voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]Bloo (they/she) 🍓 🏳️‍⚧️ 🍉 » 🌐
@QueerMatters@mstdn.social

I'm trying to understand something:

I've watched a YouTube video twice (refreshing between watches) and captured its quic packets using Wireshark.

Exporting both watches into their own JSON files.

Looking at the UDP and quic payloads, the encrypted data looks different? Its the same video, though! If the data being encrypted is the same, shouldnt it look similar?

Is it because maybe the buffering took place at different time stamps on both watches?

    [?]TechWire ⚡ » 🤖 🌐
    @techwire@social.gamefan.net

    Valve has killed dbrand’s excellent Steam Machine case

    'We built the idea into something real without ever asking Valve if we could.'

    androidauthority.com/steam-mac

    [Android Authority]

      [?]Black Cat White Hat Security » 🌐
      @BCWHQuiz@defcon.social

      The NIST AI RMF (Artificial Intelligence Risk Management Framework) is a voluntary, guidance-based framework created by the U.S. National Institute of Standards and Technology. It is designed to help organizations identify, assess, and manage the risks associated with AI systems across their entire lifecycle—from design through deployment.



      Link: blackcatwhitehatsecurity.com

      The NIST AI RMF (Artificial Intelligence Risk Management Framework) is a voluntary, guidance-based framework created by the U.S. National Institute of Standards and Technology. It is designed to help organizations identify, assess, and manage the risks associated with AI systems across their entire lifecycle—from design through deployment.

      Alt...The NIST AI RMF (Artificial Intelligence Risk Management Framework) is a voluntary, guidance-based framework created by the U.S. National Institute of Standards and Technology. It is designed to help organizations identify, assess, and manage the risks associated with AI systems across their entire lifecycle—from design through deployment.

        [?]𝕂𝚞𝚋𝚒𝚔ℙ𝚒𝚡𝚎𝚕™ » 🌐
        @kubikpixel@chaos.social

        Vibecoding Fuels a New Wave Of Stealth Attacks

        Vibe coding’s dark side, “vibe hacking,” is on the rise. companies such as McAfee and Bitdefender have observed recent spikes in vibe-coded malware, also called “,” with telltale signs such as explanatory comments or template placeholders akin to what 'd apps contain. But just how challenging is it to stop the spread of bad vibes from these emerging 's?

        💥 spectrum.ieee.org/vibecoding-m

          [?]Hugo | DevOps | Cybersecurity » 🌐
          @hugovalters@mastodon.social

          CVE-2026-13553 - Unrestricted file upload in itsourcecode Online Hotel Management System 1.0 via controller.php. CVSS 7.3. Exploit published. No patch available. Restrict access or disable uploads immediately.

          valtersit.com/cve/CVE-2026-135

            [?]TechWire ⚡ » 🤖 🌐
            @techwire@social.gamefan.net

            The Flipper Zero creators’ Busy Bar productivity display will go on sale next month

            The Busy Bar makes it obvious to others when you don’t want to be distracted. | Image: Flipper Devices First announced over a year ago in April 2025, the Busy Bar will be available for purchase starting on July 14th whe…

            theverge.com/tech/957784/flipp

            [The Verge]

              [?]deafnews » 🤖 🌐
              @deafnews@infosec.exchange

              [?]TechWire ⚡ » 🤖 🌐
              @techwire@social.gamefan.net

              Rocket Lab is buying Iridium’s satellite network for $8 billion to take on SpaceX

              Rocket Lab’s Electron launch vehicle lifting off from its launch complex in New Zealand. | Image: RocketLab Rocket Lab, the space company best known for its small satellite launcher Electron, has announced plans to acqu…

              theverge.com/science/958891/ro

              [The Verge]

                [?]WIRED - The Latest in Technology, Science, Culture and Business [Unofficial] » 🌐
                @wired.com@web.brid.gy

                Top Google Security Staff Warn Search Data Could Be Hacked if EU Rules Change

                Europe’s pro-competition proposals could see Google Search and Android systems opened up. The company claims there are serious privacy flaws.

                Top Google Security Staff Warn Search Data Could Be Hacked if EU Rules Change

                Alt...Top Google Security Staff Warn Search Data Could Be Hacked if EU Rules Change

                [?]Cyber Tips Guide » 🌐
                @cybertipsguide@mastodon.social

                FCC moves to harden emergency alerts and undersea cables—treating “invisible” infrastructure as national security assets and rewarding strong security standards.

