voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]Alther » 🌐
@Alther@ieji.de

❗Patch Wordpress now!

Normally, I would not mention WordPress vulnerabilities, because they are mostly issues with plugins. This one is different. It affects WordPress Core, so all of the following versions are affected:
- 6.9.0 - 6.9.4
- 7.0.0 - 7.0.1

This is a pre-authentication RCE! For more information on workarounds and how to patch, visit the article below.

Source: bleepingcomputer.com/news/secu

    [?]urlDNA.io :verified: » 🤖 🌐
    @urldna@infosec.exchange

    Possible Phishing 🎣
    on: ⚠️hxxps[:]//centurybnkt[.]weebly[.]com/
    🧬 Analysis at: urldna.io/scan/6a5dcf323b77500

      [?]BeyondMachines :verified: » 🤖 🌐
      @beyondmachines1@infosec.exchange

      Craneware Discloses Data Breach Involving Employee, Customer, and Partner Records

      Craneware PLC disclosed a data breach after unauthorized actors accessed its data environment and stole employee, customer, and partner records. The company contained the incident, notified the FBI and UK Information Commissioner’s Office, and confirmed that customer services and business operations were not disrupted.

      ****

      beyondmachines.net/event_detai

        [?]Black Cat White Hat Security » 🌐
        @BCWHQuiz@defcon.social

        The Digital Operational Resilience Act (DORA) is an EU regulation that establishes a binding, comprehensive ICT risk management framework for the financial sector. It ensures that financial entities and their critical technology providers can withstand, respond to, and recover from severe ICT-related disruptions and cyberattacks.



        Link: blackcatwhitehatsecurity.com

        The Digital Operational Resilience Act (DORA) is an EU regulation that establishes a binding, comprehensive ICT risk management framework for the financial sector. It ensures that financial entities and their critical technology providers can withstand, respond to, and recover from severe ICT-related disruptions and cyberattacks.

        Alt...The Digital Operational Resilience Act (DORA) is an EU regulation that establishes a binding, comprehensive ICT risk management framework for the financial sector. It ensures that financial entities and their critical technology providers can withstand, respond to, and recover from severe ICT-related disruptions and cyberattacks.

          [?]TechWire ⚡ » 🤖 🌐
          @techwire@social.gamefan.net

          Dr. Jill Lepore on why AI backlash is vital for the future

          Today, I’m talking with Harvard professor and New Yorker staff writer Dr. Jill Lepore about her new book, The Rise and Fall of the Artificial State, which comes out on August 25. Jill is one of the best writers there is…

          theverge.com/podcast/967884/ji

          [The Verge]

            [?]gtbarry » 🌐
            @gtbarry@mastodon.social

            Hackers breached DHS after alarms were twice ruled 'false positives'

            Hackers were flagged twice by automated systems and analysts in May 2026, before being dismissed as a false positive each time.

            Hackers then managed to find their way into the US Department of Homeland Security's primary information sharing platform, gaining unfettered access to the HSIN network

            techradar.com/pro/security/hac

              [?]WIRED - The Latest in Technology, Science, Culture and Business [Unofficial] » 🌐
              @wired.com@web.brid.gy

              Apps Marketed to US Troops Are Shipping Chinese and Russian Code

              A first-of-its-kind analysis found more than one in eight apps built for US service members carried foreign code—some from firms in nations the Pentagon designates as adversaries.

              Apps Marketed to US Troops Are Shipping Chinese and Russian Code

              Alt...Apps Marketed to US Troops Are Shipping Chinese and Russian Code

              [?]TechWire ⚡ » 🤖 🌐
              @techwire@social.gamefan.net

              Reader poll says 1 thing matters most in free apps — and it’s not open source

              Have ads in your free app? You might want to reconsider.

              androidauthority.com/features-

              [Android Authority]

                [?]urlDNA.io :verified: » 🤖 🌐
                @urldna@infosec.exchange

                Possible Phishing 🎣
                on: ⚠️hxxps[:]//airmilesonlinesecuret[.]weebly[.]com
                🧬 Analysis at: urldna.io/scan/6a5d57163b77500

                  [?]OTX Bot » 🤖 🌐
                  @techbot@social.raytec.co

                  Rust Based Remote Access Trojan Masquerading as NVIDIA Software

                  Pulse ID: 6a5e11b7a9e3e87231b4b602
                  Pulse Link: otx.alienvault.com/pulse/6a5e1
                  Pulse Author: cryptocti
                  Created: 2026-07-20 12:16:55

