voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
ReliaQuest is bringing OpenAI’s cybersecurity models deeper into its GreyMatter platform.
The partnership could help enterprise security teams investigate threats and patch vulnerabilities faster, but ReliaQuest has not yet revealed specific features, launch timing, pricing, or customer results.
For now, this is more about direction than delivery.
https://nerds.xyz/2026/07/reliaquest-openai-enterprise-cyber-defense/
#Cybersecurity #OpenAI #ArtificialIntelligence #EnterpriseSecurity #ReliaQuest
Apple increases iPhone prices in Japan by up to 11%
Apple has raised iPhone prices in Japan by up to 11% today. The changes affect the iPhone 17 lineup, iPhone Air, and iPhone 16e. Here are the exact increases and the likely explanation.
https://9to5mac.com/2026/07/17/apple-increases-iphone-prices-in-japan-by-up-to-11/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
Investigation reveals dozens of disguised gambling apps on the App Store in Brazil
An investigation by 9to5Mac reveals dozens of apps that disguise gambling platforms as simple games and utilities. Here are the details.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
🟠 CVE-2026-42566 - High (7.5)
Meshtastic is an open source mesh networking solution. Prior to version 2.7.23.b246bcd, a single node advertising a User.long_name that contains a malformed character encoding can render other radios unusable over BLE when managed through the iOS ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-42566/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🚨 EUVD-2026-45874
📊 Score: 7.5/10 (CVSS v3.1)
📦 Product: firmware
🏢 Vendor: meshtastic
📅 Updated: 2026-07-19
📝 Meshtastic is an open source mesh networking solution. Prior to version 2.7.23.b246bcd, a single node advertising a User.long_name that contains a malformed character encoding can render other radios unusable over BLE when managed through the iOS app. Th...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45874
🚨 EUVD-2026-45873
📊 Score: 10.0/10 (CVSS v3.1)
📦 Product: firmware
🏢 Vendor: meshtastic
📅 Updated: 2026-07-19
📝 Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml workflow is triggered by pull_request_target and multiple jobs check out the attacker's fork code and execute it ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45873
Possible Phishing 🎣
on: ⚠️hxxps[:]//docs[.]google[.]com/presentation/d/1gBvfAiCvkPTcu0YFovbn7Wwa_P3j08o0aRSbttl3JlU/pub?start=false&loop=false
🧬 Analysis at: https://urldna.io/scan/6a5ce6973b77500006020b94
#cybersecurity #phishing #infosec #urldna #scam #infosec
🔴 CVE-2026-44359 - Critical (10)
Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml workflow is triggered by pull_request_target and multiple jobs check out the attacker's fork code and execu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44359/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Rapid Ransomware Campaign Targeting Microsoft IIS Servers
Spirals is a Rust-based ransomware deployed after attackers breached a public-facing Microsoft IIS server. The attackers gained higher privileges, collected credentials, moved across the internal network, disabled security and backup services, and encrypted files throughout the affected organization.
Pulse ID: 6a5d718d2f31ed68447f90f7
Pulse Link: https://otx.alienvault.com/pulse/6a5d718d2f31ed68447f90f7
Pulse Author: cryptocti
Created: 2026-07-20 00:53:33
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Microsoft #OTX #OpenThreatExchange #RansomWare #Rust #bot #cryptocti
Apple cites paused securities fraud case in bid to halt Epic proceedings
Apple is citing a newly paused securities fraud lawsuit to support its request to pause further lower-court proceedings in its legal battle with Epic Games while the Supreme Court reviews part of the dispute. Here are t…
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
Sunday vibes are strong! 🔴
Solarpunk dreams, hacker camp chaos, and Linux gaming – all in one place. Expect cybersecurity deep dives, rants, and chill hangs. Let's build a better future (and have some fun). 🎮
Watch the chaos unfold! #Solarpunk #Cybersecurity #Linux
Sunday vibes are ON 🔴
Solarpunk dreams, hacker camp energy, and Linux gaming goodness! 🎮 Expect cybersecurity deep dives, rants, chill hangs, and maybe a little chaos. Let's build a better future, one line of code (and game) at a time.
