardware product that’s ‘slimmer than an iPhone’ [U]
Apple isn’t the only company with AI-focused products in the works. According to a new report, SpaceX has an artificial intelligence hardware prototype that’s “slimmer than an iPhone” in development. Update: Musk has de…
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
Possible Phishing 🎣
on: ⚠️hxxps[:]//psdmknyi[.]firebaseapp[.]com
🧬 Analysis at: https://urldna.io/scan/6a499e933b7750000964f6f9
#cybersecurity #phishing #infosec #urldna #scam #infosec
Claude Fable 5 cleared to return as US lifts Anthropic’s export control restriction [U: Now available]
Update July 1, 3:30 p.m: Claude Fable 5 is now available to users globally on the Claude Platform, Claude.ai, Claude Code, and Claude Cowork. As a reminder, for “Pro, Max, Team, and select Enterprise plans, Fable 5 will…
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
🛡️ Brave just released browser v1.92 with built-in Containers for secure account isolation—letting users open tabs in separate identities so cookies and site data stay confined per container. Phased rollout across Windows, macOS & Linux. 🔐 https://cyberinsider.com/brave-browser-introduces-containers-for-secure-account-isolation/ #Brave #Privacy #CyberSecurity #BrowserUpdates #AccountIsolation
🤖 Researchers at runZero say AI-assisted testing found 7 security flaws in the FatFs FAT/exFAT filesystem library (CVE-2026-6682 to CVE-2026-6688), potentially exposing millions of embedded devices via malicious USB drives/SD cards—and sometimes OTA update paths. 🔓📉 https://cyberinsider.com/ai-helps-find-flaws-in-fatfs-library-used-in-millions-of-devices/ #cybersecurity #IoT #vulnerabilities #embedded
The New York Times app adopts Liquid Glass on iPhone
The official New York Times app on iOS now supports Apple’s Liquid Glass design as of its latest update.
https://9to5mac.com/2026/07/01/the-new-york-times-app-adopts-liquid-glass-on-iphone/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
🛡️ New macOS infostealer “PamStealer” validates victims’ stolen passwords via macOS Pluggable Authentication Modules (PAM) before exfiltration. 🚨 Jamf Threat Labs found a 2-stage AppleScript/JXA/Rust chain, persistence via fake Finder/login items, and encrypted data theft. #macOS #Malware #CyberSecurity https://cyberinsider.com/new-macos-malware-pamstealer-uses-pam-to-validate-stolen-data/
🚨 Security researchers report 6 previously undocumented flaws in Apple AirDrop and Google/Samsung Quick Share that could enable wireless attacks—ranging from DoS crashes to authentication/encryption bypasses and even a potential RCE risk on Windows. 🔎📲 Learn more: https://cyberinsider.com/apple-airdrop-and-android-quick-share-flaws-expose-users-to-wireless-attacks/ #Apple #Android #Security #Cybersecurity #AirDrop #QuickShare
🟠 CVE-2026-58286 - High (8.1)
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58286/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🚨 EUVD-2026-41714
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Multi-Vendor Online Grocery Management System
🏢 Vendor: SourceCodester
📅 Updated: 2026-07-05
📝 A security vulnerability has been detected in SourceCodester Multi-Vendor Online Grocery Management System 1.0. This impacts the function update_settings_info of the file classes/SystemSettings.php of the componen...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41714
🚨 EUVD-2026-41713
📊 Score: n/a
📦 Product: Crypt::DSA
🏢 Vendor: TIMLEGGE
📅 Updated: 2026-07-05
📝 Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key from a biased random generator, leading to private-key recovery.
"Crypt::DSA::Util::makerandom forces the high bit of every value it returns to obtain an exactly N-bit integer for prim...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41713
🚨 EUVD-2026-41712
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: Multi-Vendor Online Grocery Management System
🏢 Vendor: SourceCodester
📅 Updated: 2026-07-05
📝 A weakness has been identified in SourceCodester Multi-Vendor Online Grocery Management System 1.0. This affects the function save_users of the file classes/Users.php. This manipulation causes improper authorizati...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41712
🚨 EUVD-2026-41711
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Apartment Visitor Management System
🏢 Vendor: CodeAstro
📅 Updated: 2026-07-05
📝 A security flaw has been discovered in CodeAstro Apartment Visitor Management System 1.0. The impacted element is an unknown function of the file /apartment-visitor/add-apartment.php. The manipulation of the argument apartmentno...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41711
🟠 CVE-2026-58287 - High (8.3)
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58287/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Possible Phishing 🎣
on: ⚠️hxxps[:]//netflix-clone-phi-blush-77[.]vercel[.]app
🧬 Analysis at: https://urldna.io/scan/6a496e093b7750000964f31a
#cybersecurity #phishing #infosec #urldna #scam #infosec
🟠 CVE-2026-58288 - High (8.3)
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58288/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Report: MacBook price hikes expected to contribute to 13.6% drop in global laptop shipments
A new TrendForce report says MacBook price hikes will contribute to a 13.6% drop in global laptop shipments, although Apple is still expected to outperform the broader market. Here are the details.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]