voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
8 Internet experiments and living labs #negativepid #digitalInvestigations #OSINT #cybersecurity #AI #tech #onlineInvestigations #robotics #cyberpsychology #cybercrime https://negativepid.blog/8-internet-experiments-and-living-labs/?utm_source=mastodon&utm_medium=social&utm_campaign=fedica-Negative-PID-Blog
🎣 Phishing Spotlight
Active phishing domain detected in the wild:
netflix-clone-shivang02[.]vercel[.]app
🔒 SSL exp. 2026-07-27
🌐 Stack: Vercel
🔗 https://beesint.com/pulse/38321c7a-0cdd-4d4c-8dd4-d753d86cf03a
🚨 EUVD-2026-39640
📊 Score: n/a
📦 Product: Bytes::Random::Secure
🏢 Vendor: DAVIDO
📅 Updated: 2026-06-26
📝 Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes.
When an object is initialised before forking, or when the functional interface is used, then the internal state for the PRNG is shared across processes and iden...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-39640
🚨 EUVD-2026-39639
📊 Score: 6.5/10 (CVSS v3.1)
📦 Product: User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder
🏢 Vendor: WPEverest
📅 Updated: 2026-06-26
📝 The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Cus...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-39639
Possible Phishing 🎣
on: ⚠️hxxps[:]//dammrow[.]github[.]io/hxxps-Dammrow[.]github[.]io-Netflix/
🧬 Analysis at: https://urldna.io/scan/6a3e23763b77500002b880c6
#cybersecurity #phishing #infosec #urldna #scam #infosec
💾 🟠 CFGI (cfgi.com)
✓ Verified
📊 ~248K records compromised
📂 Email addresses, Employers, Job titles, Names +2 more
📅 2026-03-06 · disclosed 104d after incident
🌐 cloudflare, WP, WPML
⚠️ No SPF/DMARC configured
🔗 https://beesint.com/pulse/bc7048b2-5b8a-4948-b591-c49c937c26ae
NAIC Confirms Data Breach Following Oracle PeopleSoft Zero-Day Exploit
The National Association of Insurance Commissioners (NAIC) suffered a data breach after attackers exploited a zero-day vulnerability in Oracle PeopleSoft to gain unauthorized access to financial reporting data. The organization is working with the FBI and external experts to analyze leaked data and restore full functionality to its payment systems.
****
#cybersecurity #infosec #incident #databreach
https://beyondmachines.net/event_details/naic-confirms-data-breach-following-oracle-peoplesoft-zero-day-exploit-s-x-0-b-r/gD2P6Ple2L
🛡️ #Cybersecurity news & tips across the #fediverse
“North Korea neighborhood watch leader shortage https://www. byteseu.com/2139949/ # Conflicts # ideology # Mobilization # NorthKorea # Pyongyang # surveillance # women # workers”
https://pubeurope.com/@byteseu/116812639348765877
🤖 via RSS feed. Not an endorsement.
Microsoft Secure Boot Certificates Expire — Over a Billion PCs and Linux Systems at Risk
#CyberSecurity
https://securebulletin.com/microsoft-secure-boot-certificates-expire-over-a-billion-pcs-and-linux-systems-at-risk/
Emlog: 65 CVEs, avg CVSS 5.99. 90% unpatched. Trust Score: C. Top flaws: XSS (CWE-79) & file upload (CWE-434). Lightweight ≠ secure. Patch now. #Emlog #infosec #cybersecurity
Polled readers love the Fitbit Air, but there’s still room for a Google smart ring
Screenless fitness trackers are here, but the smart ring hype is still alive.
https://www.androidauthority.com/fitbit-air-google-smart-ring-poll-results-3681747/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
AI meet robotics: putting a brain in a machine #negativepid #digitalInvestigations #OSINT #cybersecurity #AI #tech #onlineInvestigations #robotics #cyberpsychology #cybercrime https://negativepid.blog/ai-meet-robotics-putting-a-brain-in-a-machine/?utm_source=mastodon&utm_medium=social&utm_campaign=fedica-Negative-PID-Blog
Forget Gemini and ChatGPT — here are 5 unique AI tools I actually use
Sometimes you want a tool that's designed with a speciality in mind. Here are some of my favorites.
https://www.androidauthority.com/unique-ai-tools-i-use-not-gemini-or-chatgpt-3676432/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
#chrome extension Instagram Enhancement Sui seems malicious. Its #cybersecurity badness score is 85/100!
```json
{"id": "fpdbhcocghgfobllfholkeeilepcnbmp", "score": 85, "platform": "chrome", "name": "Instagram Enhancement Sui"}
```
#chrome extension Bonusbank Horsepower seems malicious. Its #cybersecurity badness score is 92/100!
```json
{"id": "oilfpkgoibdejfdpedhejpgkojdbbakn", "score": 92, "platform": "chrome", "name": "Bonusbank Horsepower"}
```
#chrome extension Chatgpt For Google seems malicious. Its #cybersecurity badness score is 91/100!
