voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]EUVD Bot » 🤖 🌐
@EUVD_Bot@mastodon.social

🚨 EUVD-2025-210420

📊 Score: 7.6/10 (CVSS v3.1)
📦 Product: picklescan
🏢 Vendor: Picklescan
📅 Updated: 2026-07-04

📝 picklescan before 0.0.28 fails to detect malicious torch.utils.bottleneck.__main__.run_cprofile function calls in pickle files, allowing attackers to bypass safety checks. Remote attackers can embed undetected code in pickle files to achieve arbitrar...

🔗 euvd.enisa.europa.eu/vulnerabi

    [?]EUVD Bot » 🤖 🌐
    @EUVD_Bot@mastodon.social

    🚨 EUVD-2025-210419

    📊 Score: 7.6/10 (CVSS v3.1)
    📦 Product: picklescan
    🏢 Vendor: Picklescan
    📅 Updated: 2026-07-04

    📝 picklescan before 0.0.30 fails to detect the asyncio.unix_events._UnixSubprocessTransport._start function in pickle reduce methods, allowing remote code execution. Attackers can craft malicious pickle files embedding this built-in function that evade...

    🔗 euvd.enisa.europa.eu/vulnerabi

      [?]EUVD Bot » 🤖 🌐
      @EUVD_Bot@mastodon.social

      🚨 EUVD-2025-210418

      📊 Score: 7.6/10 (CVSS v3.1)
      📦 Product: picklescan
      🏢 Vendor: Picklescan
      📅 Updated: 2026-07-04

      📝 picklescan before 0.0.33 fails to detect unsafe deserialization when numpy.f2py.crackfortran functions call eval on arbitrary strings. Attackers can embed malicious code in pickle files that executes when loaded from untrusted sources.

      🔗 euvd.enisa.europa.eu/vulnerabi

        [?]EUVD Bot » 🤖 🌐
        @EUVD_Bot@mastodon.social

        🚨 EUVD-2025-210417

        📊 Score: 7.6/10 (CVSS v3.1)
        📦 Product: picklescan
        🏢 Vendor: Picklescan
        📅 Updated: 2026-07-04

        📝 picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.calltip.get_entity function in reduce methods. Attackers can embed undetected code in pickle files that executes remote commands when loaded by victims.

        🔗 euvd.enisa.europa.eu/vulnerabi

          [?]EUVD Bot » 🤖 🌐
          @EUVD_Bot@mastodon.social

          🚨 EUVD-2025-210416

          📊 Score: 7.6/10 (CVSS v3.1)
          📦 Product: picklescan
          🏢 Vendor: Picklescan
          📅 Updated: 2026-07-04

          📝 picklescan before 0.0.29 fails to detect malicious pickle payloads that utilize lib2to3.pgen2.grammar.Grammar.loads in the reduce method, allowing remote code execution. Attackers can craft pickle files embedding dangerous code that evades picklescan...

          🔗 euvd.enisa.europa.eu/vulnerabi

            [?]EUVD Bot » 🤖 🌐
            @EUVD_Bot@mastodon.social

            🚨 EUVD-2025-210415

            📊 Score: 7.6/10 (CVSS v3.1)
            📦 Product: picklescan
            🏢 Vendor: Picklescan
            📅 Updated: 2026-07-04

            📝 picklescan before 0.0.28 fails to detect malicious torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expression function calls in pickle files. Attackers can embed undetected code in pickle files that executes remote code when loaded by ...

            🔗 euvd.enisa.europa.eu/vulnerabi

              [?]EUVD Bot » 🤖 🌐
              @EUVD_Bot@mastodon.social

              🚨 EUVD-2025-210414

              📊 Score: 7.6/10 (CVSS v3.1)
              📦 Product: picklescan
              🏢 Vendor: Picklescan
              📅 Updated: 2026-07-04

              📝 picklescan before 0.0.28 fails to detect malicious pickle files that exploit torch._dynamo.guards.GuardBuilder.get function in reduce methods. Attackers can craft pickle files with embedded code that evades picklescan detection and executes arbitrary...

              🔗 euvd.enisa.europa.eu/vulnerabi

                [?]EUVD Bot » 🤖 🌐
                @EUVD_Bot@mastodon.social

                🚨 EUVD-2025-210413

                📊 Score: 7.6/10 (CVSS v3.1)
                📦 Product: picklescan
                🏢 Vendor: Picklescan
                📅 Updated: 2026-07-04

                📝 picklescan before 0.0.33 fails to detect malicious pickle files using numpy.f2py.crackfortran.param_eval function in reduce methods, allowing attackers to bypass security checks. Remote attackers can embed undetected code in pickle files that execute...

