voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]Malicious Extension Bot » 🤖 🌐
@malicious_browser_bot@infosec.exchange

extension Super Chat CRM seems malicious. Its badness score is 97/100!

```json
{"id": "opocafnnojhngbheikamlpdmijhbobfj", "score": 97, "platform": "chrome", "name": "Super Chat CRM"}
```

    [?]Malicious Extension Bot » 🤖 🌐
    @malicious_browser_bot@infosec.exchange

    extension Sheep WA CRM seems malicious. Its badness score is 85/100!

    ```json
    {"id": "nbbgapgjdeggafgiphoamapigagdfboj", "score": 85, "platform": "chrome", "name": "Sheep WA CRM"}
    ```

      [?]Malicious Extension Bot » 🤖 🌐
      @malicious_browser_bot@infosec.exchange

      extension WHIZFLOW seems malicious. Its badness score is 93/100!

      ```json
      {"id": "ioplkfchkjdlkoobflfibdbbpjaodefk", "score": 93, "platform": "chrome", "name": "WHIZFLOW"}
      ```

        [?]Malicious Extension Bot » 🤖 🌐
        @malicious_browser_bot@infosec.exchange

        extension SOWAT seems malicious. Its badness score is 91/100!

        ```json
        {"id": "djdbpbcemdndgmlkbbediigefocfndke", "score": 91, "platform": "chrome", "name": "SOWAT"}
        ```

          [?]TechWire ⚡ » 🤖 🌐
          @techwire@social.gamefan.net

          Japanese firm launches hyper-realistic capsule toy PC parts ‘you can assemble and play with’ — tiny motherboards, cases, and CPUs are coming after Tar…

          A Japanese capsule toy maker has announced an official collaboration with ASRock, Gigabyte, MSI, and Intel to make tiny PC components that buyers 'can assemble and play with.'

          tomshardware.com/desktops/pc-b

          [Tom's Hardware]

            [?]Malicious Extension Bot » 🤖 🌐
            @malicious_browser_bot@infosec.exchange

            extension Veltora CRM Platform seems malicious. Its badness score is 98/100!

            ```json
            {"id": "fkcifkeeglocoaekandppmecohhhjjld", "score": 98, "platform": "chrome", "name": "Veltora CRM Platform"}
            ```

              [?]TechWire ⚡ » 🤖 🌐
              @techwire@social.gamefan.net

              Apple and Disney had conversations about merging, says Bob Iger

              Disney’s former CEO Bob Iger is the subject of a new profile at Financial Times, in which he shares new quotes about the long-discussed idea of Apple and Disney merging. Here’s what he said.

              9to5mac.com/2026/06/23/apple-a

              [9to5Mac]

                [?]TechWire ⚡ » 🤖 🌐
                @techwire@social.gamefan.net

                Chinese developers file antitrust complaint against Apple over App Store fees

                A group of 48 Chinese developers is asking regulators to investigate Apple over what it describes as unfairly high App Store fees and restrictive distribution rules. Here are the details.

                9to5mac.com/2026/06/23/chinese

                [9to5Mac]

                  [?]urlDNA.io :verified: » 🤖 🌐
                  @urldna@infosec.exchange

                  Possible Phishing 🎣
                  on: ⚠️hxxps[:]//amazon-clone-nine[.]vercel[.]app
                  🧬 Analysis at: urldna.io/scan/6a40802c3b77500

                    [?]Hugo | DevOps | Cybersecurity » 🌐
                    @hugovalters@mastodon.social

                    Intel: 892 CVEs tracked. 94% unpatched. Avg CVSS 6.21, max 10. Trust Score: C. Top weaknesses: Uncontrolled Search Path (CWE-427) & Input Validation. Chip vulnerabilities matter.

                    valtersit.com/vendors/intel/

                      [?]𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 :verified: » 🌐
                      @youranonnewsirc@nerdculture.de

                      ... [SENSITIVE CONTENT]

                      Geopolitical tensions remain high with US strikes on Iran (June 27, 2026) and Iran's reported retaliatory attacks. Technologically, OpenAI previews GPT-5.6 Sol, emphasizing stronger cyber safeguards and restricted access. In cybersecurity, Microsoft and Europol successfully dismantled a significant global infostealer malware network.

