voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
Android 17 QPR1 Beta 6 brings a major power-user upgrade to the Terminal app
Keyboard shortcuts arrive in the Linux Terminal app, offering granular control and custom key mapping.
https://www.androidauthority.com/android-17-qpr1-beta-6-linux-terminal-keyboard-shortcuts-3683731/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Verizon’s latest $10 freebie crashed harder than anyone expected
People say getting FIFA World Cup tickets was easier than Verizon's free gift card.
https://www.androidauthority.com/verizon-shine-rewards-gift-card-app-crash-3683722/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Possible Phishing 🎣
on: ⚠️hxxps[:]//43335[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a45bff93b775000047bce18
#cybersecurity #phishing #infosec #urldna #scam #infosec
This new Google tool brings AI agents your Fitbit and health data
Google's new Health CLI lets you build custom dashboards and AI-powered health automations.
https://www.androidauthority.com/google-health-cli-how-to-use-3683636/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Organized cybercrime: the money laundering pipeline #negativepid #digitalInvestigations #OSINT #cybersecurity #AI #tech #onlineInvestigations #robotics #cyberpsychology #cybercrime https://negativepid.blog/organized-cybercrime-the-money-laundering-pipeline/?utm_source=mastodon&utm_medium=social&utm_campaign=fedica-Negative-PID-Blog
🚨 EUVD-2026-41251
📊 Score: 6.4/10 (CVSS v3.1)
📦 Product: GiveWP – Donation Plugin and Fundraising Platform
🏢 Vendor: StellarWP
📅 Updated: 2026-07-02
📝 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sequoia[introduction][image]' parameter in all versions up to, and including, 4.16.1 ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41251
🚨 EUVD-2026-41250
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Academy LMS – WordPress LMS Plugin for Complete eLearning Solution
🏢 Vendor: kodezen
📅 Updated: 2026-07-02
📝 The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.8.1. This is due to t...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41250
🚨 EUVD-2026-41249
📊 Score: 6.4/10 (CVSS v3.1)
📦 Product: Insert Pages
🏢 Vendor: figureone
📅 Updated: 2026-07-02
📝 The Insert Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post custom field keys (meta key names) in all versions up to, and including, 3.11.4. This is due to insufficient output escaping in the the_meta() function: while ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41249
🚨 EUVD-2026-41248
📊 Score: 4.3/10 (CVSS v3.1)
📦 Product: Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress
🏢 Vendor: Icegram
📅 Updated: 2026-07-02
📝 The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to authorization by...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41248
🚨 EUVD-2026-41247
📊 Score: 8.1/10 (CVSS v3.1)
📦 Product: Image Optimizer – Optimize Images and Convert to WebP or AVIF
🏢 Vendor: elemntor
📅 Updated: 2026-07-02
📝 The Image Optimizer plugin for WordPress is vulnerable to arbitrary file deletion in versions up to and including 1.7.4. This is due to insufficient path validation in the Image_Backup::remove() function...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41247
🚨 EUVD-2026-41246
📊 Score: 4.9/10 (CVSS v3.1)
📦 Product: Houzez Property Feed
🏢 Vendor: PropertyHive
📅 Updated: 2026-07-02
📝 The Houzez Property Feed plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, and including, 2.5.46 due to insufficient escaping on the user supplied parameter and lack of sufficient prepara...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41246
🚨 EUVD-2026-41245
📊 Score: 7.5/10 (CVSS v3.1)
📦 Product: Request a Quote – Quote Forms for Any WordPress Site
🏢 Vendor: emarket-design
📅 Updated: 2026-07-02
📝 The Request a Quote plugin for WordPress is vulnerable to Code Injection in versions up to, and including, 2.5.5 via the emd_delete_file AJAX action. This is due to the emd_delete_file() handler deriving a ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41245
🚨 EUVD-2026-41244
📊 Score: 4.3/10 (CVSS v3.1)
📦 Product: Envo's Templates & Widgets for Elementor and WooCommerce
🏢 Vendor: envothemes
📅 Updated: 2026-07-02
📝 The Envo's Templates & Widgets for Elementor and WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the Envo Tabs (and Off Canvas) widget's...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41244
Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula
In May 2026, an attack campaign targeting banking users in Spain and Portugal was identified involving the Ousaban banking Trojan. The malware, previously active in Brazil, spreads through phishing PDFs that redirect victims to malicious webpages performing environment checks to ensure targets are located in Spain or Portugal. The attack chain involves VBS scripts downloading steganographic images containing the payload, which is then dropped and executed on victims' systems. Ousaban establishes persistence, monitors banking activity across multiple financial institutions, and uses daily-changing DDNS domains to resolve C2 server addresses. The malware employs screenshot capture, keylogging, clipboard injection, and remote control capabilities to steal banking credentials. It utilizes custom encryption algorithms and geofencing techniques to evade detection and limit exposure to intended targets.