Come hang out! #Solarpunk #Cybersecurity #Linux
Sunday vibes are strong! ☀️
Let's dive into a chill Sunday Game Night – think Solarpunk aesthetics, a little Hacker Summer Camp energy, and plenty of Linux gaming. Expect cybersecurity deep dives, some rants, and good times. 🎮
Come hang out and watch the chaos unfold!
If #kernel hackers are now giving #Claude Code unfettered access to do as it pleases on their development computers, what exactly is stopping #Anthropic from performing a supply-chain attack on the entire #Linux ecosystem?
Will there still be human code review going forward, to catch such an attack? And if so, how can that review be meaningful, when the computers used to perform the review are all compromised?
Desperate people do desperate things, and from the huge amounts of venture funding poured into #Anthropic, I expect them to get very desperate very quickly when the venture capitalists start demanding a return on their investments.
Other #AI companies like Google and Microsoft will still be profitable even if AI funding dries up, but Anthropic won't. What it will have is read/write access to a lot of important people's computers…
🟠 CVE-2026-12484 - High (7.8)
A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle data through the public `keras.layers.TorchModuleWrapper.from_config` method. This method invokes `torch.load(..., weights_only=...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12484/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
iOS 27 public betas are out, Siri AI hands on, and Apple sues OpenAI
Benjamin and Chance talk about their latest experiences with iOS 27 and Siri AI, with Apple releasing the public betas this week so anyone in the whole world can give the new software a go. The company also sued OpenAI …
https://9to5mac.com/2026/07/16/happy-hour-599/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
iOS 27 adds an all-new app to your iPhone’s Home Screen
Apple released the iOS 27 public beta this week, with a ton of new Siri and Apple Intelligence features. One of the biggest changes here is the addition of an all-new Siri app. This marks the first time that Siri has be…
https://9to5mac.com/2026/07/16/ios-27-adds-an-all-new-app-to-your-iphones-home-screen/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
🚀🛠️ Gitea 1.27 a fost lansat: Aduce optimizări majore pentru Gitea Actions și repară nu mai puțin de 45 de vulnerabilități (CVE)
Gitea, populara platformă lightweight auto-găzduită pentru managementul depozitelor Git, a primit o actualizare extrem de importantă: Gitea 1.27. Această versiune se remarcă printr-un accent masiv pus pe securitate, stabilitate și pe rafinarea uneltelor de integrare și livrare continuă (CI/CD).
Iată cele mai importante noutăți introduse în Gitea 1.27:
🛡️ Un salt masiv în securitate: 45 de CVE-uri rezolvate
Principala prioritate a acestei lansări a fost securizarea platformei. Echipa de dezvoltatori a auditat și a corectat 45 de vulnerabilități de securitate cunoscute (CVE-uri).
Aceste corecții acoperă o gamă largă de riscuri, de la potențiale atacuri de tip Cross-Site Scripting (XSS) și injectări de cod, până la probleme legate de drepturile de acces și autentificarea prin token-uri.
Datorită volumului uriaș de patch-uri de securitate, administratorilor de instanțe Gitea li se recomandă insistent să facă upgrade cât mai rapid la versiunea 1.27 pentru a-și proteja serverele și datele.
🔹 Îmbunătățiri majore pentru Gitea Actions (CI/CD)
Sistemul nativ de automatizare CI/CD din Gitea (compatibil cu sintaxa GitHub Actions) a primit optimizări substanțiale:
Performanță ridicată: Execuția și programarea joburilor sunt acum mult mai rapide, reducând timpii morți dintre etapele de testare și deployment.
Control mai bun: S-a îmbunătățit interfața de vizualizare a logurilor de erori, permițând dezvoltatorilor să identifice mult mai ușor de ce a eșuat un anumit build.
