voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]OTX Bot » 🤖 🌐
@techbot@social.raytec.co

Vibe Coded Extortion: Path from Legal Lure to CrownX Ransom Capabilities

A sophisticated multi-stage phishing campaign delivers a previously undocumented framework called Avalon through spoofed legal documents hosted on Proton Drive. The intrusion begins with password-protected archives containing ISO images that execute malicious MSBuild projects, loading payloads entirely in memory without conventional executable attachments. Avalon consolidates credential theft, lateral movement, recovery disruption, and ransomware capabilities within a single framework, with its encryption component branded as CrownX. The framework demonstrates hallmarks of AI-assisted development, rapidly combining multiple post-exploitation capabilities that previously required sustained development effort. Avalon targets browsers, cryptocurrency wallets, messaging platforms, VPN configurations, and infrastructure systems while implementing extensive defense evasion techniques against major security products. The framework disrupts recovery by eliminating Volume Shadow Copies, Windows Recovery Environment...

Pulse ID: 6a46d120d41fcc87a8a52932
Pulse Link: otx.alienvault.com/pulse/6a46d
Pulse Author: AlienVault
Created: 2026-07-02 20:59:12

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    [?]OTX Bot » 🤖 🌐
    @techbot@social.raytec.co

    PamStealer: a Rust-based macOS infostealer that validates credentials through PAM

    PamStealer is a two-stage macOS infostealer distributed as a compiled AppleScript impersonating Maccy, a legitimate clipboard manager, hosted on a fake domain. The first stage uses JavaScript for Automation with Objective-C APIs to download payloads while avoiding shell commands. The second stage is a Rust-based Mach-O binary that validates stolen credentials through PAM before harvesting, reads browser databases directly using bundled SQLite, captures clipboard contents repeatedly via pbpaste, and exfiltrates encrypted data using ChaCha20-Poly1305. It establishes persistence through both modern and legacy login item APIs, masquerades as Finder or System Settings, and tricks victims into granting Full Disk Access through counterfeit alerts. The stealer contacts Ethereum RPC endpoints and employs region-based exclusions targeting Apple silicon systems while avoiding Commonwealth of Independent States countries.

    Pulse ID: 6a471de6cf9848f2ef9503c0
    Pulse Link: otx.alienvault.com/pulse/6a471
    Pulse Author: AlienVault
    Created: 2026-07-03 02:26:46

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

      [?]OTX Bot » 🤖 🌐
      @techbot@social.raytec.co

      AsyncRAT and Remcos Delivered in Multi-Stage Phishing Campaign

      A widespread phishing campaign distributing AsyncRAT and Remcos RATs has been observed targeting organizations across manufacturing, media, professional services, agriculture, and chemical industries globally. The attack leverages malicious Excel spreadsheets sent via emails impersonating business communications like purchase orders and payment advice. When macros are enabled, VBA code retrieves HTA payloads through URL shorteners and Cloudflare Workers infrastructure. The multi-stage infection chain employs heavy obfuscation including Base64 encoding, steganography in PNG files, and character substitution. The campaign intensified during June 2026, affecting organizations across Europe, Asia-Pacific, and the Americas. Infrastructure includes distinctive HTA naming conventions using concatenated positive English words. The operation likely uses automation for payload generation and may leverage LLMs for development efficiency.

      Pulse ID: 6a471de4dcdacfc396979ab8
      Pulse Link: otx.alienvault.com/pulse/6a471
      Pulse Author: AlienVault
      Created: 2026-07-03 02:26:44

      Be advised, this data is unverified and should be considered preliminary. Always do further verification.

        [?]TechWire ⚡ » 🤖 🌐
        @techwire@social.gamefan.net

        Apple in Talks to Buy Memory Chips From Chinese Makers CXMT and YMTC

        Apple is in talks to buy memory from Chinese semiconductor companies ChangXin Memory Technologies Co. (CXMT) and Yangtze Memory Technologies Co. (YMTC), reports Bloomberg, citing sources with knowledge of the talks. Dis…

        macrumors.com/2026/07/01/apple

        [MacRumors]

          [?]TheHackerWire » 🤖 🌐
          @thehackerwire@mastodon.social

          🟠 CVE-2026-54998 - High (8.8)

          Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.

          🔗 thehackerwire.com/vulnerabilit

          CVE Alert: CVE-2026-54998

          Alt...CVE Alert: CVE-2026-54998

            [?]TheHackerWire » 🤖 🌐
            @thehackerwire@mastodon.social

            🔴 CVE-2026-57100 - Critical (9.9)

            Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.

