voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]EUVD Bot » 🤖 🌐
@EUVD_Bot@mastodon.social

🚨 EUVD-2026-41681

📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: Ecommerce-CodeIgniter-Bootstrap
🏢 Vendor: kirilkirkov
📅 Updated: 2026-07-04

📝 A security flaw has been discovered in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 222ff31c06687b1c6d0e1ab63953f82c3674c52b. This issue affects some unknown processing of the file application/modules/vendor/controllers/AddPr...

🔗 euvd.enisa.europa.eu/vulnerabi

    [?]EUVD Bot » 🤖 🌐
    @EUVD_Bot@mastodon.social

    🚨 EUVD-2026-41680

    📊 Score: 5.3/10 (CVSS v3.1)
    📦 Product: Ecommerce-CodeIgniter-Bootstrap
    🏢 Vendor: kirilkirkov
    📅 Updated: 2026-07-04

    📝 A vulnerability was identified in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 213babdbaa949e94557246414db0130e01394517. This vulnerability affects the function checkForPostRequests of the file application/core/MY_Controller....

    🔗 euvd.enisa.europa.eu/vulnerabi

      [?]urlDNA.io :verified: » 🤖 🌐
      @urldna@infosec.exchange

      Possible Phishing 🎣
      on: ⚠️hxxps[:]//amazon-ui-clone-pi[.]vercel[.]app
      🧬 Analysis at: urldna.io/scan/6a48cb943b77500

        [?]TechWire ⚡ » 🤖 🌐
        @techwire@social.gamefan.net

        Apple Pay now lets you pay using American Express points

        American Express has announced a new way for cardholders to redeem their rewards points: they can be used to pay for Apple Pay transactions. Here are the details.

        9to5mac.com/2026/06/30/apple-p

        [9to5Mac]

          [?]TechWire ⚡ » 🤖 🌐
          @techwire@social.gamefan.net

          Supreme Court agrees to hear Apple appeal over Epic Games ruling

          The US Supreme Court has agreed to hear Apple’s appeal over a lower court ruling that held the company in contempt related to its Epic Games case and app fees. Update: Apple has shared a statement with 9to5Mac about the…

          9to5mac.com/2026/06/30/supreme

          [9to5Mac]

            [?]urlDNA.io :verified: » 🤖 🌐
            @urldna@infosec.exchange

            Possible Phishing 🎣
            on: ⚠️hxxps[:]//inner[.]website/476f7088fwcf6e4a115bc8eceadb20162a48[.]html
            🧬 Analysis at: urldna.io/scan/6a492e153b77500

              [?]TechWire ⚡ » 🤖 🌐
              @techwire@social.gamefan.net

              Cibby is a beautifully designed iOS app for physical video game collectors

              Here’s a cool new thing coming son: Cibby, a beautifully designed iOS app for physical video game collectors.

              9to5mac.com/2026/06/30/cibby-i

              [9to5Mac]

                [?]TechWire ⚡ » 🤖 🌐
                @techwire@social.gamefan.net

                Anthropic just released a brand-new Claude Science app for Mac

                Anthropic just launched a brand-new desktop app called Claude Science. The new app joins the main Claude app on the Mac, which includes Claude AI, Cowork, and Code.

                9to5mac.com/2026/06/30/anthrop

                [9to5Mac]

                  [?]urlDNA.io :verified: » 🤖 🌐
                  @urldna@infosec.exchange

                  Possible Phishing 🎣
                  on: ⚠️hxxps[:]//loginacnancymetzfridpprofileoidcauthorexecutione1s333[.]weebly[.]com
                  🧬 Analysis at: urldna.io/scan/6a4919a53b77500

                    [?]EUVD Bot » 🤖 🌐
                    @EUVD_Bot@mastodon.social

                    🚨 EUVD-2026-41683

                    📊 Score: 5.3/10 (CVSS v3.1)
                    📦 Product: Ecommerce Website
                    🏢 Vendor: CodeAstro
                    📅 Updated: 2026-07-04

                    📝 A vulnerability has been found in CodeAstro Ecommerce Website 1.0. This impacts an unknown function of the file /ecommerce-website-php/customer/my_account.php?edit_account. Such manipulation of the argument c_name leads to sql injection. The atta...

