voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
🚨 EUVD-2026-41544
📊 Score: 2.7/10 (CVSS v3.1)
📦 Product: PowerProtect Data Domain, PowerProtect Data Domain, PowerProtect Data Domain (+1 more)
🏢 Vendor: Dell
📅 Updated: 2026-07-03
📝 Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versi...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41544
Possible Phishing 🎣
on: ⚠️hxxps[:]//netflix-clone-zeta-nine[.]vercel[.]app
🧬 Analysis at: https://urldna.io/scan/6a4725cd3b775000075ccd8a
#cybersecurity #phishing #infosec #urldna #scam #infosec
Kubota North America Discloses Data Breach Affecting Employee and Dependents Information
Kubota North America Corporation disclosed a data breach that exposed the personal and financial data of employees and their dependents. The company has offered identity monitoring services and added new security controls to prevent future unauthorized access.
****
#cybersecurity #infosec #incident #databreach
https://beyondmachines.net/event_details/kubota-north-america-discloses-data-breach-affecting-employees-and-dependents-information-4-o-h-f-8/gD2P6Ple2L
Google is finally banning Chrome extensions that let you jailbreak chatbots
Google gives Chrome extension developers a month to meet new policies.
https://www.androidauthority.com/chrome-web-store-extension-stricter-rules-3684115/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
🎣 Phishing Spotlight
netflix-clone-delta-hazel[.]vercel[.]app
🔒 SSL: exp. 2026-09-26
🌐 Stack: Vercel
🔗 https://beesint.com/pulse/68b3c14e-299a-46dc-9931-bee76afa8506
💾 🟠 Infinite Campus (infinitecampus.com)
✓ Verified
📊 ~137K records compromised
📂 Email addresses, Employers, Job titles, Names +4 more
📅 2026-03-18 · disclosed 89d after incident
🌐 Netlify
⚠️ No SPF/DMARC configured
🔗 https://beesint.com/pulse/4ca6f59f-d6fa-4852-a999-2d160f118cc2
I tried an Android phone with a 35mm camera — it completely changed how I take photos
Changing focal length is a bigger innovation than adding more AI features.
https://www.androidauthority.com/vivo-x300-ultra-35mm-camera-hands-on-3670999/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Security Tip: Effective patch management isn't just about speed; it's about strategy. 🛡️ Avoid "patch fatigue" by implementing Risk-Based Vulnerability Management (RBVM). Use CVSS scores to understand severity and EPSS data to understand the likelihood of exploitation. This helps your team focus on critical threats first. Track the latest vulnerabilities and scores at https://cvedatabase.com #CyberSecurity #InfoSec #PatchManagement #CVE #SysAdmin
Possible Phishing 🎣
on: ⚠️hxxps[:]//vdhcfg545cvcdfd[.]weebly[.]com/
🧬 Analysis at: https://urldna.io/scan/6a477a143b77500005e893a8
#cybersecurity #phishing #infosec #urldna #scam #infosec
I waited six years for the Google Home Speaker — and it wasn’t worth it
A fine smart speaker, but not a great one.
https://www.androidauthority.com/google-home-speaker-review-3681647/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
If you still own one of these 6 popular Android phones, it’s probably time to upgrade
Is it time to let go of an old favorite?
https://www.androidauthority.com/old-android-phones-worth-upgrading-2026-3681922/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
🚨 EUVD-2026-41528
📊 Score: 4.3/10 (CVSS v3.1)
📦 Product: RTMKit
🏢 Vendor: Rometheme
📅 Updated: 2026-07-03
📝 The RTMKit (rometheme-for-elementor) plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.7 This is due to insufficient path validation on the 'template' parameter in the render_templates AJAX endpoint, which is u...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41528
🚨 EUVD-2026-41527
📊 Score: 6.1/10 (CVSS v3.1)
📦 Product: Destekz
🏢 Vendor: Raera - Ankara Web Design and Digital Advertising Agency
📅 Updated: 2026-07-03
📝 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Raera - Ankara Web Design and Digital Advertising Agency Destekz allows Reflected XSS.
This issue affects ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41527
🚨 EUVD-2026-41526
📊 Score: 9.8/10 (CVSS v3.1)
📦 Product: Destekz
🏢 Vendor: Raera - Ankara Web Design and Digital Advertising Agency
📅 Updated: 2026-07-03
📝 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Raera - Ankara Web Design and Digital Advertising Agency Destekz allows SQL Injection.
