voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]TechWire ⚡ » 🤖 🌐
@techwire@social.gamefan.net

Android 17 QPR1 Beta 6 brings a major power-user upgrade to the Terminal app

Keyboard shortcuts arrive in the Linux Terminal app, offering granular control and custom key mapping.

androidauthority.com/android-1

[Android Authority]

    [?]TechWire ⚡ » 🤖 🌐
    @techwire@social.gamefan.net

    Verizon’s latest $10 freebie crashed harder than anyone expected

    People say getting FIFA World Cup tickets was easier than Verizon's free gift card.

    androidauthority.com/verizon-s

    [Android Authority]

      [?]urlDNA.io :verified: » 🤖 🌐
      @urldna@infosec.exchange

      Possible Phishing 🎣
      on: ⚠️hxxps[:]//43335[.]weebly[.]com
      🧬 Analysis at: urldna.io/scan/6a45bff93b77500

        [?]TechWire ⚡ » 🤖 🌐
        @techwire@social.gamefan.net

        This new Google tool brings AI agents your Fitbit and health data

        Google's new Health CLI lets you build custom dashboards and AI-powered health automations.

        androidauthority.com/google-he

        [Android Authority]

          [?]Negative PID SL » 🌐
          @negativepid@mastodon.social

          [?]EUVD Bot » 🤖 🌐
          @EUVD_Bot@mastodon.social

          🚨 EUVD-2026-41251

          📊 Score: 6.4/10 (CVSS v3.1)
          📦 Product: GiveWP – Donation Plugin and Fundraising Platform
          🏢 Vendor: StellarWP
          📅 Updated: 2026-07-02

          📝 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sequoia[introduction][image]' parameter in all versions up to, and including, 4.16.1 ...

          🔗 euvd.enisa.europa.eu/vulnerabi

            [?]EUVD Bot » 🤖 🌐
            @EUVD_Bot@mastodon.social

            🚨 EUVD-2026-41250

            📊 Score: 5.3/10 (CVSS v3.1)
            📦 Product: Academy LMS – WordPress LMS Plugin for Complete eLearning Solution
            🏢 Vendor: kodezen
            📅 Updated: 2026-07-02

            📝 The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.8.1. This is due to t...

            🔗 euvd.enisa.europa.eu/vulnerabi

              [?]EUVD Bot » 🤖 🌐
              @EUVD_Bot@mastodon.social

              🚨 EUVD-2026-41249

              📊 Score: 6.4/10 (CVSS v3.1)
              📦 Product: Insert Pages
              🏢 Vendor: figureone
              📅 Updated: 2026-07-02

              📝 The Insert Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post custom field keys (meta key names) in all versions up to, and including, 3.11.4. This is due to insufficient output escaping in the the_meta() function: while ...

              🔗 euvd.enisa.europa.eu/vulnerabi

                [?]EUVD Bot » 🤖 🌐
                @EUVD_Bot@mastodon.social

                🚨 EUVD-2026-41248

                📊 Score: 4.3/10 (CVSS v3.1)
                📦 Product: Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress
                🏢 Vendor: Icegram
                📅 Updated: 2026-07-02

                📝 The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to authorization by...

                🔗 euvd.enisa.europa.eu/vulnerabi

                  [?]EUVD Bot » 🤖 🌐
                  @EUVD_Bot@mastodon.social

                  🚨 EUVD-2026-41247

                  📊 Score: 8.1/10 (CVSS v3.1)
                  📦 Product: Image Optimizer – Optimize Images and Convert to WebP or AVIF
                  🏢 Vendor: elemntor
                  📅 Updated: 2026-07-02

                  📝 The Image Optimizer plugin for WordPress is vulnerable to arbitrary file deletion in versions up to and including 1.7.4. This is due to insufficient path validation in the Image_Backup::remove() function...

                  🔗 euvd.enisa.europa.eu/vulnerabi

                    [?]EUVD Bot » 🤖 🌐
                    @EUVD_Bot@mastodon.social

                    🚨 EUVD-2026-41246

                    📊 Score: 4.9/10 (CVSS v3.1)
                    📦 Product: Houzez Property Feed
                    🏢 Vendor: PropertyHive
                    📅 Updated: 2026-07-02

                    📝 The Houzez Property Feed plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, and including, 2.5.46 due to insufficient escaping on the user supplied parameter and lack of sufficient prepara...

