voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
🟠 CVE-2026-63090 - High (8.8)
ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated low-privilege attackers to achieve arbitrary code execution by sending crafted SFTP packet fragments exceeding...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63090/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-54910 - High (7.7)
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two user-controlled query parameters: `path` and `name`, both of which are used i...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54910/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-45270 - High (8.7)
CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the `Pages` backend module registers the `html_purify` validation rule on language-keyed page content but persists the raw, un-purified POST value into t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45270/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-63429 - High (8.6)
HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no global guard, no form-context validation, no `openToken` requirement, and no session cookie check. Any anonymous internet user ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63429/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🔴 CVE-2026-51027 - Critical (9.9)
An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-51027/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🔴 CVE-2026-46412 - Critical (10)
@beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker used a compromised npm publish token to publish 18 malicious versions...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-46412/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-46415 - High (8.2)
The Caddy Defender plugin is a middleware for Caddy that allows users to block or manipulate requests based on the client's IP address. Prior to version 0.10.1, Caddy Defender used `r.RemoteAddr` when evaluating whether a request should be blocked...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-46415/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-45713 - High (7.5)
Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the Mailpit SMTP server has a Server.MaxSize int field that controls the maximum allowed DATA payload size, but the field is never assigned anywhere outside test cod...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45713/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🔴 CVE-2026-35198 - Critical (9)
HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a low-privileged team member to inject malicious JavaScript that executes when a team owner views the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-35198/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🧪 NEW BETA RELEASES 🧪
📱 iOS 26.6 RC (23G71)
📱 iOS 27.0 beta 4 (24A5390f)
📱 iPadOS 26.6 RC (23G71)
📱 iPadOS 27.0 beta 4 (24A5390f)
💻 macOS 26.6 RC (25G70)
💻 macOS 27.0 beta 4 (26A5388g)
📺 tvOS 26.6 RC (23L772)
📺 tvOS 27.0 beta 4 (24J5325d)
🥽 visionOS 26.6 RC (23O770)
⌚ watchOS 26.6 RC (23U67)
AIWAF for Flask helps protect lightweight web apps without heavy manual configuration.
It can analyze routes, detect request patterns, manage temporary IP blocks, and apply context-aware security decisions while staying simple to add to an existing Flask app.
An AI agent breached Hugging Face before an AI defender caught it: What users should do next
An agentic AI infiltrated the production infrastructure of an AI project. Then an AI detected it. Is this the future of cyberattacks, and how will they be defended against?
https://www.zdnet.com/article/hugging-face-breach-blamed-on-ai-agent/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
Google Fi’s Pixel 11 Pro XL deal briefly teases us with an official early look
The Google Fi store briefly listed an image of the Pixel 11 Pro XL as part of a promotion.
https://www.androidauthority.com/google-fi-pixel-11-pro-xl-leak-3689288/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
You’ll soon be able to ask Gemini about your Chrome tab groups
Chrome is putting Gemini right into your tab groups.
https://www.androidauthority.com/chrome-tab-group-gemini-integration-3689297/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Judge pauses Paramount’s attempt to buy Warner Bros. Discovery
A judge partially granted the request from a dozen state attorneys general to temporarily place the $110 billion merger of Paramount and Warner Bros. Discovery on hold, as reported by Variety and Reuters. US District Ju…
https://www.theverge.com/business/968055/paramount-wbd-merger-pause-tro
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
#KapeTechnologies plc (ex‑Crossrider) is a UK‑Israeli firm tied to Teddy Sagi, with #VPN and cybersecurity brands like #Webselenese #IntegoAntivirus #ExpressVPN, #CyberGhost, and #PIA. Critics link its roots to Israel’s Unit 8200 and surveillance pipelines—so some call for a #Boycott. 🌍🛡️🛰️ https://irbak-action.com/company/453ca578-d616-45de-8971-d16bca765818 #Privacy #Cybersecurity #Boycott
🚨 EUVD-2026-46010
📊 Score: n/a
📦 Product: Linux, Linux, Linux (+3 more)
🏢 Vendor: Linux
📅 Updated: 2026-07-20
📝 In the Linux kernel, the following vulnerability has been resolved:
net: team: fix NULL pointer dereference in team_xmit during mode change
__team_change_mode() clears team->ops with memset() before restoring
safe dummy handlers via team_adjust_ops()....