This issue affects ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41526
Possible Phishing 🎣
on: ⚠️hxxps[:]//sites[.]google[.]com/logiwallets[.]com/uphold-login/home
🧬 Analysis at: https://urldna.io/scan/6a4709a03b775000075ccacd
#cybersecurity #phishing #infosec #urldna #scam #infosec
"Two of the world's fastest-growing skills are in the same job description"
"The future of cybersecurity depends on professionals who can secure and govern AI."
Critical phpBB Authentication Bypass Allows Instant Account Takeover
phpBB version 3.3.17 patches a critical authentication bypass (CVE-2026-48611) that allows unauthenticated attackers to take over any account, including administrators, by manipulating the auth_provider parameter.
**If you run a phpBB forum (versions 3.1.0 through 3.3.16, or 4.0.0-a2), this is important and urgent. Update to version 3.3.17 immediately. If you can't patch right away, delete the apache.php and ldap.php files from the phpbb/auth/provider/ directory, and check your server logs for suspicious auth_provider=apache and mode=login_link requests. If found, reset all user sessions and assume those accounts are compromised.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/critical-phpbb-authentication-bypass-allows-instant-account-takeover-b-z-9-a-7/gD2P6Ple2L
Roblox, Minecraft, and the Insidious Internet for Children
Children are targeted by a sprawling ecosystem of websites exploiting their interest in Roblox and Minecraft through offerwall reward schemes and phishing campaigns. These sites promise free in-game currency in exchange for completing tasks, collecting personal data, enrolling minors in paid subscriptions, and violating platform terms of service that can result in account bans. The infrastructure relies on cheap, disposable hosting with aggressive domain rotation. Using Internet-wide scan data from Censys, this analysis characterizes two categories: offerwall get-paid-to reward sites and credential harvesting generators. The exposed infrastructure handles children's data with minimal security, monetizing their attention at scale through affiliate commissions while presenting significant privacy and security risks.
Pulse ID: 6a47950711440db76d84e5de
Pulse Link: https://otx.alienvault.com/pulse/6a47950711440db76d84e5de
Pulse Author: AlienVault
Created: 2026-07-03 10:55:03
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Censys #CredentialHarvesting #CyberSecurity #InfoSec #Minecraft #Nim #OTX #OpenThreatExchange #Phishing #Privacy #RAT #bot #AlienVault
Scientists have created a 3D-printed remote-controlled cyborg cockroach equipped with IR cameras — living insects fitted with flexible 'diving suit' can survive…
Singaporean scientists outfitted remote-controlled cockroaches with scuba suits in a bid to use them in rescue operations and explore extreme environments like Mars.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
Elon Musk's SpaceX Showed Off Prototype AI Device
Elon Musk's SpaceX may be aiming to compete with Apple in the future. The company showed investors a prototype for a "handset-like device designed to reshape how humans interact with artificial intelligence," according …
https://www.macrumors.com/2026/07/01/spacex-ai-device/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #MacRumors [MacRumors]
OnePlus may be pulling back from yet another major market, and it’s a big one
After Europe, OnePlus appears to preparing a US exit.
https://www.androidauthority.com/oneplus-pulling-back-major-market-us-uk-3683986/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
🖲️ #Cybersecurity #Ciberseguridad #Ciberseguranca #Security #Seguridad #Seguranca #News #Noticia #Noticias #Tecnologia #Technology
⚫ 'Phantom Squatting': An Emerging AI-Driven Supply Chain Threat
🔗 https://www.darkreading.com/endpoint-security/phantom-squatting-ai-driven-supply-chain-threat
LLMs consistently hallucinate Web domains for legitimate brands that attackers can register for malicious activity in a difficult-to-detect attack vector.