Curățarea automată a artefactelor: Gestionarea fișierelor rezultate din procesele de build este mai eficientă, prevenind umplerea rapidă a spațiului pe disc al serverului.
🔹 Optimizări de performanță și UX
Încărcare mai rapidă a paginilor: S-a lucrat la optimizarea interfeței web, în special pentru depozitele mari care conțin mii de commit-uri și sute de Pull Request-uri deschise.
Compatibilitate crescută cu Git: Serverul intern Gitea a fost aliniat cu cele mai recente standarde din nucleul Git, oferind o stabilitate sporită la operațiunile de push/pull complexe și la gestionarea fișierelor mari prin Git LFS.
Gitea 1.27 se dovedește a fi una dintre cele mai importante actualizări de mentenanță și securitate din istoria recentă a proiectului, fiind un upgrade obligatoriu pentru oricine rulează o instanță privată sau organizațională.
#OpenSource #Gitea #GiteaActions #Git #SelfHosted #Cybersecurity #CVE #CICD #TechNews #Linuxiac
Apple TV for Android adds widgets, Apple Music gets WhatsApp sharing
Apple TV and Apple Music for Android are rolling out sizable updates today, with homescreen widgets as the shared theme.
https://9to5google.com/2026/07/16/apple-tv-widgets/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
Apple’s M6 chip is coming soon, here’s everything we know
Apple will reportedly launch its next-generation Apple Silicon chip, the M6, later this year. Here’s everything we know so far, including why this generation will be unprecedented in the Apple Silicon era.
https://9to5mac.com/2026/07/16/apples-m6-chip-is-coming-soon-heres-everything-we-know/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
Apple sends legal letters to former employees now at OpenAI
Last week, Apple filed a lawsuit against OpenAI in which it alleged that its former employees have stolen trade secrets “for the benefit of OpenAI.” As part of this process, Apple has reportedly sent letters directly to…
https://9to5mac.com/2026/07/17/apple-sends-legal-letters-to-former-employees-now-at-openai/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
🚨 EUVD-2026-45686
📊 Score: n/a
📦 Product: Linux, Linux, Linux (+15 more)
🏢 Vendor: Linux
📅 Updated: 2026-07-19
📝 In the Linux kernel, the following vulnerability has been resolved:
netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check
An unintended behavior in the TCP conntrack state machine allows a
connection to be forced in...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45686
🚨 EUVD-2026-45677
📊 Score: n/a
📦 Product: Linux, Linux, Linux (+15 more)
🏢 Vendor: Linux
📅 Updated: 2026-07-19
📝 In the Linux kernel, the following vulnerability has been resolved:
usb: usbtmc: check URB actual_length for interrupt-IN notifications
USBTMC devices can use an optional interrupt endpoint for notification
messages. These typically contain two-byte ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45677
🚨 EUVD-2026-45685
📊 Score: n/a
📦 Product: Linux, Linux, Linux (+25 more)
🏢 Vendor: Linux
📅 Updated: 2026-07-19
📝 In the Linux kernel, the following vulnerability has been resolved:
xfrm: esp: restore combined single-frag length gate
The ESP out-of-place fast path appends the trailer in esp_output_head()
before esp_output_tail() allocates the destination page fr...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45685
🚨 EUVD-2026-45676
📊 Score: n/a
📦 Product: Linux, Linux, Linux (+15 more)
🏢 Vendor: Linux
📅 Updated: 2026-07-19
📝 In the Linux kernel, the following vulnerability has been resolved:
USB: serial: belkin_sa: validate interrupt status length
The Belkin interrupt callback treats interrupt data as a four-byte
status report and reads LSR/MSR fields at offsets 2 and 3....