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46010
🚨 EUVD-2026-46008
📊 Score: n/a
📦 Product: Linux, Linux, Linux (+15 more)
🏢 Vendor: Linux
📅 Updated: 2026-07-20
📝 In the Linux kernel, the following vulnerability has been resolved:
net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()
rmnet_dellink() removes the endpoint from the hash table with
hlist_del_init_rcu() and then immediately frees it ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46008
🚨 EUVD-2026-46009
📊 Score: n/a
📦 Product: Linux, Linux, Linux (+9 more)
🏢 Vendor: Linux
📅 Updated: 2026-07-20
📝 In the Linux kernel, the following vulnerability has been resolved:
netfilter: ipset: fix race between dump and ip_set_list resize
The release path of ip_set_dump_do() and ip_set_dump_done() read
inst->ip_set_list via ip_set_ref_netlink(), a plain rcu...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46009
🚨 EUVD-2026-46007
📊 Score: n/a
📦 Product: Linux, Linux, Linux (+7 more)
🏢 Vendor: Linux
📅 Updated: 2026-07-20
📝 In the Linux kernel, the following vulnerability has been resolved:
xfs: fail recovery on a committed log item with no regions
If the first op of a transaction is a bare transaction header
(len == sizeof(struct xfs_trans_header)), xlog_recover_add_to_...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46007
🚨 EUVD-2026-46006
📊 Score: 9.8/10 (CVSS v3.1)
📦 Product: piwigo
🏢 Vendor: piwigo
📅 Updated: 2026-07-20
📝 The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them directly into a PHP configuration file without proper sanitization. On PHP 8+, the `addslashes()` protection is bypassed because it checks fo...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46006
🚨 EUVD-2026-46005
📊 Score: 6.1/10 (CVSS v3.1)
📦 Product: Network-AI
🏢 Vendor: Jovancoding
📅 Updated: 2026-07-20
📝 Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.restore(env, backupId)` computes the backup path with `join(envDir, '.backups', backupId)` and only checks that this path exists. It does not res...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46005
🚨 EUVD-2026-46004
📊 Score: 7.0/10 (CVSS v3.1)
📦 Product: libvips
🏢 Vendor: libvips
📅 Updated: 2026-07-20
📝 libvips is a fast image processing library with low memory needs. The `tiffload` operation in libvips versions before and including 8.18.1 could incorrectly determine the number of channels in a JPEG or JPEG2000-encoded tile within a TIFF image, leading to a...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46004
🚨 EUVD-2026-46003
📊 Score: 9.9/10 (CVSS v3.1)
📦 Product: Network-AI
🏢 Vendor: Jovancoding
📅 Updated: 2026-07-20
📝 Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent sandbox gates shell commands behind an allowlist (`SandboxPolicy.isCommandAllowed`), which THREAT_MODEL.md calls the main control against a compromised agen...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46003
🚨 EUVD-2026-46002
📊 Score: 6.8/10 (CVSS v3.1)
📦 Product: libvips
🏢 Vendor: libvips
📅 Updated: 2026-07-20
📝 libvips is a fast image processing library with low memory needs. The EXIF decoder within libvips versions before and including 8.18.1 was not verifying the range of EXIF tag groups before passing data to libexif, leading to a possible null pointer dereferen...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46002
🚨 EUVD-2026-46001
📊 Score: 6.8/10 (CVSS v3.1)
📦 Product: libvips
🏢 Vendor: libvips
📅 Updated: 2026-07-20
📝 libvips is a fast image processing library with low memory needs. On 32-bit systems in versions before and including 8.18.0, the `gifload` operation could incorrectly determine dimensions leading to an integer overflow. This has been patched in version 8.18.1.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46001
🚨 EUVD-2026-46000