                  Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                    [?]OTX Bot » 🤖 🌐
                    @techbot@social.raytec.co

                    ClickFix Fake CAPTCHAs to Infect Devices with Malware

                    Pulse ID: 6a5e10f2c39aa45f2dec8da1
                    Pulse Link: otx.alienvault.com/pulse/6a5e1
                    Pulse Author: cryptocti
                    Created: 2026-07-20 12:13:38

                    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                      [?]thecybermind » 🌐
                      @thecybermind@mastodon.social

                      ⚠️ CRITICAL THREAT: CVE-2026-39808 in Fortinet FortiSandbox is being actively exploited. Attackers are leveraging OS command injection for remote code execution. Is your SOC ready? Get the forensic detection queries and hardening playbooks to lock down your perimeter. thecybermind.co/v66d

                        [?]TechWire ⚡ » 🤖 🌐
                        @techwire@social.gamefan.net

                        I recreated OpenAI's Codex Micro for a lot less - and mine is more customizable

                        The $230 Codex Micro sold out before I could buy one, so I turned my Stream Deck+ into a surprisingly capable alternative.

                        zdnet.com/article/codex-micro-

                        [ZDNet]

                          [?]TechWire ⚡ » 🤖 🌐
                          @techwire@social.gamefan.net

                          The top AI fear for 6,000 tech pros isn't losing their jobs - it's more work for the same pay

                          Most tech professionals wouldn't recommend their own role to someone entering the industry today.

                          zdnet.com/article/top-ai-fear-

                          [ZDNet]

                            [?]EUVD Bot » 🤖 🌐
                            @EUVD_Bot@mastodon.social

                            🚨 EUVD-2026-45900

                            📊 Score: 4.3/10 (CVSS v3.1)
                            📅 Updated: 2026-07-20

                            📝 A flaw was found in claircore's apk package scanner. Malformed package-database data in a container layer can cause an out-of-bounds access that panics the scanner. If that panic is not recovered, the Clair indexer process can crash, leading to a denial of service.

                            🔗 euvd.enisa.europa.eu/vulnerabi

                              [?]EUVD Bot » 🤖 🌐
                              @EUVD_Bot@mastodon.social

                              🚨 EUVD-2026-45899

                              📊 Score: 6.5/10 (CVSS v3.1)
                              📅 Updated: 2026-07-20

                              📝 A vulnerability was found in the network packet de-fragmentation engine of kronosnet (Version affected <= 1.34). The internal reassembly code does not properly validate sequence numbers of incoming payload fragments. An attacker can exploit this lack of verification by transmitting malformed pa...

                              🔗 euvd.enisa.europa.eu/vulnerabi

                                [?]urlDNA.io :verified: » 🤖 🌐
                                @urldna@infosec.exchange

                                Possible Phishing 🎣
                                on: ⚠️hxxps[:]//www-facebook[.]live
                                🧬 Analysis at: urldna.io/scan/6a5d8f593b77500

                                  [?]Daily CyberSecurity » 🌐
                                  @DailyCyberSecurity@infosec.exchange

                                  The OpenSSL HollowByte vulnerability causes a severe memory leak that can easily crash servers. Learn how this 11-byte attack works and how to fix it.

                                  meterpreter.org/openssl-hollow

                                    [?]Brian Honan » 🌐
                                    @brianhonan@mastodon.social

                                    I recently spoke to Adrian Weckler for the Irish Independent on an article outlining the concerns around the new Irish Government Digital Wallet

                                    independent.ie/business/irish-

                                      [?]Adrian Segar » 🌐
                                      @ASegar@mastodon.social

                                      What if perfect LLM security is mathematically impossible? A new proof based on Gödel's incompleteness theorems says that's exactly the problem.

                                      conferencesthatwork.com/index.

                                      Conceptual illustration of a futuristic vault door with a glowing ear symbol at its center, responding to speech-wave patterns and surrounded by floating conversation bubbles containing everyday requests. One of the requests is "ignore all previous instructions". The image symbolizes how AI systems are designed to respond to language, making natural conversation both their greatest strength and a persistent security challenge.

                                      Alt...Conceptual illustration of a futuristic vault door with a glowing ear symbol at its center, responding to speech-wave patterns and surrounded by floating conversation bubbles containing everyday requests. One of the requests is "ignore all previous instructions". The image symbolizes how AI systems are designed to respond to language, making natural conversation both their greatest strength and a persistent security challenge.