                    🔗 euvd.enisa.europa.eu/vulnerabi

                      [?]EUVD Bot » 🤖 🌐
                      @EUVD_Bot@mastodon.social

                      🚨 EUVD-2026-41687

                      📊 Score: n/a
                      📦 Product: Plack::Middleware::OAuth
                      🏢 Vendor: CORNELIUS
                      📅 Updated: 2026-07-04

                      📝 Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter.

                      RequestTokenV2 builds the provider authorization redirect without issuing a state value, and AccessTokenV2 exchanges the callback code and registers th...

                      🔗 euvd.enisa.europa.eu/vulnerabi

                        [?]EUVD Bot » 🤖 🌐
                        @EUVD_Bot@mastodon.social

                        🚨 EUVD-2026-41686

                        📊 Score: n/a
                        📦 Product: Dancer2::Plugin::Auth::OAuth::Provider
                        🏢 Vendor: BIAFRA
                        📅 Updated: 2026-07-04

                        📝 Dancer2::Plugin::Auth::OAuth::Provider versions before 0.23 for Perl do not support the OAuth 2.0 state parameter.

                        The authentication_url method builds the provider authorization redirect without issuing a state value, and the callback method...

                        🔗 euvd.enisa.europa.eu/vulnerabi

                          [?]EUVD Bot » 🤖 🌐
                          @EUVD_Bot@mastodon.social

                          🚨 EUVD-2026-41685

                          📊 Score: 5.3/10 (CVSS v3.1)
                          📦 Product: Hospital Management System
                          🏢 Vendor: itsourcecode
                          📅 Updated: 2026-07-04

                          📝 A flaw has been found in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /patient.php. This manipulation of the argument editid causes sql injection. The attack may be initiated remotely. The ...

                          🔗 euvd.enisa.europa.eu/vulnerabi

                            [?]EUVD Bot » 🤖 🌐
                            @EUVD_Bot@mastodon.social

                            🚨 EUVD-2026-41684

                            📊 Score: 8.8/10 (CVSS v3.1)
                            📦 Product: Ecommerce-CodeIgniter-Bootstrap
                            🏢 Vendor: kirilkirkov
                            📅 Updated: 2026-07-04

                            📝 A security vulnerability has been detected in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 13fd582aaf49aeab7438acc0fc3eb973a1f5e6a7. The affected element is the function getCartItems in the library application/libraries/Shopp...

                            🔗 euvd.enisa.europa.eu/vulnerabi

                              [?]Hugo | DevOps | Cybersecurity » 🌐
                              @hugovalters@mastodon.social

                              Nagios: 135 CVEs, 97% unpatched. Trust Score: D. 57 XSS flaws (CWE-79). Avg CVSS 8.0. Open-source monitoring ≠ secure by default. Patch your Nagios NOW.

                              valtersit.com/vendors/nagios/

                                [?]CTI.FYI » 🤖 🌐
                                @CTI_FYI@infosec.exchange

                                🚨New ransom group blog posts!🚨

                                Group name: qilin
                                Post title: TQ Financial Services
                                Info: cti.fyi/groups/qilin.html

                                Group name: qilin
                                Post title: Sisint
                                Info: cti.fyi/groups/qilin.html

                                Group name: qilin
                                Post title: Sitmatic
                                Info: cti.fyi/groups/qilin.html

                                Group name: qilin
                                Post title: Goodwill Manasota
                                Info: cti.fyi/groups/qilin.html

                                Group name: qilin
                                Post title: Md Lewis
                                Info: cti.fyi/groups/qilin.html

                                  [?]TechWire ⚡ » 🤖 🌐
                                  @techwire@social.gamefan.net

                                  NASA launched an emergency mission to stop the Swift Observatory from crashing to Earth

                                  Engineers from Katalyst Space Technologies testing Link. | Image: NASA/Scott Wiessinger The Swift Observatory was launched in 2004, but recent solar storms have pushed its orbit lower, and it's in danger of burning up i…

                                  theverge.com/science/961459/na

                                  [The Verge]

                                    [?]Hugo | DevOps | Cybersecurity » 🌐
                                    @hugovalters@mastodon.social

                                    The Dark Web wasn't created by hackers—it was built by the US government for spy communications. Tor hides your identity with three layers of encryption. Learn how it works and why most of it is perfectly legal.

                                    valtersit.com/who-created-and-

                                      [?]TechWire ⚡ » 🤖 🌐
                                      @techwire@social.gamefan.net

                                      Memory price surge begins to cool as consumers hit affordability limit — AI demand still keeps DRAM and NAND prices climbing through Q3 2026

                                      TrendForce says DRAM and NAND prices will continue to rise through Q3 2026, but AI-driven gains are slowing as PC and smartphone makers reach their affordability limits.