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45676
🚨 EUVD-2026-45675
📊 Score: n/a
📦 Product: Linux, Linux, Linux (+15 more)
🏢 Vendor: Linux
📅 Updated: 2026-07-19
📝 In the Linux kernel, the following vulnerability has been resolved:
USB: serial: cypress_m8: validate interrupt packet headers
cypress_read_int_callback() parses the interrupt-in buffer according to
the selected Cypress packet format. Format 1 has a ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45675
🚨 EUVD-2026-45684
📊 Score: n/a
📦 Product: Linux, Linux, Linux (+5 more)
🏢 Vendor: Linux
📅 Updated: 2026-07-19
📝 In the Linux kernel, the following vulnerability has been resolved:
xfrm: iptfs: reset runtime state when cloning SAs
iptfs_clone_state() clones the IPTFS mode data with kmemdup(). This
copies runtime objects which must not be shared with the original...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45684
🚨 EUVD-2026-45674
📊 Score: n/a
📦 Product: Linux, Linux, Linux (+15 more)
🏢 Vendor: Linux
📅 Updated: 2026-07-19
📝 In the Linux kernel, the following vulnerability has been resolved:
USB: serial: digi_acceleport: fix memory corruption with small endpoints
Add the missing bulk-out buffer size sanity checks to avoid
out-of-bounds memory accesses or slab corruption ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45674
🚨 EUVD-2026-45683
📊 Score: n/a
📦 Product: Linux, Linux, Linux (+3 more)
🏢 Vendor: Linux
📅 Updated: 2026-07-19
📝 In the Linux kernel, the following vulnerability has been resolved:
dma-buf: fix UAF in dma_buf_fd() tracepoint
Once FD_ADD() returns, the fd is live in the file descriptor table
and a thread sharing that table can close() it before DMA_BUF_TRACE()
ru...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45683
🚨 EUVD-2026-45673
📊 Score: n/a
📦 Product: Linux, Linux, Linux (+15 more)
🏢 Vendor: Linux
📅 Updated: 2026-07-19
📝 In the Linux kernel, the following vulnerability has been resolved:
USB: serial: keyspan: fix missing indat transfer sanity check
Add the missing sanity check on the size of usa49wg indat transfers to
avoid parsing stale or uninitialised slab data.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45673
🚨 EUVD-2026-45672
📊 Score: n/a
📦 Product: Linux, Linux, Linux (+15 more)
🏢 Vendor: Linux
📅 Updated: 2026-07-19
📝 In the Linux kernel, the following vulnerability has been resolved:
USB: serial: mxuport: fix memory corruption with small endpoint
Make sure that the bulk-out endpoint max packet size is at least eight
bytes to avoid user-controlled slab corruption ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45672
🚨 EUVD-2026-45682
📊 Score: n/a
📦 Product: Linux, Linux, Linux (+8 more)
🏢 Vendor: Linux
📅 Updated: 2026-07-19
📝 In the Linux kernel, the following vulnerability has been resolved:
ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops
Commit d07b26f39246 ("ksmbd: require minimum ACE size in
smb_check_perm_dacl()") introduced a transposed bounds chec...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45682
🚨 EUVD-2026-45681
📊 Score: n/a
📦 Product: Linux, Linux, Linux (+15 more)
🏢 Vendor: Linux
📅 Updated: 2026-07-19
📝 In the Linux kernel, the following vulnerability has been resolved:
Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem
When a configuration file provides an object size that is larger than the
driver's known mxt_obj_size(object), the dri...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45681
🚨 EUVD-2026-45671
📊 Score: n/a
📦 Product: Linux, Linux, Linux (+15 more)
🏢 Vendor: Linux
📅 Updated: 2026-07-19
📝 In the Linux kernel, the following vulnerability has been resolved:
USB: serial: mct_u232: fix memory corruption with small endpoint
The driver overrides the maximum transfer size for a specific device