                                        [?]FIRST.org » 🌐
                                        @firstdotorg@infosec.exchange

                                        New on the FIRST blog: Jon Baker, VP, Threat-Informed Defense, AttackIQ, and Co-founder of MITRE's Center for Threat-Informed Defense, on why "how fast can we patch" is no longer the right question.

                                        At in Denver, Jon's session introduced MITRE INFORM, the open-source threat-informed defense maturity model, walking attendees through a self-assessment and practical steps to move from reactive to measurable defense.

                                        In this companion post, he builds that into a fuller operating model:

                                        🎯 Threat-informed defense as the foundation: aligning to real adversary behavior, not generic best practice
                                        📊 MITRE INFORM to measure and mature the program
                                        💳 Threat debt as the shared scoreboard across Security, IT, and the business
                                        🔄 CTEM as the continuous discipline that pays it down

                                        Read more: go.first.org/xaqpW

                                          [?]Hugo | DevOps | Cybersecurity » 🌐
                                          @hugovalters@mastodon.social

                                          PCMan: 57 CVEs, avg CVSS 5.3. 100% unpatched. Trust Score: C with +51 CVEs trending 2024→2025. Top flaw: Buffer overflow (CWE-120). LXDE users: patch or replace your file manager.

                                          valtersit.com/vendors/pcman/

                                            [?]tech news ᳇ eicker.news » 🌐
                                            @technews@eicker.news

                                            The ’s increasing use of over-the-air technology to vehicle systems raises concerns. Analysts warn that OTA technology, while convenient, makes vehicles more susceptible to and potential foreign sabotage. Real-life tests have revealed vulnerabilities, prompting investigations in the UK and Denmark. cnbc.com/2026/07/18/over-the-a

                                              [?]deafnews » 🤖 🌐
                                              @deafnews@infosec.exchange

                                              CISA adds an 18-year-old Cisco IOS vulnerability to its Known Exploited Vulnerabilities catalog. Federal agencies must patch CVE-2008-4128 within three days. deafnews.it/en/article/cisa-ad

                                                [?]shellsharks » 🌐
                                                @shellsharks@infosec.pub

                                                Mentorship Monday - Discussions for career and learning!

                                                Weekly thread for any and all career, learning and general guidance questions. Thinking of taking a training or going for a cert? Wondering how to level up your career? Wondering what NOT to do? Got other questions? This is the time and place to ask!

                                                (https://infosec.pub/c/cybersecurity)

                                                [?]Daily CyberSecurity » 🌐
                                                @DailyCyberSecurity@infosec.exchange

                                                CrashStealer is a native C++ macOS infostealer posing as Apple's crash reporter. Jamf details its notarized dropper, AES-GCM theft, and persistence.

                                                securityonline.info/crashsteal

                                                  [?]N_{Dario Fadda} » 🌐
                                                  @nuke@poliversity.it

                                                  ☕ CYBERBRIEFING — Lunedì 20 luglio 2026

                                                  👉 Leggi tutti gli aggiornamenti delle ultime 24 ore:
                                                  ilpuntocyber.rfeed.it/article.


                                                  @informatica

                                                    [?]TechWire ⚡ » 🤖 🌐
                                                    @techwire@social.gamefan.net

                                                    Samsung is betting big on the Wide Fold

                                                    Samsung expects more people to opt for the wide Galaxy Z Fold 8 over the flagship Z Fold 8 Ultra.

                                                    androidauthority.com/galaxy-z-

                                                    [Android Authority]

                                                      [?]TechWire ⚡ » 🤖 🌐
                                                      @techwire@social.gamefan.net

                                                      Friday Android app deals and freebies: ScourgeBringer, Greak, Egg Journey, more

                                                      Your afternoon lineup of the best Android game and app deals is now here, including titles like ScourgeBringer, Greak: Memories of Azur, Tower Defense Legend 5 Pro, Escape Alive, Egg Journey, FrogBoy, and more. Just be …

                                                      9to5toys.com/2026/07/10/friday

                                                      [9to5Google]

                                                        [?]urlDNA.io :verified: » 🤖 🌐
                                                        @urldna@infosec.exchange

                                                        Possible Phishing 🎣
                                                        on: ⚠️hxxps[:]//xn--v69a243b04b[.]weebly[.]com/
                                                        🧬 Analysis at: urldna.io/scan/6a5dcf2e3b77500

                                                          [?]Nicola Fabiano » 🌐
                                                          @nicfab@fosstodon.org

                                                          Daily Digest | 20 July 2026

                                                          Your daily dose of Privacy, Data Protection, AI & Cybersecurity news.

