voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
❗Patch Wordpress now!
Normally, I would not mention WordPress vulnerabilities, because they are mostly issues with plugins. This one is different. It affects WordPress Core, so all of the following versions are affected:
- 6.9.0 - 6.9.4
- 7.0.0 - 7.0.1
This is a pre-authentication RCE! For more information on workarounds and how to patch, visit the article below.
#cybersecurity #security #infosec #vulnerability #wordpress #rce
Possible Phishing 🎣
on: ⚠️hxxps[:]//centurybnkt[.]weebly[.]com/
🧬 Analysis at: https://urldna.io/scan/6a5dcf323b7750000282662e
#cybersecurity #phishing #infosec #urldna #scam #infosec
Craneware Discloses Data Breach Involving Employee, Customer, and Partner Records
Craneware PLC disclosed a data breach after unauthorized actors accessed its data environment and stole employee, customer, and partner records. The company contained the incident, notified the FBI and UK Information Commissioner’s Office, and confirmed that customer services and business operations were not disrupted.
****
#cybersecurity #infosec #incident #databreach
https://beyondmachines.net/event_details/craneware-discloses-data-breach-involving-employee-customer-and-partner-records-5-v-b-t-y/gD2P6Ple2L
The Digital Operational Resilience Act (DORA) is an EU regulation that establishes a binding, comprehensive ICT risk management framework for the financial sector. It ensures that financial entities and their critical technology providers can withstand, respond to, and recover from severe ICT-related disruptions and cyberattacks.
#cybersecurity #governance #risk #technology #gaming #programming #ai #business #engineering
Link: https://blackcatwhitehatsecurity.com
Dr. Jill Lepore on why AI backlash is vital for the future
Today, I’m talking with Harvard professor and New Yorker staff writer Dr. Jill Lepore about her new book, The Rise and Fall of the Artificial State, which comes out on August 25. Jill is one of the best writers there is…
https://www.theverge.com/podcast/967884/jill-lepore-history-ai-artificial-state-elon-musk
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Hackers breached DHS after alarms were twice ruled 'false positives'
Hackers were flagged twice by automated systems and analysts in May 2026, before being dismissed as a false positive each time.
Hackers then managed to find their way into the US Department of Homeland Security's primary information sharing platform, gaining unfettered access to the HSIN network
#DHS #HSIN #databreach #security #cybersecurity #hackers #hacking #hacked
WIRED - The Latest in Technology, Science, Culture and Business [Unofficial] » 🌐
@wired.com@web.brid.gy
A first-of-its-kind analysis found more than one in eight apps built for US service members carried foreign code—some from firms in nations the Pentagon designates as adversaries.
Reader poll says 1 thing matters most in free apps — and it’s not open source
Have ads in your free app? You might want to reconsider.
https://www.androidauthority.com/features-free-apps-poll-results-3689146/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Possible Phishing 🎣
on: ⚠️hxxps[:]//airmilesonlinesecuret[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a5d57163b77500002804cb1
#cybersecurity #phishing #infosec #urldna #scam #infosec
Rust Based Remote Access Trojan Masquerading as NVIDIA Software
Pulse ID: 6a5e11b7a9e3e87231b4b602
Pulse Link: https://otx.alienvault.com/pulse/6a5e11b7a9e3e87231b4b602
Pulse Author: cryptocti
Created: 2026-07-20 12:16:55
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #RemoteAccessTrojan #Rust #Trojan #bot #cryptocti
ClickFix Fake CAPTCHAs to Infect Devices with Malware
Pulse ID: 6a5e10f2c39aa45f2dec8da1
Pulse Link: https://otx.alienvault.com/pulse/6a5e10f2c39aa45f2dec8da1
Pulse Author: cryptocti
Created: 2026-07-20 12:13:38
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CAPTCHA #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #bot #cryptocti
⚠️ CRITICAL THREAT: CVE-2026-39808 in Fortinet FortiSandbox is being actively exploited. Attackers are leveraging OS command injection for remote code execution. Is your SOC ready? Get the forensic detection queries and hardening playbooks to lock down your perimeter. https://thecybermind.co/v66d
I recreated OpenAI's Codex Micro for a lot less - and mine is more customizable
The $230 Codex Micro sold out before I could buy one, so I turned my Stream Deck+ into a surprisingly capable alternative.
