voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
Your Pixel phone now supports high-res Bluetooth audio — here’s how to use it
Everything you need to know about LHDC.
https://www.androidauthority.com/pixel-lhdc-bluetooth-explained-3679869/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Possible Phishing 🎣
on: ⚠️hxxps[:]//093421tr[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a4315343b7750000550305f
#cybersecurity #phishing #infosec #urldna #scam #infosec
European digital ID wallets are a gift to Google and Apple
https://waag.org/en/article/european-digital-id-wallets-are-gift-google-and-apple/
#HackerNews #EuropeanDigitalID #Google #Apple #PrivacyTech #DigitalWallets #Cybersecurity
🚨 EUVD-2026-40275
📊 Score: 7.0/10 (CVSS v3.1)
📦 Product: PROMOD V
🏢 Vendor: Hitachi Energy
📅 Updated: 2026-06-30
📝 PROMOD V is using insecure HTTP communication instead of HTTPS. The vulnerability is due to the lack of HTTPS support from 3rd party Digipede server.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-40275
🚨 EUVD-2026-40274
📊 Score: 7.2/10 (CVSS v3.1)
📦 Product: Ajax Load More - Filters
🏢 Vendor: Connekt Media
📅 Updated: 2026-06-30
📝 The Ajax Load More - Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'taxonomy_include_children' parameter in all versions up to, and including, 3.4.1 due to insufficient input sanitization and output ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-40274
🚨 EUVD-2026-40273
📊 Score: 9.8/10 (CVSS v3.1)
📦 Product: EventON (Pro) - WordPress Virtual Event Calendar Plugin
🏢 Vendor: EventON
📅 Updated: 2026-06-30
📝 The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the WordPress 'search' parameter in versions up to, and including, 5.0.11 due to insufficient...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-40273
🚨 EUVD-2026-40272
📊 Score: 9.3/10 (CVSS v3.1)
📦 Product: Raytha
🏢 Vendor: Raytha
📅 Updated: 2026-06-30
📝 Raytha CMS is vulnerable to SQL Injection within the OData filter parsing pipeline. The vulnerability allows a remote, unauthenticated attacker to execute
arbitrary SQL statements against the underlying PostgreSQL database,
leading to full database compromi...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-40272
🚨 EUVD-2025-210371
📊 Score: n/a
📦 Product: MantaRay NM
🏢 Vendor: Nokia
📅 Updated: 2026-06-30
📝 Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administrative (local admin) privileges can escalate to full root privileges on the host. Successful exploitation results in root-level access to the filesyst...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-210371
🚨 EUVD-2025-210370
📊 Score: n/a
📦 Product: MantaRay NM
🏢 Vendor: Nokia
📅 Updated: 2026-06-30
📝 Nokia MantaRay is subject to an Improper Access Control vulnerability due to insufficient authorization within the API. Successful exploitation could allow an authenticated attacker to retrieve confidential information beyond their assigned privileges.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-210370
🚨 EUVD-2025-210369
📊 Score: n/a
📦 Product: MantaRay NM
🏢 Vendor: Nokia
📅 Updated: 2026-06-30
📝 Nokia MantaRay NM is subject to an unrestricted file upload vulnerability due to insufficient file type validation. Successful exploitation could allow an authenticated attacker to upload malicious files onto the system.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-210369
🚨 EUVD-2026-40271
📊 Score: 5.1/10 (CVSS v3.1)
📦 Product: WebControl CMS
🏢 Vendor: Intermark IT
📅 Updated: 2026-06-30
📝 Cross-Site Scripting (XSS) vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to execute JavaScript code or inject a dynamic iframe into the victim’s browser by sending a malicious URL via the 'urlDestino' ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-40271
🚨 EUVD-2026-40270
📊 Score: 5.1/10 (CVSS v3.1)
📦 Product: WebControl CMS
🏢 Vendor: Intermark IT
📅 Updated: 2026-06-30
📝 HTML injection vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to send an email containing malicious HTML code to a victim via the contact form. To exploit this vulnerability, the attacker must send a re...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-40270
🚨 EUVD-2026-40269
📊 Score: 7.7/10 (CVSS v3.1)
📦 Product: brace-expansion
🏢 Vendor: juliangruber
📅 Updated: 2026-06-30
📝 brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), direc...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-40269
🚨 EUVD-2026-40268
📊 Score: 6.4/10 (CVSS v3.1)
📅 Updated: 2026-06-30
📝 A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of ser...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-40268
Dell Patches Critical Remote Code Execution Flaws in Wyse Management Suite
Dell addressed two vulnerabilities in its Wyse Management Suite, including a critical remote code execution flaw (CVE-2026-41120) that allows unauthenticated attackers to take over management servers.
