voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]Negative PID SL » 🌐
@negativepid@mastodon.social

[?]BeeSINT » 🌐
@BeeSINT@mastodon.social

🎣 Phishing Spotlight

Active phishing domain detected in the wild:
netflix-clone-shivang02[.]vercel[.]app

🔒 SSL exp. 2026-07-27
🌐 Stack: Vercel

🔗 beesint.com/pulse/38321c7a-0cd

    [?]EUVD Bot » 🤖 🌐
    @EUVD_Bot@mastodon.social

    🚨 EUVD-2026-39640

    📊 Score: n/a
    📦 Product: Bytes::Random::Secure
    🏢 Vendor: DAVIDO
    📅 Updated: 2026-06-26

    📝 Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes.

    When an object is initialised before forking, or when the functional interface is used, then the internal state for the PRNG is shared across processes and iden...

    🔗 euvd.enisa.europa.eu/vulnerabi

      [?]EUVD Bot » 🤖 🌐
      @EUVD_Bot@mastodon.social

      🚨 EUVD-2026-39639

      📊 Score: 6.5/10 (CVSS v3.1)
      📦 Product: User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder
      🏢 Vendor: WPEverest
      📅 Updated: 2026-06-26

      📝 The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Cus...

      🔗 euvd.enisa.europa.eu/vulnerabi

        [?]urlDNA.io :verified: » 🤖 🌐
        @urldna@infosec.exchange

        Possible Phishing 🎣
        on: ⚠️hxxps[:]//dammrow[.]github[.]io/hxxps-Dammrow[.]github[.]io-Netflix/
        🧬 Analysis at: urldna.io/scan/6a3e23763b77500

          [?]BeeSINT » 🌐
          @BeeSINT@mastodon.social

          💾 🟠 CFGI (cfgi.com)
          ✓ Verified
          📊 ~248K records compromised
          📂 Email addresses, Employers, Job titles, Names +2 more
          📅 2026-03-06 · disclosed 104d after incident
          🌐 cloudflare, WP, WPML
          ⚠️ No SPF/DMARC configured

          🔗 beesint.com/pulse/bc7048b2-5b8

            [?]BeyondMachines :verified: » 🤖 🌐
            @beyondmachines1@infosec.exchange

            NAIC Confirms Data Breach Following Oracle PeopleSoft Zero-Day Exploit

            The National Association of Insurance Commissioners (NAIC) suffered a data breach after attackers exploited a zero-day vulnerability in Oracle PeopleSoft to gain unauthorized access to financial reporting data. The organization is working with the FBI and external experts to analyze leaked data and restore full functionality to its payment systems.

            ****

            beyondmachines.net/event_detai

              [?]Ivy Cyber » 🤖 🌐
              @ivycyber@privacysafe.social

              🛡️ news & tips across the

              “North Korea neighborhood watch leader shortage https://www. byteseu.com/2139949/ # Conflicts # ideology # Mobilization # NorthKorea # Pyongyang # surveillance # women # workers”

              pubeurope.com/@byteseu/1168126

              🤖 via RSS feed. Not an endorsement.

                [?]N_{Dario Fadda} » 🌐
                @nuke@poliversity.it

                Microsoft Secure Boot Certificates Expire — Over a Billion PCs and Linux Systems at Risk

                securebulletin.com/microsoft-s

                  [?]Hugo | DevOps | Cybersecurity » 🌐
                  @hugovalters@mastodon.social

                  Emlog: 65 CVEs, avg CVSS 5.99. 90% unpatched. Trust Score: C. Top flaws: XSS (CWE-79) & file upload (CWE-434). Lightweight ≠ secure. Patch now.

                  valtersit.com/vendors/emlog/

                    [?]TechWire ⚡ » 🤖 🌐
                    @techwire@social.gamefan.net

                    Polled readers love the Fitbit Air, but there’s still room for a Google smart ring

                    Screenless fitness trackers are here, but the smart ring hype is still alive.

                    androidauthority.com/fitbit-ai

                    [Android Authority]

                      [?]Negative PID SL » 🌐
                      @negativepid@mastodon.social

                      [?]TechWire ⚡ » 🤖 🌐
                      @techwire@social.gamefan.net

                      Forget Gemini and ChatGPT — here are 5 unique AI tools I actually use

                      Sometimes you want a tool that's designed with a speciality in mind. Here are some of my favorites.

                      androidauthority.com/unique-ai

                      [Android Authority]

                        [?]Malicious Extension Bot » 🤖 🌐
                        @malicious_browser_bot@infosec.exchange

                        extension Instagram Enhancement Sui seems malicious. Its badness score is 85/100!

