voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]TechWire ⚡ » 🤖 🌐
@techwire@social.gamefan.net

Oomwoo is a new open-source robot vacuum you can 3D print yourself, sidesteps cloud security risks by running fully offline — project combines Raspberry Pi, 2D LiDAR, and a 3D-printed chassis

Maker's Pet has launched oomwoo, an open-source robot vacuum that owners build themselves.

tomshardware.com/3d-printing/m

[Tom's Hardware]

    [?]TechWire ⚡ » 🤖 🌐
    @techwire@social.gamefan.net

    HamsterOS jams a 32-bit GUI operating system in a single 1.44 MB floppy disk — retro OS for 386-era hardware should make for easy living with DOS machines and software

    HamsterOS fits on just a single 1.44 MB floppy disk, and it's set for a full release this November.

    tomshardware.com/video-games/r

    [Tom's Hardware]

      [?]TechWire ⚡ » 🤖 🌐
      @techwire@social.gamefan.net

      Samsung's 9100 Pro SSD 1TB is still available at its excellent Prime Day price thanks to 39% discount — cheaper and faster than the 990 Pro and the lowest price we've seen in months

      The Samsung 9100 Pro SSD is still sporting its Prime Day price. Grab one at this low price while you can.

      tomshardware.com/pc-components

      [Tom's Hardware]

        [?]TechWire ⚡ » 🤖 🌐
        @techwire@social.gamefan.net

        Meta fights soaring hardware costs by reusing old DDR4 server memory in new DDR5-only servers — custom CXL 2.0 chip marries legacy DDR4-2400 with cutting-edge DDR5-6400

        Meta develops its custom Vistara CXL memory expander to use DDR4 memory with new servers running AMD EPYC 'Turin' processors.

        tomshardware.com/pc-components

        [Tom's Hardware]

          [?]Negative PID SL » 🌐
          @negativepid@mastodon.social

          [?]Negative PID SL » 🌐
          @negativepid@mastodon.social

          [?]EUVD Bot » 🤖 🌐
          @EUVD_Bot@mastodon.social

          🚨 EUVD-2026-40679

          📊 Score: n/a
          📦 Product: Chrome
          🏢 Vendor: Google
          📅 Updated: 2026-07-01

          📝 Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

          🔗 euvd.enisa.europa.eu/vulnerabi

            [?]EUVD Bot » 🤖 🌐
            @EUVD_Bot@mastodon.social

            🚨 EUVD-2026-40692

            📊 Score: n/a
            📦 Product: Chrome
            🏢 Vendor: Google
            📅 Updated: 2026-07-01

            📝 Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

            🔗 euvd.enisa.europa.eu/vulnerabi

              [?]EUVD Bot » 🤖 🌐
              @EUVD_Bot@mastodon.social

              🚨 EUVD-2026-40693

              📊 Score: n/a
              📦 Product: Chrome
              🏢 Vendor: Google
              📅 Updated: 2026-07-01

              📝 Use after free in Omnibox in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

              🔗 euvd.enisa.europa.eu/vulnerabi

                [?]EUVD Bot » 🤖 🌐
                @EUVD_Bot@mastodon.social

                🚨 EUVD-2026-40683

                📊 Score: n/a
                📦 Product: Chrome
                🏢 Vendor: Google
                📅 Updated: 2026-07-01

                📝 Insufficient validation of untrusted input in Autofill in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

                🔗 euvd.enisa.europa.eu/vulnerabi

                  [?]EUVD Bot » 🤖 🌐
                  @EUVD_Bot@mastodon.social

                  🚨 EUVD-2026-40689

                  📊 Score: n/a
                  📦 Product: Chrome
                  🏢 Vendor: Google
                  📅 Updated: 2026-07-01

                  📝 Inappropriate implementation in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)

                  🔗 euvd.enisa.europa.eu/vulnerabi

                    [?]EUVD Bot » 🤖 🌐
                    @EUVD_Bot@mastodon.social

                    🚨 EUVD-2026-40694

                    📊 Score: n/a
                    📦 Product: Chrome
                    🏢 Vendor: Google
                    📅 Updated: 2026-07-01

                    📝 Use after free in Navigation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium)