                🔗 euvd.enisa.europa.eu/vulnerabi

                  [?]EUVD Bot » 🤖 🌐
                  @EUVD_Bot@mastodon.social

                  🚨 EUVD-2025-210412

                  📊 Score: 7.6/10 (CVSS v3.1)
                  📦 Product: picklescan
                  🏢 Vendor: Picklescan
                  📅 Updated: 2026-07-04

                  📝 picklescan before 0.0.30 fails to detect malicious pickle files that invoke torch.utils.bottleneck.__main__.run_autograd_prof function. Attackers can embed undetected code in pickle files that executes during deserialization, enabling remote code exe...

                  🔗 euvd.enisa.europa.eu/vulnerabi

                    [?]EUVD Bot » 🤖 🌐
                    @EUVD_Bot@mastodon.social

                    🚨 EUVD-2025-210411

                    📊 Score: 7.6/10 (CVSS v3.1)
                    📦 Product: picklescan
                    🏢 Vendor: Picklescan
                    📅 Updated: 2026-07-04

                    📝 picklescan before 0.0.30 fails to detect malicious pickle files that exploit lib2to3.pgen2.pgen.ParserGenerator.make_label function in the reduce method. Attackers can craft malicious pickle files with embedded code that evades detection but executes...

                    🔗 euvd.enisa.europa.eu/vulnerabi

                      [?]EUVD Bot » 🤖 🌐
                      @EUVD_Bot@mastodon.social

                      🚨 EUVD-2025-210410

                      📊 Score: 7.6/10 (CVSS v3.1)
                      📦 Product: picklescan
                      🏢 Vendor: Picklescan
                      📅 Updated: 2026-07-04

                      📝 picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.run.Executive.runcode in reduce methods. Attackers can embed undetected code in pickle files that executes during pickle.load, enabling remote code execution in PyTorch mod...

                      🔗 euvd.enisa.europa.eu/vulnerabi

                        [?]EUVD Bot » 🤖 🌐
                        @EUVD_Bot@mastodon.social

                        🚨 EUVD-2026-41656

                        📊 Score: 7.8/10 (CVSS v3.1)
                        📦 Product: nltk/nltk
                        🏢 Vendor: nltk
                        📅 Updated: 2026-07-04

                        📝 In nltk/nltk versions 3.9.3 and earlier, five Stanford interface classes (StanfordPOSTagger, StanfordNERTagger, StanfordParser, StanfordDependencyParser, and StanfordNeuralDependencyParser) are vulnerable to untrusted JAR code execution. These classes accept ...

                        🔗 euvd.enisa.europa.eu/vulnerabi

                          [?]Malicious Extension Bot » 🤖 🌐
                          @malicious_browser_bot@infosec.exchange

                          extension ImTranslator: Translator, Dictionary, TTS seems malicious. Its badness score is 93/100!

                          ```json
                          {"id": "bbofakpgfmlfjpjcahodgpbddocpibge", "score": 93, "platform": "chrome", "name": "ImTranslator: Translator, Dictionary, TTS"}
                          ```

                            [?]Malicious Extension Bot » 🤖 🌐
                            @malicious_browser_bot@infosec.exchange

                            extension Image Downloader - Batch Download Image seems malicious. Its badness score is 98/100!

                            ```json
                            {"id": "ngeoikidkjbegoifbnmfimacmbilfcgi", "score": 98, "platform": "chrome", "name": "Image Downloader - Batch Download Image"}
                            ```

                              [?]Malicious Extension Bot » 🤖 🌐
                              @malicious_browser_bot@infosec.exchange

                              extension imcbcfmohachfahkbgijokokjpfmoogb seems malicious. Its badness score is 86/100!

                              ```json
                              {"id": "imcbcfmohachfahkbgijokokjpfmoogb", "score": 86, "platform": "chrome", "name": "imcbcfmohachfahkbgijokokjpfmoogb"}
                              ```

                                [?]Malicious Extension Bot » 🤖 🌐
                                @malicious_browser_bot@infosec.exchange

                                extension AI Weather Forecast seems malicious. Its badness score is 100/100!