https://www.zdnet.com/article/codex-micro-keypad-alternative-stream-deck-plus/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
The top AI fear for 6,000 tech pros isn't losing their jobs - it's more work for the same pay
Most tech professionals wouldn't recommend their own role to someone entering the industry today.
https://www.zdnet.com/article/top-ai-fear-tech-survey/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
🚨 EUVD-2026-45900
📊 Score: 4.3/10 (CVSS v3.1)
📅 Updated: 2026-07-20
📝 A flaw was found in claircore's apk package scanner. Malformed package-database data in a container layer can cause an out-of-bounds access that panics the scanner. If that panic is not recovered, the Clair indexer process can crash, leading to a denial of service.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45900
🚨 EUVD-2026-45899
📊 Score: 6.5/10 (CVSS v3.1)
📅 Updated: 2026-07-20
📝 A vulnerability was found in the network packet de-fragmentation engine of kronosnet (Version affected <= 1.34). The internal reassembly code does not properly validate sequence numbers of incoming payload fragments. An attacker can exploit this lack of verification by transmitting malformed pa...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45899
Possible Phishing 🎣
on: ⚠️hxxps[:]//www-facebook[.]live
🧬 Analysis at: https://urldna.io/scan/6a5d8f593b7750000431c480
#cybersecurity #phishing #infosec #urldna #scam #infosec
The OpenSSL HollowByte vulnerability causes a severe memory leak that can easily crash servers. Learn how this 11-byte attack works and how to fix it.
#OpenSSL #HollowByte #CyberSecurity #MemoryLeak #Vulnerability
I recently spoke to Adrian Weckler for the Irish Independent on an article outlining the #cybersecurity concerns around the new Irish Government Digital Wallet
What if perfect LLM security is mathematically impossible? A new proof based on Gödel's incompleteness theorems says that's exactly the problem.
#newpost #AI #CyberSecurity #LLM #SoftwareEngineering
https://www.conferencesthatwork.com/index.php/technology/2026/07/godel-llm-security
New on the FIRST blog: Jon Baker, VP, Threat-Informed Defense, AttackIQ, and Co-founder of MITRE's Center for Threat-Informed Defense, on why "how fast can we patch" is no longer the right question.
At #FIRSTCON26 in Denver, Jon's session introduced MITRE INFORM, the open-source threat-informed defense maturity model, walking attendees through a self-assessment and practical steps to move from reactive to measurable defense.
In this companion post, he builds that into a fuller operating model:
🎯 Threat-informed defense as the foundation: aligning to real adversary behavior, not generic best practice
📊 MITRE INFORM to measure and mature the program
💳 Threat debt as the shared scoreboard across Security, IT, and the business
🔄 CTEM as the continuous discipline that pays it down
Read more: https://go.first.org/xaqpW
PCMan: 57 CVEs, avg CVSS 5.3. 100% unpatched. Trust Score: C with +51 CVEs trending 2024→2025. Top flaw: Buffer overflow (CWE-120). LXDE users: patch or replace your file manager. #PCMan #cybersecurity #infosec
The #automotiveindustry’s increasing use of over-the-air #OTA technology to #update vehicle systems raises #cybersecurity concerns. Analysts warn that OTA technology, while convenient, makes vehicles more susceptible to #cyberattacks and potential foreign sabotage. Real-life tests have revealed vulnerabilities, prompting investigations in the UK and Denmark. https://www.cnbc.com/2026/07/18/over-the-air-tech-in-vehicles-poses-cybersecurity-risks.html?eicker.news #tech #media #news
CISA adds an 18-year-old Cisco IOS vulnerability to its Known Exploited Vulnerabilities catalog. Federal agencies must patch CVE-2008-4128 within three days. #Cybersecurity https://deafnews.it/en/article/cisa-adds-cve-2008-4128-to-kev-an-18-year-old-cisco-ios-bug-resurfaces
Weekly thread for any and all career, learning and general guidance questions. Thinking of taking a training or going for a cert? Wondering how to level up your career? Wondering what NOT to do? Got other questions? This is the time and place to ask!