                                      tomshardware.com/pc-components

                                      [Tom's Hardware]

                                        [?]AmmarSpaces » 🌐
                                        @AmmarSpaces@infosec.exchange

                                        So, Agentic ransomware are now a thing huh? I still a bit skeptic though, but I am very welcome to any crazy shits that happen in infosecverse.

                                        Via Bleeping Computer

                                        sysdig.com/blog/jadepuffer-age

                                          [?]urlDNA.io :verified: » 🤖 🌐
                                          @urldna@infosec.exchange

                                          Possible Phishing 🎣
                                          on: ⚠️hxxp[:]//instagram-2-0-4p6f5s6nd-chibokaxavier[.]vercel[.]app
                                          🧬 Analysis at: urldna.io/scan/6a48c55f3b77500

                                            [?]TechWire ⚡ » 🤖 🌐
                                            @techwire@social.gamefan.net

                                            AOC U27G4XM 27-inch 4K 160 Hz Dual-Refresh Gaming Monitor Review: Speed, Flexibility And Value

                                            AOC brings speed, flexibility, and value in its U27G4XM. It’s a 27-inch dual-mode IPS panel with 4K resolution at 160 Hz, FHD resolution at 320 Hz and Adaptive-Sync. It also has a Mini LED backlight with 1,000 nits for …

                                            tomshardware.com/monitors/gami

                                            [Tom's Hardware]

                                              [?]Graham Perrin » 🌐
                                              @grahamperrin@mastodon.bsd.cafe

                                              Beijing Plane Crash Tests China's Security State – FP

                                              foreignpolicy.com/2026/06/30/c

                                              ― The highlights this week: Fallout from a fatal plane crash in Beijing ripples through the security state, a Chinese billionaire is sentenced to 30 years in U.S. prison, and Chinese artificial intelligence models close the U.S. lead on cybersecurity. …

                                                [?]TechWire ⚡ » 🤖 🌐
                                                @techwire@social.gamefan.net

                                                Meta data center water discharges suspended after contaminating the city's water supply with bacterium — closed-loop cooling system purge spread rare metal-resistant bacterium in…

                                                Fill-and-flush is a commissioning step whereby crews fill a cooling loop's piping with water and flush it to clear debris before the system is run.

                                                tomshardware.com/tech-industry

                                                [Tom's Hardware]

                                                  [?]TheHackerWire » 🤖 🌐
                                                  @thehackerwire@mastodon.social

                                                  🟠 CVE-2026-14535 - High (8.8)

                                                  In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls AnalysisContext.shorten_code(node) on every import node it inspects, regardless of whether the import is flagged as unsafe. This...

                                                  🔗 thehackerwire.com/vulnerabilit

                                                  CVE Alert: CVE-2026-14535

                                                  Alt...CVE Alert: CVE-2026-14535

                                                    [?]urlDNA.io :verified: » 🤖 🌐
                                                    @urldna@infosec.exchange

                                                    Possible Phishing 🎣
                                                    on: ⚠️hxxps[:]//www[.]robiox[.]com[.]ps/users/4233503025/profile
                                                    🧬 Analysis at: urldna.io/scan/6a48b7343b77500

                                                      [?]TheHackerWire » 🤖 🌐
                                                      @thehackerwire@mastodon.social

                                                      🟠 CVE-2026-14534 - High (8.8)

                                                      Trail of Bits fickling versions up to and including 0.1.10 do not include the Python standard library modules _posixsubprocess, site, and atexit in the UNSAFE_IMPORTS denylist (fickle.py). Because these modules are absent from the denylist, fickli...

                                                      🔗 thehackerwire.com/vulnerabilit

                                                      CVE Alert: CVE-2026-14534

                                                      Alt...CVE Alert: CVE-2026-14534

                                                        [?]EUVD Bot » 🤖 🌐
                                                        @EUVD_Bot@mastodon.social

                                                        🚨 EUVD-2026-41676

                                                        📊 Score: 8.8/10 (CVSS v3.1)
                                                        📦 Product: fickling
                                                        🏢 Vendor: trailofbits
                                                        📅 Updated: 2026-07-04

                                                        📝 In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls AnalysisContext.shorten_code(node) on every import node it inspects, regardless of whether the import is flagged as unsafe. This call ...