                        [?]TechWire ⚡ » 🤖 🌐
                        @techwire@social.gamefan.net

                        TMD’s keyless bike lock is a $280 solution to a $60 problem

                        A $280 bike lock on a $10,000 e-bike. I've seen lots of so-called "smart" bike locks over the years, but none so far could justify the added cost. A newcomer that got its start securing ATMs for banks is trying to chang…

                        theverge.com/tech/957603/tmd-s

                        [The Verge]

                          [?]urlDNA.io :verified: » 🤖 🌐
                          @urldna@infosec.exchange

                          Possible Phishing 🎣
                          on: ⚠️hxxps[:]//veirifcaemail[.]webcindario[.]com/
                          🧬 Analysis at: urldna.io/scan/6a40a4233b77500

                            [?]AllAboutSecurity » 🌐
                            @allaboutsecurity@mastodon.social

                            GPT-5.6: OpenAI startet neue KI-Modellfamilie Sol, Terra, Luna

                            Stärkerer Fokus auf Cybersicherheit

                            Es unterstützt legitime Anwendungsfälle wie Schwachstellenforschung, Patch-Entwicklung, Code-Review, Debugging, Sicherheitsschulungen und defensive Systemtests.

                            all-about-security.de/gpt-5-6-

                              [?]Malicious Extension Bot » 🤖 🌐
                              @malicious_browser_bot@infosec.exchange

                              extension CRM no Whatsapp para corretores de seguro seems malicious. Its badness score is 98/100!

                              ```json
                              {"id": "ihcekhkenpafgnlnppeldehaidbplopb", "score": 98, "platform": "chrome", "name": "CRM no Whatsapp para corretores de seguro"}
                              ```

                                [?]Malicious Extension Bot » 🤖 🌐
                                @malicious_browser_bot@infosec.exchange

                                extension Claude Chat WhatsApp seems malicious. Its badness score is 90/100!

                                ```json
                                {"id": "pgahbfgpejdkcnhkehniglkjkmidgifg", "score": 90, "platform": "chrome", "name": "Claude Chat WhatsApp"}
                                ```

                                  [?]Malicious Extension Bot » 🤖 🌐
                                  @malicious_browser_bot@infosec.exchange

                                  extension CRM no Whatsapp para Delivery seems malicious. Its badness score is 91/100!

                                  ```json
                                  {"id": "neelgaajhioohpoenjbjhfldmlfpiocf", "score": 91, "platform": "chrome", "name": "CRM no Whatsapp para Delivery"}
                                  ```

                                    [?]Malicious Extension Bot » 🤖 🌐
                                    @malicious_browser_bot@infosec.exchange

                                    extension Zap Web seems malicious. Its badness score is 100/100!

                                    ```json
                                    {"id": "ikacabonlldjhidajbjbpjnbcilhokdi", "score": 100, "platform": "chrome", "name": "Zap Web"}
                                    ```

                                      [?]Malicious Extension Bot » 🤖 🌐
                                      @malicious_browser_bot@infosec.exchange

                                      extension GL MEDLEAD CRM seems malicious. Its badness score is 85/100!

                                      ```json
                                      {"id": "fcmjkjmkpgfhchcekjdgolldhnmacpfa", "score": 85, "platform": "chrome", "name": "GL MEDLEAD CRM"}
                                      ```

                                        [?]ransomNews » 🌐
                                        @ransomnews.online@bsky.brid.gy

                                        📰 Biometric breaches leave victims no reset button

                                        Unlike passwords, stolen faces, fingerprints or voiceprints cannot be reissued, turning one healthcare biometric leak into permanent identity risk.

                                        🔗 read more: blog.baited.io/2026/biometr...

                                        Field Notes - Healthcare biome...

                                          [?]TechWire ⚡ » 🤖 🌐
                                          @techwire@social.gamefan.net

                                          Apple Invites updated with three changes, including a new cohosting feature

                                          Apple’s digital event planning app, Invites, is out with three changes today, including a new cohosting feature.

                                          9to5mac.com/2026/06/23/apple-i

                                          [9to5Mac]

                                            [?]TechWire ⚡ » 🤖 🌐
                                            @techwire@social.gamefan.net

                                            LG UltraFine 6K Review: A Premium 6K Display Designed With Mac Users in Mind

                                            With Apple's discontinuation of the Pro Display XDR earlier this year, Mac users looking for a larger high-resolution display suddenly found themselves with fewer options on the market. Apple's current display lineup no…

                                            macrumors.com/review/lg-ultraf

                                            [MacRumors]

                                              [?]TechWire ⚡ » 🤖 🌐
                                              @techwire@social.gamefan.net

                                              iPhone 18 Pro and Pro Max May See $200 Price Increase

                                              Apple's iPhone 18 Pro models could be up to $200 more expensive, according to a prediction from analytics firm IDC. IDC expected Apple to raise iPhone 18 prices, but prior to yesterday's Mac and iPad price hike, the pre…

                                              macrumors.com/2026/06/26/iphon

                                              [MacRumors]

                                                [?]urlDNA.io :verified: » 🤖 🌐
                                                @urldna@infosec.exchange

                                                Possible Phishing 🎣
                                                on: ⚠️hxxps[:]//microsoft-clone-neon[.]vercel[.]app
                                                🧬 Analysis at: urldna.io/scan/6a4072353b77500

                                                  [?]EUVD Bot » 🤖 🌐
                                                  @EUVD_Bot@mastodon.social

                                                  🚨 EUVD-2026-39978

                                                  📊 Score: 6.9/10 (CVSS v3.1)
                                                  📦 Product: nmap
                                                  🏢 Vendor: Nmap
                                                  📅 Updated: 2026-06-28

                                                  📝 Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (libnetutil/netutil.cc), so the pointer advances past the buffer and the remaining-length computation underflows to a large value. A scanned target...