CrashStealer is a native C++ macOS infostealer posing as Apple's crash reporter. Jamf details its notarized dropper, AES-GCM theft, and persistence.
#CrashStealer #macOSMalware #Infostealer #JamfThreatLabs #CyberSecurity
☕ CYBERBRIEFING — Lunedì 20 luglio 2026
👉 Leggi tutti gli aggiornamenti delle ultime 24 ore:
https://ilpuntocyber.rfeed.it/article.php?s=2026-07-20
Samsung is betting big on the Wide Fold
Samsung expects more people to opt for the wide Galaxy Z Fold 8 over the flagship Z Fold 8 Ultra.
https://www.androidauthority.com/galaxy-z-fold-8-production-volume-increased-3689103/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Friday Android app deals and freebies: ScourgeBringer, Greak, Egg Journey, more
Your afternoon lineup of the best Android game and app deals is now here, including titles like ScourgeBringer, Greak: Memories of Azur, Tower Defense Legend 5 Pro, Escape Alive, Egg Journey, FrogBoy, and more. Just be …
https://9to5toys.com/2026/07/10/friday-android-app-deals-free-scourgebringer-greak/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Google [9to5Google]
Possible Phishing 🎣
on: ⚠️hxxps[:]//xn--v69a243b04b[.]weebly[.]com/
🧬 Analysis at: https://urldna.io/scan/6a5dcf2e3b775000079497a9
#cybersecurity #phishing #infosec #urldna #scam #infosec
Daily Digest | 20 July 2026
Your daily dose of Privacy, Data Protection, AI & Cybersecurity news.
5 stories you should not miss.
Read more: https://www.nicfab.eu/daily-digest/
Weekly macOS & iOS threat update: July 13–20, 2026
A newly documented Mac infostealer called ClickLock is using fake human-verification pages to trick people into pasting malicious commands into Terminal.
Once launched, it can repeatedly close Finder, Terminal, Activity Monitor, and System Settings while displaying a fake password prompt. It also targets browser data, the macOS Keychain, password managers, and cryptocurrency wallets.
The practical rule is simple: a legitimate website won’t ask you to paste a command into Terminal to prove you’re human.
Apple is also facing a proposed class action over Hide My Email. The lawsuit alleges that some masked addresses could be linked to a user’s real email address. These claims haven’t been proven in court.
The problems with Google Pixel price hikes
Like everything else in the tech industry, Google’s Pixel 11 series appears to be getting a price hike, but there are a few factors that make this one a bit harder to accept. This issue of 9to5Google Weekender is a part…
https://9to5google.com/2026/07/12/google-pixel-price-hike-problems/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Google [9to5Google]
Critical #NGINX #Vulnerability Can #Crash Workers and May Allow Remote Code Execution
source: thehackernews.com/2026/07/crit…
The #overflow lives in nginx's #script engine, the code that assembles strings from directives at request time. It only surfaces under a specific #configuration: a regex-based map whose output variable is referenced in a #string expression after a capture from an earlier #regex match.
#web #www #internet #online #exploit #hack #hacker #cybersecurity #news #webserver #server #security #software #bug
Location: Matrix
Pixel 11 Pro Fold in ‘Pine’ leaks & could Pixel Glow just be the camera flash?
With the launch event one month away, Pixel 11 leaks are picking up, and we now have a look at the “Pine” color for the 11 Pro Fold.
