voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]EUVD Bot » 🤖 🌐
@EUVD_Bot@mastodon.social

🚨 EUVD-2026-39482

📊 Score: 6.0/10 (CVSS v3.1)
📦 Product: wolfSSL
🏢 Vendor: wolfSSL
📅 Updated: 2026-06-25

📝 Bleichenbacher padding oracle in PKCS#7 KTRI decryption. When decrypting PKCS#7 EnvelopedData using RSA PKCS#1 v1.5 key transport, wolfSSL returned distinguishable error codes depending on whether RSA padding validation failed versus whether the decrypted co...

🔗 euvd.enisa.europa.eu/vulnerabi

    [?]EUVD Bot » 🤖 🌐
    @EUVD_Bot@mastodon.social

    🚨 EUVD-2026-39481

    📊 Score: 7.5/10 (CVSS v3.1)
    📦 Product: pnpm, pnpm
    🏢 Vendor: pnpm
    📅 Updated: 2026-06-25

    📝 pnpm is a package manager. Prior to 10.34.2 and 11.5.3, the generic peer-suffix normalizer also stripped parenthesized text from git, URL, tarball, file, and other opaque locators. Approval for one source string could therefore authorize a different attacker...

    🔗 euvd.enisa.europa.eu/vulnerabi

      [?]EUVD Bot » 🤖 🌐
      @EUVD_Bot@mastodon.social

      🚨 EUVD-2026-39480

      📊 Score: 6.3/10 (CVSS v3.1)
      📦 Product: wolfSSL
      🏢 Vendor: wolfSSL
      📅 Updated: 2026-06-25

      📝 Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically be triggered by attacker-supplied data delivered via S/MIME or CMS.

      🔗 euvd.enisa.europa.eu/vulnerabi

        [?]TechWire ⚡ » 🤖 🌐
        @techwire@social.gamefan.net

        Xbox prices spike another $100 or more

        Microsoft is increasing the prices of Xbox consoles again. Starting August 1st, 512GB models will be $100 more expensive, while 1TB models will be $150 more expensive. This means that the Xbox Series S will start at $49…

        theverge.com/games/957042/xbox

        [The Verge]

          [?]deafnews » 🤖 🌐
          @deafnews@infosec.exchange

          [?]Hugo | DevOps | Cybersecurity » 🌐
          @hugovalters@mastodon.social

          wolfSSL: 54 CVEs, 68% unpatched. 15 critical/high flaws, max CVSS 9.8. Trust Score: C. Top weakness: CWE-295 (certificate validation). IoT security at risk.

          valtersit.com/vendors/wolfssl/

            [?]TechWire ⚡ » 🤖 🌐
            @techwire@social.gamefan.net

            Prime pick: The Pixel Buds Pro 2 drop to their lowest price in a year

            Prime Day takes excellent Google earbuds below their previous 2026 low at just $161.

            androidauthority.com/pixel-bud

            [Android Authority]

              [?]urlDNA.io :verified: » 🤖 🌐
              @urldna@infosec.exchange

              Possible Phishing 🎣
              on: ⚠️hxxps[:]//85875943[.]weebly[.]com
              🧬 Analysis at: urldna.io/scan/6a3cc3fb3b77500

                [?]The New Oil » 🤖 🌐
                @thenewoil@mastodon.thenewoil.org

                [?]TechWire ⚡ » 🤖 🌐
                @techwire@social.gamefan.net

                Here’s a bunch of Prime Day deals on keyboards, mice, and other peripherals we like

                You can get a great, color-accurate 5K monitor for half the price of an Apple Studio Display. | Photo by John Higgins / The Verge RAMageddon has come for computers. The price of memory chips, hard drives, and solid stat…

                theverge.com/gadgets/956938/pr

                [The Verge]

                  [?]TechWire ⚡ » 🤖 🌐
                  @techwire@social.gamefan.net

                  Here’s how bad Microsoft’s latest XBOX price hike is going to hurt

                  Microsoft confirms another price hike is coming.