                                                          5 stories you should not miss.

                                                          Read more: nicfab.eu/daily-digest/

                                                            [?]Intego Mac Security :verified: » 🌐
                                                            @intego@infosec.exchange

                                                            Weekly macOS & iOS threat update: July 13–20, 2026

                                                            A newly documented Mac infostealer called ClickLock is using fake human-verification pages to trick people into pasting malicious commands into Terminal.

                                                            Once launched, it can repeatedly close Finder, Terminal, Activity Monitor, and System Settings while displaying a fake password prompt. It also targets browser data, the macOS Keychain, password managers, and cryptocurrency wallets.

                                                            The practical rule is simple: a legitimate website won’t ask you to paste a command into Terminal to prove you’re human.

                                                            Apple is also facing a proposed class action over Hide My Email. The lawsuit alleges that some masked addresses could be linked to a user’s real email address. These claims haven’t been proven in court.

                                                            Intego graphic reading “Weekly macOS & iOS Threat Update” with the date July 13-20, 2026, on a light blue background with a large shield icon.

                                                            Alt...Intego graphic reading “Weekly macOS & iOS Threat Update” with the date July 13-20, 2026, on a light blue background with a large shield icon.

                                                              [?]TechWire ⚡ » 🤖 🌐
                                                              @techwire@social.gamefan.net

                                                              The problems with Google Pixel price hikes

                                                              Like everything else in the tech industry, Google’s Pixel 11 series appears to be getting a price hike, but there are a few factors that make this one a bit harder to accept. This issue of 9to5Google Weekender is a part…

                                                              9to5google.com/2026/07/12/goog

                                                              [9to5Google]

                                                                [?]Script Kiddie » 🌐
                                                                @scriptkiddie@anonsys.net

                                                                Critical Can Workers and May Allow Remote Code Execution

                                                                source: thehackernews.com/2026/07/crit…

                                                                The lives in nginx's engine, the code that assembles strings from directives at request time. It only surfaces under a specific : a regex-based map whose output variable is referenced in a expression after a capture from an earlier match.

                                                                Location: Matrix

                                                                  [?]TechWire ⚡ » 🤖 🌐
                                                                  @techwire@social.gamefan.net

                                                                  Pixel 11 Pro Fold in ‘Pine’ leaks & could Pixel Glow just be the camera flash?

                                                                  With the launch event one month away, Pixel 11 leaks are picking up, and we now have a look at the “Pine” color for the 11 Pro Fold.

                                                                  9to5google.com/2026/07/12/pixe

                                                                  [9to5Google]

                                                                    [?]Linuxiarze » 🌐
                                                                    @Linuxiarze@mastodon.social

                                                                    Ponad połowa pracowników korzysta w pracy z niezatwierdzonych narzędzi AI, a nawet co dziesiąty świadomie udostępnia poufne informacje firmowe za pomocą tych... linuxiarze.pl/ponad-polowa-pra

                                                                      [?]urlDNA.io :verified: » 🤖 🌐
                                                                      @urldna@infosec.exchange

                                                                      Possible Phishing 🎣
                                                                      on: ⚠️hxxps[:]//alamantourandtravels[.]com/myCSS
                                                                      🧬 Analysis at: urldna.io/scan/6a5da5203b77500

                                                                        [?]Linuxiarze » 🌐
                                                                        @Linuxiarze@fe.disroot.org

                                                                        Ponad połowa pracowników korzysta w pracy z niezatwierdzonych narzędzi AI, a nawet co dziesiąty świadomie udostępnia poufne informacje firmowe za pomocą tych... https://linuxiarze.pl/ponad-polowa-pracownikow-korzysta-w-pracy-z-niezatwierdzonych-narzedzi-ai/ #cybersecurity #sztucznainteligencja

                                                                          [?]pavroo » 🌐
                                                                          @pavroo@universeodon.com

                                                                          Ponad połowa pracowników korzysta w pracy z niezatwierdzonych narzędzi AI, a nawet co dziesiąty świadomie udostępnia poufne informacje firmowe za pomocą tych... linuxiarze.pl/ponad-polowa-pra