https://9to5google.com/2026/07/12/pixel-11-pro-pine-color-leak/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Google [9to5Google]
Ponad połowa pracowników korzysta w pracy z niezatwierdzonych narzędzi AI, a nawet co dziesiąty świadomie udostępnia poufne informacje firmowe za pomocą tych... https://linuxiarze.pl/ponad-polowa-pracownikow-korzysta-w-pracy-z-niezatwierdzonych-narzedzi-ai/ #cybersecurity #sztucznainteligencja
Possible Phishing 🎣
on: ⚠️hxxps[:]//alamantourandtravels[.]com/myCSS
🧬 Analysis at: https://urldna.io/scan/6a5da5203b77500004426656
#cybersecurity #phishing #infosec #urldna #scam #infosec
Ponad połowa pracowników korzysta w pracy z niezatwierdzonych narzędzi AI, a nawet co dziesiąty świadomie udostępnia poufne informacje firmowe za pomocą tych... https://linuxiarze.pl/ponad-polowa-pracownikow-korzysta-w-pracy-z-niezatwierdzonych-narzedzi-ai/ #cybersecurity #sztucznainteligencja
🎣 Phishing Spotlight
facebook-khqi4s[.]pages[.]dev
🔗 https://beesint.com/pulse/cb26bef0-0d29-4599-a60a-5f4911eefb15
Hugging Face Production Infrastructure Breached by Autonomous AI Agent
Hugging Face disclosed a data breach after an autonomous AI agent exploited code-execution flaws in its data-processing pipeline, collected cloud and cluster credentials, and moved laterally across internal clusters. The company used a self-hosted open-weight AI model for forensic analysis after commercial AI services blocked requests containing real attack artifacts.
****
#cybersecurity #infosec #incident #databreach
https://beyondmachines.net/event_details/hugging-face-production-infrastructure-breached-by-autonomous-ai-agent-h-1-j-6-l/gD2P6Ple2L
Exploit brokers pay $500k for WordPress RCEs. I found one with GPT5.6 and $25
Comments: https://news.ycombinator.com/item?id=48975665
#HackerNews #ExploitBrokers #WordPress #RCE #CyberSecurity #GPT5 #Hacking
In a shocking twist of fate, it turns out you don't need half a million bucks or elite hacker skills to discover #WordPress vulnerabilities; just toss $25 at #GPT5.6 and let it work its magic. 🤖💸 Who knew the future of #cybersecurity was this hilariously #cheap and easy? 🙃
https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/ #Vulnerabilities #Hacking #Made #Easy #Solutions #HackerNews #ngated
Hugging Face: Security incident disclosure — July 2026. “Earlier this week, we detected and responded to an intrusion into part of our production infrastructure. This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system – and we detected and dissected it largely with AI of our own.”
https://rbfirehose.com/2026/07/19/hugging-face-security-incident-disclosure-july-2026/La rivoluzione partecipata di A.I.P.S.: Intervista a Leonardo Lomma, Presidente nazionale A.I.P.S. Formazione tecnica, qualita' certificata, cybersecurity e manutenzione programmata: questi i temi al centro dell'intervista a Leonardo Lomma, nuovo Presidente nazionale di A.I.P.S., Associazione Installatori Professionali Sicurezza. Lomma...
#LeonardoLomma #AIPS #cybersecurity #security #sicurezza http://dlvr.it/TTcVFV
YouTube picture-in-picture (PiP) mode is broken on iPhone, Android
YouTube is aware of an issue on Android and iPhone where picture-in-picture (PiP) mode does not activate when closing the app.
https://9to5google.com/2026/07/18/youtube-pip-broken/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
Is Apple One worth it for you after recent price hikes?
Yesterday, Apple announced price increases for Apple Music as well as two of its Apple One bundles. Apple offers a broad range of services nowadays, ranging from Apple TV to Apple Music, Apple Fitness+, and more. Apple …
https://9to5mac.com/2026/07/18/is-apple-one-worth-it-for-you/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
Apple is raising prices on more than just Macs and iPads
Apple’s hardware price increases in June were costly and unwelcome. They were also just the start of a wave of higher prices on Apple products and services. Over the last few weeks, Apple has been raising prices in all …
https://9to5mac.com/2026/07/18/here-are-all-the-ways-apple-is-raising-prices-and-why/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
Apple’s scrapped Mac Pro plans reportedly included a new Intel model
In March, Apple announced it was discontinuing the Mac Pro and confirmed that it had no plans to offer future Mac Pro hardware. A new report from Bloomberg today offers more context on Apple’s Mac Pro strategy, with a s…
https://9to5mac.com/2026/07/19/apples-scrapped-mac-pro-plans-reportedly-included-an-intel-model/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]