                🔗zurl.co/Laq3P

                  [?]The New Oil » 🤖 🌐
                  @thenewoil@mastodon.thenewoil.org

                  [?]urlDNA.io :verified: » 🤖 🌐
                  @urldna@infosec.exchange

                  Possible Phishing 🎣
                  on: ⚠️hxxps[:]//566772[.]com/index[.]html?userId=6a008ceb602ca97f688f&secret=7457c7226e732255ad90c91b26f23056aaa313b2e882f9afbbda8f4b1a211712&expire=2026-05-10T14%3A49%3A31[.]457%2B00%3A00&project=6a008ceb50f329c73996
                  🧬 Analysis at: urldna.io/scan/6a42119f3b77500

                    [?]TechWire ⚡ » 🤖 🌐
                    @techwire@social.gamefan.net

                    Miss out on the AYANEO Pocket Micro 2? More might be on the way

                    Very few units were available internationally.

                    androidauthority.com/ayaneo-po

                    [Android Authority]

                      [?]CTI.FYI » 🤖 🌐
                      @CTI_FYI@infosec.exchange

                      🚨New ransom group blog posts!🚨

                      Group name: dragonforce
                      Post title: vipimaging
                      Info: cti.fyi/groups/dragonforce.html

                      Group name: dragonforce
                      Post title: stni.co.kr
                      Info: cti.fyi/groups/dragonforce.html

                      Group name: dragonforce
                      Post title: agroprime
                      Info: cti.fyi/groups/dragonforce.html

                      Group name: dragonforce
                      Post title: hwaseng
                      Info: cti.fyi/groups/dragonforce.html

                      Group name: dragonforce
                      Post title: medipakpharma.com
                      Info: cti.fyi/groups/dragonforce.html

                      Group name: qilin
                      Post title: Gsma
                      Info: cti.fyi/groups/qilin.html

                      Group name: qilin
                      Post title: Bristol Place
                      Info: cti.fyi/groups/qilin.html

                      Group name: qilin
                      Post title: Lam Soon
                      Info: cti.fyi/groups/qilin.html

                        [?]hackers-arise.official » 🌐
                        @hackers_arise@mastodon.social

                        [?]Malicious Extension Bot » 🤖 🌐
                        @malicious_browser_bot@infosec.exchange

                        extension Adblocker For Youtube – B seems malicious. Its badness score is 99/100!

                        ```json
                        {"id": "ipnjloolnfhadaamlcjnabbgkaakpfaa", "score": 99, "platform": "chrome", "name": "Adblocker For Youtube \u2013 B"}
                        ```

                          [?]Malicious Extension Bot » 🤖 🌐
                          @malicious_browser_bot@infosec.exchange

                          extension Walead Extension seems malicious. Its badness score is 100/100!

                          ```json
                          {"id": "hmagoojnoelenmjkdofmbdklgipcpmkg", "score": 100, "platform": "chrome", "name": "Walead Extension"}
                          ```

                            [?]TechWire ⚡ » 🤖 🌐
                            @techwire@social.gamefan.net

                            Samsung’s rollable phone may finally be rolling toward reality

                            Samsung reportedly eyes 2028 launch for its first rollable smartphone.

                            androidauthority.com/samsungs-

                            [Android Authority]

                              [?]BeeSINT » 🌐
                              @BeeSINT@mastodon.social

                              🎣 Phishing Spotlight

                              Active phishing domain detected in the wild:
                              www[.]facebookaccountsmanager[.]blogspot[.]com

                              🌐 Stack: GSE, blogger

                              🔗 beesint.com/pulse/616e8397-997

                                [?]EUVD Bot » 🤖 🌐
                                @EUVD_Bot@mastodon.social

                                🚨 EUVD-2026-40048

                                📊 Score: 5.3/10 (CVSS v3.1)
                                📦 Product: Hospital Management System
                                🏢 Vendor: itsourcecode
                                📅 Updated: 2026-06-29

                                📝 A vulnerability was identified in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /doctortimings.php. The manipulation of the argument editid leads to sql injection. Remote exploitation of the ...

                                🔗 euvd.enisa.europa.eu/vulnerabi

                                  [?]EUVD Bot » 🤖 🌐
                                  @EUVD_Bot@mastodon.social

                                  🚨 EUVD-2026-40046

                                  📊 Score: 6.9/10 (CVSS v3.1)
                                  📦 Product: CMS, CMS
                                  🏢 Vendor: Feehi
                                  📅 Updated: 2026-06-29

                                  📝 A vulnerability was found in Feehi CMS up to 2.1.1. This vulnerability affects unknown code of the file /api/articles of the component REST API Endpoint. Performing a manipulation results in missing authentication. The attack may be initiated remotely. The ex...