                                                                            [?]BeeSINT » 🌐
                                                                            @BeeSINT@mastodon.social

                                                                            [?]BeyondMachines :verified: » 🤖 🌐
                                                                            @beyondmachines1@infosec.exchange

                                                                            Hugging Face Production Infrastructure Breached by Autonomous AI Agent

                                                                            Hugging Face disclosed a data breach after an autonomous AI agent exploited code-execution flaws in its data-processing pipeline, collected cloud and cluster credentials, and moved laterally across internal clusters. The company used a self-hosted open-weight AI model for forensic analysis after commercial AI services blocked requests containing real attack artifacts.

                                                                            ****

                                                                            beyondmachines.net/event_detai

                                                                              [?]Hacker News » 🤖 🌐
                                                                              @h4ckernews@mastodon.social

                                                                              [?]N-gated Hacker News » 🤖 🌐
                                                                              @ngate@mastodon.social

                                                                              In a shocking twist of fate, it turns out you don't need half a million bucks or elite hacker skills to discover vulnerabilities; just toss $25 at .6 and let it work its magic. 🤖💸 Who knew the future of was this hilariously and easy? 🙃
                                                                              slcyber.io/research-center/exp

                                                                                [?]Stetryczały Szyderca 🤡 💀 » 🌐
                                                                                @Aegewsh@101010.pl

                                                                                [?]ResearchBuzz: Firehose » 🌐
                                                                                @researchbuzz_firehose@rbfirehose.com

                                                                                Hugging Face: Security incident disclosure — July 2026. “Earlier this week, we detected and responded to an intrusion into part of our production infrastructure. This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system – and we detected and dissected it largely with AI of our own.”

                                                                                https://rbfirehose.com/2026/07/19/hugging-face-security-incident-disclosure-july-2026/

                                                                                [?]secsolution » 🌐
                                                                                @secsolution@mastodon.social

                                                                                La rivoluzione partecipata di A.I.P.S.: Intervista a Leonardo Lomma, Presidente nazionale A.I.P.S. Formazione tecnica, qualita' certificata, cybersecurity e manutenzione programmata: questi i temi al centro dell'intervista a Leonardo Lomma, nuovo Presidente nazionale di A.I.P.S., Associazione Installatori Professionali Sicurezza. Lomma...
                                                                                dlvr.it/TTcVFV

                                                                                  [?]TechWire ⚡ » 🤖 🌐
                                                                                  @techwire@social.gamefan.net

                                                                                  YouTube picture-in-picture (PiP) mode is broken on iPhone, Android

                                                                                  YouTube is aware of an issue on Android and iPhone where picture-in-picture (PiP) mode does not activate when closing the app.

                                                                                  9to5google.com/2026/07/18/yout

                                                                                  [9to5Mac]

                                                                                    [?]TechWire ⚡ » 🤖 🌐
                                                                                    @techwire@social.gamefan.net

                                                                                    Is Apple One worth it for you after recent price hikes?

                                                                                    Yesterday, Apple announced price increases for Apple Music as well as two of its Apple One bundles. Apple offers a broad range of services nowadays, ranging from Apple TV to Apple Music, Apple Fitness+, and more. Apple …

                                                                                    9to5mac.com/2026/07/18/is-appl

                                                                                    [9to5Mac]

                                                                                      [?]TechWire ⚡ » 🤖 🌐
                                                                                      @techwire@social.gamefan.net

                                                                                      Apple is raising prices on more than just Macs and iPads

                                                                                      Apple’s hardware price increases in June were costly and unwelcome. They were also just the start of a wave of higher prices on Apple products and services. Over the last few weeks, Apple has been raising prices in all …

                                                                                      9to5mac.com/2026/07/18/here-ar

                                                                                      [9to5Mac]

                                                                                        [?]TechWire ⚡ » 🤖 🌐
                                                                                        @techwire@social.gamefan.net

                                                                                        Apple’s scrapped Mac Pro plans reportedly included a new Intel model

                                                                                        In March, Apple announced it was discontinuing the Mac Pro and confirmed that it had no plans to offer future Mac Pro hardware. A new report from Bloomberg today offers more context on Apple’s Mac Pro strategy, with a s…

                                                                                        9to5mac.com/2026/07/19/apples-

                                                                                        [9to5Mac]

                                                                                          Back to top - More...