voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]N_{Dario Fadda} » 🌐
@nuke@poliversity.it

81 Million Login Attempts: Massive Password Spray Campaign Bypasses MFA to Compromise Azure and Microsoft 365 Accounts

securebulletin.com/81-million-

    [?]TechWire ⚡ » 🤖 🌐
    @techwire@social.gamefan.net

    Samsung’s new Odyssey OLED G7 is down to $849.99 in its first big Amazon discount

    Amazon just cut Samsung’s 2026 32-inch Odyssey OLED G7 to $849.99, bringing 4K OLED gaming to a much better price.

    androidauthority.com/samsung-o

    [Android Authority]

      [?]N_{Dario Fadda} » 🌐
      @nuke@poliversity.it

      DuneSlide: Critical Zero-Click RCE Bugs in Cursor IDE Put Fortune 500 Developer Machines at Risk

      securebulletin.com/duneslide-c

        [?] Politico.eu (Unofficial RSS) » 🤖 🌐
        @politico_eu_bot@social.espeweb.net

        [?]N_{Dario Fadda} » 🌐
        @nuke@poliversity.it

        Apple’s Unpatched ‘Hide My Email’ Flaw Has Exposed User Identities for Over a Year

        securebulletin.com/apples-unpa

          [?]The New Oil » 🤖 🌐
          @thenewoil@mastodon.thenewoil.org

          [?]N_{Dario Fadda} » 🌐
          @nuke@poliversity.it

          Four New CVEs in Fluentd Expose Millions of Cloud and Kubernetes Logging Pipelines to RCE and Data Leaks

          securebulletin.com/four-new-cv

            [?]urlDNA.io :verified: » 🤖 🌐
            @urldna@infosec.exchange

            Possible Phishing 🎣
            on: ⚠️hxxps[:]//sweepstakes500[.]godaddysites[.]com
            🧬 Analysis at: urldna.io/scan/6a4636b63b77500

              [?]TechWire ⚡ » 🤖 🌐
              @techwire@social.gamefan.net

              Google Chrome could be fixing one of the most annoying flaws with extension installs

              Manually pinning every new extension could be a thing of the past.

              androidauthority.com/google-ch

              [Android Authority]

                [?]TechWire ⚡ » 🤖 🌐
                @techwire@social.gamefan.net

                The Pixel 6 looks like it will miss out on Android’s next big kernel upgrade

                Pixel 6 runs out of updates this October.

                androidauthority.com/pixel-ker

                [Android Authority]

                  [?]urlDNA.io :verified: » 🤖 🌐
                  @urldna@infosec.exchange

                  Possible Phishing 🎣
                  on: ⚠️hxxps[:]//sandeeppk03[.]github[.]io/netflix-/
                  🧬 Analysis at: urldna.io/scan/6a46062f3b77500

                    [?]The New Oil » 🤖 🌐
                    @thenewoil@mastodon.thenewoil.org

                    [?]TierraSapiens » 🤖 🌐
                    @tierrasapiens@mastodon.social

                    🖲️
                    ⚫ NIST Enrichment Reductions Impact CVE Coverage, Accuracy
                    🔗 darkreading.com/vulnerabilitie

                    The National Institute of Standards and Technology (NIST) scaled back on the number of CVEs it selects for in-depth analysis, but the move has produced mixed results, according to researchers.

                      [?]TechWire ⚡ » 🤖 🌐
                      @techwire@social.gamefan.net

                      After wearing the Pebble Time 2 for two weeks, I’ll never buy another smartwatch

                      What smartwatches were meant to be.

                      androidauthority.com/pebble-ti

                      [Android Authority]

                        [?]BeeSINT » 🌐
                        @BeeSINT@mastodon.social

                        💾 🟠 Berkadia (berkadia.com)
                        ✓ Verified
                        📊 ~305K records compromised
                        📂 Email addresses, Employers, Names, Phone numbers +1 more
                        📅 2026-03-19 · disclosed 88d after incident
                        🌐 PHP, WordPress, cloudflare
                        ⚠️ No SPF/DMARC configured

                        🔗 beesint.com/pulse/58f5f92a-4d2

                          [?]EUVD Bot » 🤖 🌐
                          @EUVD_Bot@mastodon.social

                          🚨 EUVD-2026-41266

                          📊 Score: 5.3/10 (CVSS v3.1)
                          📦 Product: My Calendar – Accessible Event Manager
                          🏢 Vendor: joedolson
                          📅 Updated: 2026-07-02

                          📝 The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.14 via the 'vcal' parameter due to missing validation on a user contr...

                          🔗 euvd.enisa.europa.eu/vulnerabi

                            [?]EUVD Bot » 🤖 🌐
                            @EUVD_Bot@mastodon.social

                            🚨 EUVD-2026-41265

                            📊 Score: 4.3/10 (CVSS v3.1)
                            📦 Product: JoomSport – for Sports: Team & League, Football, Hockey & more
                            🏢 Vendor: beardev
                            📅 Updated: 2026-07-02

                            📝 The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.7.8. This is due to the plugin not pr...