                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                    [?]BeeSINT » 🌐
                                    @BeeSINT@mastodon.social

                                    💾 🟠 Sysco (sysco.com)
                                    ✓ Verified
                                    📊 ~2.7M records compromised
                                    📂 Customer feedback, Email addresses, Employers, Job titles +4 more
                                    📅 2026-06-15 · disclosed 13d after incident
                                    🌐 Next.js, Varnish (CDN)
                                    ⚠️ No SPF/DMARC configured

                                    🔗 beesint.com/pulse/612ca83f-45d

                                      [?]urlDNA.io :verified: » 🤖 🌐
                                      @urldna@infosec.exchange

                                      Possible Phishing 🎣
                                      on: ⚠️hxxps[:]//www[.]robiox[.]com[.]py/users/238255169582/profile
                                      🧬 Analysis at: urldna.io/scan/6a421fb73b77500

                                        [?]Ivy Cyber » 🤖 🌐
                                        @ivycyber@privacysafe.social

                                        🛡️ news & tips across the

                                        “RE: https:// mastodon.social/@chatcontrol/1 16812506724557428 I just sent the emails as suggested by @ chatcontrol because # surveillance is just one of the first steps toward # oppression . Thank you f...”

                                        mastodon.social/@marcow/116829

                                        🤖 via RSS feed. Not an endorsement.

                                          [?]OTX Bot » 🤖 🌐
                                          @techbot@social.raytec.co

                                          Miasma Mini Shai-Hulud Hits ImmobiliareLabs npm Packages

                                          A fresh wave of the Miasma Mini Shai-Hulud supply chain campaign compromised legitimate npm packages under the @immobiliarelabs scope on June 26, 2026. The attack targeted Backstage plugins used for GitLab integration and LDAP authentication, affecting 22 package versions across multiple releases. The malware employs sophisticated techniques including hidden payloads that bypass standard package reviews, steals developer credentials and CI/CD secrets, and exploits GitHub Actions workflows for propagation. The campaign appears linked to a compromised upstream GitHub Action (codfish/semantic-release-action) and leverages deployment-triggered workflows for execution. Stolen credentials include npm tokens, GitHub tokens, cloud credentials, SSH keys, and various authentication secrets, which are exfiltrated to attacker-controlled repositories for further propagation across the ecosystem.

                                          Pulse ID: 6a3f2df93c2f6387d1b27726
                                          Pulse Link: otx.alienvault.com/pulse/6a3f2
                                          Pulse Author: AlienVault
                                          Created: 2026-06-27 01:57:13

                                          Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                            [?]OTX Bot » 🤖 🌐
                                            @techbot@social.raytec.co

                                            Understanding Langflow CVE-2026-55255, and why higher CVSS vulnerabilities aren't always the most exploited

                                            On June 25, 2026, the first active exploitation of CVE-2026-55255, a critical CVSS 9.9 Langflow vulnerability, was documented. Langflow is an open-source framework for building AI agents and RAG pipelines. A single operator exploited both CVE-2026-55255 (cross-tenant IDOR) and CVE-2026-33017 (unauthenticated RCE, CVSS 9.3) against the same instance. Despite its lower score, the RCE has been exploited thousands of times and is listed in CISA KEV, while the IDOR showed no prior in-the-wild exploitation. The operator focused primarily on the RCE for code execution and implant delivery, using the IDOR opportunistically for credential theft across tenants. The financially motivated threat actor deployed a scripted loader to harvest AWS keys, environment files, and API credentials. This demonstrates that CVSS scores don't always correlate with real-world exploitation rates, as unauthenticated vulnerabilities require less effort than those needing authorization and disclosed object IDs.

                                            Pulse ID: 6a3eefb892e3d749bcf92233
                                            Pulse Link: otx.alienvault.com/pulse/6a3ee
                                            Pulse Author: AlienVault
                                            Created: 2026-06-26 21:31:36

                                            Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                              [?]Hugo | DevOps | Cybersecurity » 🌐
                                              @hugovalters@mastodon.social

                                              Elementor: 74 CVEs, avg CVSS 5.9, max 8.8. 100% unpatched. Trust Score: C. Millions of WordPress sites at risk. Patch NOW.

                                              valtersit.com/vendors/elemento

                                                [?]TechWire ⚡ » 🤖 🌐
                                                @techwire@social.gamefan.net

                                                This might finally be the best PS2 emulator on Android after recent updates

                                                PS2 emulation on Android is no longer a one-horse race.

                                                androidauthority.com/armsx2-re

                                                [Android Authority]

                                                  [?]Negative PID SL » 🌐
                                                  @negativepid@mastodon.social

                                                  [?]TechWire ⚡ » 🤖 🌐
                                                  @techwire@social.gamefan.net

                                                  You might not use this powerful Android utility, but nearly a third of polled readers do

                                                  Only 1 in every 10 readers don't bother using it.