                  androidauthority.com/microsoft

                  [Android Authority]

                    [?]Negative PID SL » 🌐
                    @negativepid@mastodon.social

                    [?]TechWire ⚡ » 🤖 🌐
                    @techwire@social.gamefan.net

                    Samsung’s budget Galaxy A27 is here, and you’ll notice the biggest change instantly

                    Samsung finally ditches age-old teardrop notch from its 120Hz AMOLED.

                    androidauthority.com/samsung-g

                    [Android Authority]

                      [?]TechWire ⚡ » 🤖 🌐
                      @techwire@social.gamefan.net

                      EverQuest Legends is a powerful nostalgia machine

                      Lady Vox, the mighty dragon. (No affiliation with Vox Media.) I wasn't surprised when I got the call that my dad was dying, even though we'd been estranged for many years. He'd suffered addiction for decades and eventua…

                      theverge.com/games/954841/ever

                      [The Verge]

                        [?]N_{Dario Fadda} » 🌐
                        @nuke@poliversity.it

                        ✨ Kit AiTM contro AWS: Datadog svela una campagna di phishing che bypassa l’MFA in tempo reale

                        insicurezzadigitale.com/kit-ai

                        @informatica

                          [?]urlDNA.io :verified: » 🤖 🌐
                          @urldna@infosec.exchange

                          Possible Phishing 🎣
                          on: ⚠️hxxps[:]//pub-2ba2f00d7b84414c955f7291fd3bcc1c[.]r2[.]dev/index[.]html
                          🧬 Analysis at: urldna.io/scan/6a3d42823b77500

                            [?]The New Oil » 🤖 🌐
                            @thenewoil@mastodon.thenewoil.org

                            [?]OTX Bot » 🤖 🌐
                            @techbot@social.raytec.co

                            Operation Endgame disrupts Amadey and Stealc

                            ESET Research contributed to a global disruption operation targeting the Amadey botnet and Stealc infostealer, both malware-as-a-service offerings. The operation, coordinated by Microsoft Digital Crimes Unit, BitSight, Lumen, and MBSD, impacted approximately 50 domains and nearly 200 active IP-based command and control servers. ESET provided technical analyses, statistical information, C&C server lists, encryption keys, campaign identifiers, and affiliate-level insights gathered from three years of tracking. Both malware families operate through affiliate networks where operators deploy their own infrastructure, making disruption efforts particularly challenging. Amadey primarily functions as a modular loader distributing additional payloads, while Stealc focuses on credential theft from browsers, crypto wallets, and applications. The largest Amadey botnet cluster accounted for 34% of all samples and distributed an average of 14 payloads per victim, operating a pay-per-install model that monetized compromi...

                            Pulse ID: 6a3c278cadbc5a0ba0a18ce3
                            Pulse Link: otx.alienvault.com/pulse/6a3c2
                            Pulse Author: AlienVault
                            Created: 2026-06-24 18:53:00

                            Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                              [?]OTX Bot » 🤖 🌐
                              @techbot@social.raytec.co

                              Behind the console: An AiTM phishing kit harvesting AWS console credentials and beyond

                              Between June 16 and 19, 2026, a sophisticated adversary-in-the-middle phishing campaign targeted AWS console users through three domains registered within 48 hours and hosted on Cloudflare. The campaign impersonated AWS login pages and captured credentials along with real-time multi-factor authentication codes through email, SMS, and authenticator apps. Phishing emails were delivered through legitimate platforms like SendGrid and Nimbu to bypass spam filters. The kit employed JavaScript-based credential harvesting with victim validation through encrypted URL parameters, preventing sandbox analysis. Targets were primarily US-based software engineers and engineering leadership, suggesting a curated target list rather than mass phishing. The same kit was linked to concurrent SendGrid impersonation campaigns and previous cryptocurrency wallet targeting since July 2025. The small sample of fewer than 50 targeted email addresses indicates highly selective targeting of technical personnel with AWS access.