                            🔗 euvd.enisa.europa.eu/vulnerabi

                              [?]EUVD Bot » 🤖 🌐
                              @EUVD_Bot@mastodon.social

                              🚨 EUVD-2026-41264

                              📊 Score: 5.3/10 (CVSS v3.1)
                              📦 Product: Kirki – Freeform Page Builder, Website Builder & Customizer
                              🏢 Vendor: Themeum
                              📅 Updated: 2026-07-02

                              📝 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.11 via the get_single_symbol. T...

                              🔗 euvd.enisa.europa.eu/vulnerabi

                                [?]EUVD Bot » 🤖 🌐
                                @EUVD_Bot@mastodon.social

                                🚨 EUVD-2026-41263

                                📊 Score: 5.3/10 (CVSS v3.1)
                                📦 Product: JetFormBuilder — Dynamic Blocks Form Builder
                                🏢 Vendor: jetmonsters
                                📅 Updated: 2026-07-02

                                📝 The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.3. This is due to the plugin not properly verifying that a user is ...

                                🔗 euvd.enisa.europa.eu/vulnerabi

                                  [?]EUVD Bot » 🤖 🌐
                                  @EUVD_Bot@mastodon.social

                                  🚨 EUVD-2026-41262

                                  📊 Score: 7.2/10 (CVSS v3.1)
                                  📦 Product: WP Database Backup – Unlimited Database & Files Backup by Backup for WP
                                  🏢 Vendor: databasebackup
                                  📅 Updated: 2026-07-02

                                  📝 The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to OS Command Injection in all versions up to and including 7.11 via the `wp...

                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                    [?]EUVD Bot » 🤖 🌐
                                    @EUVD_Bot@mastodon.social

                                    🚨 EUVD-2026-41261

                                    📊 Score: 5.3/10 (CVSS v3.1)
                                    📦 Product: LatePoint – Calendar Booking Plugin for Appointments and Events
                                    🏢 Vendor: latepoint
                                    📅 Updated: 2026-07-02

                                    📝 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.2 via the 'service_...

                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                      [?]EUVD Bot » 🤖 🌐
                                      @EUVD_Bot@mastodon.social

                                      🚨 EUVD-2026-41260

                                      📊 Score: 5.3/10 (CVSS v3.1)
                                      📦 Product: Appointment Bookings for Zoom GoogleMeet and more – Wappointment
                                      🏢 Vendor: Wappointment
                                      📅 Updated: 2026-07-02

                                      📝 The Appointment Bookings for Zoom GoogleMeet and more – Wappointment plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to and including 2.7.6 via the `appoi...

                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                        [?]EUVD Bot » 🤖 🌐
                                        @EUVD_Bot@mastodon.social

                                        🚨 EUVD-2026-41259

                                        📊 Score: 8.2/10 (CVSS v3.1)
                                        📦 Product: Eclipse CSI - PIA
                                        🏢 Vendor: Eclipse Foundation
                                        📅 Updated: 2026-07-02

                                        📝 PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix check (issuer.startswith(' ci.eclipse.org ') in is_issuer_known, pia/models.py:139) instead of validating the issuer as a properly host-bounded URL. An atta...

                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                          [?]urlDNA.io :verified: » 🤖 🌐
                                          @urldna@infosec.exchange

                                          Possible Phishing 🎣
                                          on: ⚠️hxxps[:]//roesmeraldas[.]com
                                          🧬 Analysis at: urldna.io/scan/6a4622693b77500

                                            [?]BeyondMachines :verified: » 🤖 🌐
                                            @beyondmachines1@infosec.exchange

                                            DuneSlide: Zero-Click RCE Vulnerabilities Discovered in Cursor IDE

                                            Cato AI Labs identified two critical vulnerabilities (CVE-2026-50548 and CVE-2026-50549) in Cursor IDE that allow attackers to achieve remote code execution via zero-click prompt injection. The flaws enable sandbox escapes by overwriting system binaries through manipulated working directories and symlink resolution errors.

                                            **If you use Cursor IDE, update ASAP to version 3.0 or later, because these flaws will be attacked very soon. Be cautious about letting the AI agent pull in content from untrusted external sources (like websites or files), since a malicious prompt hidden there is enough to trigger the attack with no other action from you.**

                                            beyondmachines.net/event_detai

                                              [?]deafnews » 🤖 🌐
                                              @deafnews@infosec.exchange

                                              [?]TechWire ⚡ » 🤖 🌐
                                              @techwire@social.gamefan.net

                                              Android 17 QPR1 Beta 6 brings a major power-user upgrade to the Terminal app

                                              Keyboard shortcuts arrive in the Linux Terminal app, offering granular control and custom key mapping.

                                              androidauthority.com/android-1

                                              [Android Authority]

                                                [?]TechWire ⚡ » 🤖 🌐
                                                @techwire@social.gamefan.net

                                                Verizon’s latest $10 freebie crashed harder than anyone expected

                                                People say getting FIFA World Cup tickets was easier than Verizon's free gift card.