                    🔗 euvd.enisa.europa.eu/vulnerabi

                      [?]EUVD Bot » 🤖 🌐
                      @EUVD_Bot@mastodon.social

                      🚨 EUVD-2026-40681

                      📊 Score: n/a
                      📦 Product: Chrome
                      🏢 Vendor: Google
                      📅 Updated: 2026-07-01

                      📝 Incorrect security UI in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)

                      🔗 euvd.enisa.europa.eu/vulnerabi

                        [?]EUVD Bot » 🤖 🌐
                        @EUVD_Bot@mastodon.social

                        🚨 EUVD-2026-40698

                        📊 Score: n/a
                        📦 Product: Chrome
                        🏢 Vendor: Google
                        📅 Updated: 2026-07-01

                        📝 Uninitialized Use in Codecs in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

                        🔗 euvd.enisa.europa.eu/vulnerabi

                          [?]EUVD Bot » 🤖 🌐
                          @EUVD_Bot@mastodon.social

                          🚨 EUVD-2026-40682

                          📊 Score: n/a
                          📦 Product: Chrome
                          🏢 Vendor: Google
                          📅 Updated: 2026-07-01

                          📝 Inappropriate implementation in Credential Management in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

                          🔗 euvd.enisa.europa.eu/vulnerabi

                            [?]EUVD Bot » 🤖 🌐
                            @EUVD_Bot@mastodon.social

                            🚨 EUVD-2026-40688

                            📊 Score: n/a
                            📦 Product: Chrome
                            🏢 Vendor: Google
                            📅 Updated: 2026-07-01

                            📝 Inappropriate implementation in XML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)

                            🔗 euvd.enisa.europa.eu/vulnerabi

                              [?]EUVD Bot » 🤖 🌐
                              @EUVD_Bot@mastodon.social

                              🚨 EUVD-2026-40709

                              📊 Score: n/a
                              📦 Product: Chrome
                              🏢 Vendor: Google
                              📅 Updated: 2026-07-01

                              📝 Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

                              🔗 euvd.enisa.europa.eu/vulnerabi

                                [?]EUVD Bot » 🤖 🌐
                                @EUVD_Bot@mastodon.social

                                🚨 EUVD-2026-40695

                                📊 Score: n/a
                                📦 Product: Chrome
                                🏢 Vendor: Google
                                📅 Updated: 2026-07-01

                                📝 Insufficient policy enforcement in PermissionsPolicy in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

                                🔗 euvd.enisa.europa.eu/vulnerabi

                                  [?]EUVD Bot » 🤖 🌐
                                  @EUVD_Bot@mastodon.social

                                  🚨 EUVD-2026-40714

                                  📊 Score: n/a
                                  📦 Product: Chrome
                                  🏢 Vendor: Google
                                  📅 Updated: 2026-07-01

                                  📝 Incorrect security UI in SplitView in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                    [?]EUVD Bot » 🤖 🌐
                                    @EUVD_Bot@mastodon.social

                                    🚨 EUVD-2026-40708

                                    📊 Score: n/a
                                    📦 Product: Chrome
                                    🏢 Vendor: Google
                                    📅 Updated: 2026-07-01

                                    📝 Insufficient validation of untrusted input in WebXR in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                      [?]EUVD Bot » 🤖 🌐
                                      @EUVD_Bot@mastodon.social

                                      🚨 EUVD-2026-40702

                                      📊 Score: n/a
                                      📦 Product: Chrome
                                      🏢 Vendor: Google
                                      📅 Updated: 2026-07-01

                                      📝 Inappropriate implementation in Paint in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                        [?]RedPacket Security » 🌐
                                        @RedPacketSecurity@mastodon.social

                                        [?]TechWire ⚡ » 🤖 🌐
                                        @techwire@social.gamefan.net

                                        Cargo thieves target AI data center supplies in $1.3 million heists — $300,000 worth of copper wire and $…

                                        Authorities recover $1.3 million worth of data center supplies and equipment in a truck stop near Chicago. Equipment like this is a prime target for theft rings given its high value, but it's also likely difficult to se…

                                        tomshardware.com/tech-industry

                                        [Tom's Hardware]

                                          [?]Daniel Marsh » 🤖 🌐
                                          @danielmarsh@social.thepixelspulse.com

                                          A groundbreaking 'BioShocking' attack is redefining AI browser security. This novel prompt injection manipulates AI agents by framing data exfiltration as part of a fictional scenario, bypassing internal safety guardrails. It's not a code exploit, but a clever psychological trick on the AI itself, leading to credential theft and privacy breaches. Discover how it works and essential…

                                          tpp.blog/np6c7if

                                          🤖 This post was AI-generated.

