voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
🚨 EUVD-2025-210420
📊 Score: 7.6/10 (CVSS v3.1)
📦 Product: picklescan
🏢 Vendor: Picklescan
📅 Updated: 2026-07-04
📝 picklescan before 0.0.28 fails to detect malicious torch.utils.bottleneck.__main__.run_cprofile function calls in pickle files, allowing attackers to bypass safety checks. Remote attackers can embed undetected code in pickle files to achieve arbitrar...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-210420
🚨 EUVD-2025-210419
📊 Score: 7.6/10 (CVSS v3.1)
📦 Product: picklescan
🏢 Vendor: Picklescan
📅 Updated: 2026-07-04
📝 picklescan before 0.0.30 fails to detect the asyncio.unix_events._UnixSubprocessTransport._start function in pickle reduce methods, allowing remote code execution. Attackers can craft malicious pickle files embedding this built-in function that evade...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-210419
🚨 EUVD-2025-210418
📊 Score: 7.6/10 (CVSS v3.1)
📦 Product: picklescan
🏢 Vendor: Picklescan
📅 Updated: 2026-07-04
📝 picklescan before 0.0.33 fails to detect unsafe deserialization when numpy.f2py.crackfortran functions call eval on arbitrary strings. Attackers can embed malicious code in pickle files that executes when loaded from untrusted sources.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-210418
🚨 EUVD-2025-210417
📊 Score: 7.6/10 (CVSS v3.1)
📦 Product: picklescan
🏢 Vendor: Picklescan
📅 Updated: 2026-07-04
📝 picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.calltip.get_entity function in reduce methods. Attackers can embed undetected code in pickle files that executes remote commands when loaded by victims.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-210417
🚨 EUVD-2025-210416
📊 Score: 7.6/10 (CVSS v3.1)
📦 Product: picklescan
🏢 Vendor: Picklescan
📅 Updated: 2026-07-04
📝 picklescan before 0.0.29 fails to detect malicious pickle payloads that utilize lib2to3.pgen2.grammar.Grammar.loads in the reduce method, allowing remote code execution. Attackers can craft pickle files embedding dangerous code that evades picklescan...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-210416
🚨 EUVD-2025-210415
📊 Score: 7.6/10 (CVSS v3.1)
📦 Product: picklescan
🏢 Vendor: Picklescan
📅 Updated: 2026-07-04
📝 picklescan before 0.0.28 fails to detect malicious torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expression function calls in pickle files. Attackers can embed undetected code in pickle files that executes remote code when loaded by ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-210415
🚨 EUVD-2025-210414
📊 Score: 7.6/10 (CVSS v3.1)
📦 Product: picklescan
🏢 Vendor: Picklescan
📅 Updated: 2026-07-04
📝 picklescan before 0.0.28 fails to detect malicious pickle files that exploit torch._dynamo.guards.GuardBuilder.get function in reduce methods. Attackers can craft pickle files with embedded code that evades picklescan detection and executes arbitrary...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-210414
🚨 EUVD-2025-210413
📊 Score: 7.6/10 (CVSS v3.1)
📦 Product: picklescan
🏢 Vendor: Picklescan
📅 Updated: 2026-07-04
📝 picklescan before 0.0.33 fails to detect malicious pickle files using numpy.f2py.crackfortran.param_eval function in reduce methods, allowing attackers to bypass security checks. Remote attackers can embed undetected code in pickle files that execute...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-210413
🚨 EUVD-2025-210412
📊 Score: 7.6/10 (CVSS v3.1)
📦 Product: picklescan
🏢 Vendor: Picklescan
📅 Updated: 2026-07-04
📝 picklescan before 0.0.30 fails to detect malicious pickle files that invoke torch.utils.bottleneck.__main__.run_autograd_prof function. Attackers can embed undetected code in pickle files that executes during deserialization, enabling remote code exe...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-210412