                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                          [?]EUVD Bot » 🤖 🌐
                                                          @EUVD_Bot@mastodon.social

                                                          🚨 EUVD-2026-41675

                                                          📊 Score: 8.8/10 (CVSS v3.1)
                                                          📦 Product: fickling
                                                          🏢 Vendor: trailofbits
                                                          📅 Updated: 2026-07-04

                                                          📝 Trail of Bits fickling versions up to and including 0.1.10 do not include the Python standard library modules _posixsubprocess, site, and atexit in the UNSAFE_IMPORTS denylist (fickle.py). Because these modules are absent from the denylist, fickling's c...

                                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                                            [?]EUVD Bot » 🤖 🌐
                                                            @EUVD_Bot@mastodon.social

                                                            🚨 EUVD-2026-41674

                                                            📊 Score: 5.3/10 (CVSS v3.1)
                                                            📦 Product: RT-Thread, RT-Thread, RT-Thread
                                                            📅 Updated: 2026-07-04

                                                            📝 A flaw has been found in RT-Thread up to 5.2.2. Affected is the function read/write/sys_ioctl of the file components/lwp/lwp_syscall.c of the component Parameter Handler. Executing a manipulation can lead to divide by zero. The attack may be launched r...

                                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                                              [?]TheHackerWire » 🤖 🌐
                                                              @thehackerwire@mastodon.social

                                                              🟠 CVE-2025-71343 - High (8.1)

                                                              picklescan before 0.0.30 fails to detect malicious pickle files that exploit lib2to3.pgen2.pgen.ParserGenerator.make_label function in the reduce method. Attackers can craft malicious pickle files with embedded code that evades detection but execu...

                                                              🔗 thehackerwire.com/vulnerabilit

                                                              CVE Alert: CVE-2025-71343

                                                              Alt...CVE Alert: CVE-2025-71343

                                                                [?]TheHackerWire » 🤖 🌐
                                                                @thehackerwire@mastodon.social

                                                                🟠 CVE-2025-71345 - High (8.1)

                                                                picklescan before 0.0.30 fails to detect malicious pickle files that invoke torch.utils.bottleneck.__main__.run_autograd_prof function. Attackers can embed undetected code in pickle files that executes during deserialization, enabling remote code ...

                                                                🔗 thehackerwire.com/vulnerabilit

                                                                CVE Alert: CVE-2025-71345

                                                                Alt...CVE Alert: CVE-2025-71345

                                                                  [?]TheHackerWire » 🤖 🌐
                                                                  @thehackerwire@mastodon.social

                                                                  🟠 CVE-2025-71347 - High (8.1)

                                                                  picklescan before 0.0.33 fails to detect malicious pickle files using numpy.f2py.crackfortran.param_eval function in reduce methods, allowing attackers to bypass security checks. Remote attackers can embed undetected code in pickle files that exec...

                                                                  🔗 thehackerwire.com/vulnerabilit

                                                                  CVE Alert: CVE-2025-71347

                                                                  Alt...CVE Alert: CVE-2025-71347

                                                                    [?]deafnews » 🤖 🌐
                                                                    @deafnews@infosec.exchange

                                                                    JadePuffer: The First Agentic Ransomware — AI Automates the Entire Kill Chain deafnews.it/en/article/jadepuf

                                                                      [?]TechWire ⚡ » 🤖 🌐
                                                                      @techwire@social.gamefan.net

                                                                      Flatbush Zombies’ Erick the Architect misses his BlackBerry keyboard

                                                                      That is the face of a man who enjoys what he does. | Image: Reato Morris Erick the Architect is a founding member of, and the primary producer for, the legendary Flatbush Zombies. He's toured the world, performed on Kim…

                                                                      theverge.com/entertainment/960

                                                                      [The Verge]

                                                                        [?]TierraSapiens » 🤖 🌐
                                                                        @tierrasapiens@mastodon.social

                                                                        🖲️
                                                                        ⚫ Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS
                                                                        🔗 darkreading.com/application-se

                                                                        Attackers fingerprint victims through user-agent data to deliver OS-specific payloads, increasing compromise rates and campaign profitability.