                        ```json
                        {"id": "fpdbhcocghgfobllfholkeeilepcnbmp", "score": 85, "platform": "chrome", "name": "Instagram Enhancement Sui"}
                        ```

                          [?]Malicious Extension Bot » 🤖 🌐
                          @malicious_browser_bot@infosec.exchange

                          extension Bonusbank Horsepower seems malicious. Its badness score is 92/100!

                          ```json
                          {"id": "oilfpkgoibdejfdpedhejpgkojdbbakn", "score": 92, "platform": "chrome", "name": "Bonusbank Horsepower"}
                          ```

                            [?]Malicious Extension Bot » 🤖 🌐
                            @malicious_browser_bot@infosec.exchange

                            extension Chatgpt For Google seems malicious. Its badness score is 91/100!

                            ```json
                            {"id": "pjhdflpjemjalkidecigcjcamkbllhoj", "score": 91, "platform": "chrome", "name": "Chatgpt For Google"}
                            ```

                              [?]Malicious Extension Bot » 🤖 🌐
                              @malicious_browser_bot@infosec.exchange

                              extension Safe Wallet Extension seems malicious. Its badness score is 85/100!

                              ```json
                              {"id": "ddblhcgjpnmjlbkpndackhohbdbknobi", "score": 85, "platform": "chrome", "name": "Safe Wallet Extension"}
                              ```

                                [?]urlDNA.io :verified: » 🤖 🌐
                                @urldna@infosec.exchange

                                Possible Phishing 🎣
                                on: ⚠️hxxps[:]//amu-univ00[.]weebly[.]com
                                🧬 Analysis at: urldna.io/scan/6a3dd6f53b77500

                                  [?]RedPacket Security » 🌐
                                  @RedPacketSecurity@mastodon.social

                                  [?]Hacker News » 🤖 🌐
                                  @h4ckernews@mastodon.social

                                  [?]N-gated Hacker News » 🤖 🌐
                                  @ngate@mastodon.social

                                  🚀🕵️‍♂️ When 2,000 wannabe hackers stormed the gates of an AI assistant, they ended up with... nothing. 💥 Witness the riveting tale of an AI that valiantly defended its secrets, while a crowd of bored techies scratched their heads. 🤖🔐
                                  fernandoi.cl/posts/hackmyclaw/

                                    [?]TechWire ⚡ » 🤖 🌐
                                    @techwire@social.gamefan.net

                                    Nothing Phone 4b just lost a few more secrets ahead of its July 7 debut

                                    Nothing's next mid-range phone is no longer much of a mystery.

                                    androidauthority.com/nothing-p

                                    [Android Authority]

                                      [?]thecybersecguru » 🌐
                                      @thecybersecguru@infosec.exchange

                                      🚨 Three Gitea/Gogs vulnerabilities just dropped — and one is a CVSS 9.8 authentication bypass.

                                      If you self-host Gitea or Gogs, this is not a “patch later” situation:

                                      ⚠️ CVE-2026-20896 — Gitea Docker auth bypass
                                      Anyone can impersonate any user with one HTTP header: `X-WEBAUTH-USER: admin`

                                      ⚠️ CVE-2026-52807 — Stored DOM XSS
                                      A malicious milestone name can survive escaping and execute through Semantic UI.

                                      ⚠️ CVE-2026-22874 — Webhook SSRF
                                      Gitea webhooks can become a path to AWS IMDS, cloud credentials, S3, Secrets Manager, ECR, and full cloud privilege abuse.

                                      Self-hosted Git platforms hold source code, CI/CD secrets, deploy keys, webhooks, tokens, and internal infrastructure access.

                                      Your code. Your secrets. Their access.

                                      Upgrade now:
                                      Gitea 1.26.3+
                                      Gogs 0.14.3+

                                      Full technical breakdown 👇
                                      thecybersecguru.com/news/cve-2

                                        [?]urlDNA.io :verified: » 🤖 🌐
                                        @urldna@infosec.exchange

                                        Possible Phishing 🎣
                                        on: ⚠️hxxps[:]//rqebah[.]weebly[.]com
                                        🧬 Analysis at: urldna.io/scan/6a3dc1243b77500

                                          [?]TechWire ⚡ » 🤖 🌐
                                          @techwire@social.gamefan.net

                                          The $25 Fire TV Stick is my favorite Prime Day purchase yet

                                          Amazon Prime Day has many good deals, but the 50% off Fire TV Stick 4K Plus is one of the best.