**Make sure all your Wyse Management Suite servers and the thin-client devices they manage are isolated from the internet and reachable only from trusted internal networks. Then update Dell Wyse Management Suite to version 5.5 HF1 ASAP.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/dell-patches-critical-remote-code-execution-flaws-in-wyse-management-suite-5-u-x-o-e/gD2P6Ple2L
📣 🔐 WhatsApp is adding usernames so you can start chats without sharing your phone number. Users can reserve a username now, with the full feature expected later this year.
Read or listen to this news: https://hackread.com/whatsapp-usernames-chat-without-sharing-phone-number/
Google swears (again) that data-sharing rules will help scammers, threaten your search history
Google warns that forced data-sharing on Android and Search will basically hand your private info straight to hackers.
https://www.androidauthority.com/google-warns-cybercrime-incidents-amid-dma-proposals-3682866/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Została wydana nowa wersja Parrot 7.3. Parrot Security OS to specjalistyczna dystrybucja Linuksa stworzona do testów penetracyjnych, informatyki śledczej, łamania zabezpieczeń, testów zabezpieczeń... https://linuxiarze.pl/parrot-7-3/ #linux #debian #cybersecurity
Została wydana nowa wersja Parrot 7.3. Parrot Security OS to specjalistyczna dystrybucja Linuksa stworzona do testów penetracyjnych, informatyki śledczej, łamania zabezpieczeń, testów zabezpieczeń... https://linuxiarze.pl/parrot-7-3/ #linux #debian #cybersecurity
💾 🟡 Ralph Lauren (ralphlauren.com)
✓ Verified
📊 ~140K records compromised
📂 Age groups, Email addresses, Genders, Names +1 more
📅 2026-06-11 · disclosed 7d after incident
🌐 Varnish
⚠️ No SPF/DMARC configured
🔗 https://beesint.com/pulse/2f99c6da-c05c-4876-b04d-edc23ea0a656
Google Patches Maximum-Severity RCE Vulnerability in Gemini CLI and GitHub Actions
Google patched a maximum-severity RCE vulnerability (CVE-2026-12537) in Gemini CLI and its GitHub Action that allowed attackers to execute host-level commands via malicious workspace configurations. The flaw exploited implicit trust in headless CI/CD environments to steal secrets and compromise build pipelines.
**If you use the Gemini CLI or its GitHub Action in your development pipelines, immediately upgrade to Gemini CLI version 0.39.1 (or 0.40.0-preview.3) and the run-gemini-cli action to version 0.1.22 to patch CVE-2026-12537. Only enable workspace trust for repositories you fully control. Review your automated workflows to make sure they never run shell commands on untrusted inputs.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/google-patches-maximum-severity-rce-vulnerability-in-gemini-cli-and-github-actions-c-g-6-4-g/gD2P6Ple2L
Hackers Actively Exploit CVE-2026-46817 in Oracle E-Business Suite — 456 Attacks Recorded in 24 Hours
#CyberSecurity
https://securebulletin.com/hackers-actively-exploit-cve-2026-46817-in-oracle-e-business-suite-456-attacks-recorded-in-24-hours/
🛡️ #Cybersecurity news & tips across the #fediverse
“James Carville wants to disenfranchise all the # voters in NY-13 bc he disagrees w/some of Darializa's comments. He said recently the Dems should refuse to let her # caucus w/ them(!), that he wouldn't be in the pa...”
https://masto.nyc/@GetMisch/116836792541383019
🤖 via RSS feed. Not an endorsement.