                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                    [?]EUVD Bot » 🤖 🌐
                                                    @EUVD_Bot@mastodon.social

                                                    🚨 EUVD-2026-39977

                                                    📊 Score: 2.3/10 (CVSS v3.1)
                                                    📦 Product: Flowise
                                                    🏢 Vendor: Flowise
                                                    📅 Updated: 2026-06-28

                                                    📝 Flowise before 3.1.3 validates Custom MCP stdio environment variables against a denylist using a case-sensitive comparison, so on Windows, where environment names are case-insensitive, supplying 'node_options' bypasses the NODE_OPTIONS denylist entry. An aut...

                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                      [?]EUVD Bot » 🤖 🌐
                                                      @EUVD_Bot@mastodon.social

                                                      🚨 EUVD-2026-39975

                                                      📊 Score: 6.3/10 (CVSS v3.1)
                                                      📦 Product: nghttp2
                                                      🏢 Vendor: nghttp2
                                                      📅 Updated: 2026-06-28

                                                      📝 nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A...

                                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                                        [?]EUVD Bot » 🤖 🌐
                                                        @EUVD_Bot@mastodon.social

                                                        🚨 EUVD-2026-39976

                                                        📊 Score: 7.2/10 (CVSS v3.1)
                                                        📦 Product: RustDesk
                                                        🏢 Vendor: RustDesk
                                                        📅 Updated: 2026-06-28

                                                        📝 RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer session does not clear those flags. A peer holding only a valid FileTransfer authorization can inject keyboard and...

                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                          [?]EUVD Bot » 🤖 🌐
                                                          @EUVD_Bot@mastodon.social

                                                          🚨 EUVD-2026-39974

                                                          📊 Score: 8.6/10 (CVSS v3.1)
                                                          📦 Product: MyBB
                                                          🏢 Vendor: MyBB
                                                          📅 Updated: 2026-06-28

                                                          📝 MyBB 1.8.40 does not restrict which usergroup a limited Admin Control Panel user may assign when creating or editing users; the user module offers the Administrators group (gid 4) and its datahandler's verify_usergroup() unconditionally returns true. An admin hold...

                                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                                            [?]EUVD Bot » 🤖 🌐
                                                            @EUVD_Bot@mastodon.social

                                                            🚨 EUVD-2026-39973

                                                            📊 Score: 9.4/10 (CVSS v3.1)
                                                            📦 Product: act_runner
                                                            🏢 Vendor: Gitea
                                                            📅 Updated: 2026-06-28

                                                            📝 Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging options such ...

                                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                                              [?]EUVD Bot » 🤖 🌐
                                                              @EUVD_Bot@mastodon.social

                                                              🚨 EUVD-2026-39972

                                                              📊 Score: 4.8/10 (CVSS v3.1)
                                                              📦 Product: 7-Zip
                                                              🏢 Vendor: 7-Zip
                                                              📅 Updated: 2026-06-28

                                                              📝 7-Zip for Windows through 26.02 fails to preserve the Mark-of-the-Web when extracting a crafted RAR5 archive, because its guard that suppresses an archive-supplied Zone.Identifier stream matches the exact name 'Zone.Identifier' while a RAR5 STM record named ':Zo...

                                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                                [?]EUVD Bot » 🤖 🌐
                                                                @EUVD_Bot@mastodon.social

                                                                🚨 EUVD-2026-39971

                                                                📊 Score: 8.3/10 (CVSS v3.1)
                                                                📦 Product: libssh2
                                                                🏢 Vendor: libssh2
                                                                📅 Updated: 2026-06-28

                                                                📝 libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A m...

                                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                                  [?]EUVD Bot » 🤖 🌐
                                                                  @EUVD_Bot@mastodon.social

                                                                  🚨 EUVD-2026-39970

                                                                  📊 Score: 8.3/10 (CVSS v3.1)
                                                                  📦 Product: libssh2
                                                                  🏢 Vendor: libssh2
                                                                  📅 Updated: 2026-06-28

                                                                  📝 libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication ov...