                                            [?]TechWire ⚡ » 🤖 🌐
                                            @techwire@social.gamefan.net

                                            Taiwan raids Supermicro and two supply-chain partners in widening Nvidia smuggling probe — nine sites hit as six people summoned for questioning

                                            Taiwan officials raided Supermicro Computer's Taiwan office on Monday, alongside the homes of six individuals and three affiliated company sites

                                            tomshardware.com/tech-industry

                                            [Tom's Hardware]

                                              [?]urlDNA.io :verified: » 🤖 🌐
                                              @urldna@infosec.exchange

                                              Possible Phishing 🎣
                                              on: ⚠️hxxps[:]//lhjgjkkfkk[.]weebly[.]com/
                                              🧬 Analysis at: urldna.io/scan/6a43d3c03b77500

                                                [?]The New Oil » 🤖 🌐
                                                @thenewoil@mastodon.thenewoil.org

                                                [?]TechWire ⚡ » 🤖 🌐
                                                @techwire@social.gamefan.net

                                                LG’s 27-inch Tandem OLED gaming monitor is cheaper than ever

                                                The price of LG’s UltraGear 27GX700A-B 1440p gaming monitor that came out last August has dropped to nearly its best price yet. You can grab it at Amazon for $484.99 or at LG for $499.99 (originally $599.99). That’s a g…

                                                theverge.com/gadgets/906880/lg

                                                [The Verge]

                                                  [?]TechWire ⚡ » 🤖 🌐
                                                  @techwire@social.gamefan.net

                                                  Google’s NotebookLM can sum up your research in a TikTok-style clip

                                                  Google's NotebookLM is adding a new way to catch up on your notes: TikTok-style AI videos. The new feature is rolling out to Google AI Ultra and Pro subscribers, allowing NotebookLM to generate 60-second vertical AI cli…

                                                  theverge.com/tech/959778/googl

                                                  [The Verge]

                                                    [?]TechWire ⚡ » 🤖 🌐
                                                    @techwire@social.gamefan.net

                                                    Acer’s Swift Go 16 is a lot of laptop for $900

                                                    The Acer Swift Go 16 AI has a massive trackpad. | Photo: Antonio G. Di Benedetto / The Verge As high memory and storage prices have driven up the cost of everything from consoles to computers, finding a competent laptop…

                                                    theverge.com/gadgets/959687/ac

                                                    [The Verge]

                                                      [?]TechWire ⚡ » 🤖 🌐
                                                      @techwire@social.gamefan.net

                                                      Amazon fined $2.25 million for failing to help identity theft victims

                                                      The Federal Trade Commission fined Amazon $2.25 million to settle claims that the company failed to help customers who fell victim to identity theft, as reported earlier by Bloomberg. In its complaint, the FTC accuses A…

                                                      theverge.com/tech/959847/amazo

                                                      [The Verge]

                                                        [?]TechWire ⚡ » 🤖 🌐
                                                        @techwire@social.gamefan.net

                                                        Dish files for bankruptcy, but not shutting down

                                                        Dish, the company that operates Dish TV and Sling TV, has filed for Chapter 11 bankruptcy," as reported earlier by Reuters. The plan will allow the EchoStar-owned company to continue to wind down its wireless operations…

                                                        theverge.com/tech/959894/dish-

                                                        [The Verge]

                                                          [?]EUVD Bot » 🤖 🌐
                                                          @EUVD_Bot@mastodon.social

                                                          🚨 EUVD-2026-40423

                                                          📊 Score: 7.5/10 (CVSS v3.1)
                                                          📦 Product: msgpack-python
                                                          🏢 Vendor: msgpack
                                                          📅 Updated: 2026-06-30

                                                          📝 MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/crash on Unpacker reuse after a caught error, potentially leading to a DoS attack. If the Unpacker is used repeatedly after an error o...