                    🔗 euvd.enisa.europa.eu/vulnerabi

                      [?]EUVD Bot » 🤖 🌐
                      @EUVD_Bot@mastodon.social

                      🚨 EUVD-2026-41245

                      📊 Score: 7.5/10 (CVSS v3.1)
                      📦 Product: Request a Quote – Quote Forms for Any WordPress Site
                      🏢 Vendor: emarket-design
                      📅 Updated: 2026-07-02

                      📝 The Request a Quote plugin for WordPress is vulnerable to Code Injection in versions up to, and including, 2.5.5 via the emd_delete_file AJAX action. This is due to the emd_delete_file() handler deriving a ...

                      🔗 euvd.enisa.europa.eu/vulnerabi

                        [?]EUVD Bot » 🤖 🌐
                        @EUVD_Bot@mastodon.social

                        🚨 EUVD-2026-41244

                        📊 Score: 4.3/10 (CVSS v3.1)
                        📦 Product: Envo's Templates & Widgets for Elementor and WooCommerce
                        🏢 Vendor: envothemes
                        📅 Updated: 2026-07-02

                        📝 The Envo's Templates & Widgets for Elementor and WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the Envo Tabs (and Off Canvas) widget's...

                        🔗 euvd.enisa.europa.eu/vulnerabi

                          [?]OTX Bot » 🤖 🌐
                          @techbot@social.raytec.co

                          Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula

                          In May 2026, an attack campaign targeting banking users in Spain and Portugal was identified involving the Ousaban banking Trojan. The malware, previously active in Brazil, spreads through phishing PDFs that redirect victims to malicious webpages performing environment checks to ensure targets are located in Spain or Portugal. The attack chain involves VBS scripts downloading steganographic images containing the payload, which is then dropped and executed on victims' systems. Ousaban establishes persistence, monitors banking activity across multiple financial institutions, and uses daily-changing DDNS domains to resolve C2 server addresses. The malware employs screenshot capture, keylogging, clipboard injection, and remote control capabilities to steal banking credentials. It utilizes custom encryption algorithms and geofencing techniques to evade detection and limit exposure to intended targets.

                          Pulse ID: 6a45880f3df872860c77a553
                          Pulse Link: otx.alienvault.com/pulse/6a458
                          Pulse Author: AlienVault
                          Created: 2026-07-01 21:35:11

                          Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                            [?]OTX Bot » 🤖 🌐
                            @techbot@social.raytec.co

                            Iran-Nexus Disseminates MarkiRAT Surveillance Tool

                            TAG-182, an Iran-nexus threat cluster, is conducting surveillance operations targeting Iranian citizens both domestically and abroad using MarkiRAT malware. The group distributes fake Android applications masquerading as VPN services and media players through social media platforms, particularly Instagram. Following Iran's partial internet restoration in May 2026 after an 88-day shutdown, these surveillance activities have intensified as Iranian security apparatus seeks to monitor perceived dissidents and anti-government activists. MarkiRAT samples demonstrate tradecraft overlaps with previously documented Ferocious Kitten operations, including use of Background Intelligent Transfer Service (BITS). The group operates infrastructure across multiple autonomous systems, utilizing domains with naming conventions mimicking legitimate services like Microsoft, Google, and Facebook.

                            Pulse ID: 6a45471afccee96152675f88
                            Pulse Link: otx.alienvault.com/pulse/6a454
                            Pulse Author: AlienVault
                            Created: 2026-07-01 16:58:02

                            Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                              [?]OTX Bot » 🤖 🌐
                              @techbot@social.raytec.co

                              How a single ScreenConnect incident exposed a massive campaign

                              A massive campaign distributes malicious installer archives hosted on spoofed websites masquerading as popular software like OBS Studio, DNS Jumper, DS4Windows, and Bandicam. Over 90 domain names localized across 10 languages were discovered. The malicious archives bundle a legitimate Microsoft-signed install.exe binary with a rogue install.res.1033.dll library deployed via DLL sideloading. This installs the ScreenConnect remote access service, which then deploys AsyncRAT payloads through PowerShell and VBS scripts. The threat actors leverage SEO techniques to position fraudulent sites at the top of search engine results, targeting both individual users and corporate networks. The infrastructure spans three IP addresses with domains registered between October 2025 and March 2026, creating a global footprint with multi-language support.

