voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
🚨 EUVD-2026-39482
📊 Score: 6.0/10 (CVSS v3.1)
📦 Product: wolfSSL
🏢 Vendor: wolfSSL
📅 Updated: 2026-06-25
📝 Bleichenbacher padding oracle in PKCS#7 KTRI decryption. When decrypting PKCS#7 EnvelopedData using RSA PKCS#1 v1.5 key transport, wolfSSL returned distinguishable error codes depending on whether RSA padding validation failed versus whether the decrypted co...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-39482
🚨 EUVD-2026-39481
📊 Score: 7.5/10 (CVSS v3.1)
📦 Product: pnpm, pnpm
🏢 Vendor: pnpm
📅 Updated: 2026-06-25
📝 pnpm is a package manager. Prior to 10.34.2 and 11.5.3, the generic peer-suffix normalizer also stripped parenthesized text from git, URL, tarball, file, and other opaque locators. Approval for one source string could therefore authorize a different attacker...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-39481
🚨 EUVD-2026-39480
📊 Score: 6.3/10 (CVSS v3.1)
📦 Product: wolfSSL
🏢 Vendor: wolfSSL
📅 Updated: 2026-06-25
📝 Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically be triggered by attacker-supplied data delivered via S/MIME or CMS.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-39480
Xbox prices spike another $100 or more
Microsoft is increasing the prices of Xbox consoles again. Starting August 1st, 512GB models will be $100 more expensive, while 1TB models will be $150 more expensive. This means that the Xbox Series S will start at $49…
https://www.theverge.com/games/957042/xbox-price-increase-memory-shortage
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Ransomware: Europe Overtakes US as Top Target With 55% Surge in Attacks https://deafnews.it/en/article/ransomware-europe-overtakes-us-as-top-target-with-55-surge-in-attacks #Cybersecurity
wolfSSL: 54 CVEs, 68% unpatched. 15 critical/high flaws, max CVSS 9.8. Trust Score: C. Top weakness: CWE-295 (certificate validation). IoT security at risk. #wolfSSL #cybersecurity #infosec
Prime pick: The Pixel Buds Pro 2 drop to their lowest price in a year
Prime Day takes excellent Google earbuds below their previous 2026 low at just $161.
https://www.androidauthority.com/pixel-buds-pro-2-prime-deal-3681614/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Possible Phishing 🎣
on: ⚠️hxxps[:]//85875943[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a3cc3fb3b775000050c9747
#cybersecurity #phishing #infosec #urldna #scam #infosec
Here’s a bunch of Prime Day deals on keyboards, mice, and other peripherals we like
You can get a great, color-accurate 5K monitor for half the price of an Apple Studio Display. | Photo by John Higgins / The Verge RAMageddon has come for computers. The price of memory chips, hard drives, and solid stat…
https://www.theverge.com/gadgets/956938/prime-day-deals-keyboards-mice-monitors-peripherals
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Here’s how bad Microsoft’s latest XBOX price hike is going to hurt
Microsoft confirms another price hike is coming.
https://www.androidauthority.com/microsoft-xbox-price-increase-in-august-3681588/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Debunking common quantum computing myths #negativepid #digitalInvestigations #OSINT #cybersecurity #AI #tech #onlineInvestigations #robotics #cyberpsychology #cybercrime https://negativepid.blog/debunking-common-quantum-computing-myths/?utm_source=mastodon&utm_medium=social&utm_campaign=fedica-Negative-PID-Blog
Samsung’s budget Galaxy A27 is here, and you’ll notice the biggest change instantly
Samsung finally ditches age-old teardrop notch from its 120Hz AMOLED.
https://www.androidauthority.com/samsung-galaxy-a27-launch-3681462/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
EverQuest Legends is a powerful nostalgia machine
Lady Vox, the mighty dragon. (No affiliation with Vox Media.) I wasn't surprised when I got the call that my dad was dying, even though we'd been estranged for many years. He'd suffered addiction for decades and eventua…
https://www.theverge.com/games/954841/everquest-legends-nostalgia
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
✨ Kit AiTM contro AWS: Datadog svela una campagna di phishing che bypassa l’MFA in tempo reale
#CyberSecurity
https://insicurezzadigitale.com/kit-aitm-contro-aws-datadog-svela-una-campagna-di-phishing-che-bypassa-lmfa-in-tempo-reale/
Possible Phishing 🎣
on: ⚠️hxxps[:]//pub-2ba2f00d7b84414c955f7291fd3bcc1c[.]r2[.]dev/index[.]html
🧬 Analysis at: https://urldna.io/scan/6a3d42823b77500003c359da
#cybersecurity #phishing #infosec #urldna #scam #infosec
Operation Endgame disrupts Amadey and Stealc
ESET Research contributed to a global disruption operation targeting the Amadey botnet and Stealc infostealer, both malware-as-a-service offerings. The operation, coordinated by Microsoft Digital Crimes Unit, BitSight, Lumen, and MBSD, impacted approximately 50 domains and nearly 200 active IP-based command and control servers. ESET provided technical analyses, statistical information, C&C server lists, encryption keys, campaign identifiers, and affiliate-level insights gathered from three years of tracking. Both malware families operate through affiliate networks where operators deploy their own infrastructure, making disruption efforts particularly challenging. Amadey primarily functions as a modular loader distributing additional payloads, while Stealc focuses on credential theft from browsers, crypto wallets, and applications. The largest Amadey botnet cluster accounted for 34% of all samples and distributed an average of 14 payloads per victim, operating a pay-per-install model that monetized compromi...
