voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
81 Million Login Attempts: Massive Password Spray Campaign Bypasses MFA to Compromise Azure and Microsoft 365 Accounts
#CyberSecurity
https://securebulletin.com/81-million-login-attempts-massive-password-spray-campaign-bypasses-mfa-to-compromise-azure-and-microsoft-365-accounts/
Samsung’s new Odyssey OLED G7 is down to $849.99 in its first big Amazon discount
Amazon just cut Samsung’s 2026 32-inch Odyssey OLED G7 to $849.99, bringing 4K OLED gaming to a much better price.
https://www.androidauthority.com/samsung-odyssey-oled-g7-monitor-deal-3683844/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
DuneSlide: Critical Zero-Click RCE Bugs in Cursor IDE Put Fortune 500 Developer Machines at Risk
#CyberSecurity
https://securebulletin.com/duneslide-critical-zero-click-rce-bugs-in-cursor-ide-put-fortune-500-developer-machines-at-risk/
Apple’s Unpatched ‘Hide My Email’ Flaw Has Exposed User Identities for Over a Year
#CyberSecurity
https://securebulletin.com/apples-unpatched-hide-my-email-flaw-has-exposed-user-identities-for-over-a-year/
Four New CVEs in Fluentd Expose Millions of Cloud and Kubernetes Logging Pipelines to RCE and Data Leaks
#CyberSecurity
https://securebulletin.com/four-new-cves-in-fluentd-expose-millions-of-cloud-and-kubernetes-logging-pipelines-to-rce-and-data-leaks/
Possible Phishing 🎣
on: ⚠️hxxps[:]//sweepstakes500[.]godaddysites[.]com
🧬 Analysis at: https://urldna.io/scan/6a4636b63b77500007deecf7
#cybersecurity #phishing #infosec #urldna #scam #infosec
Google Chrome could be fixing one of the most annoying flaws with extension installs
Manually pinning every new extension could be a thing of the past.
https://www.androidauthority.com/google-chrome-auto-extension-pinning-3683826/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
The Pixel 6 looks like it will miss out on Android’s next big kernel upgrade
Pixel 6 runs out of updates this October.
https://www.androidauthority.com/pixel-kernel-6-12-leak-3683790/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Possible Phishing 🎣
on: ⚠️hxxps[:]//sandeeppk03[.]github[.]io/netflix-/
🧬 Analysis at: https://urldna.io/scan/6a46062f3b77500007dee6eb
#cybersecurity #phishing #infosec #urldna #scam #infosec
#Cryptomator for #Android: Freemium Now Available
https://cryptomator.org/blog/2026/07/01/cryptomator-android-freemium/
🖲️ #Cybersecurity #Ciberseguridad #Ciberseguranca #Security #Seguridad #Seguranca #News #Noticia #Noticias #Tecnologia #Technology
⚫ NIST Enrichment Reductions Impact CVE Coverage, Accuracy
🔗 https://www.darkreading.com/vulnerabilities-threats/nist-enrichment-reductions-cve-coverage-accuracy
The National Institute of Standards and Technology (NIST) scaled back on the number of CVEs it selects for in-depth analysis, but the move has produced mixed results, according to researchers.
After wearing the Pebble Time 2 for two weeks, I’ll never buy another smartwatch
What smartwatches were meant to be.