            🔗 thehackerwire.com/vulnerabilit

            CVE Alert: CVE-2026-57100

            Alt...CVE Alert: CVE-2026-57100

              [?]TechWire ⚡ » 🤖 🌐
              @techwire@social.gamefan.net

              Singapore cops seize $42 million mansion, freeze $772k bank account of suspected Nvidia AI GPU smugglers …

              Four individuals suspected of smuggling Nvidia AI GPUs into China by using Singapore as a transshipment point are facing multiple charges. Singaporean authorities say they are not obliged to enforce foreign export contr…

              tomshardware.com/tech-industry

              [Tom's Hardware]

                [?]TechWire ⚡ » 🤖 🌐
                @techwire@social.gamefan.net

                HP has slashed $1,300 off this colossal 5080 gaming laptop for July 4 — 34% discount gets you 32GB of RAM and 24-core Arrow Lake mobile gaming for $2,499

                Get $1,300 off this HP Omen Max Gaming laptop with Intel Core Ultra 9 275HX, RTX 5080, and 32GB of RAM.

                tomshardware.com/laptops/gamin

                [Tom's Hardware]

                  [?]Negative PID SL » 🌐
                  @negativepid@mastodon.social

                  [?]urlDNA.io :verified: » 🤖 🌐
                  @urldna@infosec.exchange

                  Possible Phishing 🎣
                  on: ⚠️hxxp[:]//aartisahu15[.]github[.]io/task5-amazon_clone
                  🧬 Analysis at: urldna.io/scan/6a4684ba3b77500

                    [?]TechWire ⚡ » 🤖 🌐
                    @techwire@social.gamefan.net

                    Save $521 on this 4K-capable RTX 5070 gaming PC from CyberPowerPC, now just $1,349 — huge price drop for budget-friendly rig with impressive I…

                    Save over $500 on this powerful CyberPowerPC gaming machine with an RTX 5070 and brand-new Intel Core Ultra 5 250KF CPU, alongside a 1TB SSD and 16GB of DDR5 RAM, all for only $1,349.

                    tomshardware.com/desktops/gami

                    [Tom's Hardware]

                      [?]TechWire ⚡ » 🤖 🌐
                      @techwire@social.gamefan.net

                      Startup activates nuclear microreactor live on stage to power an Nvidia RTX Spark desktop PC — firm worki…

                      Valar Atomics claims to be the first startup to produce nuclear power, and it demonstrated that ability on stage by using its Ward 250 microreactor to power an RTX Spark unit. It also announced a partnership with Nvidia…

                      tomshardware.com/tech-industry

                      [Tom's Hardware]

                        [?]Malicious Extension Bot » 🤖 🌐
                        @malicious_browser_bot@infosec.exchange

                        extension Satoru Gojo Vs Suguru Get seems malicious. Its badness score is 92/100!

                        ```json
                        {"id": "gpfdgpikbndcmbfnemoplnkcepogomkl", "score": 92, "platform": "chrome", "name": "Satoru Gojo Vs Suguru Get"}
                        ```

                          [?]Malicious Extension Bot » 🤖 🌐
                          @malicious_browser_bot@infosec.exchange

                          extension Check Bm KiểM Tra Business seems malicious. Its badness score is 86/100!

                          ```json
                          {"id": "nfelknjakpojmdnobefebknmijjgclnp", "score": 86, "platform": "chrome", "name": "Check Bm Ki\u1ec3M Tra Business"}
                          ```

                            [?]urlDNA.io :verified: » 🤖 🌐
                            @urldna@infosec.exchange

                            Possible Phishing 🎣
                            on: ⚠️hxxps[:]//mirror-google[.]com
                            🧬 Analysis at: urldna.io/scan/6a4684ca3b77500

                              [?]TechWire ⚡ » 🤖 🌐
                              @techwire@social.gamefan.net

                              OpenAI mulling giving US gov't a 5% stake in the company, days after Washington delayed GPT-5.6 — Altman reportedly wants every leading U.S. AI lab paying into an Alaska-style pub…

                              Altman is understood to have raised the idea with President Donald Trump, Commerce Secretary Howard Lutnick, and Treasury Secretary Scott Bessent.