Pulse ID: 6a3c278cadbc5a0ba0a18ce3
Pulse Link: https://otx.alienvault.com/pulse/6a3c278cadbc5a0ba0a18ce3
Pulse Author: AlienVault
Created: 2026-06-24 18:53:00
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Amadey #Bitsight #Browser #CandC #CyberSecurity #ESET #Encryption #InfoSec #InfoStealer #Malware #MalwareAsAService #Microsoft #OTX #OpenThreatExchange #RAT #Stealc #bot #botnet #AlienVault
Behind the console: An AiTM phishing kit harvesting AWS console credentials and beyond
Between June 16 and 19, 2026, a sophisticated adversary-in-the-middle phishing campaign targeted AWS console users through three domains registered within 48 hours and hosted on Cloudflare. The campaign impersonated AWS login pages and captured credentials along with real-time multi-factor authentication codes through email, SMS, and authenticator apps. Phishing emails were delivered through legitimate platforms like SendGrid and Nimbu to bypass spam filters. The kit employed JavaScript-based credential harvesting with victim validation through encrypted URL parameters, preventing sandbox analysis. Targets were primarily US-based software engineers and engineering leadership, suggesting a curated target list rather than mass phishing. The same kit was linked to concurrent SendGrid impersonation campaigns and previous cryptocurrency wallet targeting since July 2025. The small sample of fewer than 50 targeted email addresses indicates highly selective targeting of technical personnel with AWS access.
Pulse ID: 6a3d48ab212d2dc37bad0d1b
Pulse Link: https://otx.alienvault.com/pulse/6a3d48ab212d2dc37bad0d1b
Pulse Author: AlienVault
Created: 2026-06-25 15:26:35
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #AdversaryInTheMiddle #AitM #Cloud #CredentialHarvesting #CyberSecurity #Email #InfoSec #Java #JavaScript #Nim #OTX #OpenThreatExchange #Phishing #RAT #SMS #Spam #bot #cryptocurrency #AlienVault
This dumb password rule is from Hetzner.
- 8 or more characters
- At least one uppercase and one lowercase letter
- At least one number or special character
Okay, fair enough, but after putting in a password with some special characters this message appears:
- Invalid characters, allowed are: A-Z a-z 0-9 ä ö ü ß Ä Ö Ü ^ ! $ % / ( ) = ?...
https://dumbpasswordrules.com/sites/hetzner/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager
In early 2026, a threat actor targeted SD-WAN infrastructure at a service provider, exploiting a zero-day vulnerability in Cisco Catalyst SD-WAN to escalate privileges. The attacker initially gained access through unauthorized peering connections and manipulated default account passwords. They then exploited CVE-2026-20245, a privilege escalation flaw in the file upload feature, by uploading a malicious CSV file to achieve root-level access. The vulnerability allowed the creation of a privileged user account through manipulation of system password files. Throughout the intrusion, the threat actor employed extensive anti-forensic techniques, systematically deleting malicious files, restoring modified system configurations, and executing validation scripts to ensure removal of indicators. This campaign demonstrates the living off the edge paradigm, where adversaries compromise network appliances to bypass traditional security perimeters and maintain persistent access.