                                ```json
                                {"id": "iaehhmhmdidpkfmddiodkloefndpggcj", "score": 100, "platform": "chrome", "name": "AI Weather Forecast"}
                                ```

                                  [?]TechWire ⚡ » 🤖 🌐
                                  @techwire@social.gamefan.net

                                  iPhone 18 With 9GB RAM Still Won't Support Two New iOS 27 Features

                                  The lower-end iPhone 18 and iPhone 18e will be equipped with 9GB of RAM, up from 8GB in the iPhone 17 and iPhone 17e, according to supply chain analyst Ming-Chi Kuo. In a social media post, Kuo said the 1GB increase in …

                                  macrumors.com/2026/07/03/iphon

                                  [MacRumors]

                                    [?]TierraSapiens » 🤖 🌐
                                    @tierrasapiens@mastodon.social

                                    🖲️
                                    ⚫ FortiBleed Actors Collaborating With Inc, Lynx Ransomware Gangs
                                    🔗 darkreading.com/threat-intelli

                                    After gaining a foothold in thousands of Fortinet firewalls, the attackers are starting to monetize that access, and are also piling on a Nextcloud zero-day bug.

                                      [?]TierraSapiens » 🤖 🌐
                                      @tierrasapiens@mastodon.social

                                      🖲️
                                      ⚫ Chinese LLMs Broaden the Gap Between Attackers & Defenders
                                      🔗 darkreading.com/cyber-risk/chi

                                      Two new models from Chinese firms compete with top US mainstream and frontier models. Should cyber-defenders be worried?

                                        [?]TheHackerWire » 🤖 🌐
                                        @thehackerwire@mastodon.social

                                        🟠 CVE-2026-14605 - High (7.8)

                                        A vulnerability was identified in RT-Thread up to 5.0.2. Affected by this vulnerability is the function recvmsg in the library bsp/loongson/ls1cdev/libraries/ls1c_can.h of the component ls1c CAN Handler. Such manipulation leads to stack-based buff...

                                        🔗 thehackerwire.com/vulnerabilit

                                        CVE Alert: CVE-2026-14605

                                        Alt...CVE Alert: CVE-2026-14605

                                          [?]TheHackerWire » 🤖 🌐
                                          @thehackerwire@mastodon.social

                                          🟠 CVE-2026-14606 - High (7.8)

                                          A security flaw has been discovered in RT-Thread up to 5.0.2. Affected by this issue is the function CAN_Receive in the library bsp/synwit/libraries/SWM341_CSL/CMSIS/DeviceSupport/SWM341.h of the component SWM341 CAN Handler. Performing a manipula...

                                          🔗 thehackerwire.com/vulnerabilit

                                          CVE Alert: CVE-2026-14606

                                          Alt...CVE Alert: CVE-2026-14606

                                            [?]TheHackerWire » 🤖 🌐
                                            @thehackerwire@mastodon.social

                                            🟠 CVE-2026-10055 - High (8.5)

                                            In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client connected to the standard /services messaging endpoint, performs the HTTP request server-side, and returns the full...

                                            🔗 thehackerwire.com/vulnerabilit

                                            CVE Alert: CVE-2026-10055

                                            Alt...CVE Alert: CVE-2026-10055

                                              [?]TechWire ⚡ » 🤖 🌐
                                              @techwire@social.gamefan.net

                                              Intel confirms price hikes on select consumer and server CPUs citing supply costs and demand — select Xeon processors now over $1,000 more expensive

                                              Intel confirms price increases for Core Ultra 200S Plus, Xeon 6 processors, cites market dynamics, rising costs, soaring demand.

                                              tomshardware.com/pc-components

                                              [Tom's Hardware]

                                                [?]Negative PID SL » 🌐
                                                @negativepid@mastodon.social

                                                [?]Hacker News » 🤖 🌐
                                                @h4ckernews@mastodon.social

                                                [?]TechWire ⚡ » 🤖 🌐
                                                @techwire@social.gamefan.net

                                                Intel reportedly adding two new 22-core SKUs with game-boosting cache to Nova Lake-S lineup — 125W unlocked and 65W loc…

                                                Intel is apparently cooking up two new 22-core Nova Lake-S SKUs with up to 144MB of bLLC. One is a locked 65W variant and one is an unlocked 125W part, and both are said to be part of the Core Ultra 5 tier.

                                                tomshardware.com/pc-components

                                                [Tom's Hardware]

                                                  [?]Negative PID SL » 🌐
                                                  @negativepid@mastodon.social

                                                  [?]Miguel Afonso Caetano » 🌐
                                                  @remixtures@tldr.nettime.org

                                                  "Security researchers have confirmed that a European politician had his phone hacked with the Pegasus spyware while serving on an investigatory committee probing abuses of the notorious surveillance tool. This has reignited fresh controversy over governments abusing spyware to collect information about their critics.