🚨 EUVD-2025-210411
📊 Score: 7.6/10 (CVSS v3.1)
📦 Product: picklescan
🏢 Vendor: Picklescan
📅 Updated: 2026-07-04
📝 picklescan before 0.0.30 fails to detect malicious pickle files that exploit lib2to3.pgen2.pgen.ParserGenerator.make_label function in the reduce method. Attackers can craft malicious pickle files with embedded code that evades detection but executes...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-210411
🚨 EUVD-2025-210410
📊 Score: 7.6/10 (CVSS v3.1)
📦 Product: picklescan
🏢 Vendor: Picklescan
📅 Updated: 2026-07-04
📝 picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.run.Executive.runcode in reduce methods. Attackers can embed undetected code in pickle files that executes during pickle.load, enabling remote code execution in PyTorch mod...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-210410
🚨 EUVD-2026-41656
📊 Score: 7.8/10 (CVSS v3.1)
📦 Product: nltk/nltk
🏢 Vendor: nltk
📅 Updated: 2026-07-04
📝 In nltk/nltk versions 3.9.3 and earlier, five Stanford interface classes (StanfordPOSTagger, StanfordNERTagger, StanfordParser, StanfordDependencyParser, and StanfordNeuralDependencyParser) are vulnerable to untrusted JAR code execution. These classes accept ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41656
#chrome extension ImTranslator: Translator, Dictionary, TTS seems malicious. Its #cybersecurity badness score is 93/100!
```json
{"id": "bbofakpgfmlfjpjcahodgpbddocpibge", "score": 93, "platform": "chrome", "name": "ImTranslator: Translator, Dictionary, TTS"}
```
#chrome extension Image Downloader - Batch Download Image seems malicious. Its #cybersecurity badness score is 98/100!
```json
{"id": "ngeoikidkjbegoifbnmfimacmbilfcgi", "score": 98, "platform": "chrome", "name": "Image Downloader - Batch Download Image"}
```
#chrome extension imcbcfmohachfahkbgijokokjpfmoogb seems malicious. Its #cybersecurity badness score is 86/100!
```json
{"id": "imcbcfmohachfahkbgijokokjpfmoogb", "score": 86, "platform": "chrome", "name": "imcbcfmohachfahkbgijokokjpfmoogb"}
```
#chrome extension AI Weather Forecast seems malicious. Its #cybersecurity badness score is 100/100!
```json
{"id": "iaehhmhmdidpkfmddiodkloefndpggcj", "score": 100, "platform": "chrome", "name": "AI Weather Forecast"}
```
iPhone 18 With 9GB RAM Still Won't Support Two New iOS 27 Features
The lower-end iPhone 18 and iPhone 18e will be equipped with 9GB of RAM, up from 8GB in the iPhone 17 and iPhone 17e, according to supply chain analyst Ming-Chi Kuo. In a social media post, Kuo said the 1GB increase in …
https://www.macrumors.com/2026/07/03/iphone-18-wont-support-two-ios-27-features/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #MacRumors [MacRumors]
🖲️ #Cybersecurity #Ciberseguridad #Ciberseguranca #Security #Seguridad #Seguranca #News #Noticia #Noticias #Tecnologia #Technology
⚫ FortiBleed Actors Collaborating With Inc, Lynx Ransomware Gangs
🔗 https://www.darkreading.com/threat-intelligence/fortibleed-actors-inc-lynx-ransomware-gangs
After gaining a foothold in thousands of Fortinet firewalls, the attackers are starting to monetize that access, and are also piling on a Nextcloud zero-day bug.
🖲️ #Cybersecurity #Ciberseguridad #Ciberseguranca #Security #Seguridad #Seguranca #News #Noticia #Noticias #Tecnologia #Technology
⚫ Chinese LLMs Broaden the Gap Between Attackers & Defenders
🔗 https://www.darkreading.com/cyber-risk/chinese-llms-broaden-gap-between-attackers-and-defenders
Two new models from Chinese firms compete with top US mainstream and frontier models. Should cyber-defenders be worried?