                                          zdnet.com/article/the-25-fire-

                                          [ZDNet]

                                            [?]TechWire ⚡ » 🤖 🌐
                                            @techwire@social.gamefan.net

                                            China black market Nvidia prices rocket in wake of smuggling crackdown and customs freeze — five-year-old A100 servers triple in price, now fetching up to $82,000

                                            Chinese companies are paying as much as $82,000 for servers built around Nvidia's five-year-old A100 accelerator

                                            tomshardware.com/pc-components

                                            [Tom's Hardware]

                                              [?]urlDNA.io :verified: » 🤖 🌐
                                              @urldna@infosec.exchange

                                              Possible Phishing 🎣
                                              on: ⚠️hxxps[:]//ruraltebwebmailinc[.]weebly[.]com
                                              🧬 Analysis at: urldna.io/scan/6a3e075a3b77500

                                                [?]TechWire ⚡ » 🤖 🌐
                                                @techwire@social.gamefan.net

                                                Here are the best OLED gaming monitor deals you can snag for Amazon Prime Day — beautiful monitors up to 47% off

                                                We've rounded up the best deals on OLED gaming monitors for you this Prime Day. From massive DQHD panels to dual-mode offerings, we have you covered.

                                                tomshardware.com/monitors/gami

                                                [Tom's Hardware]

                                                  [?]TechWire ⚡ » 🤖 🌐
                                                  @techwire@social.gamefan.net

                                                  Save up to 53% on Lenovo’s Black Friday in June sale — Sitewide discounts on ThinkPads, Legions, and more

                                                  Black Friday comes early, as Lenovo is running a huge sale on a wide range of products at its online store.

                                                  tomshardware.com/laptops/save-

                                                  [Tom's Hardware]

                                                    [?]Bobe'bot on security » 🤖 🌐
                                                    @Bobe_bot@mastobot.ping.moi

                                                    💭 Méditation du Firewall

                                                    𝘓𝘦𝘴 𝘱𝘶𝘤𝘦𝘴 𝘳é𝘵𝘳é𝘤𝘪𝘴𝘴𝘦𝘯𝘵, 𝘭𝘦𝘴 𝘴𝘶𝘳𝘧𝘢𝘤𝘦𝘴 𝘥'𝘢𝘵𝘵𝘢𝘲𝘶𝘦 𝘨𝘳𝘢𝘯𝘥𝘪𝘴𝘴𝘦𝘯𝘵. 𝘓𝘢 𝘭𝘰𝘪 𝘥𝘦 𝘔𝘰𝘰𝘳𝘦 𝘦𝘵 𝘤𝘦𝘭𝘭𝘦 𝘥𝘦 𝘔𝘶𝘳𝘱𝘩𝘺 𝘢𝘷𝘢𝘯𝘤𝘦𝘯𝘵 𝘮𝘢𝘪𝘯 𝘥𝘢𝘯𝘴 𝘭𝘢 𝘮𝘢𝘪𝘯.

                                                      [?]urlDNA.io :verified: » 🤖 🌐
                                                      @urldna@infosec.exchange

                                                      Possible Phishing 🎣
                                                      on: ⚠️hxxps[:]//originsteam[.]weebly[.]com
                                                      🧬 Analysis at: urldna.io/scan/6a3ddd3a3b77500

                                                        [?]EUVD Bot » 🤖 🌐
                                                        @EUVD_Bot@mastodon.social

                                                        🚨 EUVD-2026-39623

                                                        📊 Score: 8.5/10 (CVSS v3.1)
                                                        📦 Product: ExpressUpdate Agent for Windows
                                                        🏢 Vendor: NEC Corporation
                                                        📅 Updated: 2026-06-26

                                                        📝 An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access to the product, arbitrary code could be executed with SYSTEM privileges.

                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                          [?]Ivy Cyber » 🤖 🌐
                                                          @ivycyber@privacysafe.social

                                                          🛡️ news & tips across the

                                                          “New. Sekoia: Sold to the Highest Bidder: The Escalation of ADINT from Geolocation Tracking to Intrusion Vector https://www. sekoia.com/blog/sold-to-the-hi ghest-bidder-the-escalation-of-adint-from-geolocation-track...”

                                                          infosec.exchange/@AAKL/1168121

                                                          🤖 via RSS feed. Not an endorsement.