📊 Score: 7.0/10 (CVSS v3.1)
📦 Product: libvips
🏢 Vendor: libvips
📅 Updated: 2026-07-20
📝 libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and including 8.18.0 could incorrectly determine image dimensions leading to an integer overflow and a subsequent heap-based buffer overflow. This h...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46000
🚨 EUVD-2026-45999
📊 Score: 7.3/10 (CVSS v3.1)
📦 Product: dataCycle-CORE
🏢 Vendor: datacycle-engine
📅 Updated: 2026-07-20
📝 dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the applicatio...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45999
🚨 EUVD-2026-45998
📊 Score: 7.3/10 (CVSS v3.1)
📦 Product: dataCycle-CORE
🏢 Vendor: datacycle-engine
📅 Updated: 2026-07-20
📝 dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, a low-privileg...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45998
🚨 EUVD-2026-45997
📊 Score: 4.3/10 (CVSS v3.1)
📦 Product: dataCycle-CORE
🏢 Vendor: datacycle-engine
📅 Updated: 2026-07-20
📝 dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the applicatio...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45997
🚨 EUVD-2026-45996
📊 Score: 8.1/10 (CVSS v3.1)
📦 Product: dataCycle-CORE
🏢 Vendor: datacycle-engine
📅 Updated: 2026-07-20
📝 dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any authentica...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45996
🚨 EUVD-2026-45995
📊 Score: 7.5/10 (CVSS v3.1)
📦 Product: dataCycle-CORE
🏢 Vendor: datacycle-engine
📅 Updated: 2026-07-20
📝 dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any authentica...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45995
🚨 EUVD-2026-45994
📊 Score: 7.5/10 (CVSS v3.1)
📦 Product: dataCycle-CORE
🏢 Vendor: datacycle-engine
📅 Updated: 2026-07-20
📝 dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the documentat...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45994
🚨 EUVD-2026-45993
📊 Score: 4.3/10 (CVSS v3.1)
📦 Product: dataCycle-CORE
🏢 Vendor: datacycle-engine
📅 Updated: 2026-07-20
📝 dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, a Standard use...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45993
Thank you Offensive Security (OffSec) https://arcticwolf.com/ for being a Bronze sponsor of Bsides Edmonton 2026. We’re grateful for your support of Edmonton’s cybersecurity community.
Be sure to visit them at our 9th annual event September 24–25, 2026.
Our Silver tier is almost full. If your company wants to be part of this year’s community-driven security event, now’s the time to lock in a Gold sponsorship. Visit https://bsidesyeg.org/SponsorApplication
#BSidesEdmonton #InformationSecurity #Cybersecurity
🚨 EUVD-2026-45966
📊 Score: 5.8/10 (CVSS v3.1)
📦 Product: mailpit
🏢 Vendor: axllent
📅 Updated: 2026-07-20
📝 Mailpit is an email testing tool and API for developers. The fix for GHSA-6jxm-fv7w-rw5j (CVE-2026-23845, "Server-Side Request Forgery (SSRF) via HTML Check API"), shipped in mailpit `v1.28.3`, hardened `internal/htmlcheck/css.go::downloadCSSToBytes` with a ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45966
RE: https://mastodon.social/@gtbarry/116952430686277972
"…mischaracterization of the security lapse allowed it to become a much bigger issue than it would have been if it had been contained from the start. Despite security flags and analysts highlighting the breach as early as the 15th of May, the hackers essentially had free rein to operate until at least the 3rd of June thanks to initial reports being dismissed as false positives.”
#infosec #security #maga #USpoli #DHS #cybersecurity
Hackers breached DHS after alarms were twice ruled 'false positives'
Hackers were flagged twice by automated systems and analysts in May 2026, before being dismissed as a false positive each time.