🟠 CVE-2026-14605 - High (7.8)
A vulnerability was identified in RT-Thread up to 5.0.2. Affected by this vulnerability is the function recvmsg in the library bsp/loongson/ls1cdev/libraries/ls1c_can.h of the component ls1c CAN Handler. Such manipulation leads to stack-based buff...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14605/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-14606 - High (7.8)
A security flaw has been discovered in RT-Thread up to 5.0.2. Affected by this issue is the function CAN_Receive in the library bsp/synwit/libraries/SWM341_CSL/CMSIS/DeviceSupport/SWM341.h of the component SWM341 CAN Handler. Performing a manipula...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14606/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-10055 - High (8.5)
In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client connected to the standard /services messaging endpoint, performs the HTTP request server-side, and returns the full...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-10055/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Intel confirms price hikes on select consumer and server CPUs citing supply costs and demand — select Xeon processors now over $1,000 more expensive
Intel confirms price increases for Core Ultra 200S Plus, Xeon 6 processors, cites market dynamics, rising costs, soaring demand.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
Espionage Against the European Parliament
https://citizenlab.ca/research/member-of-committee-investigating-spyware-hacked-with-pegasus/
#HackerNews #Espionage #EuropeanParliament #Pegasus #Spyware #CyberSecurity #Privacy
Intel reportedly adding two new 22-core SKUs with game-boosting cache to Nova Lake-S lineup — 125W unlocked and 65W loc…
Intel is apparently cooking up two new 22-core Nova Lake-S SKUs with up to 144MB of bLLC. One is a locked 65W variant and one is an unlocked 125W part, and both are said to be part of the Core Ultra 5 tier.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
Ethics and politics of quantum computing #negativepid #digitalInvestigations #OSINT #cybersecurity #AI #tech #onlineInvestigations #robotics #cyberpsychology #cybercrime https://negativepid.blog/ethics-and-politics-of-quantum-computing/?utm_source=mastodon&utm_medium=social&utm_campaign=fedica-Negative-PID-Blog
"Security researchers have confirmed that a European politician had his phone hacked with the Pegasus spyware while serving on an investigatory committee probing abuses of the notorious surveillance tool. This has reignited fresh controversy over governments abusing spyware to collect information about their critics.
The researchers at the University of Toronto’s digital rights unit The Citizen Lab say the confirmed phone hacking of Greek journalist and former politician Stelios Kouloglou during 2022 and 2023 marks the first time that a member of the European Parliament’s PEGA committee, tasked with investigating phone spyware attacks by European governments, has been publicly identified as a victim of spyware.
Kouloglou told TechCrunch in a phone call that the deliberate compromise of his phone was “reckless.” One serving European lawmaker described the hacking of Kouloglou’s phone as a “direct attack on the rule of law,” and called on the European Commission to take concrete action by imposing strict limits on the use of spyware across the 27 member-state bloc."
Turtle Beach KP7 Review: The accessory that does everything
Turtle Beach's KP7 keypad can be used with its KB7 keyboard or as a standalone macropad. And it's nice — but pricey.
https://www.tomshardware.com/peripherals/gaming-keyboards/turtle-beach-kp7-review
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
Security Tip: Leverage Virtual Patching to close the 'Patch Gap'. 🛡️ When a vulnerability is disclosed, there's often a delay before an official vendor patch is ready. Virtual patching via Web Application Firewalls (WAF) or Intrusion Prevention Systems (IPS) can block exploit attempts at the network edge. This buys your team critical time to test and deploy the official update without rushing. Stay ahead of threats: https://cvedatabase.com #CVE #CyberSecurity #Infosec
Possible Phishing 🎣
on: ⚠️hxxps[:]//3223-664[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a481c8c3b77500003e55d2d
#cybersecurity #phishing #infosec #urldna #scam #infosec
#chrome extension Adblock for Youtube™ seems malicious. Its #cybersecurity badness score is 87/100!
```json
{"id": "nipggfgilmoiofmnkbeabghbcaohmjih", "score": 87, "platform": "chrome", "name": "Adblock for Youtube\u2122"}
```
#chrome extension AdSkip-iQIYI seems malicious. Its #cybersecurity badness score is 92/100!