https://www.androidauthority.com/pebble-time-2-smartwatch-hands-on-3680077/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
💾 🟠 Berkadia (berkadia.com)
✓ Verified
📊 ~305K records compromised
📂 Email addresses, Employers, Names, Phone numbers +1 more
📅 2026-03-19 · disclosed 88d after incident
🌐 PHP, WordPress, cloudflare
⚠️ No SPF/DMARC configured
🔗 https://beesint.com/pulse/58f5f92a-4d21-4ab7-8b67-0186afc8629c
🚨 EUVD-2026-41266
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: My Calendar – Accessible Event Manager
🏢 Vendor: joedolson
📅 Updated: 2026-07-02
📝 The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.14 via the 'vcal' parameter due to missing validation on a user contr...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41266
🚨 EUVD-2026-41265
📊 Score: 4.3/10 (CVSS v3.1)
📦 Product: JoomSport – for Sports: Team & League, Football, Hockey & more
🏢 Vendor: beardev
📅 Updated: 2026-07-02
📝 The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.7.8. This is due to the plugin not pr...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41265
🚨 EUVD-2026-41264
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Kirki – Freeform Page Builder, Website Builder & Customizer
🏢 Vendor: Themeum
📅 Updated: 2026-07-02
📝 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.11 via the get_single_symbol. T...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41264
🚨 EUVD-2026-41263
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: JetFormBuilder — Dynamic Blocks Form Builder
🏢 Vendor: jetmonsters
📅 Updated: 2026-07-02
📝 The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.3. This is due to the plugin not properly verifying that a user is ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41263
🚨 EUVD-2026-41262
📊 Score: 7.2/10 (CVSS v3.1)
📦 Product: WP Database Backup – Unlimited Database & Files Backup by Backup for WP
🏢 Vendor: databasebackup
📅 Updated: 2026-07-02
📝 The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to OS Command Injection in all versions up to and including 7.11 via the `wp...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41262
🚨 EUVD-2026-41261
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: LatePoint – Calendar Booking Plugin for Appointments and Events
🏢 Vendor: latepoint
📅 Updated: 2026-07-02
📝 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.2 via the 'service_...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41261
🚨 EUVD-2026-41260
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Appointment Bookings for Zoom GoogleMeet and more – Wappointment
🏢 Vendor: Wappointment
📅 Updated: 2026-07-02
📝 The Appointment Bookings for Zoom GoogleMeet and more – Wappointment plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to and including 2.7.6 via the `appoi...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41260
🚨 EUVD-2026-41259
📊 Score: 8.2/10 (CVSS v3.1)
📦 Product: Eclipse CSI - PIA
🏢 Vendor: Eclipse Foundation
📅 Updated: 2026-07-02
📝 PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix check (issuer.startswith(' https://ci.eclipse.org ') in is_issuer_known, pia/models.py:139) instead of validating the issuer as a properly host-bounded URL. An atta...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41259
Possible Phishing 🎣
on: ⚠️hxxps[:]//roesmeraldas[.]com
🧬 Analysis at: https://urldna.io/scan/6a4622693b77500007deea2b
#cybersecurity #phishing #infosec #urldna #scam #infosec
DuneSlide: Zero-Click RCE Vulnerabilities Discovered in Cursor IDE
Cato AI Labs identified two critical vulnerabilities (CVE-2026-50548 and CVE-2026-50549) in Cursor IDE that allow attackers to achieve remote code execution via zero-click prompt injection. The flaws enable sandbox escapes by overwriting system binaries through manipulated working directories and symlink resolution errors.
**If you use Cursor IDE, update ASAP to version 3.0 or later, because these flaws will be attacked very soon. Be cautious about letting the AI agent pull in content from untrusted external sources (like websites or files), since a malicious prompt hidden there is enough to trigger the attack with no other action from you.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/duneslide-zero-click-rce-vulnerabilities-discovered-in-cursor-ide-5-n-j-t-d/gD2P6Ple2L
Cisco Confirms: Unified CM SSRF Exploited, 48-Hour Window from PoC to Attacks https://deafnews.it/en/article/cisco-confirms-unified-cm-ssrf-exploited-48-hour-window-from-poc-to-attacks #Cybersecurity
Android 17 QPR1 Beta 6 brings a major power-user upgrade to the Terminal app
Keyboard shortcuts arrive in the Linux Terminal app, offering granular control and custom key mapping.