Meta’s new app is basically social media for vibe coded games and experiences
You don't need to be a developer to create a fun new game.
https://www.androidauthority.com/meta-pocket-vibe-code-games-experiences-3683989/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
🚨 EUVD-2026-41492
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: MotoPress Appointment Booking
🏢 Vendor: jetmonsters
📅 Updated: 2026-07-03
📝 The MotoPress Appointment Booking plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 2.4.4. This is due to the `POST /motopress/appointment/v1/bookings` REST ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41492
🚨 EUVD-2026-41491
📊 Score: 6.4/10 (CVSS v3.1)
📦 Product: CM Business Directory – Optimise and showcase local business
🏢 Vendor: CreativeMindsSolutions
📅 Updated: 2026-07-03
📝 The CM Business Directory – Optimise and showcase local business plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Business Address Meta Fields in all versions up to, and...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41491
🚨 EUVD-2026-41490
📊 Score: 6.4/10 (CVSS v3.1)
📦 Product: JSON API User
🏢 Vendor: parorrey
📅 Updated: 2026-07-03
📝 The JSON API User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content' parameter of the post_comment API endpoint in versions up to, and including, 4.1.0 This is due to insufficient input sanitization in the post_comment...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41490
🚨 EUVD-2026-41489
📊 Score: 5.5/10 (CVSS v3.1)
📦 Product: WP Import Export Lite
🏢 Vendor: VJInfotech
📅 Updated: 2026-07-03
📝 The WP Import Export Lite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to and including 3.9.30 via the wpie_import_upload_file_from_url AJAX action. The plugin's URL downloader first calls wp_safe_remo...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41489
🚨 EUVD-2026-41488
📊 Score: 9.1/10 (CVSS v3.1)
📦 Product: Printcart Web to Print Product Designer for WooCommerce
🏢 Vendor: printcart
📅 Updated: 2026-07-03
📝 The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5.2 This is due to insufficient path validation in...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41488
🚨 EUVD-2026-41487
📊 Score: 7.2/10 (CVSS v3.1)
📦 Product: NEX-Forms – Ultimate Forms Plugin for WordPress
🏢 Vendor: webaways
📅 Updated: 2026-07-03
📝 The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'real_val__' parameter in all versions up to, and including, 9.2.2 due to insufficient inpu...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41487
🚨 EUVD-2026-41486
📊 Score: 6.4/10 (CVSS v3.1)
📦 Product: Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
🏢 Vendor: ultimatemember
📅 Updated: 2026-07-03
📝 The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerabl...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41486
🚨 EUVD-2026-41485
📊 Score: 7.5/10 (CVSS v3.1)
📦 Product: AR For Woocommerce
🏢 Vendor: webandprint
📅 Updated: 2026-07-03
📝 The AR for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.40 via the 'file' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitr...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41485
🚨 EUVD-2026-41484
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Ninja Forms - File Uploads
🏢 Vendor: SaturdayDrive
📅 Updated: 2026-07-03
📝 The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.29. This is due to the plugin not properly verifying that a user is authorized to perform an action. ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41484
Possible Phishing 🎣
on: ⚠️hxxps[:]//mnnbnkvfy[.]weebly[.]com/
🧬 Analysis at: https://urldna.io/scan/6a47099c3b775000075ccac6
#cybersecurity #phishing #infosec #urldna #scam #infosec
Foxit: 191 CVEs, 115 high-severity. 99% unpatched. Trust Score: C. PDF tools are a top attack vector—stay current. #Foxit #cybersecurity #infosec
Branded Gambling Campaigns: How Scammers Are Exploiting Trusted Brand Names to Drive Casino Traffic
Scam advertising campaigns have been identified that impersonate trusted brands to redirect consumers to unrelated online gambling sites. These operations utilize paid social media advertisements on platforms like Facebook, Instagram, and TikTok, combined with fake app store pages and Progressive Web Apps. The campaigns target UK consumers primarily, with variants observed in German and Spanish. Scammers impersonate major brands including financial institutions like Monzo, Revolut, and Barclays, as well as household names such as Tesco, Amazon, Netflix, and Facebook. The scheme involves three stages: paid ads claiming brands have launched official casino products, fake landing pages mimicking app stores, and PWAs that redirect to gambling sites through affiliate tracking links. Typical affiliate payouts range from $50 to $350 per depositing player, indicating significant financial motivation behind these operations.
Pulse ID: 6a46d12100d65a16f173e8a4
Pulse Link: https://otx.alienvault.com/pulse/6a46d12100d65a16f173e8a4
Pulse Author: AlienVault
Created: 2026-07-02 20:59:13
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Amazon #CyberSecurity #Facebook #InfoSec #Instagram #Mimic #OTX #OpenThreatExchange #RAT #Rust #SocialMedia #UK #bot #AlienVault