voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]TechWire ⚡ » 🤖 🌐
@techwire@social.gamefan.net

Your Pixel phone now supports high-res Bluetooth audio — here’s how to use it

Everything you need to know about LHDC.

androidauthority.com/pixel-lhd

[Android Authority]

    [?]urlDNA.io :verified: » 🤖 🌐
    @urldna@infosec.exchange

    Possible Phishing 🎣
    on: ⚠️hxxps[:]//093421tr[.]weebly[.]com
    🧬 Analysis at: urldna.io/scan/6a4315343b77500

      [?]Hacker News » 🤖 🌐
      @h4ckernews@mastodon.social

      [?]EUVD Bot » 🤖 🌐
      @EUVD_Bot@mastodon.social

      🚨 EUVD-2026-40275

      📊 Score: 7.0/10 (CVSS v3.1)
      📦 Product: PROMOD V
      🏢 Vendor: Hitachi Energy
      📅 Updated: 2026-06-30

      📝 PROMOD V is using insecure HTTP communication instead of HTTPS. The vulnerability is due to the lack of HTTPS support from 3rd party Digipede server.

      🔗 euvd.enisa.europa.eu/vulnerabi

        [?]EUVD Bot » 🤖 🌐
        @EUVD_Bot@mastodon.social

        🚨 EUVD-2026-40274

        📊 Score: 7.2/10 (CVSS v3.1)
        📦 Product: Ajax Load More - Filters
        🏢 Vendor: Connekt Media
        📅 Updated: 2026-06-30

        📝 The Ajax Load More - Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'taxonomy_include_children' parameter in all versions up to, and including, 3.4.1 due to insufficient input sanitization and output ...

        🔗 euvd.enisa.europa.eu/vulnerabi

          [?]EUVD Bot » 🤖 🌐
          @EUVD_Bot@mastodon.social

          🚨 EUVD-2026-40273

          📊 Score: 9.8/10 (CVSS v3.1)
          📦 Product: EventON (Pro) - WordPress Virtual Event Calendar Plugin
          🏢 Vendor: EventON
          📅 Updated: 2026-06-30

          📝 The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the WordPress 'search' parameter in versions up to, and including, 5.0.11 due to insufficient...

          🔗 euvd.enisa.europa.eu/vulnerabi

            [?]EUVD Bot » 🤖 🌐
            @EUVD_Bot@mastodon.social

            🚨 EUVD-2026-40272

            📊 Score: 9.3/10 (CVSS v3.1)
            📦 Product: Raytha
            🏢 Vendor: Raytha
            📅 Updated: 2026-06-30

            📝 Raytha CMS is vulnerable to SQL Injection within the OData filter parsing pipeline.  The vulnerability allows a remote, unauthenticated attacker to execute
            arbitrary SQL statements against the underlying PostgreSQL database,
            leading to full database compromi...

            🔗 euvd.enisa.europa.eu/vulnerabi

              [?]EUVD Bot » 🤖 🌐
              @EUVD_Bot@mastodon.social

              🚨 EUVD-2025-210371

              📊 Score: n/a
              📦 Product: MantaRay NM
              🏢 Vendor: Nokia
              📅 Updated: 2026-06-30

              📝 Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administrative (local admin) privileges can escalate to full root privileges on the host. Successful exploitation results in root-level access to the filesyst...

              🔗 euvd.enisa.europa.eu/vulnerabi

                [?]EUVD Bot » 🤖 🌐
                @EUVD_Bot@mastodon.social

                🚨 EUVD-2025-210370

                📊 Score: n/a
                📦 Product: MantaRay NM
                🏢 Vendor: Nokia
                📅 Updated: 2026-06-30

                📝 Nokia MantaRay is subject to an Improper Access Control vulnerability due to insufficient authorization within the API. Successful exploitation could allow an authenticated attacker to retrieve confidential information beyond their assigned privileges.