                              Pulse ID: 6a3d48ab212d2dc37bad0d1b
                              Pulse Link: otx.alienvault.com/pulse/6a3d4
                              Pulse Author: AlienVault
                              Created: 2026-06-25 15:26:35

                              Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                [?]Dumb Password Rules » 🤖 🌐
                                @dumbpasswordrules@infosec.exchange

                                This dumb password rule is from Hetzner.

                                - 8 or more characters
                                - At least one uppercase and one lowercase letter
                                - At least one number or special character

                                Okay, fair enough, but after putting in a password with some special characters this message appears:
                                - Invalid characters, allowed are: A-Z a-z 0-9 ä ö ü ß Ä Ö Ü ^ ! $ % / ( ) = ?...

                                dumbpasswordrules.com/sites/he

                                  [?]OTX Bot » 🤖 🌐
                                  @techbot@social.raytec.co

                                  Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager

                                  In early 2026, a threat actor targeted SD-WAN infrastructure at a service provider, exploiting a zero-day vulnerability in Cisco Catalyst SD-WAN to escalate privileges. The attacker initially gained access through unauthorized peering connections and manipulated default account passwords. They then exploited CVE-2026-20245, a privilege escalation flaw in the file upload feature, by uploading a malicious CSV file to achieve root-level access. The vulnerability allowed the creation of a privileged user account through manipulation of system password files. Throughout the intrusion, the threat actor employed extensive anti-forensic techniques, systematically deleting malicious files, restoring modified system configurations, and executing validation scripts to ensure removal of indicators. This campaign demonstrates the living off the edge paradigm, where adversaries compromise network appliances to bypass traditional security perimeters and maintain persistent access.

                                  Pulse ID: 6a3d476551c12310394b4adc
                                  Pulse Link: otx.alienvault.com/pulse/6a3d4
                                  Pulse Author: AlienVault
                                  Created: 2026-06-25 15:21:09

                                  Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                    [?]OTX Bot » 🤖 🌐
                                    @techbot@social.raytec.co

                                    ClickFix campaign delivers macOS infostealer via DMG

                                    A new macOS ClickFix campaign employs fake CAPTCHA pages to deceive users into executing malicious Terminal commands. The attack chain downloads and invisibly mounts a DMG file containing a self-signed information-stealer application bundle. This payload, assessed as belonging to the AMOS (Atomic macOS Stealer) lineage—specifically the Odyssey variant—prompts users for passwords through fake System Preferences dialogs. The stealer harvests extensive data including browser credentials, cryptocurrency wallet information from 13 standalone applications and 201 browser extensions, messaging app data, Apple Notes, Safari cookies, and macOS keychain entries. Exfiltrated data is compressed and sent to two command-and-control servers. The malware establishes persistence via LaunchAgent and trojanizes legitimate cryptocurrency applications including Ledger Live and Trezor Suite, replacing them with compromised versions downloaded from attacker infrastructure.

                                    Pulse ID: 6a3d42cc11f8fec9a3aab237
                                    Pulse Link: otx.alienvault.com/pulse/6a3d4
                                    Pulse Author: AlienVault
                                    Created: 2026-06-25 15:01:32

                                    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                      [?]TechWire ⚡ » 🤖 🌐
                                      @techwire@social.gamefan.net

                                      Apple just raised Mac and iPad prices, and that’s bad news for Android, too

                                      Your next Android device could get pricier, thanks to Apple.

                                      androidauthority.com/apple-pro

                                      [Android Authority]

                                        [?]TechWire ⚡ » 🤖 🌐
                                        @techwire@social.gamefan.net

                                        Bungie hit with ‘significant’ layoffs after ending Destiny 2

                                        Now that Bungie has moved on from Destiny 2, the game studio is being hit with its latest round of layoffs. In a statement posted on X, the studio said that "we are announcing a reduction in force as we reorganize Bungi…

                                        theverge.com/entertainment/956

                                        [The Verge]

                                          [?]EUVD Bot » 🤖 🌐
                                          @EUVD_Bot@mastodon.social

                                          📊 EUVD Daily CVSS Summary

                                          🟡 Average Score: 6.94/10 (Medium)
                                          📈 Vulnerabilities: 246
                                          ⬇️ Min: 1.1 | ⬆️ Max: 10.0

                                          📅 Date: 2026-06-24

                                            [?]BeeSINT » 🌐
                                            @BeeSINT@mastodon.social

                                            💾 🟠 CFGI (cfgi.com)
                                            ✓ Verified
                                            📊 ~248K records compromised
                                            📂 Email addresses, Employers, Job titles, Names +2 more
                                            📅 2026-03-06 · disclosed 104d after incident
                                            🌐 cloudflare, WP, WPML
                                            ⚠️ No SPF/DMARC configured

                                            🔗 beesint.com/pulse/4c8c4a57-9b6

                                              [?]TechWire ⚡ » 🤖 🌐
                                              @techwire@social.gamefan.net

                                              The FCC wants to make it harder to buy burner phones, but critics call it a privacy threat

                                              That anonymous phone plan may not stay anonymous for long.

                                              androidauthority.com/fcc-killi

                                              [Android Authority]

                                                [?]deafnews » 🤖 🌐
                                                @deafnews@infosec.exchange

                                                [?]TechWire ⚡ » 🤖 🌐
                                                @techwire@social.gamefan.net

                                                I wanted Google’s secret AI dictation app to replace Wispr Flow, but it couldn’t

                                                Free, offline, and frustratingly unreliable at times.

                                                androidauthority.com/google-ai

                                                [Android Authority]

                                                  [?]urlDNA.io :verified: » 🤖 🌐
                                                  @urldna@infosec.exchange

                                                  Possible Phishing 🎣
                                                  on: ⚠️hxxps[:]//decentralbridge[.]pages[.]dev
                                                  🧬 Analysis at: urldna.io/scan/6a3c93623b77500

                                                    [?]Technoholic.me » 🌐
                                                    @technoholic@mastodon.social

                                                    Cybersecurity alert: New campaign uses malicious Google Ads to deliver CastleStealer via OXLOADER. Likely Russian-speaking, financially motivated threat actors. thehackernews.com/2026/06/new-

                                                      [?]Linuxiarze » 🌐
                                                      @Linuxiarze@mastodon.social

                                                      74000 zapór sieciowych Fortinet zaatakowanych – efekt kampanii FortiBleed. Jest to nowa, zakrojona na szeroką skalę zmasowana kampania cybernetycznego szpiegostwa, która po cichu naruszyła bezpieczeństwo... linuxiarze.pl/74000-zapor-siec

                                                        [?]Linuxiarze » 🌐
                                                        @Linuxiarze@fe.disroot.org

                                                        74000 zapór sieciowych Fortinet zaatakowanych – efekt kampanii FortiBleed. Jest to nowa, zakrojona na szeroką skalę zmasowana kampania cybernetycznego szpiegostwa, która po cichu naruszyła bezpieczeństwo... https://linuxiarze.pl/74000-zapor-sieciowych-fortinet-zaatakowanych-efekt-kampanii-fortibleed/ #cybersecurity #cyberattack

                                                          [?]pavroo » 🌐
                                                          @pavroo@universeodon.com

                                                          74000 zapór sieciowych Fortinet zaatakowanych – efekt kampanii FortiBleed. Jest to nowa, zakrojona na szeroką skalę zmasowana kampania cybernetycznego szpiegostwa, która po cichu naruszyła bezpieczeństwo... linuxiarze.pl/74000-zapor-siec

                                                            Back to top - More...