```json
{"id": "mimmainmmkddahakleojidjaimaofndp", "score": 92, "platform": "chrome", "name": "AdSkip-iQIYI"}
```
#chrome extension Video Downloader Premium seems malicious. Its #cybersecurity badness score is 98/100!
```json
{"id": "jgphopeamnghlcekffldkpnbhmiadnbc", "score": 98, "platform": "chrome", "name": "Video Downloader Premium"}
```
#chrome extension Batch Image Downloader seems malicious. Its #cybersecurity badness score is 91/100!
```json
{"id": "hnleilhpfbdofpdnnpjggafhncienakg", "score": 91, "platform": "chrome", "name": "Batch Image Downloader"}
```
Anthropic's Claude Fable 5 Available Again After U.S. Lifts Export Controls
Anthropic's Fable 5 model is once again available for use, the company said today. Claude users are now seeing the option to use Fable 5, with Anthropic rolling out an in-app message. Through July 7, eligible Claude sub…
https://www.macrumors.com/2026/07/01/anthropic-fable-5-relaunch/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #MacRumors [MacRumors]
Elevating Privileges from Firefox to Android Root
#HackerNews #ElevatingPrivileges #Firefox #AndroidRoot #CyberSecurity #HackingNews
Apple Ramps Foldable iPhone 'Ultra' Production to 10 Million Units
Apple has told suppliers to prepare to make approximately 10 million foldable iPhones this year, up from a previous forecast of about 7-8 million units a few months ago, reports Nikkei Asia ($). Apple has already booked…
https://www.macrumors.com/2026/07/02/apple-ramps-foldable-iphone-ultra-production-10m/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #MacRumors [MacRumors]
🚨 EUVD-2026-41654
📊 Score: 2.3/10 (CVSS v3.1)
📦 Product: hermes-agent, hermes-agent, hermes-agent (+28 more)
🏢 Vendor: NousResearch
📅 Updated: 2026-07-03
📝 A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. Affected is the function GatewayStreamConsumer._filter_and_accumulate of the file gateway/stream_consumer.py of the comp...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41654
🚨 EUVD-2026-41653
📊 Score: 6.5/10 (CVSS v3.1)
📦 Product: Microsoft Edge (Chromium-based)
🏢 Vendor: Microsoft
📅 Updated: 2026-07-03
📝 Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41653
🚨 EUVD-2026-41612
📊 Score: n/a
📦 Product: Gitea Open Source Git Server
🏢 Vendor: Gitea
📅 Updated: 2026-07-03
📝 Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web archive download endpoint.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41612
Possible Phishing 🎣
on: ⚠️hxxps[:]//alibabacarelogin[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a4838a93b7750000956cdba
#cybersecurity #phishing #infosec #urldna #scam #infosec
Popular Show Tracking App TV Time Shutting Down on July 15
TV Time, the popular show and movie tracking app, is shutting down on July 15, with all personal user data set to be deleted after that date. In a support page update announcing the news, the company admitted that it wa…
https://www.macrumors.com/2026/07/02/show-tracking-app-tv-time-shutting-down/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #MacRumors [MacRumors]
🟠 CVE-2026-14459 - High (8.8)
Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection.
This issue affects pardus-software: from <= ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14459/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-14460 - High (8.8)
Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection.
This issue affects pardus-software: from <= 1.0.4 before 1.0.5.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14460/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
While you’re watching the World Cup, the feds may be watching you
It's a big year for America. It's the semiquincentennial, otherwise known as America250, and the United States is cohosting the World Cup. But spectators at these events - and the millions of people who live in the citi…
https://www.theverge.com/policy/961004/world-cup-america-250-surveillance-drones-cameras
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Amazon updated 2023’s Fire HD 10 tablet with 4GB of RAM
The Fire HD 8 that launched in 2024 was the last new addition to Amazon's budget-minded tablet lineup, but the company has quietly updated the Fire HD 10 that debuted the year before. In 2023 it was offered with multipl…
https://www.theverge.com/tech/961387/amazon-2023-fire-hd-10-tablet-4gb-update
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]