                🔗 euvd.enisa.europa.eu/vulnerabi

                  [?]EUVD Bot » 🤖 🌐
                  @EUVD_Bot@mastodon.social

                  🚨 EUVD-2025-210369

                  📊 Score: n/a
                  📦 Product: MantaRay NM
                  🏢 Vendor: Nokia
                  📅 Updated: 2026-06-30

                  📝 Nokia MantaRay NM is subject to an unrestricted file upload vulnerability due to insufficient file type validation. Successful exploitation could allow an authenticated attacker to upload malicious files onto the system.

                  🔗 euvd.enisa.europa.eu/vulnerabi

                    [?]EUVD Bot » 🤖 🌐
                    @EUVD_Bot@mastodon.social

                    🚨 EUVD-2026-40271

                    📊 Score: 5.1/10 (CVSS v3.1)
                    📦 Product: WebControl CMS
                    🏢 Vendor: Intermark IT
                    📅 Updated: 2026-06-30

                    📝 Cross-Site Scripting (XSS) vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to execute JavaScript code or inject a dynamic iframe into the victim’s browser by sending a malicious URL via the 'urlDestino' ...

                    🔗 euvd.enisa.europa.eu/vulnerabi

                      [?]EUVD Bot » 🤖 🌐
                      @EUVD_Bot@mastodon.social

                      🚨 EUVD-2026-40270

                      📊 Score: 5.1/10 (CVSS v3.1)
                      📦 Product: WebControl CMS
                      🏢 Vendor: Intermark IT
                      📅 Updated: 2026-06-30

                      📝 HTML injection vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to send an email containing malicious HTML code to a victim via the contact form. To exploit this vulnerability, the attacker must send a re...

                      🔗 euvd.enisa.europa.eu/vulnerabi

                        [?]EUVD Bot » 🤖 🌐
                        @EUVD_Bot@mastodon.social

                        🚨 EUVD-2026-40269

                        📊 Score: 7.7/10 (CVSS v3.1)
                        📦 Product: brace-expansion
                        🏢 Vendor: juliangruber
                        📅 Updated: 2026-06-30

                        📝 brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), direc...

                        🔗 euvd.enisa.europa.eu/vulnerabi

                          [?]EUVD Bot » 🤖 🌐
                          @EUVD_Bot@mastodon.social

                          🚨 EUVD-2026-40268

                          📊 Score: 6.4/10 (CVSS v3.1)
                          📅 Updated: 2026-06-30

                          📝 A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of ser...

                          🔗 euvd.enisa.europa.eu/vulnerabi

                            [?]BeyondMachines :verified: » 🤖 🌐
                            @beyondmachines1@infosec.exchange

                            Dell Patches Critical Remote Code Execution Flaws in Wyse Management Suite

                            Dell addressed two vulnerabilities in its Wyse Management Suite, including a critical remote code execution flaw (CVE-2026-41120) that allows unauthenticated attackers to take over management servers.

                            **Make sure all your Wyse Management Suite servers and the thin-client devices they manage are isolated from the internet and reachable only from trusted internal networks. Then update Dell Wyse Management Suite to version 5.5 HF1 ASAP.**

                            beyondmachines.net/event_detai

                              [?]Hackread.com » 🌐
                              @Hackread@mstdn.social

                              📣 🔐 WhatsApp is adding usernames so you can start chats without sharing your phone number. Users can reserve a username now, with the full feature expected later this year.

                              Read or listen to this news: hackread.com/whatsapp-username

                                [?]TechWire ⚡ » 🤖 🌐
                                @techwire@social.gamefan.net

                                Google swears (again) that data-sharing rules will help scammers, threaten your search history

                                Google warns that forced data-sharing on Android and Search will basically hand your private info straight to hackers.