https://www.androidauthority.com/android-17-qpr1-beta-6-linux-terminal-keyboard-shortcuts-3683731/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Verizon’s latest $10 freebie crashed harder than anyone expected
People say getting FIFA World Cup tickets was easier than Verizon's free gift card.
https://www.androidauthority.com/verizon-shine-rewards-gift-card-app-crash-3683722/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Possible Phishing 🎣
on: ⚠️hxxps[:]//43335[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a45bff93b775000047bce18
#cybersecurity #phishing #infosec #urldna #scam #infosec
This new Google tool brings AI agents your Fitbit and health data
Google's new Health CLI lets you build custom dashboards and AI-powered health automations.
https://www.androidauthority.com/google-health-cli-how-to-use-3683636/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Organized cybercrime: the money laundering pipeline #negativepid #digitalInvestigations #OSINT #cybersecurity #AI #tech #onlineInvestigations #robotics #cyberpsychology #cybercrime https://negativepid.blog/organized-cybercrime-the-money-laundering-pipeline/?utm_source=mastodon&utm_medium=social&utm_campaign=fedica-Negative-PID-Blog
🚨 EUVD-2026-41251
📊 Score: 6.4/10 (CVSS v3.1)
📦 Product: GiveWP – Donation Plugin and Fundraising Platform
🏢 Vendor: StellarWP
📅 Updated: 2026-07-02
📝 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sequoia[introduction][image]' parameter in all versions up to, and including, 4.16.1 ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41251
🚨 EUVD-2026-41250
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Academy LMS – WordPress LMS Plugin for Complete eLearning Solution
🏢 Vendor: kodezen
📅 Updated: 2026-07-02
📝 The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.8.1. This is due to t...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41250
🚨 EUVD-2026-41249
📊 Score: 6.4/10 (CVSS v3.1)
📦 Product: Insert Pages
🏢 Vendor: figureone
📅 Updated: 2026-07-02
📝 The Insert Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post custom field keys (meta key names) in all versions up to, and including, 3.11.4. This is due to insufficient output escaping in the the_meta() function: while ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41249
🚨 EUVD-2026-41248
📊 Score: 4.3/10 (CVSS v3.1)
📦 Product: Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress
🏢 Vendor: Icegram
📅 Updated: 2026-07-02
📝 The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to authorization by...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41248
🚨 EUVD-2026-41247
📊 Score: 8.1/10 (CVSS v3.1)
📦 Product: Image Optimizer – Optimize Images and Convert to WebP or AVIF
🏢 Vendor: elemntor
📅 Updated: 2026-07-02
📝 The Image Optimizer plugin for WordPress is vulnerable to arbitrary file deletion in versions up to and including 1.7.4. This is due to insufficient path validation in the Image_Backup::remove() function...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41247
🚨 EUVD-2026-41246
📊 Score: 4.9/10 (CVSS v3.1)
📦 Product: Houzez Property Feed
🏢 Vendor: PropertyHive
📅 Updated: 2026-07-02
📝 The Houzez Property Feed plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, and including, 2.5.46 due to insufficient escaping on the user supplied parameter and lack of sufficient prepara...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41246
🚨 EUVD-2026-41245
📊 Score: 7.5/10 (CVSS v3.1)
📦 Product: Request a Quote – Quote Forms for Any WordPress Site
🏢 Vendor: emarket-design
📅 Updated: 2026-07-02
📝 The Request a Quote plugin for WordPress is vulnerable to Code Injection in versions up to, and including, 2.5.5 via the emd_delete_file AJAX action. This is due to the emd_delete_file() handler deriving a ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41245
🚨 EUVD-2026-41244
📊 Score: 4.3/10 (CVSS v3.1)
📦 Product: Envo's Templates & Widgets for Elementor and WooCommerce
🏢 Vendor: envothemes
📅 Updated: 2026-07-02
📝 The Envo's Templates & Widgets for Elementor and WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the Envo Tabs (and Off Canvas) widget's...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41244