                              Pulse ID: 6a4545dbc77aff75fe16cee7
                              Pulse Link: otx.alienvault.com/pulse/6a454
                              Pulse Author: AlienVault
                              Created: 2026-07-01 16:52:43

                              Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                [?]OTX Bot » 🤖 🌐
                                @techbot@social.raytec.co

                                Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique

                                Check Point Research discovered a novel browser-native ransomware technique that emerged from AI-generated code attributed to DeepSeek. The attack leverages the File System Access API in Chromium browsers to encrypt files without requiring native payloads, exploits, or app installations. A malicious sample disguised as an AI image upscaler was analyzed, revealing how LLMs can connect theoretical platform risks to practical attack workflows. The technique is particularly concerning on Android, where Chrome allows web pages to access photo directories after user approval through legitimate permission prompts. By using social engineering with a fake AI enhancement tool, attackers can persuade victims to grant folder-level access, enabling file exfiltration and encryption entirely within the browser. This demonstrates how frontier AI models can autonomously design novel attack chains by reasoning across existing knowledge.

                                Pulse ID: 6a4500ffd044499efcd70db1
                                Pulse Link: otx.alienvault.com/pulse/6a450
                                Pulse Author: AlienVault
                                Created: 2026-07-01 11:58:55

                                Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                  [?]Hugo | DevOps | Cybersecurity » 🌐
                                  @hugovalters@mastodon.social

                                  Marvell: 57 CVEs, avg CVSS 7.78, max 9.8. 87% unpatched. Trust Score: C. Hardware chips for cloud & 5G—patch your firmware now.

                                  valtersit.com/vendors/marvell/

                                    [?]TechWire ⚡ » 🤖 🌐
                                    @techwire@social.gamefan.net

                                    Apple Now Sells Refurbished iPhone 16e Starting at $419

                                    Apple today updated its online refurbished store in the United States, adding the iPhone 16e. Refurbished iPhone 16e models are available at discounted prices for the first time since the device launched in February 202…

                                    macrumors.com/2026/06/30/apple

                                    [MacRumors]

                                      [?]TechWire ⚡ » 🤖 🌐
                                      @techwire@social.gamefan.net

                                      Supreme Court Will Hear Apple's Appeal in Epic Games App Store Fight

                                      The United States Supreme Court has agreed to hear Apple's appeal against the contempt ruling that forced it to change its App Store linking rules, reports Reuters. In a statement to MacRumors, Apple said the court's de…

                                      macrumors.com/2026/06/30/apple

                                      [MacRumors]

                                        [?]urlDNA.io :verified: » 🤖 🌐
                                        @urldna@infosec.exchange

                                        Possible Phishing 🎣
                                        on: ⚠️hxxps[:]//webmailnetinsupdate[.]weebly[.]com
                                        🧬 Analysis at: urldna.io/scan/6a45a3c73b77500

                                          [?]TierraSapiens » 🤖 🌐
                                          @tierrasapiens@mastodon.social

                                          🖲️
                                          ⚫ Phishers Gain Persistence at EU, Asia Hospitality Orgs
                                          🔗 darkreading.com/cyberattacks-d

                                          Separate but similar campaigns described by Microsoft and Trend Micro use malicious zip files to spread malware via social engineering and obsfucation, including blockchain abuse.

                                            [?]TheHackerWire » 🤖 🌐
                                            @thehackerwire@mastodon.social

                                            🟠 CVE-2026-14429 - High (8.3)

                                            Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security sever...

                                            🔗 thehackerwire.com/vulnerabilit

                                            CVE Alert: CVE-2026-14429

                                            Alt...CVE Alert: CVE-2026-14429

                                              [?]TheHackerWire » 🤖 🌐
                                              @thehackerwire@mastodon.social

                                              🔴 CVE-2026-14416 - Critical (9.6)

                                              Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

                                              🔗 thehackerwire.com/vulnerabilit

                                              CVE Alert: CVE-2026-14416

                                              Alt...CVE Alert: CVE-2026-14416

                                                [?]TheHackerWire » 🤖 🌐
                                                @thehackerwire@mastodon.social

                                                🔴 CVE-2026-14417 - Critical (9.6)

                                                Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

                                                🔗 thehackerwire.com/vulnerabilit

                                                CVE Alert: CVE-2026-14417

                                                Alt...CVE Alert: CVE-2026-14417

                                                  [?]TheHackerWire » 🤖 🌐
                                                  @thehackerwire@mastodon.social