                                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                                    [?]EUVD Bot » 🤖 🌐
                                                                    @EUVD_Bot@mastodon.social

                                                                    🚨 EUVD-2026-39969

                                                                    📊 Score: 8.8/10 (CVSS v3.1)
                                                                    📦 Product: FFmpeg
                                                                    🏢 Vendor: FFMPEG
                                                                    📅 Updated: 2026-06-28

                                                                    📝 FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can access se...

                                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                                      [?]TechWire ⚡ » 🤖 🌐
                                                                      @techwire@social.gamefan.net

                                                                      Apple Loses Another Top Executive to OpenAI

                                                                      Paul Meade, who oversees development on the Vision Pro and Apple's upcoming smart glasses, is leaving Apple for OpenAI, reports Bloomberg. Meade took over leadership of Apple's Vision Products Group when Vision Pro chie…

                                                                      macrumors.com/2026/06/26/apple

                                                                      [MacRumors]

                                                                        [?]TechWire ⚡ » 🤖 🌐
                                                                        @techwire@social.gamefan.net

                                                                        iOS 27 Makes the Shortcuts App Much Less Intimidating

                                                                        The Shortcuts app can be intimidating to casual iPhone users, but with iOS 27, it's a lot easier to use. With Apple Intelligence integration, shortcuts can be created using natural language, and they're much more access…

                                                                        macrumors.com/guide/ios-27-sho

                                                                        [MacRumors]

                                                                          [?]urlDNA.io :verified: » 🤖 🌐
                                                                          @urldna@infosec.exchange

                                                                          Possible Phishing 🎣
                                                                          on: ⚠️hxxps[:]//gmxmainde[.]weebly[.]com
                                                                          🧬 Analysis at: urldna.io/scan/6a4047f73b77500

                                                                            [?]Technoholic.me » 🌐
                                                                            @technoholic@mastodon.social

                                                                            Since April 2026, a phishing campaign using photo ZIP files targets hotels in Europe and Asia, dropping a Node.js implant into front-desk systems. motives unknown. thehackernews.com/2026/06/micr

                                                                              [?]TechWire ⚡ » 🤖 🌐
                                                                              @techwire@social.gamefan.net

                                                                              Top Stories: Massive Apple Price Increases, iOS 27 Beta 2, and More

                                                                              The Apple community was rocked this week as the company instituted massive price hikes on a broad array of products, with many products seeing increases of 10–20 percent and a few as high as 50 percent or more. The move…

                                                                              macrumors.com/2026/06/27/top-s

                                                                              [MacRumors]

                                                                                [?]Malicious Extension Bot » 🤖 🌐
                                                                                @malicious_browser_bot@infosec.exchange

                                                                                extension CRM no WhatsApp para Corban seems malicious. Its badness score is 98/100!

                                                                                ```json
                                                                                {"id": "cfhoklhgomgfghpjamadhngdiaailanj", "score": 98, "platform": "chrome", "name": "CRM no WhatsApp para Corban"}
                                                                                ```

                                                                                  [?]TechWire ⚡ » 🤖 🌐
                                                                                  @techwire@social.gamefan.net

                                                                                  Bambu Lab A2L 3D printer review: The A1 grows up

                                                                                  Bambu Lab adds a bigger bed slinger to their lineup.

                                                                                  tomshardware.com/3d-printing/b

                                                                                  [Tom's Hardware]

                                                                                    [?]TechWire ⚡ » 🤖 🌐
                                                                                    @techwire@social.gamefan.net

                                                                                    Intel's next-gen 52-core Nova Lake CPU could pull up to 474W — high-end LGA1954 motherboards may need thr…

                                                                                    Intel's flagship 52-core Nova Lake processor could feature a 474W PL2 power limit. At the same time, the new LGA1954 platform may introduce motherboard tiers for up to 175W CPUs and optional triple EPS power connectors …

                                                                                    tomshardware.com/pc-components

                                                                                    [Tom's Hardware]

                                                                                      [?]CVEDatabase.com » 🌐
                                                                                      @cvedatabase@techhub.social

                                                                                      Security Tip: Integrate container image scanning into your CI/CD pipeline. 🛡️ Vulnerabilities often hide in base images or outdated libraries within your layers. Using scanners like Trivy or Clair helps you catch known CVEs before they are deployed. A secure container starts with a clean image. For technical deep dives and vulnerability intelligence, visit cvedatabase.com

                                                                                        [?]urlDNA.io :verified: » 🤖 🌐
                                                                                        @urldna@infosec.exchange

                                                                                        Possible Phishing 🎣
                                                                                        on: ⚠️hxxps[:]//mensajedevoz[.]weebly[.]com
                                                                                        🧬 Analysis at: urldna.io/scan/6a401dd53b77500

                                                                                          Back to top - More...