```json
{"id": "pjhdflpjemjalkidecigcjcamkbllhoj", "score": 91, "platform": "chrome", "name": "Chatgpt For Google"}
```
#chrome extension Safe Wallet Extension seems malicious. Its #cybersecurity badness score is 85/100!
```json
{"id": "ddblhcgjpnmjlbkpndackhohbdbknobi", "score": 85, "platform": "chrome", "name": "Safe Wallet Extension"}
```
Possible Phishing 🎣
on: ⚠️hxxps[:]//amu-univ00[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a3dd6f53b77500008e7fa64
#cybersecurity #phishing #infosec #urldna #scam #infosec
Cybersecurity Compliance and Regulations: What They Require and How to Meet Them - https://www.redpacketsecurity.com/cybersecurity-compliance-and-regulations-what-they-require-and-how-to-meet-them/
#Cybersecurity_compliance_and_regulations #CyberSecurity #OSINT #Cyber
What happened after 2k people tried to hack my AI assistant
https://www.fernandoi.cl/posts/hackmyclaw/
#HackerNews #hacking #AI #assistant #cybersecurity #tech #stories #AI #research #community #insights
🚀🕵️♂️ When 2,000 wannabe hackers stormed the gates of an AI assistant, they ended up with... nothing. 💥 Witness the riveting tale of an AI that valiantly defended its secrets, while a crowd of bored techies scratched their heads. 🤖🔐
https://www.fernandoi.cl/posts/hackmyclaw/ #AIsecurity #wannabehackers #technews #cybersecurity #innovation #HackerNews #ngated
Nothing Phone 4b just lost a few more secrets ahead of its July 7 debut
Nothing's next mid-range phone is no longer much of a mystery.
https://www.androidauthority.com/nothing-phone-4b-specs-leak-3681699/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
🚨 Three Gitea/Gogs vulnerabilities just dropped — and one is a CVSS 9.8 authentication bypass.
If you self-host Gitea or Gogs, this is not a “patch later” situation:
⚠️ CVE-2026-20896 — Gitea Docker auth bypass
Anyone can impersonate any user with one HTTP header: `X-WEBAUTH-USER: admin`
⚠️ CVE-2026-52807 — Stored DOM XSS
A malicious milestone name can survive escaping and execute through Semantic UI.
⚠️ CVE-2026-22874 — Webhook SSRF
Gitea webhooks can become a path to AWS IMDS, cloud credentials, S3, Secrets Manager, ECR, and full cloud privilege abuse.
Self-hosted Git platforms hold source code, CI/CD secrets, deploy keys, webhooks, tokens, and internal infrastructure access.
Your code. Your secrets. Their access.
Upgrade now:
Gitea 1.26.3+
Gogs 0.14.3+
Full technical breakdown 👇
https://thecybersecguru.com/news/cve-2026-20896-gitea-authentication-bypass-dom-xss-ssrf/
#Gitea #Gogs #CyberSecurity #InfoSec #AppSec #DevSecOps #CVE #SSRF #XSS #Docker #CloudSecurity #AWS #IAM #AuthenticationBypass #Vulnerability #SelfHosted #Security
Possible Phishing 🎣
on: ⚠️hxxps[:]//rqebah[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a3dc1243b77500004cb9c13
#cybersecurity #phishing #infosec #urldna #scam #infosec
The $25 Fire TV Stick is my favorite Prime Day purchase yet
Amazon Prime Day has many good deals, but the 50% off Fire TV Stick 4K Plus is one of the best.
https://www.zdnet.com/article/the-25-fire-tv-stick-is-my-favorite-prime-day-purchase-yet/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
China black market Nvidia prices rocket in wake of smuggling crackdown and customs freeze — five-year-old A100 servers triple in price, now fetching up to $82,000
Chinese companies are paying as much as $82,000 for servers built around Nvidia's five-year-old A100 accelerator
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
Possible Phishing 🎣
on: ⚠️hxxps[:]//ruraltebwebmailinc[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a3e075a3b7750000583faf2
#cybersecurity #phishing #infosec #urldna #scam #infosec
Here are the best OLED gaming monitor deals you can snag for Amazon Prime Day — beautiful monitors up to 47% off
We've rounded up the best deals on OLED gaming monitors for you this Prime Day. From massive DQHD panels to dual-mode offerings, we have you covered.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
Save up to 53% on Lenovo’s Black Friday in June sale — Sitewide discounts on ThinkPads, Legions, and more
Black Friday comes early, as Lenovo is running a huge sale on a wide range of products at its online store.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
💭 Méditation du Firewall
𝘓𝘦𝘴 𝘱𝘶𝘤𝘦𝘴 𝘳é𝘵𝘳é𝘤𝘪𝘴𝘴𝘦𝘯𝘵, 𝘭𝘦𝘴 𝘴𝘶𝘳𝘧𝘢𝘤𝘦𝘴 𝘥'𝘢𝘵𝘵𝘢𝘲𝘶𝘦 𝘨𝘳𝘢𝘯𝘥𝘪𝘴𝘴𝘦𝘯𝘵. 𝘓𝘢 𝘭𝘰𝘪 𝘥𝘦 𝘔𝘰𝘰𝘳𝘦 𝘦𝘵 𝘤𝘦𝘭𝘭𝘦 𝘥𝘦 𝘔𝘶𝘳𝘱𝘩𝘺 𝘢𝘷𝘢𝘯𝘤𝘦𝘯𝘵 𝘮𝘢𝘪𝘯 𝘥𝘢𝘯𝘴 𝘭𝘢 𝘮𝘢𝘪𝘯.