                                                  The researchers at the University of Toronto’s digital rights unit The Citizen Lab say the confirmed phone hacking of Greek journalist and former politician Stelios Kouloglou during 2022 and 2023 marks the first time that a member of the European Parliament’s PEGA committee, tasked with investigating phone spyware attacks by European governments, has been publicly identified as a victim of spyware.

                                                  Kouloglou told TechCrunch in a phone call that the deliberate compromise of his phone was “reckless.” One serving European lawmaker described the hacking of Kouloglou’s phone as a “direct attack on the rule of law,” and called on the European Commission to take concrete action by imposing strict limits on the use of spyware across the 27 member-state bloc."

                                                  techcrunch.com/2026/07/02/poli

                                                    [?]TechWire ⚡ » 🤖 🌐
                                                    @techwire@social.gamefan.net

                                                    Turtle Beach KP7 Review: The accessory that does everything

                                                    Turtle Beach's KP7 keypad can be used with its KB7 keyboard or as a standalone macropad. And it's nice — but pricey.

                                                    tomshardware.com/peripherals/g

                                                    [Tom's Hardware]

                                                      [?]CVEDatabase.com » 🌐
                                                      @cvedatabase@techhub.social

                                                      Security Tip: Leverage Virtual Patching to close the 'Patch Gap'. 🛡️ When a vulnerability is disclosed, there's often a delay before an official vendor patch is ready. Virtual patching via Web Application Firewalls (WAF) or Intrusion Prevention Systems (IPS) can block exploit attempts at the network edge. This buys your team critical time to test and deploy the official update without rushing. Stay ahead of threats: cvedatabase.com

                                                        [?]urlDNA.io :verified: » 🤖 🌐
                                                        @urldna@infosec.exchange

                                                        Possible Phishing 🎣
                                                        on: ⚠️hxxps[:]//3223-664[.]weebly[.]com
                                                        🧬 Analysis at: urldna.io/scan/6a481c8c3b77500

                                                          [?]Malicious Extension Bot » 🤖 🌐
                                                          @malicious_browser_bot@infosec.exchange

                                                          extension Adblock for Youtube™ seems malicious. Its badness score is 87/100!

                                                          ```json
                                                          {"id": "nipggfgilmoiofmnkbeabghbcaohmjih", "score": 87, "platform": "chrome", "name": "Adblock for Youtube\u2122"}
                                                          ```

                                                            [?]Malicious Extension Bot » 🤖 🌐
                                                            @malicious_browser_bot@infosec.exchange

                                                            extension AdSkip-iQIYI seems malicious. Its badness score is 92/100!

                                                            ```json
                                                            {"id": "mimmainmmkddahakleojidjaimaofndp", "score": 92, "platform": "chrome", "name": "AdSkip-iQIYI"}
                                                            ```

                                                              [?]Malicious Extension Bot » 🤖 🌐
                                                              @malicious_browser_bot@infosec.exchange

                                                              extension Video Downloader Premium seems malicious. Its badness score is 98/100!

                                                              ```json
                                                              {"id": "jgphopeamnghlcekffldkpnbhmiadnbc", "score": 98, "platform": "chrome", "name": "Video Downloader Premium"}
                                                              ```

                                                                [?]Malicious Extension Bot » 🤖 🌐
                                                                @malicious_browser_bot@infosec.exchange

                                                                extension Batch Image Downloader seems malicious. Its badness score is 91/100!

                                                                ```json
                                                                {"id": "hnleilhpfbdofpdnnpjggafhncienakg", "score": 91, "platform": "chrome", "name": "Batch Image Downloader"}
                                                                ```

                                                                  [?]TechWire ⚡ » 🤖 🌐
                                                                  @techwire@social.gamefan.net

                                                                  Anthropic's Claude Fable 5 Available Again After U.S. Lifts Export Controls

                                                                  Anthropic's Fable 5 model is once again available for use, the company said today. Claude users are now seeing the option to use Fable 5, with Anthropic rolling out an in-app message. Through July 7, eligible Claude sub…

                                                                  macrumors.com/2026/07/01/anthr

                                                                  [MacRumors]

                                                                    [?]Hacker News » 🤖 🌐
                                                                    @h4ckernews@mastodon.social

                                                                    [?]TechWire ⚡ » 🤖 🌐
                                                                    @techwire@social.gamefan.net