Hackers then managed to find their way into the US Department of Homeland Security's primary information sharing platform, gaining unfettered access to the HSIN network
#DHS #HSIN #databreach #security #cybersecurity #hackers #hacking #hacked
Possible Phishing 🎣
on: ⚠️hxxps[:]//takipcigir[.]com/login
🧬 Analysis at: https://urldna.io/scan/6a5da5043b7750000442661f
#cybersecurity #phishing #infosec #urldna #scam #infosec
NadMesh僵尸网络分析:AI服务时代的产品级威胁
Pulse ID: 6a5e30032da40036f1fb2078
Pulse Link: https://otx.alienvault.com/pulse/6a5e30032da40036f1fb2078
Pulse Author: CyberHunter_NL
Created: 2026-07-20 14:26:11
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #CyberHunter_NL
SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor - StepSecurity
Pulse ID: 6a5e2feb8fea5be337f15a0c
Pulse Link: https://otx.alienvault.com/pulse/6a5e2feb8fea5be337f15a0c
Pulse Author: CyberHunter_NL
Created: 2026-07-20 14:25:47
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #CyberHunter_NL
When 90.6% of AI-discovered vulnerabilities validate as real, and 6% get patched, what we have is not a vulnerability problem but a remediation-capacity problem. The NVD is at breaking point; coordinated disclosure was designed for human-speed discovery. The model has changed.
https://vulntrends.org/blog/ai-finds-bugs-faster-than-humans-can-fix-them/
Introducing CylindricalCanine: The GoldenEyeDog subgroup responsible for the April DigiCert incident | Expel
Pulse ID: 6a5e2fdbf65e4e0fa3dd49df
Pulse Link: https://otx.alienvault.com/pulse/6a5e2fdbf65e4e0fa3dd49df
Pulse Author: CyberHunter_NL
Created: 2026-07-20 14:25:31
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #CyberHunter_NL
TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains — Elastic Security Labs
An emerging MaaS malware is in active development and spreading fast, according to Elastic Security Labs. the company's research.. and its analysis is based on data collected from a network of C2 domains.
Pulse ID: 6a5e2fc4c429c2733a775cf0
Pulse Link: https://otx.alienvault.com/pulse/6a5e2fc4c429c2733a775cf0
Pulse Author: CyberHunter_NL
Created: 2026-07-20 14:25:08
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #ElasticSecurityLabs #InfoSec #MaaS #Malware #OTX #OpenThreatExchange #Vidar #bot #CyberHunter_NL
#Router #Hacking: Why the World’s Most Popular Budget Router Keeps Making Headlines for the Wrong Reasons
#Tenda has earned a reputation that is far from flattering. In this article, we explore the issues that have contributed to this negative perception
https://hackers-arise.com/router-hacking-why-the-worlds-most-popular-budget-router-keeps-making-headlines-for-the-wrong-reasons/
#CYBERsecurity #DIgitalArt
The AirPods Max 2 are down to their second-best price
There are a ton of deals available to shop today thanks to Best Buy’s “Black Friday in July” sale lasting all week. The sale typically aligns closely with Prime Day each year, but of course, Amazon’s shopping holiday ha…
https://www.theverge.com/gadgets/967822/airpods-max-2-logitech-superstrike-kodak-charmera-deal-sale
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Die BaFin hat TeamViewer SE mit 240.000 Euro bestraft, nicht wegen des Cyberangriffs selbst, sondern wegen zu später Offenlegung. Ende Juni 2024 wurde TeamViewer Opfer eines mutmaßlich staatlich gesteuerten Angriffs (APT-Gruppe „Cozy Bear", Russland). Das Unternehmen informierte die Öffentlichkeit, aber nach Ansicht der BaFin nicht schnell genug. #Cybersecurity #BaFin #TeamViewer #ITSecurity
One fake download page ➡️ full remote access to your network ⚠️
SnappyClient shows how quickly a single click can turn into stolen credentials, hijacked payments, and a foothold attackers can exploit long after the initial breach.
👨💻 Learn more: https://any.run/malware-trends/snappyclient/?utm_source=mastodon&utm_medium=post&utm_campaign=snappyclient&utm_content=linktomtt&utm_term=200726
Save $148 on an AMD Ryzen 7 9800X3D bundle with 32GB of RAM, motherboard, and liquid AIO — start your AM5 gaming build for just $1,039
Grab an AMD Ryzen 7 9800X3D, Gigabyte B850 motherboard, 32GB of Corsair Vengeance DDR5, and a CPU cooler for $1,039.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]