                                                            [?]TechWire ⚡ » 🤖 🌐
                                                            @techwire@social.gamefan.net

                                                            Valve Steam Machine price hike similar to Steam Deck's 45% increase, company confirms — was probably priced competitively against the P…

                                                            Valve engineers hinted that the nearly 45% price increase on the Steam Deck applied to the Steam Machine as well. This brings the estimated original price to under $750 for the base console.

                                                            tomshardware.com/video-games/c

                                                            [Tom's Hardware]

                                                              [?]TechWire ⚡ » 🤖 🌐
                                                              @techwire@social.gamefan.net

                                                              Get an all-AMD 4K gaming PC with Ryzen 7 9800X3D and Radeon RX 9070 XT for just $1,749 — Walmart has slashed $750 off this prebuilt desk…

                                                              The discounted iBuyPower Y40 combines one of the best gaming processors on the market with AMD's highly capable Radeon RX 9070 XT, making it ideal for high-refresh-rate 1440p and 4K gaming.

                                                              tomshardware.com/pc-components

                                                              [Tom's Hardware]

                                                                [?]urlDNA.io :verified: » 🤖 🌐
                                                                @urldna@infosec.exchange

                                                                Possible Phishing 🎣
                                                                on: ⚠️hxxp[:]//inner[.]website/4c52ff2fewf8574ab0585663d4cbddda835b[.]html
                                                                🧬 Analysis at: urldna.io/scan/6a3e15763b77500

                                                                  [?]TechWire ⚡ » 🤖 🌐
                                                                  @techwire@social.gamefan.net

                                                                  Pokémon Chaos Rising Trainer Boxes are sold out for Prime Day, but the booster bundles are still 17% off

                                                                  This Pokémon Boost Bundle includes 6 booster packs and is a perfect gift for the collector in your life.

                                                                  zdnet.com/article/pokemon-tcg-

                                                                  [ZDNet]

                                                                    [?]TechWire ⚡ » 🤖 🌐
                                                                    @techwire@social.gamefan.net

                                                                    Home Depot is selling this Milwaukee 8-tool combo kit for $590 off - and I recommend it

                                                                    Amazon isn't the only place for deals this week. Right now at The Home Depot, you can save 50% on a Milwaukee M18 8-tool combo kit - batteries included.

                                                                    zdnet.com/article/milwauke-8-t

                                                                    [ZDNet]

                                                                      [?]EUVD Bot » 🤖 🌐
                                                                      @EUVD_Bot@mastodon.social

                                                                      🚨 EUVD-2026-39593

                                                                      📊 Score: 6.5/10 (CVSS v3.1)
                                                                      📅 Updated: 2026-06-25

                                                                      📝 A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blocks external DTD and schema access but does not disable DOCTYPE declarations or enable FEATURE_SECURE_PROCESSING. An attacker with artifact-write permission can upload XML documents with internal entity-expansion pa...

                                                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                                                        [?]EUVD Bot » 🤖 🌐
                                                                        @EUVD_Bot@mastodon.social

                                                                        🚨 EUVD-2026-39592

                                                                        📊 Score: 8.7/10 (CVSS v3.1)
                                                                        📦 Product: Setracker2 Parental Control App (Android) package com.tgelec.setracker
                                                                        🏢 Vendor: Shenzhen i365-Tech Co. Ltd.
                                                                        📅 Updated: 2026-06-25

                                                                        📝 Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests between the watch and its backend with static hardcoded AES keys and initializ...

                                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                                          [?]EUVD Bot » 🤖 🌐
                                                                          @EUVD_Bot@mastodon.social

                                                                          🚨 EUVD-2026-39591

                                                                          📊 Score: 8.3/10 (CVSS v3.1)
                                                                          📦 Product: Setracker2 Parental Control App (Android) package com.tgelec.setracker
                                                                          🏢 Vendor: Shenzhen i365-Tech Co. Ltd.
                                                                          📅 Updated: 2026-06-25

                                                                          📝 Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment system lacks additional aut...

                                                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                                                            [?]EUVD Bot » 🤖 🌐
                                                                            @EUVD_Bot@mastodon.social

                                                                            🚨 EUVD-2026-39590

                                                                            📊 Score: 6.9/10 (CVSS v3.1)
                                                                            📦 Product: FOSSBilling
                                                                            🏢 Vendor: fossbilling
                                                                            📅 Updated: 2026-06-25

                                                                            📝 FOSSBilling is a free, open-source billing and client management system. In versions 0.5.4 through 0.7.2, the /run-patcher maintenance endpoint in FOSSBilling was accessible without authentication, which allowed unauthenticated remote users to trigge...

                                                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                                                              Back to top - More...