                                                  androidauthority.com/shizuku-a

                                                  [Android Authority]

                                                    [?]AllAboutSecurity » 🌐
                                                    @allaboutsecurity@mastodon.social

                                                    [?]CVEDatabase.com » 🌐
                                                    @cvedatabase@techhub.social

                                                    🛡️ Weekly CVE Roundup is here! We're highlighting a critical path traversal bypass in Node.js (CVE-2026-3102) and discussing why experimental features can be a liability in production. Stay ahead of the latest security trends. 🔒 Read more: cvedatabase.com/blog/weekly-cv

                                                      [?]urlDNA.io :verified: » 🤖 🌐
                                                      @urldna@infosec.exchange

                                                      Possible Phishing 🎣
                                                      on: ⚠️hxxps[:]//evo-help[.]ru
                                                      🧬 Analysis at: urldna.io/scan/6a41f5a93b77500

                                                        [?]OTX Bot » 🤖 🌐
                                                        @techbot@social.raytec.co

                                                        Phishing Campaign PasasteSinTAG - New domain rotation identified associated with the campaign impersonating the PasasteSinTAG portal

                                                        A phishing campaign targeting Chile continues to evolve with significant infrastructure expansion. Security researchers identified 99 new domains impersonating the legitimate PasasteSinTAG portal, with 22 domains confirmed active and 77 registered but not yet activated. The active domains utilize various top-level domains including .click, .cfd, .cyou, .mom, .best, .rest, .top, .help, .sbs, .icu, .life, .xyz, .buzz, .casa, and .pics. The infrastructure is hosted across seven IP addresses. This campaign represents an ongoing threat to Chilean users through brand impersonation tactics, with threat actors maintaining a large reserve of dormant domains for future rotation.

                                                        Pulse ID: 6a42124a18e7d2cb639c06dd
                                                        Pulse Link: otx.alienvault.com/pulse/6a421
                                                        Pulse Author: AlienVault
                                                        Created: 2026-06-29 06:35:54

                                                        Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                                          [?]TechWire ⚡ » 🤖 🌐
                                                          @techwire@social.gamefan.net

                                                          After 10 months with the Pixel 10 Pro, I can’t stand these 3 issues

                                                          Sorry Pixel, it's not me, it's definitely you.

                                                          androidauthority.com/google-pi

                                                          [Android Authority]

                                                            [?]TechWire ⚡ » 🤖 🌐
                                                            @techwire@social.gamefan.net

                                                            Google Translate could soon borrow another one of Duolingo’s best ideas

                                                            A new "Practice streak" widget will soon let Translate users see their language-learning progress front and center.

                                                            androidauthority.com/google-tr

                                                            [Android Authority]

                                                              [?]thecybersecguru » 🌐
                                                              @thecybersecguru@infosec.exchange

                                                              🚨 If you booked a hotel through Booking.com, read this before your next trip.

                                                              Attackers are hijacking hotel partner accounts, stealing REAL reservation details, and sending convincing phishing messages with your hotel name, booking ID, and check-in date. Booking.com has suffered a major data breach.

                                                              This isn't a fake database leak. It's a supply chain security failure affecting hotels worldwide, with Japan currently at the center of the latest campaign.

                                                              🔒 Learn:
                                                              • How the attack works
                                                              • Why hotel extranet accounts are being targeted
                                                              • How guest data is abused
                                                              • Red flags to spot before you lose your money

                                                              Read the full investigation 👇
                                                              thecybersecguru.com/news/booki

                                                                [?]Negative PID SL » 🌐
                                                                @negativepid@mastodon.social

                                                                [?]thecybersecguru » 🌐
                                                                @thecybersecguru@infosec.exchange

                                                                🚨 Discord is testing **Incode** for age verification, but the real privacy story is far more complicated.

                                                                📌 On-device facial age estimation
                                                                📌 Government ID verification
                                                                📌 Credit card & Google Wallet checks
                                                                📌 TikTok comparisons explained
                                                                📌 What happens to your biometric data?
                                                                📌 The hidden behavioral profiling almost nobody is discussing

                                                                If you use Discord, read this before you verify your age.

                                                                🔗 thecybersecguru.com/news/disco

                                                                  [?]TechWire ⚡ » 🤖 🌐
                                                                  @techwire@social.gamefan.net

                                                                  PSA: Samsung Messages is going away soon

                                                                  Still using Samsung Messages? Time is running out to make the switch.

                                                                  androidauthority.com/samsung-m

                                                                  [Android Authority]

                                                                    [?]Negative PID SL » 🌐
                                                                    @negativepid@mastodon.social

                                                                    Back to top - More...