🚨New ransom group blog posts!🚨
Group name: qilin
Post title: Hemmersbach GmbH & Co. KG
Info: https://cti.fyi/groups/qilin.html
Group name: qilin
Post title: Chamco
Info: https://cti.fyi/groups/qilin.html
#ransomware #cti #threatintelligence #cybersecurity #infosec
WordPress: 152 CVEs, avg CVSS 6.03. 100% unpatched. Trust Score: D. Top weakness: XSS (CWE-79). Popular plugins = prime target. Update your CMS now. #WordPress #cybersecurity #infosec
Malicious ClawHub Skills Compromise AI Agents With Hidden Backdoors — 247,000 Installs, $2.3M Stolen
#CyberSecurity
https://securebulletin.com/malicious-clawhub-skills-compromise-ai-agents-with-hidden-backdoors-247000-installs-2-3m-stolen/
I automated my day with ChatGPT Scheduled Tasks. Here’s what’s great — and what’s broken
ChatGPT’s new automation feature gets a lot right, but it's not perfect.
https://www.androidauthority.com/chatgpt-scheduled-tasks-hands-on-3682039/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Russia’s Turla APT Deploys STOCKSTAY Backdoor Against Ukrainian Government and Military Targets
#CyberSecurity
https://securebulletin.com/russias-turla-apt-deploys-stockstay-backdoor-against-ukrainian-government-and-military-targets/
OnePlus just launched a budget phone with a 3-day battery, but there’s a huge catch
It also looks quite good, even with that dummy camera lens.
https://www.androidauthority.com/oneplus-n6-specs-price-availability-3682794/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Security Tip: Stop relying on perimeter-based security. 🛡️ Zero Trust Architecture (ZTA) assumes the network is already compromised. Implement micro-segmentation to isolate workloads and enforce strict identity verification for every access request. This prevents lateral movement after an initial breach. Track the vulnerabilities that bypass traditional defenses at https://cvedatabase.com #ZeroTrust #InfoSec #CyberSecurity #SecurityTips
Possible Phishing 🎣
on: ⚠️hxxps[:]//globalarubapro[.]pages[.]dev
🧬 Analysis at: https://urldna.io/scan/6a431cf03b77500008e2b144
#cybersecurity #phishing #infosec #urldna #scam #infosec
https://winbuzzer.com/2026/06/30/microsoft-details-edge-security-controls-for-shadow-ai-xcxwbn/
Microsoft has improved Edge for Business controls for shadow AI, data loss prevention, contractors, extensions, and scareware.
#AI #EdgeForBusiness #MicrosoftEdge #Microsoft #ShadowAI #MicrosoftSecurity #Cybersecurity
🚨 Earthquake relief scams weaponize breaking disasters
Fraudsters rapidly registered #Venezuela earthquake-themed domains to harvest donations and personal information through fake relief campaigns.
🔗 read more: hackread.com/venezuela-ea...
Google’s chatty Keep Live and Gmail Live interfaces make first appearance
The feature is promised to go live some time this summer.
https://www.androidauthority.com/google-gmail-keep-gemini-live-chat-3682788/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Critical Microsoft 365 RCE Flaw CVE-2025-60727 Exploitable via Malicious Excel Files — Patch Now
#CyberSecurity
https://securebulletin.com/critical-microsoft-365-rce-flaw-cve-2025-60727-exploitable-via-malicious-excel-files-patch-now/
Versicherer 2026: Risiken wachsen, KI bleibt Nebensache
Im Zentrum des Berichts steht die Lücke zwischen versicherten und unversicherten Cyberschäden.
https://www.all-about-security.de/versicherer-2026-risiken-wachsen-ki-bleibt-nebensache/
Possible Phishing 🎣
on: ⚠️hxxps[:]//webvideotron12[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a434d743b77500008e2b52c
#cybersecurity #phishing #infosec #urldna #scam #infosec
🚨 SimpleHelp flaw already fuels real intrusions
Attackers are actively exploiting an authentication bypass in #SimpleHelp remote support software, prompting urgent patching for exposed servers.
🔗 read more: securityonline.info/simplehelp-a...