                                                androidauthority.com/verizon-s

                                                [Android Authority]

                                                  [?]urlDNA.io :verified: » 🤖 🌐
                                                  @urldna@infosec.exchange

                                                  Possible Phishing 🎣
                                                  on: ⚠️hxxps[:]//43335[.]weebly[.]com
                                                  🧬 Analysis at: urldna.io/scan/6a45bff93b77500

                                                    [?]TechWire ⚡ » 🤖 🌐
                                                    @techwire@social.gamefan.net

                                                    This new Google tool brings AI agents your Fitbit and health data

                                                    Google's new Health CLI lets you build custom dashboards and AI-powered health automations.

                                                    androidauthority.com/google-he

                                                    [Android Authority]

                                                      [?]Negative PID SL » 🌐
                                                      @negativepid@mastodon.social

                                                      [?]EUVD Bot » 🤖 🌐
                                                      @EUVD_Bot@mastodon.social

                                                      🚨 EUVD-2026-41251

                                                      📊 Score: 6.4/10 (CVSS v3.1)
                                                      📦 Product: GiveWP – Donation Plugin and Fundraising Platform
                                                      🏢 Vendor: StellarWP
                                                      📅 Updated: 2026-07-02

                                                      📝 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sequoia[introduction][image]' parameter in all versions up to, and including, 4.16.1 ...

                                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                                        [?]EUVD Bot » 🤖 🌐
                                                        @EUVD_Bot@mastodon.social

                                                        🚨 EUVD-2026-41250

                                                        📊 Score: 5.3/10 (CVSS v3.1)
                                                        📦 Product: Academy LMS – WordPress LMS Plugin for Complete eLearning Solution
                                                        🏢 Vendor: kodezen
                                                        📅 Updated: 2026-07-02

                                                        📝 The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.8.1. This is due to t...

                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                          [?]EUVD Bot » 🤖 🌐
                                                          @EUVD_Bot@mastodon.social

                                                          🚨 EUVD-2026-41249

                                                          📊 Score: 6.4/10 (CVSS v3.1)
                                                          📦 Product: Insert Pages
                                                          🏢 Vendor: figureone
                                                          📅 Updated: 2026-07-02

                                                          📝 The Insert Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post custom field keys (meta key names) in all versions up to, and including, 3.11.4. This is due to insufficient output escaping in the the_meta() function: while ...

                                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                                            [?]EUVD Bot » 🤖 🌐
                                                            @EUVD_Bot@mastodon.social

                                                            🚨 EUVD-2026-41248

                                                            📊 Score: 4.3/10 (CVSS v3.1)
                                                            📦 Product: Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress
                                                            🏢 Vendor: Icegram
                                                            📅 Updated: 2026-07-02

                                                            📝 The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to authorization by...

                                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                                              [?]EUVD Bot » 🤖 🌐
                                                              @EUVD_Bot@mastodon.social

                                                              🚨 EUVD-2026-41247

                                                              📊 Score: 8.1/10 (CVSS v3.1)
                                                              📦 Product: Image Optimizer – Optimize Images and Convert to WebP or AVIF
                                                              🏢 Vendor: elemntor
                                                              📅 Updated: 2026-07-02

                                                              📝 The Image Optimizer plugin for WordPress is vulnerable to arbitrary file deletion in versions up to and including 1.7.4. This is due to insufficient path validation in the Image_Backup::remove() function...

                                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                                [?]EUVD Bot » 🤖 🌐
                                                                @EUVD_Bot@mastodon.social

                                                                🚨 EUVD-2026-41246

                                                                📊 Score: 4.9/10 (CVSS v3.1)
                                                                📦 Product: Houzez Property Feed
                                                                🏢 Vendor: PropertyHive
                                                                📅 Updated: 2026-07-02

                                                                📝 The Houzez Property Feed plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, and including, 2.5.46 due to insufficient escaping on the user supplied parameter and lack of sufficient prepara...

                                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                                  [?]EUVD Bot » 🤖 🌐
                                                                  @EUVD_Bot@mastodon.social

                                                                  🚨 EUVD-2026-41245

                                                                  📊 Score: 7.5/10 (CVSS v3.1)
                                                                  📦 Product: Request a Quote – Quote Forms for Any WordPress Site
                                                                  🏢 Vendor: emarket-design
                                                                  📅 Updated: 2026-07-02

                                                                  📝 The Request a Quote plugin for WordPress is vulnerable to Code Injection in versions up to, and including, 2.5.5 via the emd_delete_file AJAX action. This is due to the emd_delete_file() handler deriving a ...

                                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                                    [?]EUVD Bot » 🤖 🌐
                                                                    @EUVD_Bot@mastodon.social

                                                                    🚨 EUVD-2026-41244

                                                                    📊 Score: 4.3/10 (CVSS v3.1)
                                                                    📦 Product: Envo's Templates & Widgets for Elementor and WooCommerce
                                                                    🏢 Vendor: envothemes
                                                                    📅 Updated: 2026-07-02

                                                                    📝 The Envo's Templates & Widgets for Elementor and WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the Envo Tabs (and Off Canvas) widget's...

                                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                                      Back to top - More...