                                                                          [?]BeeSINT » 🌐
                                                                          @BeeSINT@mastodon.social

                                                                          [?]BeeSINT » 🌐
                                                                          @BeeSINT@mastodon.social

                                                                          💾 🟠 Moody Bible Institute (moody.edu)
                                                                          ✓ Verified
                                                                          📊 ~2.3M records compromised
                                                                          📂 Dates of birth, Email addresses, Genders, Marital statuses +3 more
                                                                          📅 2026-06-15 · disclosed 18d after incident
                                                                          🌐 cloudflare
                                                                          ⚠️ No SPF/DMARC configured

                                                                          🔗 beesint.com/pulse/3a83792c-203

                                                                            [?]BeyondMachines :verified: » 🤖 🌐
                                                                            @beyondmachines1@infosec.exchange

                                                                            IBM Patches High-Severity XSS Flaws in WebSphere Application Server

                                                                            IBM released security updates for WebSphere Application Server to fix three cross-site scripting vulnerabilities, including a high-severity flaw on the login page that allows attackers to hijack administrative sessions.

                                                                            **Restrict access to your WebSphere administrative console so it's only reachable from trusted internal networks, and enable multi-factor authentication on all admin accounts. Then apply IBM's interim fix for APAR PH71757 ASAP, and plan to upgrade to Fix Pack 9.0.5.29 (for version 9.0) or 8.5.5.30 (for version 8.5) as soon as they're released.**

                                                                            beyondmachines.net/event_detai

                                                                              [?]𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 :verified: » 🌐
                                                                              @youranonnewsirc@nerdculture.de

                                                                              ... [SENSITIVE CONTENT]

                                                                              Recent 24-hour news: Cybersecurity faces active exploitation of Microsoft Defender (BlueHammer) & SharePoint RCE, plus new DirtyClone Linux flaw. An AI-driven ransomware attack via Langflow vulnerability was reported. Geopolitically, US-Iran talks paused for Khamenei's funeral, while Russia claims control of Kostiantynivka. Anthropic's Fable 5 AI model is globally re-released following lifted US export controls. (July 3-4, 2026).

                                                                                [?]Hugo | DevOps | Cybersecurity » 🌐
                                                                                @hugovalters@mastodon.social

                                                                                Cacti: 45 CVEs, avg CVSS 7.19, max 10. 100% unpatched. 1 CISA KEV exploited. Trust Score: D. Open-source network monitor needs urgent patching.

                                                                                valtersit.com/vendors/cacti/

                                                                                  [?]TechWire ⚡ » 🤖 🌐
                                                                                  @techwire@social.gamefan.net

                                                                                  [?]Malicious Extension Bot » 🤖 🌐
                                                                                  @malicious_browser_bot@infosec.exchange

                                                                                  extension kakgeonhimhojdncehlopejkfaapboeo seems malicious. Its badness score is 92/100!

                                                                                  ```json
                                                                                  {"id": "kakgeonhimhojdncehlopejkfaapboeo", "score": 92, "platform": "chrome", "name": "kakgeonhimhojdncehlopejkfaapboeo"}
                                                                                  ```

                                                                                    [?]eteryu » 🌐
                                                                                    @eteryu@infosec.exchange

                                                                                    Jak szybko przejść od rzucania oskarżeń do zablokowania rozmówcy? Krótka historia mojej dyskusji z profilem @czynna.

                                                                                    Wszystko zaczęło się od ich głośnych zapowiedzi o masowej inwigilacji. Z czystej ciekawości zacząłem dopytywać w komentarzach o techniczne szczegóły i dowody. Druga strona przy każdym pytaniu regularnie stosowała klasyczne „przesuwanie bramki". Uciekali od konkretów i serwowali wyłącznie ogólniki, linki promocyjne czy screeny z darmowych wtyczek do przeglądarki.

                                                                                    Gdy nadal czekałem na jakiekolwiek konkrety, wrzuciłem u siebie luźny wpis o Open’erze. Pokazałem w nim ludziom, że przed opisywanym profilowaniem można obronić się samemu w ustawieniach telefonu, i oznaczyłem w tym poście drugą stronę. Efekt? Zamiast odpowiedzi na techniczne pytania, dostałem po prostu natychmiastową blokadę konta.

                                                                                    Szkoda, bo liczyłem na poważną debatę o prywatności. Okazało się jednak, że chęć kręcenia dramy wygrała z otwartością na merytoryczne pytania. Mam mimo wszystko nadzieję, że kiedyś jeszcze doczekam się konkretnej odpowiedzi na moje pytania.

                                                                                    Rozmowa ze Stroną Czynną

                                                                                    Alt...Rozmowa ze Stroną Czynną

                                                                                      Back to top - More...