                                androidauthority.com/google-wa

                                [Android Authority]

                                  [?]Linuxiarze » 🌐
                                  @Linuxiarze@mastodon.social

                                  Została wydana nowa wersja Parrot 7.3. Parrot Security OS to specjalistyczna dystrybucja Linuksa stworzona do testów penetracyjnych, informatyki śledczej, łamania zabezpieczeń, testów zabezpieczeń... linuxiarze.pl/parrot-7-3/

                                    [?]Linuxiarze » 🌐
                                    @Linuxiarze@fe.disroot.org

                                    Została wydana nowa wersja Parrot 7.3. Parrot Security OS to specjalistyczna dystrybucja Linuksa stworzona do testów penetracyjnych, informatyki śledczej, łamania zabezpieczeń, testów zabezpieczeń... https://linuxiarze.pl/parrot-7-3/ #linux #debian #cybersecurity

                                      [?]pavroo » 🌐
                                      @pavroo@universeodon.com

                                      Została wydana nowa wersja Parrot 7.3. Parrot Security OS to specjalistyczna dystrybucja Linuksa stworzona do testów penetracyjnych, informatyki śledczej, łamania zabezpieczeń, testów zabezpieczeń... linuxiarze.pl/parrot-7-3/

                                        [?]BeeSINT » 🌐
                                        @BeeSINT@mastodon.social

                                        💾 🟡 Ralph Lauren (ralphlauren.com)
                                        ✓ Verified
                                        📊 ~140K records compromised
                                        📂 Age groups, Email addresses, Genders, Names +1 more
                                        📅 2026-06-11 · disclosed 7d after incident
                                        🌐 Varnish
                                        ⚠️ No SPF/DMARC configured

                                        🔗 beesint.com/pulse/2f99c6da-c05

                                          [?]BeyondMachines :verified: » 🤖 🌐
                                          @beyondmachines1@infosec.exchange

                                          Google Patches Maximum-Severity RCE Vulnerability in Gemini CLI and GitHub Actions

                                          Google patched a maximum-severity RCE vulnerability (CVE-2026-12537) in Gemini CLI and its GitHub Action that allowed attackers to execute host-level commands via malicious workspace configurations. The flaw exploited implicit trust in headless CI/CD environments to steal secrets and compromise build pipelines.

                                          **If you use the Gemini CLI or its GitHub Action in your development pipelines, immediately upgrade to Gemini CLI version 0.39.1 (or 0.40.0-preview.3) and the run-gemini-cli action to version 0.1.22 to patch CVE-2026-12537. Only enable workspace trust for repositories you fully control. Review your automated workflows to make sure they never run shell commands on untrusted inputs.**

                                          beyondmachines.net/event_detai

                                            [?]N_{Dario Fadda} » 🌐
                                            @nuke@poliversity.it

                                            Hackers Actively Exploit CVE-2026-46817 in Oracle E-Business Suite — 456 Attacks Recorded in 24 Hours

                                            securebulletin.com/hackers-act

                                              [?]Ivy Cyber » 🤖 🌐
                                              @ivycyber@privacysafe.social

                                              🛡️ news & tips across the

                                              “James Carville wants to disenfranchise all the # voters in NY-13 bc he disagrees w/some of Darializa's comments. He said recently the Dems should refuse to let her # caucus w/ them(!), that he wouldn't be in the pa...”

                                              masto.nyc/@GetMisch/1168367925

                                              🤖 via RSS feed. Not an endorsement.

                                                [?]CTI.FYI » 🤖 🌐
                                                @CTI_FYI@infosec.exchange

                                                🚨New ransom group blog posts!🚨

                                                Group name: qilin
                                                Post title: Hemmersbach GmbH & Co. KG
                                                Info: cti.fyi/groups/qilin.html

                                                Group name: qilin
                                                Post title: Chamco
                                                Info: cti.fyi/groups/qilin.html

                                                  [?]Hugo | DevOps | Cybersecurity » 🌐
                                                  @hugovalters@mastodon.social

                                                  WordPress: 152 CVEs, avg CVSS 6.03. 100% unpatched. Trust Score: D. Top weakness: XSS (CWE-79). Popular plugins = prime target. Update your CMS now.

                                                  valtersit.com/vendors/wordpres

                                                    [?]N_{Dario Fadda} » 🌐
                                                    @nuke@poliversity.it

                                                    Malicious ClawHub Skills Compromise AI Agents With Hidden Backdoors — 247,000 Installs, $2.3M Stolen

                                                    securebulletin.com/malicious-c

                                                      [?]TechWire ⚡ » 🤖 🌐
                                                      @techwire@social.gamefan.net

                                                      I automated my day with ChatGPT Scheduled Tasks. Here’s what’s great — and what’s broken

                                                      ChatGPT’s new automation feature gets a lot right, but it's not perfect.