                              tomshardware.com/tech-industry

                              [Tom's Hardware]

                                [?]TechWire ⚡ » 🤖 🌐
                                @techwire@social.gamefan.net

                                Intel hikes pricing for its flagship desktop PC chips by up to $50 — official Core Ultra 270K Plus and 250K Plus product pages now …

                                Intel's Arrow Lake Refresh processors remain among the company's strongest desktop offerings, but newly updated pricing makes both CPUs noticeably more expensive than when they debuted in March.

                                tomshardware.com/pc-components

                                [Tom's Hardware]

                                  [?]EUVD Bot » 🤖 🌐
                                  @EUVD_Bot@mastodon.social

                                  🚨 EUVD-2026-41471

                                  📊 Score: 7.5/10 (CVSS v3.1)
                                  📦 Product: AR For WordPress
                                  🏢 Vendor: webandprint
                                  📅 Updated: 2026-07-03

                                  📝 The AR for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.40 via the 'file' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary ...

                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                    [?]EUVD Bot » 🤖 🌐
                                    @EUVD_Bot@mastodon.social

                                    🚨 EUVD-2026-41470

                                    📊 Score: 6.4/10 (CVSS v3.1)
                                    📦 Product: weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot
                                    🏢 Vendor: wedevs
                                    📅 Updated: 2026-07-03

                                    📝 The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'sectionTitleTag' and 'articleTitleTag' Block...

                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                      [?]EUVD Bot » 🤖 🌐
                                      @EUVD_Bot@mastodon.social

                                      🚨 EUVD-2026-41469

                                      📊 Score: 4.9/10 (CVSS v3.1)
                                      📦 Product: Cookie Banner for GDPR / CCPA – WPLP Cookie Consent
                                      🏢 Vendor: wplegalpages
                                      📅 Updated: 2026-07-03

                                      📝 The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 4.3.5 due to insufficient escapin...

                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                        [?]urlDNA.io :verified: » 🤖 🌐
                                        @urldna@infosec.exchange

                                        Possible Phishing 🎣
                                        on: ⚠️hxxps[:]//recreate-instagrampage[.]vercel[.]app
                                        🧬 Analysis at: urldna.io/scan/6a466efd3b77500

                                          [?]EUVD Bot » 🤖 🌐
                                          @EUVD_Bot@mastodon.social

                                          🚨 EUVD-2026-41468

                                          📊 Score: 4.3/10 (CVSS v3.1)
                                          📦 Product: weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot
                                          🏢 Vendor: wedevs
                                          📅 Updated: 2026-07-03

                                          📝 The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.3.0. This is due to a...

                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                            [?]EUVD Bot » 🤖 🌐
                                            @EUVD_Bot@mastodon.social

                                            🚨 EUVD-2026-41467

                                            📊 Score: 6.4/10 (CVSS v3.1)
                                            📦 Product: weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot
                                            🏢 Vendor: wedevs
                                            📅 Updated: 2026-07-03

                                            📝 The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'connectorWidth' Block Attribute in all versi...

                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                              [?]TechWire ⚡ » 🤖 🌐
                                              @techwire@social.gamefan.net

                                              Asus B850-Creator Wifi Neo motherboard review: AM5 Creator mobo looks the part, but is missing useful features

                                              Asus' B850-Creator Wifi Neo offers fast dual 5 GbE, 3x video outputs, and loads of EZ PC DIY/AI features, but lacks enough USB ports (no 40 Gbps at all) and is expensive for the B850 platform.

                                              tomshardware.com/pc-components

                                              [Tom's Hardware]

                                                [?]TheHackerWire » 🤖 🌐
                                                @thehackerwire@mastodon.social

                                                🟠 CVE-2026-58460 - High (7.7)

                                                react-native-receive-sharing-intent contains a path traversal vulnerability that allows a co-resident malicious application to write files outside the intended cache directory by supplying a crafted _display_name value containing dot-dot path comp...

                                                🔗 thehackerwire.com/vulnerabilit

                                                CVE Alert: CVE-2026-58460

                                                Alt...CVE Alert: CVE-2026-58460

                                                  [?]TheHackerWire » 🤖 🌐
                                                  @thehackerwire@mastodon.social

                                                  🔴 CVE-2026-52830 - Critical (9.4)

                                                  fast-mcp-telegram is a Telegram MCP Server. Prior to 0.19.1, fast-mcp-telegram validates HTTP Bearer tokens by joining the raw token string into a session-file path. The verifier rejects the exact reserved token telegram, but it does not reject pa...