                                                  🔴 CVE-2026-14419 - Critical (9.6)

                                                  Use after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

                                                  🔗 thehackerwire.com/vulnerabilit

                                                  CVE Alert: CVE-2026-14419

                                                  Alt...CVE Alert: CVE-2026-14419

                                                    [?]Hacker News » 🤖 🌐
                                                    @h4ckernews@mastodon.social

                                                    [?]Hacker News » 🤖 🌐
                                                    @h4ckernews@mastodon.social

                                                    [?]Black Cat White Hat Security » 🌐
                                                    @BCWHQuiz@defcon.social

                                                    Defend & Respond: High-Risk User
                                                    A "high-risk user" refers to an account highly suspected of being compromised by threat actors. This status is triggered by identity threat indicators like impossible travel, anomalous IP activity, leaked credentials, or token theft. Organizations must actively identify, investigate, and remediate these accounts to prevent data breaches.



                                                    Link: blackcatwhitehatsecurity.com

                                                    Defend & Respond: High-Risk User
A "high-risk user" refers to an account highly suspected of being compromised by threat actors. This status is triggered by identity threat indicators like impossible travel, anomalous IP activity, leaked credentials, or token theft. Organizations must actively identify, investigate, and remediate these accounts to prevent data breaches.

                                                    Alt...Defend & Respond: High-Risk User A "high-risk user" refers to an account highly suspected of being compromised by threat actors. This status is triggered by identity threat indicators like impossible travel, anomalous IP activity, leaked credentials, or token theft. Organizations must actively identify, investigate, and remediate these accounts to prevent data breaches.

                                                      [?]TechWire ⚡ » 🤖 🌐
                                                      @techwire@social.gamefan.net

                                                      I wore the Oura Ring 5 for a month, and it's an even bigger upgrade than expected

                                                      But there's one feature that makes the Oura Ring 5 truly worth buying.

                                                      zdnet.com/article/oura-ring-5-

                                                      [ZDNet]

                                                        [?]urlDNA.io :verified: » 🤖 🌐
                                                        @urldna@infosec.exchange

                                                        Possible Phishing 🎣
                                                        on: ⚠️hxxps[:]//netcoinslogi-shop[.]webflow[.]io
                                                        🧬 Analysis at: urldna.io/scan/6a4595a33b77500

                                                          [?]TechWire ⚡ » 🤖 🌐
                                                          @techwire@social.gamefan.net

                                                          Private and community servers for Minecraft and COD are illegal and amount to piracy, ESA tells California Senate — Stop Killing Games-backed bill fails t…

                                                          The Entertainment Software Association, in its infinite wisdom, has told a California Senate committee that private and community servers are illegal and amount to piracy.

                                                          tomshardware.com/video-games/p

                                                          [Tom's Hardware]

                                                            [?]TechWire ⚡ » 🤖 🌐
                                                            @techwire@social.gamefan.net

                                                            32GB Corsair Vengeance DDR5 is $314 in this Woot sale — the lowest standalone RAM price in months, thanks to $125 discount

                                                            Get Corsair Vengeance DDR5 for just $314 at Woot.

                                                            tomshardware.com/pc-components

                                                            [Tom's Hardware]

                                                              [?]TheHackerWire » 🤖 🌐
                                                              @thehackerwire@mastodon.social

                                                              🟠 CVE-2026-14426 - High (7.5)

                                                              Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

                                                              🔗 thehackerwire.com/vulnerabilit

                                                              CVE Alert: CVE-2026-14426

                                                              Alt...CVE Alert: CVE-2026-14426

                                                                [?]urlDNA.io :verified: » 🤖 🌐
                                                                @urldna@infosec.exchange

                                                                Possible Phishing 🎣
                                                                on: ⚠️hxxp[:]//amazon-clone-taupe-six[.]vercel[.]app
                                                                🧬 Analysis at: urldna.io/scan/6a4571ee3b77500

                                                                  [?]TheHackerWire » 🤖 🌐
                                                                  @thehackerwire@mastodon.social

                                                                  🟠 CVE-2026-14430 - High (8.8)

                                                                  Integer overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

                                                                  🔗 thehackerwire.com/vulnerabilit

                                                                  CVE Alert: CVE-2026-14430

                                                                  Alt...CVE Alert: CVE-2026-14430

                                                                    Back to top - More...