Pulse ID: 6a45880f3df872860c77a553
Pulse Link: https://otx.alienvault.com/pulse/6a45880f3df872860c77a553
Pulse Author: AlienVault
Created: 2026-07-01 21:35:11
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Bank #BankingTrojan #Brazil #Clipboard #CyberSecurity #DNS #Encryption #InfoSec #Malware #OTX #OpenThreatExchange #PDF #Phishing #Portugal #Spain #Trojan #VBS #bot #AlienVault
Iran-Nexus Disseminates MarkiRAT Surveillance Tool
TAG-182, an Iran-nexus threat cluster, is conducting surveillance operations targeting Iranian citizens both domestically and abroad using MarkiRAT malware. The group distributes fake Android applications masquerading as VPN services and media players through social media platforms, particularly Instagram. Following Iran's partial internet restoration in May 2026 after an 88-day shutdown, these surveillance activities have intensified as Iranian security apparatus seeks to monitor perceived dissidents and anti-government activists. MarkiRAT samples demonstrate tradecraft overlaps with previously documented Ferocious Kitten operations, including use of Background Intelligent Transfer Service (BITS). The group operates infrastructure across multiple autonomous systems, utilizing domains with naming conventions mimicking legitimate services like Microsoft, Google, and Facebook.
Pulse ID: 6a45471afccee96152675f88
Pulse Link: https://otx.alienvault.com/pulse/6a45471afccee96152675f88
Pulse Author: AlienVault
Created: 2026-07-01 16:58:02
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #CyberSecurity #Facebook #Google #Government #InfoSec #Instagram #Iran #Malware #Microsoft #Mimic #OTX #OpenThreatExchange #RAT #RCE #SocialMedia #VPN #bot #AlienVault
How a single ScreenConnect incident exposed a massive campaign
A massive campaign distributes malicious installer archives hosted on spoofed websites masquerading as popular software like OBS Studio, DNS Jumper, DS4Windows, and Bandicam. Over 90 domain names localized across 10 languages were discovered. The malicious archives bundle a legitimate Microsoft-signed install.exe binary with a rogue install.res.1033.dll library deployed via DLL sideloading. This installs the ScreenConnect remote access service, which then deploys AsyncRAT payloads through PowerShell and VBS scripts. The threat actors leverage SEO techniques to position fraudulent sites at the top of search engine results, targeting both individual users and corporate networks. The infrastructure spans three IP addresses with domains registered between October 2025 and March 2026, creating a global footprint with multi-language support.
Pulse ID: 6a4545dbc77aff75fe16cee7
Pulse Link: https://otx.alienvault.com/pulse/6a4545dbc77aff75fe16cee7
Pulse Author: AlienVault
Created: 2026-07-01 16:52:43
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AsyncRAT #CyberSecurity #DNS #InfoSec #Microsoft #OTX #OpenThreatExchange #PowerShell #RAT #ScreenConnect #SideLoading #VBS #Windows #bot #AlienVault
Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique
Check Point Research discovered a novel browser-native ransomware technique that emerged from AI-generated code attributed to DeepSeek. The attack leverages the File System Access API in Chromium browsers to encrypt files without requiring native payloads, exploits, or app installations. A malicious sample disguised as an AI image upscaler was analyzed, revealing how LLMs can connect theoretical platform risks to practical attack workflows. The technique is particularly concerning on Android, where Chrome allows web pages to access photo directories after user approval through legitimate permission prompts. By using social engineering with a fake AI enhancement tool, attackers can persuade victims to grant folder-level access, enabling file exfiltration and encryption entirely within the browser. This demonstrates how frontier AI models can autonomously design novel attack chains by reasoning across existing knowledge.