                                                  🔗 thehackerwire.com/vulnerabilit

                                                  CVE Alert: CVE-2026-52830

                                                  Alt...CVE Alert: CVE-2026-52830

                                                    [?]TheHackerWire » 🤖 🌐
                                                    @thehackerwire@mastodon.social

                                                    🔴 CVE-2026-59099 - Critical (9.1)

                                                    Apereo CAS 7.3.0 before 8.0.0-RC6 contains a cryptographic vulnerability that allows remote unauthenticated attackers to recover plaintext conversation state by exploiting AES-GCM initialization vector reuse across the server lifetime. Attackers c...

                                                    🔗 thehackerwire.com/vulnerabilit

                                                    CVE Alert: CVE-2026-59099

                                                    Alt...CVE Alert: CVE-2026-59099

                                                      [?]TierraSapiens » 🤖 🌐
                                                      @tierrasapiens@mastodon.social

                                                      🖲️
                                                      ⚫ Why Identity Security Is Your Cyber Career Entry Point
                                                      🔗 darkreading.com/cybersecurity-

                                                      As AI reshapes cybersecurity workflows, John Paul Cunningham, CISO at SIlverfort, says the technology is creating opportunities rather than eliminating jobs — and there are more ways than ever to break into

                                                        [?]:awesome:🐦‍🔥nemo™🐦‍⬛ 🇺🇦🍉 » 🌐
                                                        @nemo@mas.to

                                                        Tor Project released Arti 2.5.0, moving its next-gen Counter Galois Onion (CGO) encryption to stable status—now included in full feature builds. The update also patches two DoS issues in Arti’s Rust Tor implementation and enables congestion control by default for better performance. 🚀🔒 cyberinsider.com/tor-releases-

                                                          [?]TechWire ⚡ » 🤖 🌐
                                                          @techwire@social.gamefan.net

                                                          Google loses final fight over its $4.7 billion Android antitrust fine

                                                          Google’s long-running battle over a huge Android antitrust fine has ended with the EU’s top court upholding the penalty.

                                                          androidauthority.com/google-an

                                                          [Android Authority]

                                                            [?]TechWire ⚡ » 🤖 🌐
                                                            @techwire@social.gamefan.net

                                                            Tesla driver faces manslaughter charges over Texas crash that killed a woman inside her home

                                                            The man whose Tesla struck and killed a woman inside her Texas home last month is now facing manslaughter charges, as reported earlier by The Wall Street Journal and local news outlet KHOU 11. 44-year-old Michael Butler…

                                                            theverge.com/transportation/96

                                                            [The Verge]

                                                              [?]TechWire ⚡ » 🤖 🌐
                                                              @techwire@social.gamefan.net

                                                              I've been reviewing laptops for years: These are the 15+ best July 4th laptop deals

                                                              The Fourth of July weekend brings tons of sales on top laptops we've reviewed, from Apple, Acer, Lenovo, and more.

                                                              zdnet.com/article/july-4-lapto

                                                              [ZDNet]

                                                                [?]Hacker News » 🤖 🌐
                                                                @h4ckernews@mastodon.social

                                                                [?]CVEDatabase.com » 🌐
                                                                @cvedatabase@techhub.social

                                                                Security Tip: Use lockfiles to ensure deterministic builds. 🛡️

                                                                Relying on version ranges in manifest files can lead to different versions being installed across environments. By committing lockfiles (package-lock.json, Gemfile.lock, etc.), you ensure every build uses the exact same dependency tree, preventing "silent" security regressions.

                                                                Track the latest vulnerabilities at: cvedatabase.com

                                                                  [?]urlDNA.io :verified: » 🤖 🌐
                                                                  @urldna@infosec.exchange

                                                                  Possible Phishing 🎣
                                                                  on: ⚠️hxxps[:]//general-trading[.]weebly[.]com
                                                                  🧬 Analysis at: urldna.io/scan/6a463e7f3b77500

                                                                    [?]Negative PID SL » 🌐
                                                                    @negativepid@mastodon.social

                                                                    [?]TechWire ⚡ » 🤖 🌐
                                                                    @techwire@social.gamefan.net

                                                                    LG is giving away free single-door refrigerators - how to qualify for the deal

                                                                    When you buy this refrigerator model on sale, LG will give you a free single-door refrigerator too - perfect for the garage or basement.

                                                                    zdnet.com/article/lg-free-refr

                                                                    [ZDNet]

                                                                      Back to top - More...