Possible Phishing 🎣
on: ⚠️hxxps[:]//originsteam[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a3ddd3a3b77500002b87ab2
#cybersecurity #phishing #infosec #urldna #scam #infosec
🚨 EUVD-2026-39623
📊 Score: 8.5/10 (CVSS v3.1)
📦 Product: ExpressUpdate Agent for Windows
🏢 Vendor: NEC Corporation
📅 Updated: 2026-06-26
📝 An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access to the product, arbitrary code could be executed with SYSTEM privileges.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-39623
🛡️ #Cybersecurity news & tips across the #fediverse
“New. Sekoia: Sold to the Highest Bidder: The Escalation of ADINT from Geolocation Tracking to Intrusion Vector https://www. sekoia.com/blog/sold-to-the-hi ghest-bidder-the-escalation-of-adint-from-geolocation-track...”
https://infosec.exchange/@AAKL/116812106234030297
🤖 via RSS feed. Not an endorsement.
Valve Steam Machine price hike similar to Steam Deck's 45% increase, company confirms — was probably priced competitively against the P…
Valve engineers hinted that the nearly 45% price increase on the Steam Deck applied to the Steam Machine as well. This brings the estimated original price to under $750 for the base console.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
Get an all-AMD 4K gaming PC with Ryzen 7 9800X3D and Radeon RX 9070 XT for just $1,749 — Walmart has slashed $750 off this prebuilt desk…
The discounted iBuyPower Y40 combines one of the best gaming processors on the market with AMD's highly capable Radeon RX 9070 XT, making it ideal for high-refresh-rate 1440p and 4K gaming.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
Possible Phishing 🎣
on: ⚠️hxxp[:]//inner[.]website/4c52ff2fewf8574ab0585663d4cbddda835b[.]html
🧬 Analysis at: https://urldna.io/scan/6a3e15763b77500008e7fae3
#cybersecurity #phishing #infosec #urldna #scam #infosec
Pokémon Chaos Rising Trainer Boxes are sold out for Prime Day, but the booster bundles are still 17% off
This Pokémon Boost Bundle includes 6 booster packs and is a perfect gift for the collector in your life.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
Home Depot is selling this Milwaukee 8-tool combo kit for $590 off - and I recommend it
Amazon isn't the only place for deals this week. Right now at The Home Depot, you can save 50% on a Milwaukee M18 8-tool combo kit - batteries included.
https://www.zdnet.com/article/milwauke-8-tool-combo-kit-deal-home-depot-amazon-prime-day-2026/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
🚨 EUVD-2026-39593
📊 Score: 6.5/10 (CVSS v3.1)
📅 Updated: 2026-06-25
📝 A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blocks external DTD and schema access but does not disable DOCTYPE declarations or enable FEATURE_SECURE_PROCESSING. An attacker with artifact-write permission can upload XML documents with internal entity-expansion pa...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-39593
🚨 EUVD-2026-39592
📊 Score: 8.7/10 (CVSS v3.1)
📦 Product: Setracker2 Parental Control App (Android) package com.tgelec.setracker
🏢 Vendor: Shenzhen i365-Tech Co. Ltd.
📅 Updated: 2026-06-25
📝 Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests between the watch and its backend with static hardcoded AES keys and initializ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-39592
🚨 EUVD-2026-39591
📊 Score: 8.3/10 (CVSS v3.1)
📦 Product: Setracker2 Parental Control App (Android) package com.tgelec.setracker
🏢 Vendor: Shenzhen i365-Tech Co. Ltd.
📅 Updated: 2026-06-25
📝 Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment system lacks additional aut...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-39591
🚨 EUVD-2026-39590
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: FOSSBilling
🏢 Vendor: fossbilling
📅 Updated: 2026-06-25
📝 FOSSBilling is a free, open-source billing and client management system. In versions 0.5.4 through 0.7.2, the /run-patcher maintenance endpoint in FOSSBilling was accessible without authentication, which allowed unauthenticated remote users to trigge...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-39590