Pulse ID: 6a4500ffd044499efcd70db1
Pulse Link: https://otx.alienvault.com/pulse/6a4500ffd044499efcd70db1
Pulse Author: AlienVault
Created: 2026-07-01 11:58:55
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #Browser #CheckPoint #Chrome #CyberSecurity #Edge #Encryption #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #SocialEngineering #bot #AlienVault
Marvell: 57 CVEs, avg CVSS 7.78, max 9.8. 87% unpatched. Trust Score: C. Hardware chips for cloud & 5G—patch your firmware now. #Marvell #cybersecurity #infosec
Apple Now Sells Refurbished iPhone 16e Starting at $419
Apple today updated its online refurbished store in the United States, adding the iPhone 16e. Refurbished iPhone 16e models are available at discounted prices for the first time since the device launched in February 202…
https://www.macrumors.com/2026/06/30/apple-refurbished-iphone-16e/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #MacRumors [MacRumors]
Supreme Court Will Hear Apple's Appeal in Epic Games App Store Fight
The United States Supreme Court has agreed to hear Apple's appeal against the contempt ruling that forced it to change its App Store linking rules, reports Reuters. In a statement to MacRumors, Apple said the court's de…
https://www.macrumors.com/2026/06/30/apple-epic-games-supreme-court/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #MacRumors [MacRumors]
Possible Phishing 🎣
on: ⚠️hxxps[:]//webmailnetinsupdate[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a45a3c73b77500007deddb1
#cybersecurity #phishing #infosec #urldna #scam #infosec
🖲️ #Cybersecurity #Ciberseguridad #Ciberseguranca #Security #Seguridad #Seguranca #News #Noticia #Noticias #Tecnologia #Technology
⚫ Phishers Gain Persistence at EU, Asia Hospitality Orgs
🔗 https://www.darkreading.com/cyberattacks-data-breaches/phishers-persistence-eu-asia-hospitality-orgs
Separate but similar campaigns described by Microsoft and Trend Micro use malicious zip files to spread malware via social engineering and obsfucation, including blockchain abuse.
🟠 CVE-2026-14429 - High (8.3)
Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security sever...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14429/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🔴 CVE-2026-14416 - Critical (9.6)
Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14416/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🔴 CVE-2026-14417 - Critical (9.6)
Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14417/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🔴 CVE-2026-14419 - Critical (9.6)
Use after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14419/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
A new Android malware from Google
https://f-droid.org/2026/07/01/adv-malware.html
#HackerNews #Android #Malware #Google #Security #Threats #Cybersecurity #TechNews
Opening up 'Zero-Knowledge Proof' technology to promote privacy in age assurance
#HackerNews #ZeroKnowledgeProof #privacy #AgeAssurance #techInnovation #Cybersecurity
Defend & Respond: High-Risk User
A "high-risk user" refers to an account highly suspected of being compromised by threat actors. This status is triggered by identity threat indicators like impossible travel, anomalous IP activity, leaked credentials, or token theft. Organizations must actively identify, investigate, and remediate these accounts to prevent data breaches.
#cybersecurity #governance #risk #technology #gaming #programming #ai #business #engineering
Link: https://blackcatwhitehatsecurity.com
I wore the Oura Ring 5 for a month, and it's an even bigger upgrade than expected
But there's one feature that makes the Oura Ring 5 truly worth buying.
https://www.zdnet.com/article/oura-ring-5-review/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
Possible Phishing 🎣
on: ⚠️hxxps[:]//netcoinslogi-shop[.]webflow[.]io
🧬 Analysis at: https://urldna.io/scan/6a4595a33b77500007dedc3a
#cybersecurity #phishing #infosec #urldna #scam #infosec
Private and community servers for Minecraft and COD are illegal and amount to piracy, ESA tells California Senate — Stop Killing Games-backed bill fails t…
The Entertainment Software Association, in its infinite wisdom, has told a California Senate committee that private and community servers are illegal and amount to piracy.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
32GB Corsair Vengeance DDR5 is $314 in this Woot sale — the lowest standalone RAM price in months, thanks to $125 discount
Get Corsair Vengeance DDR5 for just $314 at Woot.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
🟠 CVE-2026-14426 - High (7.5)
Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14426/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Possible Phishing 🎣
on: ⚠️hxxp[:]//amazon-clone-taupe-six[.]vercel[.]app
🧬 Analysis at: https://urldna.io/scan/6a4571ee3b77500007ded898
#cybersecurity #phishing #infosec #urldna #scam #infosec
🟠 CVE-2026-14430 - High (8.8)
Integer overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14430/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack