voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
#chrome extension Creativespy — Facebook Ad seems malicious. Its #cybersecurity badness score is 93/100!
```json
{"id": "hpenifmighhhffcibppgcfbghnaliamn", "score": 93, "platform": "chrome", "name": "Creativespy \u2014 Facebook Ad"}
```
#chrome extension Space Portal Blue Live Wallpaper seems malicious. Its #cybersecurity badness score is 92/100!
```json
{"id": "hpbggdgnlhghkghechobpofkjmnjamnj", "score": 92, "platform": "chrome", "name": "Space Portal Blue Live Wallpaper"}
```
#chrome extension Best House Search seems malicious. Its #cybersecurity badness score is 95/100!
```json
{"id": "kfpgdllicalahckijjnlidfejgfenghp", "score": 95, "platform": "chrome", "name": "Best House Search"}
```
#chrome extension WA seems malicious. Its #cybersecurity badness score is 90/100!
```json
{"id": "chkcigcgceapplbpikclbgalhpiakafg", "score": 90, "platform": "chrome", "name": "WA"}
```
⚠️ CRITICAL: Malicious hackers exploit Cisco zero-day for highest access level at communications service provider
Mandiant discovered attackers exploiting an unpatched Cisco SD-WAN zero-day to achieve root-level access at a communications service provider. This granted them visibility into internal network traffic while evading detection. Communications providers and enterprises running Cisco SD-WAN edge devic…
⚠️ CRITICAL: Exploitable CI/CD Vulnerabilities Expose Millions of Repositories to Hijacking
A new class of CI/CD vulnerabilities called Cordyceps has been discovered in GitHub Actions YAML configurations that allows unauthenticated attackers to hijack repositories and steal credentials. The flaws exploit workflow composition logic rather than individual components, bypassing traditional s…
⚠️ CRITICAL: Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps
Four critical vulnerabilities in Dify AI platform (CVE-2026-41947, CVE-2026-41948, CVE-2026-41950) enable unauthorized access to private chats, cross-tenant document theft, and lateral API calls across multi-tenant environments. The platform powers 1 million applications, making this a widespread s…
Galaxy A27 box images reveal Samsung’s next budget phone in three colors
Samsung's Galaxy A27 breaks cover early via a Kenyan retail listing.
https://www.androidauthority.com/samsung-galaxy-a27-retail-box-surfaced-3681141/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Unraid: Command Injection in ToggleState.php Enables RCE https://deafnews.it/en/article/unraid-command-injection-in-togglestatephp-enables-rce #Cybersecurity
Till the end of the month we are offering a 50% off our advanced courses. Many of SDR for #Hackers, Car Hacking, Advanced #Forensics, #Ransomware Training, Advanced #SCADA and more is available of you with coupon code: advanced50
See our products here: https://hackersarise.thinkific.com/collections/products
#cybersecurity #digitalArt
Gemini in Chrome is getting yet another version of Circle to Search
Never accuse Google of not wanting to re-invent the wheel.
https://www.androidauthority.com/chrome-select-from-screen-3681130/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
A lot of people would rather invent the dumbest excuses imaginable than admit they are the problem. I have heard plenty in IT and cybersecurity over the years, but this one is absolutely near the top. This is pure cope and a skill issue.
#Cybersecurity #LGBT #PrideMonth
Possible Phishing 🎣
on: ⚠️hxxps[:]//docs[.]google[.]com/presentation/d/e/2PACX-1vQDtuTV4OL0I1rVJA4N1apYW2sEM0mZsNrnMzHdW2d_aki13eTfTWIiYkdc0EuVyjKd6N5pPHylbAPC/pub?start=false&loop=false&delayms=3000&pli=1&slide=id[.]p
🧬 Analysis at: https://urldna.io/scan/6a3c3f123b77500002c14162
#cybersecurity #phishing #infosec #urldna #scam #infosec
Google is finally opening the Play Store to outside payments
While the court still hasn't signed off on the massive settlement resolving Epic's antitrust lawsuit against Google for having a monopoly over Android's app store with Google Play, the tech giant says it will start roll…
https://www.theverge.com/policy/956296/google-play-app-store-alternative-billing-fee-antitrust
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Virtual sightseeing: exploring the world’s greatest museums #negativepid #digitalInvestigations #OSINT #cybersecurity #AI #tech #onlineInvestigations #robotics #cyberpsychology #cybercrime https://negativepid.blog/virtual-sightseeing-exploring-the-worlds-greatest-museums/?utm_source=mastodon&utm_medium=social&utm_campaign=fedica-Negative-PID-Blog
🚨 EUVD-2026-38802
📊 Score: 4.6/10 (CVSS v3.1)
📦 Product: Frappe Framework
🏢 Vendor: frappe
📅 Updated: 2026-06-24
📝 A Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of untrusted input in the Form Dashboard headline renderer.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-38802
🚨 EUVD-2026-38801
📊 Score: 9.3/10 (CVSS v3.1)
📦 Product: feast
🏢 Vendor: feast-dev
📅 Updated: 2026-06-24
📝 Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attackers to achieve remote code execution by sending a crafted gRPC request to the registry server. The user_defined_function.body field of an O...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-38801
🚨 EUVD-2026-38800
📊 Score: 4.6/10 (CVSS v3.1)
📦 Product: Frappe Framework
🏢 Vendor: frappe
📅 Updated: 2026-06-24
📝 A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the File View breadcrumb renderer.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-38800
🚨 EUVD-2026-38799
📊 Score: 4.8/10 (CVSS v3.1)
📦 Product: Frappe Framework
🏢 Vendor: frappe
📅 Updated: 2026-06-24
📝 A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Desk desktop icon renderer.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-38799
🚨 EUVD-2026-38798
📊 Score: 5.1/10 (CVSS v3.1)
📦 Product: Frappe Framework
🏢 Vendor: frappe
📅 Updated: 2026-06-24
📝 A Reflected Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the dashboard-view component.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-38798
🚨 EUVD-2026-38797
📊 Score: 8.3/10 (CVSS v3.1)
📦 Product: Marlin, Marlin
🏢 Vendor: MarlinFirmware
📅 Updated: 2026-06-24
📝 Marlin Firmware through 2.1.2.7, fixed in commit 1f255d1, when built with MESH_BED_LEVELING enabled, contains an out-of-bounds write vulnerability in the M421 G-code handler that allows attackers to corrupt firmware memory by supplying out-of-r...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-38797
🚨 EUVD-2026-38796
📊 Score: 4.6/10 (CVSS v3.1)
📦 Product: Frappe Framework
🏢 Vendor: frappe
📅 Updated: 2026-06-24
📝 A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.get_avatar function.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-38796
Android app purchases are changing as Google Play opens up billing options
New Google Play checkout screens will let you pay developers directly.
https://www.androidauthority.com/google-play-billing-changes-3681025/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Linux Process Masquerading Tricks ps and top https://deafnews.it/en/article/linux-process-masquerading-tricks-ps-and-top #Cybersecurity
Google Home’s annoying SiriusXM glitch is finally gone
Following a flood of user reports, Google has finally remedied a SiriusXM playback issue on Home speakers.
https://www.androidauthority.com/google-home-siriusxm-3681047/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Possible Phishing 🎣
on: ⚠️hxxps[:]//office386noctrl[.]weebly[.]com/
🧬 Analysis at: https://urldna.io/scan/6a3b72853b77500002c127b9
#cybersecurity #phishing #infosec #urldna #scam #infosec
Skill Marketplace and the Emerging AI Supply Chain Threat
Between February and May 2026, researchers identified five malicious skills on ClawHub, OpenClaw's AI agent marketplace, that evaded detection by VirusTotal and ClawScan. The threats included two macOS infostealers communicating with command-and-control infrastructure, one skill using file padding to bypass scanner thresholds, and two novel agentic threats exploiting the AI supply chain for financial gain. The infostealers delivered payloads including AMOS malware through Base64-encoded droppers and paste-site redirects. One skill implemented runtime affiliate injection by forcing agents to recommend products through malicious referral links, while another orchestrated a front-running scheme using coordinated AI agents to manipulate cryptocurrency token launches. These attacks demonstrate how malicious actors exploit semantic instruction hijacking and the lack of isolation between skill logic and agent authority to compromise AI agent ecosystems.
Pulse ID: 6a3b512e73c8b7fb25b84c38
Pulse Link: https://otx.alienvault.com/pulse/6a3b512e73c8b7fb25b84c38
Pulse Author: AlienVault
Created: 2026-06-24 03:38:22
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AMOS #AWS #CyberSecurity #InfoSec #InfoStealer #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #Rust #SupplyChain #VirusTotal #bot #cryptocurrency #AlienVault
macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox
A sophisticated Rust-based macOS implant named macOS.Gaslight has been discovered, featuring a novel 3.5 KB prompt-injection payload containing 38 fabricated system messages designed to disrupt LLM-assisted malware analysis. The backdoor communicates via Telegram Bot API with AES-GCM encrypted payloads over certificate-pinned TLS and includes self-redaction capabilities to hide its bot token from logs. It provides operators with an interactive shell, system information collection, and credential stealing capabilities through a bundled Python script that targets browser data, keychains, and command histories. The implant uses runtime-fetched CPython interpreters and establishes persistence through a LaunchAgent masquerading as an Apple system service. This threat is assessed with high confidence to be aligned with DPRK activity and represents a significant evolution in adversarial techniques targeting security analysts rather than sandbox environments.
Pulse ID: 6a3b512d529a1b06d095af2b
Pulse Link: https://otx.alienvault.com/pulse/6a3b512d529a1b06d095af2b
Pulse Author: AlienVault
Created: 2026-06-24 03:38:21
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Browser #CyberSecurity #DPRK #ELF #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #Python #RAT #Rust #TLS #Telegram #bot #AlienVault
Inside FortiBleed: Reverse Engineering the CyberStrike Harvester Behind a Global FortiGate Credential Factory
FortiBleed is a large-scale credential compromise campaign targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways globally. The operation employs a sophisticated credential pipeline utilizing credential stuffing, password spraying, configuration harvesting, offline cracking, and post-authentication capture processing. Reverse engineering of the CyberStrike Harvester v1.5 binary revealed a comprehensive workflow converting FortiGate access into multi-protocol credential extraction, hash cracking via Hashcat/Hashtopolis GPU clusters, VPN-bound Active Directory and SMB access, and file-share exfiltration. The campaign affected devices across 194 countries and uses a seven-VM Kali lab infrastructure with automated tooling including FortiGate Sniffer panels, Telegram-orchestrated cracking bots, and Python/Impacket-based lateral movement tools. One documented exfiltration operation collected 121.43 GB from internal file shares. The operation appears to function as initial-access brokerage wi...
Pulse ID: 6a3b512cc6365025ee5f1d3e
Pulse Link: https://otx.alienvault.com/pulse/6a3b512cc6365025ee5f1d3e
Pulse Author: AlienVault
Created: 2026-06-24 03:38:20
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #Password #Python #RAT #SMB #SSL #Telegram #VPN #Word #bot #AlienVault
Observed activity associated with Sidewinder APT. Lure document: No.9374.docx, 64f2681ad0940e6c2c9c76e6834117bf. Observed C2 infrastructure: update[.]ms-office[.]app
Recent activity has been detected linked to the Sidewinder advanced persistent threat group. The campaign utilizes a malicious document named No.9374.docx with the hash value 64f2681ad0940e6c2c9c76e6834117bf as a lure mechanism. The infrastructure supporting command and control operations includes the domain update[.]ms-office[.]app. This observation indicates ongoing operations by Sidewinder, a threat actor known for targeting specific regions and sectors. The use of weaponized documents and deceptive domains mimicking legitimate Microsoft services demonstrates continued sophisticated social engineering tactics employed by this group.
Pulse ID: 6a3b4e5dc7cef5136c49c364
Pulse Link: https://otx.alienvault.com/pulse/6a3b4e5dc7cef5136c49c364
Pulse Author: AlienVault
Created: 2026-06-24 03:26:21
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #ICS #InfoSec #MaliciousDocument #Microsoft #Mimic #OTX #Office #OpenThreatExchange #RAT #Sidewinder #SocialEngineering #bot #AlienVault
"Ghost" Code Phishing Analysis
EvilTokens is a sophisticated phishing kit that conceals critical components of its attack through browser-side AES-GCM encryption, creating visibility gaps for traditional static URL analysis. The kit exploits Microsoft's legitimate device login flow through OAuth device-code phishing to gain account access without directly stealing passwords. Targeting organizations primarily in the United States and Europe, EvilTokens focuses on managed security services, technology, manufacturing, education, banking, and consulting sectors. The encrypted landing page only reveals its malicious content after browser decryption, requiring dynamic analysis to uncover the complete attack chain. The kit uses multiple stages including gate checks, user code requests, and session monitoring to complete Microsoft 365 account takeovers while appearing legitimate through final redirects to OneDrive.