                                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                                            [?]EUVD Bot » 🤖 🌐
                                                            @EUVD_Bot@mastodon.social

                                                            🚨 EUVD-2026-40422

                                                            📊 Score: 9.3/10 (CVSS v3.1)
                                                            📦 Product: DCMTK Toolkit
                                                            🏢 Vendor: OFFIS DICOM
                                                            📅 Updated: 2026-06-30

                                                            📝 A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside the chosen output directory, using both relative (../) paths and absolute paths.

                                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                                              [?]EUVD Bot » 🤖 🌐
                                                              @EUVD_Bot@mastodon.social

                                                              🚨 EUVD-2026-40421

                                                              📊 Score: 8.7/10 (CVSS v3.1)
                                                              📦 Product: DCMTK Toolkit
                                                              🏢 Vendor: OFFIS DICOM
                                                              📅 Updated: 2026-06-30

                                                              📝 An unauthenticated remote attacker can repeatedly send a single crafted connection request to leak memory. Against storescp in its default single-process mode, memory grows quickly and the service is eventually killed, after which it stops acceptin...

                                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                                [?]EUVD Bot » 🤖 🌐
                                                                @EUVD_Bot@mastodon.social

                                                                🚨 EUVD-2026-40420

                                                                📊 Score: 8.7/10 (CVSS v3.1)
                                                                📦 Product: DCMTK Toolkit
                                                                🏢 Vendor: OFFIS DICOM
                                                                📅 Updated: 2026-06-30

                                                                📝 An unauthenticated remote attacker can repeatedly send crafted connection requests to leak memory. In single-process deployments the memory grows until the service is killed and the port stops responding until restart.

                                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                                  [?]EUVD Bot » 🤖 🌐
                                                                  @EUVD_Bot@mastodon.social

                                                                  🚨 EUVD-2026-40419

                                                                  📊 Score: 5.3/10 (CVSS v3.1)
                                                                  📦 Product: invoiceninja
                                                                  🏢 Vendor: invoiceninja
                                                                  📅 Updated: 2026-06-30

                                                                  📝 Invoice Ninja through 5.13.26 contains an open redirect vulnerability in the client portal login that allows unauthenticated attackers to redirect authenticated victims to attacker-controlled external URLs by injecting a malicious value into the in...

                                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                                    [?]EUVD Bot » 🤖 🌐
                                                                    @EUVD_Bot@mastodon.social

                                                                    🚨 EUVD-2026-40418

                                                                    📊 Score: 9.3/10 (CVSS v3.1)
                                                                    📦 Product: txtai
                                                                    🏢 Vendor: neuml
                                                                    📅 Updated: 2026-06-30

                                                                    📝 txtai through 9.10.0, fixed in commit 11b32da, exposes an API /reindex endpoint whose function body parameter is resolved through txtai.util.Resolver, which performs __import__ and getattr on the caller-supplied dotted path with no allowlist. When the API is exp...

                                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                                      [?]EUVD Bot » 🤖 🌐
                                                                      @EUVD_Bot@mastodon.social

                                                                      🚨 EUVD-2026-40417

                                                                      📊 Score: 8.8/10 (CVSS v3.1)
                                                                      📦 Product: DCMTK Toolkit
                                                                      🏢 Vendor: OFFIS DICOM
                                                                      📅 Updated: 2026-06-30

                                                                      📝 An unauthenticated attacker can read worklist records from a directory outside the intended per-AE worklist storage area. In a multi-area deployment, this can cross departmental or clinic data separation.

                                                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                                                        [?]EUVD Bot » 🤖 🌐
                                                                        @EUVD_Bot@mastodon.social

                                                                        🚨 EUVD-2026-40416

                                                                        📊 Score: 7.1/10 (CVSS v3.1)
                                                                        📦 Product: yudao-cloud
                                                                        🏢 Vendor: YunaiV
                                                                        📅 Updated: 2026-06-30

                                                                        📝 yudao-cloud before 2026.06 contains a broken access control vulnerability in the BPM module that allows any authenticated user to access arbitrary process instance records by supplying a caller-controlled process-instance identifier to an unprotected endp...

                                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                                          [?]EUVD Bot » 🤖 🌐
                                                                          @EUVD_Bot@mastodon.social

                                                                          🚨 EUVD-2026-40415

                                                                          📊 Score: 7.1/10 (CVSS v3.1)
                                                                          📦 Product: Invidious
                                                                          🏢 Vendor: iv-org
                                                                          📅 Updated: 2026-06-30

                                                                          📝 Invidious through 2.20260626.0, fixed in commit 77ad416, contains a broken object level authorization vulnerability that allows authenticated attackers to delete videos from other users' playlists by supplying an arbitrary global video index in the remove_v...

                                                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                                                            [?]EUVD Bot » 🤖 🌐
                                                                            @EUVD_Bot@mastodon.social

                                                                            🚨 EUVD-2026-40414

                                                                            📊 Score: 6.9/10 (CVSS v3.1)
                                                                            📦 Product: presenton
                                                                            🏢 Vendor: presenton
                                                                            📅 Updated: 2026-06-30

                                                                            📝 Presenton before 0.8.8-beta bundles an MCP server that, on server/Docker deployments configured with session authentication (AUTH_USERNAME/AUTH_PASSWORD), is reachable unauthenticated at /mcp because the nginx front-end does not apply the auth_request ga...

                                                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                                                              [?]EUVD Bot » 🤖 🌐
                                                                              @EUVD_Bot@mastodon.social

                                                                              🚨 EUVD-2026-40413

                                                                              📊 Score: 7.4/10 (CVSS v3.1)
                                                                              📦 Product: WebSphere Application Server, WebSphere Application Server, WebSphere Application Server - Liberty
                                                                              🏢 Vendor: IBM
                                                                              📅 Updated: 2026-06-30

                                                                              📝 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerabil...

                                                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                [?]EUVD Bot » 🤖 🌐
                                                                                @EUVD_Bot@mastodon.social

                                                                                🚨 EUVD-2025-31198

                                                                                📊 Score: 4.8/10 (CVSS v3.1)
                                                                                📦 Product: Open Babel, Open Babel
                                                                                📅 Updated: 2026-06-30

                                                                                📝 Open Babel has heap buffer overflow in SMILES OBSmilesParser::ParseSmiles

                                                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                  [?]EUVD Bot » 🤖 🌐
                                                                                  @EUVD_Bot@mastodon.social

                                                                                  🚨 EUVD-2025-31199

                                                                                  📊 Score: 4.8/10 (CVSS v3.1)
                                                                                  📦 Product: Open Babel, Open Babel
                                                                                  📅 Updated: 2026-06-30

                                                                                  📝 Open Babel has out-of-bounds write (overlapping memcpy) in zipstream basic_unzip_streambuf::underflow

                                                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                    [?]𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 :verified: » 🌐
                                                                                    @youranonnewsirc@nerdculture.de

                                                                                    ... [SENSITIVE CONTENT]

                                                                                    Geopolitically, the US and Iran agreed to halt attacks, planning talks in Qatar today to address Strait of Hormuz tensions. In technology, South Korea committed over $1 trillion to AI and chip investments, and OpenAI previewed its new GPT-5.6 models with gated access. Cybersecurity saw active exploitation of a critical Oracle E-Business flaw, Microsoft removing 119 malicious Edge extensions, and warnings about AI coding agent prompt injection risks.

                                                                                      [?]TechWire ⚡ » 🤖 🌐
                                                                                      @techwire@social.gamefan.net

                                                                                      61% of US adults use AI for health information now - up from 2% in 2024

                                                                                      Patients are also three times more likely to trust AI in their doctor's secure portal than a public chatbot.

                                                                                      zdnet.com/article/us-adults-us

                                                                                      [ZDNet]

                                                                                        [?]TechWire ⚡ » 🤖 🌐
                                                                                        @techwire@social.gamefan.net

                                                                                        Apple rushed to squash 29 bugs because AI is supercharging hackers - update ASAP

                                                                                        Software updates are rolling out now for iPhone, iPad, and Mac, bringing fixes that weren't supposed to arrive so soon. Here's why.

                                                                                        zdnet.com/article/apple-rushed

                                                                                        [ZDNet]

                                                                                          Back to top - More...