                                                                    Apple Ramps Foldable iPhone 'Ultra' Production to 10 Million Units

                                                                    Apple has told suppliers to prepare to make approximately 10 million foldable iPhones this year, up from a previous forecast of about 7-8 million units a few months ago, reports Nikkei Asia ($). Apple has already booked…

                                                                    macrumors.com/2026/07/02/apple

                                                                    [MacRumors]

                                                                      [?]EUVD Bot » 🤖 🌐
                                                                      @EUVD_Bot@mastodon.social

                                                                      🚨 EUVD-2026-41654

                                                                      📊 Score: 2.3/10 (CVSS v3.1)
                                                                      📦 Product: hermes-agent, hermes-agent, hermes-agent (+28 more)
                                                                      🏢 Vendor: NousResearch
                                                                      📅 Updated: 2026-07-03

                                                                      📝 A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. Affected is the function GatewayStreamConsumer._filter_and_accumulate of the file gateway/stream_consumer.py of the comp...

                                                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                                                        [?]EUVD Bot » 🤖 🌐
                                                                        @EUVD_Bot@mastodon.social

                                                                        🚨 EUVD-2026-41653

                                                                        📊 Score: 6.5/10 (CVSS v3.1)
                                                                        📦 Product: Microsoft Edge (Chromium-based)
                                                                        🏢 Vendor: Microsoft
                                                                        📅 Updated: 2026-07-03

                                                                        📝 Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network.

                                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                                          [?]EUVD Bot » 🤖 🌐
                                                                          @EUVD_Bot@mastodon.social

                                                                          🚨 EUVD-2026-41612

                                                                          📊 Score: n/a
                                                                          📦 Product: Gitea Open Source Git Server
                                                                          🏢 Vendor: Gitea
                                                                          📅 Updated: 2026-07-03

                                                                          📝 Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web archive download endpoint.

                                                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                                                            [?]urlDNA.io :verified: » 🤖 🌐
                                                                            @urldna@infosec.exchange

                                                                            Possible Phishing 🎣
                                                                            on: ⚠️hxxps[:]//alibabacarelogin[.]weebly[.]com
                                                                            🧬 Analysis at: urldna.io/scan/6a4838a93b77500

                                                                              [?]TechWire ⚡ » 🤖 🌐
                                                                              @techwire@social.gamefan.net

                                                                              Popular Show Tracking App TV Time Shutting Down on July 15

                                                                              TV Time, the popular show and movie tracking app, is shutting down on July 15, with all personal user data set to be deleted after that date. In a support page update announcing the news, the company admitted that it wa…

                                                                              macrumors.com/2026/07/02/show-

                                                                              [MacRumors]

                                                                                [?]TheHackerWire » 🤖 🌐
                                                                                @thehackerwire@mastodon.social

                                                                                🟠 CVE-2026-14459 - High (8.8)

                                                                                Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection.

                                                                                This issue affects pardus-software: from <= ...

                                                                                🔗 thehackerwire.com/vulnerabilit

                                                                                CVE Alert: CVE-2026-14459

                                                                                Alt...CVE Alert: CVE-2026-14459

                                                                                  [?]TheHackerWire » 🤖 🌐
                                                                                  @thehackerwire@mastodon.social

                                                                                  🟠 CVE-2026-14460 - High (8.8)

                                                                                  Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection.

                                                                                  This issue affects pardus-software: from <= 1.0.4 before 1.0.5.

                                                                                  🔗 thehackerwire.com/vulnerabilit

                                                                                  CVE Alert: CVE-2026-14460

                                                                                  Alt...CVE Alert: CVE-2026-14460

                                                                                    [?]TechWire ⚡ » 🤖 🌐
                                                                                    @techwire@social.gamefan.net

                                                                                    While you’re watching the World Cup, the feds may be watching you

                                                                                    It's a big year for America. It's the semiquincentennial, otherwise known as America250, and the United States is cohosting the World Cup. But spectators at these events - and the millions of people who live in the citi…

                                                                                    theverge.com/policy/961004/wor

                                                                                    [The Verge]

                                                                                      [?]TechWire ⚡ » 🤖 🌐
                                                                                      @techwire@social.gamefan.net

                                                                                      Amazon updated 2023’s Fire HD 10 tablet with 4GB of RAM

                                                                                      The Fire HD 8 that launched in 2024 was the last new addition to Amazon's budget-minded tablet lineup, but the company has quietly updated the Fire HD 10 that debuted the year before. In 2023 it was offered with multipl…

                                                                                      theverge.com/tech/961387/amazo

                                                                                      [The Verge]

                                                                                        Back to top - More...