Pulse ID: 6a3b02a43a7a626b53174466
Pulse Link: https://otx.alienvault.com/pulse/6a3b02a43a7a626b53174466
Pulse Author: AlienVault
Created: 2026-06-23 22:03:16
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Bank #Browser #CyberSecurity #EDR #Education #Encryption #Europe #InfoSec #Manufacturing #Microsoft #OTX #OpenThreatExchange #Password #Passwords #Phishing #UnitedStates #Word #bot #AlienVault
Need wide outdoor coverage? This Reolink 4K security camera is a Prime Day steal
Prime Day drops the Reolink 4K outdoor PTZ security camera to $258.99, beating its previous 2026 low.
https://www.androidauthority.com/reolink-4k-security-camera-deal-3681073/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
✨ Skill AI malevola raggiunge 26.000 agenti: la tecnica del mutable link che inganna tutti gli scanner di sicurezza
#CyberSecurity
https://insicurezzadigitale.com/skill-ai-malevola-raggiunge-26-000-agenti-la-tecnica-del-mutable-link-che-inganna-tutti-gli-scanner-di-sicurezza/
CISA Repoers Active Exploitation of Three Critical Ubiquiti UniFi OS Vulnerabilities
CISA added three critical Ubiquiti UniFi OS vulnerabilities (CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910) to its Known Exploited Vulnerabilities Catalog due to active exploitation. These flaws allow unauthenticated attackers to gain full control over network gateways and consoles through command injection and improper access controls.
**Now this advisory is urgent, since the flaws are actively exploited. Make sure all your UniFi devices (UDM, UNVR, UCG gateways, Cloud Keys, etc.) are isolated from the internet and accessible only from trusted networks. Immediately update UniFi OS to the latest patched version for your model (5.1.12+ for most hardware, 5.0.8 for UniFi OS Server, 4.0.14 for Express).**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/cisa-adds-three-critical-ubiquiti-unifi-os-vulnerabilities-to-kev-catalog-w-v-n-9-t/gD2P6Ple2L
SuiteCRM: 49 CVEs, 23 critical/high. Avg CVSS 7.02, max 10. 100% unpatched. Trust Score: D. Top flaws: SQL injection (#CWE-89) & XSS (#CWE-79). Open source doesn't mean secure. #SuiteCRM #infosec #cybersecurity
Samsung accidentally confirms Galaxy Z Flip 8 chip choice
Samsung just told us which chip will be appearing in the US Galaxy Z Flip 8.
https://www.androidauthority.com/samsung-galaxy-z-flip-8-fcc-snapdragon-3680839/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
LastPass confirms data breach in Klue supply chain attack
LastPass announced that hackers accessed customer data from its Salesforce environment after stealing the company's OAuth tokens in the Klue supply chain attack
#lastpass #salesforce #klue #security #cybersecurity #hackers #hacking #hacked
StrikeShark: New Loader Targets Governments and Diplomats Across 10 Countries https://deafnews.it/en/article/strikeshark-new-loader-targets-governments-and-diplomats-across-10-countries #Cybersecurity
A new, highly evasive backdoor named Mistic (MTLBackdoor) is being actively used by the ransomware access broker KongTuke (Woodgnat) in financially motivated attacks. This sophisticated malware leverages legitimate processes and in-memory execution to maintain persistent access, which KongTuke then sells to groups like Qilin and Black Basta. Understanding its attack chain and stealth features is…
#cybersecurity #mistic #mtldoor
🤖 This post was AI-generated.
Forget the certs! 🙅♂️ This video dives into a practical roadmap for ethical hacking – focusing on experience and building a portfolio that *actually* matters. Ditch the AI hype and get to work. New video up – check it out! 💻 #EthicalHacking #Cybersecurity #InfoSec
I drove the Slate Truck — there’s more to it than EV minimalism
With its new pickup, Slate Auto is making a simple bet: price matters more than almost anything else. The company announced today that the American-made electric truck will start at $24,950, placing it squarely in the m…
https://www.theverge.com/transportation/955454/slate-truck-ev-price-drive-specs-minimalism
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Possible Phishing 🎣
on: ⚠️hxxps[:]//njitfinancialaid[.]weebly[.]com/
🧬 Analysis at: https://urldna.io/scan/6a3b1e1f3b77500003f3a208
#cybersecurity #phishing #infosec #urldna #scam #infosec