                                                      androidauthority.com/chatgpt-s

                                                      [Android Authority]

                                                        [?]N_{Dario Fadda} » 🌐
                                                        @nuke@poliversity.it

                                                        Russia’s Turla APT Deploys STOCKSTAY Backdoor Against Ukrainian Government and Military Targets

                                                        securebulletin.com/russias-tur

                                                          [?]TechWire ⚡ » 🤖 🌐
                                                          @techwire@social.gamefan.net

                                                          OnePlus just launched a budget phone with a 3-day battery, but there’s a huge catch

                                                          It also looks quite good, even with that dummy camera lens.

                                                          androidauthority.com/oneplus-n

                                                          [Android Authority]

                                                            [?]CVEDatabase.com » 🌐
                                                            @cvedatabase@techhub.social

                                                            Security Tip: Stop relying on perimeter-based security. 🛡️ Zero Trust Architecture (ZTA) assumes the network is already compromised. Implement micro-segmentation to isolate workloads and enforce strict identity verification for every access request. This prevents lateral movement after an initial breach. Track the vulnerabilities that bypass traditional defenses at cvedatabase.com

                                                              [?]urlDNA.io :verified: » 🤖 🌐
                                                              @urldna@infosec.exchange

                                                              Possible Phishing 🎣
                                                              on: ⚠️hxxps[:]//globalarubapro[.]pages[.]dev
                                                              🧬 Analysis at: urldna.io/scan/6a431cf03b77500

                                                                [?]Winbuzzer » 🌐
                                                                @winbuzzer@mastodon.social

                                                                winbuzzer.com/2026/06/30/micro

                                                                Microsoft has improved Edge for Business controls for shadow AI, data loss prevention, contractors, extensions, and scareware.

                                                                  [?]ransomNews » 🌐
                                                                  @ransomnews.online@bsky.brid.gy

                                                                  🚨 Earthquake relief scams weaponize breaking disasters

                                                                  Fraudsters rapidly registered earthquake-themed domains to harvest donations and personal information through fake relief campaigns.

                                                                  🔗 read more: hackread.com/venezuela-ea...

                                                                    [?]TechWire ⚡ » 🤖 🌐
                                                                    @techwire@social.gamefan.net

                                                                    Google’s chatty Keep Live and Gmail Live interfaces make first appearance

                                                                    The feature is promised to go live some time this summer.

                                                                    androidauthority.com/google-gm

                                                                    [Android Authority]

                                                                      [?]N_{Dario Fadda} » 🌐
                                                                      @nuke@poliversity.it

                                                                      Critical Microsoft 365 RCE Flaw CVE-2025-60727 Exploitable via Malicious Excel Files — Patch Now

                                                                      securebulletin.com/critical-mi

                                                                        [?]AllAboutSecurity » 🌐
                                                                        @allaboutsecurity@mastodon.social

                                                                        Versicherer 2026: Risiken wachsen, KI bleibt Nebensache

                                                                        Im Zentrum des Berichts steht die Lücke zwischen versicherten und unversicherten Cyberschäden.

                                                                        all-about-security.de/versiche

                                                                          [?]urlDNA.io :verified: » 🤖 🌐
                                                                          @urldna@infosec.exchange

                                                                          Possible Phishing 🎣
                                                                          on: ⚠️hxxps[:]//webvideotron12[.]weebly[.]com
                                                                          🧬 Analysis at: urldna.io/scan/6a434d743b77500

                                                                            [?]ransomNews » 🌐
                                                                            @ransomnews.online@bsky.brid.gy

                                                                            🚨 SimpleHelp flaw already fuels real intrusions

                                                                            Attackers are actively exploiting an authentication bypass in remote support software, prompting urgent patching for exposed servers.

                                                                            🔗 read more: securityonline.info/simplehelp-a...

                                                                              Back to top - More...