Pulse ID: 6a3d476551c12310394b4adc
Pulse Link: https://otx.alienvault.com/pulse/6a3d476551c12310394b4adc
Pulse Author: AlienVault
Created: 2026-06-25 15:21:09
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cisco #CyberSecurity #Edge #InfoSec #OTX #OpenThreatExchange #Password #Passwords #RAT #Vulnerability #Word #ZeroDay #bot #AlienVault
ClickFix campaign delivers macOS infostealer via DMG
A new macOS ClickFix campaign employs fake CAPTCHA pages to deceive users into executing malicious Terminal commands. The attack chain downloads and invisibly mounts a DMG file containing a self-signed information-stealer application bundle. This payload, assessed as belonging to the AMOS (Atomic macOS Stealer) lineage—specifically the Odyssey variant—prompts users for passwords through fake System Preferences dialogs. The stealer harvests extensive data including browser credentials, cryptocurrency wallet information from 13 standalone applications and 201 browser extensions, messaging app data, Apple Notes, Safari cookies, and macOS keychain entries. Exfiltrated data is compressed and sent to two command-and-control servers. The malware establishes persistence via LaunchAgent and trojanizes legitimate cryptocurrency applications including Ledger Live and Trezor Suite, replacing them with compromised versions downloaded from attacker infrastructure.
Pulse ID: 6a3d42cc11f8fec9a3aab237
Pulse Link: https://otx.alienvault.com/pulse/6a3d42cc11f8fec9a3aab237
Pulse Author: AlienVault
Created: 2026-06-25 15:01:32
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AMOS #Atomic #Browser #CAPTCHA #Cookies #CyberSecurity #ELF #Edge #InfoSec #InfoStealer #Mac #MacOS #Malware #OTX #OpenThreatExchange #Password #Passwords #RAT #Safari #Trojan #Word #bot #cryptocurrency #AlienVault
Apple just raised Mac and iPad prices, and that’s bad news for Android, too
Your next Android device could get pricier, thanks to Apple.
https://www.androidauthority.com/apple-products-price-hike-3681451/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Bungie hit with ‘significant’ layoffs after ending Destiny 2
Now that Bungie has moved on from Destiny 2, the game studio is being hit with its latest round of layoffs. In a statement posted on X, the studio said that "we are announcing a reduction in force as we reorganize Bungi…
https://www.theverge.com/entertainment/956880/bungie-layoffs-destiny-2
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
📊 EUVD Daily CVSS Summary
🟡 Average Score: 6.94/10 (Medium)
📈 Vulnerabilities: 246
⬇️ Min: 1.1 | ⬆️ Max: 10.0
📅 Date: 2026-06-24
💾 🟠 CFGI (cfgi.com)
✓ Verified
📊 ~248K records compromised
📂 Email addresses, Employers, Job titles, Names +2 more
📅 2026-03-06 · disclosed 104d after incident
🌐 cloudflare, WP, WPML
⚠️ No SPF/DMARC configured
🔗 https://beesint.com/pulse/4c8c4a57-9b61-45a0-b25a-36b32d97ff9c
The FCC wants to make it harder to buy burner phones, but critics call it a privacy threat
That anonymous phone plan may not stay anonymous for long.
https://www.androidauthority.com/fcc-killing-burner-phones-feedback-3681302/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Gaslight: macOS Malware Tricks AI Analyzers with Prompt Injection https://deafnews.it/en/article/gaslight-macos-malware-tricks-ai-analyzers-with-prompt-injection #Cybersecurity
I wanted Google’s secret AI dictation app to replace Wispr Flow, but it couldn’t
Free, offline, and frustratingly unreliable at times.
https://www.androidauthority.com/google-ai-edge-eloquent-vs-wispr-flow-3678620/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Possible Phishing 🎣
on: ⚠️hxxps[:]//decentralbridge[.]pages[.]dev
🧬 Analysis at: https://urldna.io/scan/6a3c93623b775000050c9295
#cybersecurity #phishing #infosec #urldna #scam #infosec
Cybersecurity alert: New campaign uses malicious Google Ads to deliver CastleStealer via OXLOADER. Likely Russian-speaking, financially motivated threat actors. #Cybersecurity https://thehackernews.com/2026/06/new-oxloader-loader-uses-malicious.html
74000 zapór sieciowych Fortinet zaatakowanych – efekt kampanii FortiBleed. Jest to nowa, zakrojona na szeroką skalę zmasowana kampania cybernetycznego szpiegostwa, która po cichu naruszyła bezpieczeństwo... https://linuxiarze.pl/74000-zapor-sieciowych-fortinet-zaatakowanych-efekt-kampanii-fortibleed/ #cybersecurity #cyberattack
74000 zapór sieciowych Fortinet zaatakowanych – efekt kampanii FortiBleed. Jest to nowa, zakrojona na szeroką skalę zmasowana kampania cybernetycznego szpiegostwa, która po cichu naruszyła bezpieczeństwo... https://linuxiarze.pl/74000-zapor-sieciowych-fortinet-zaatakowanych-efekt-kampanii-fortibleed/ #cybersecurity #cyberattack