which only accepts 16 byte packets for its 32 by...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45671
🚨 EUVD-2026-45680
📊 Score: n/a
📦 Product: Linux, Linux, Linux (+3 more)
🏢 Vendor: Linux
📅 Updated: 2026-07-19
📝 In the Linux kernel, the following vulnerability has been resolved:
uio: uio_pci_generic_sva: fix double free of devm_kzalloc() memory
uio_pci_sva allocates struct uio_pci_sva_dev with devm_kzalloc() in
probe(), but then calls kfree(udev) both on the ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45680
🚨 EUVD-2026-45771
📊 Score: n/a
📦 Product: Linux, Linux, Linux (+11 more)
🏢 Vendor: Linux
📅 Updated: 2026-07-19
📝 In the Linux kernel, the following vulnerability has been resolved:
scsi: target: iscsi: Validate CHAP_R length before base64 decode
chap_server_compute_hash() allocates client_digest as
kzalloc(chap->digest_size) and then, for BASE64-encoded respons...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45771
🚨 EUVD-2026-45679
📊 Score: n/a
📦 Product: Linux, Linux, Linux (+14 more)
🏢 Vendor: Linux
📅 Updated: 2026-07-19
📝 In the Linux kernel, the following vulnerability has been resolved:
usb: musb: omap2430: Fix use-after-free in omap2430_probe()
In omap2430_probe(), of_node_put(np) is called prematurely before the
last access to np, leading to a use-after-free if th...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45679
🚨 EUVD-2026-45678
📊 Score: n/a
📦 Product: Linux, Linux, Linux (+15 more)
🏢 Vendor: Linux
📅 Updated: 2026-07-19
📝 In the Linux kernel, the following vulnerability has been resolved:
usbip: vudc: Fix use after free bug in vudc_remove due to race condition
This patch follows up Zheng Wang's 2023 report of a use-after-free in
vudc_remove(). The original thread stal...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45678
🚨 EUVD-2026-45770
📊 Score: n/a
📦 Product: Linux, Linux, Linux (+2 more)
🏢 Vendor: Linux
📅 Updated: 2026-07-19
📝 In the Linux kernel, the following vulnerability has been resolved:
drm/gem: fix race between change_handle and handle_delete
drm_gem_change_handle_ioctl leaves the old handle live in the IDR
during the window between spin_unlock(table_lock) and the f...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45770
📰 The FBI has arrested 21-year-old student Zyaire Wilkins for publishing fake video games on Steam that contained malware, infecting thousands of victims and stealing crypto from some of them.
This unpronounceable series of glyphs is an incredible side project from Kieran Hebden (aka Four Tet)
Sure is a lot of porcelein in there. | Image: Kieran Hebden Just why? ʅ͡͡͡͡͡͡͡͡͡͡͡(̸̢̛̼̞̭͋ͅ)̸͚̰͛̔̾̀̿͒͂:̴͓̞̑̌̂̆̊͋̀:̸͎̟̯̂̓̌ ҉ ͡ ͞ ͞ ͞ ҉● ࿀ ● ࿀ ● ҉⃝ ⃝͢ ͞ ͘ ͞⃝̕ ͢ ̛ ⃝ ̸ ̡ ͢⃝̧ ͡ ͡ ̀ ̧ ̢⃝͜ ҉ ͞ ͞ ⃝͞ ͞ ͡⃝ ⃝҉҈҉҈҉҈҉҈҉҈҉ :̶̢͙͙͕̠̩͆…
https://www.theverge.com/entertainment/967696/four-tet-wingdings-album-review
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
How to Use the AUR Safely: Lessons from the June 2026 AUR Malware Attack #arch_linux #arch_user_repository_(aur) #cybersecurity #linux #linux_administration #linux_distributions #linux_security #package_management #security #arch_linux_aur #arch_user_repository #arch_user_repository_security #atomic_arch #aur #aur_best_practices #aur_malware #aur_malware_attack #aur_security #june_2026_aur_malware_attack #pkgbuild_security #supply_chain_attack #use_aur_safely
https://ostechnix.com/use-the-aur-safely-arch-linux/
🟠 CVE-2026-62234 - High (8.1)
Grav before 2.0.4 fails to restrict cURL protocols in webhook dispatch, allowing authenticated users with api.webhooks.write permission to create webhooks with file://, dict://, or gopher:// URLs. Attackers can trigger webhook events to read local...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62234/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🔴 CVE-2026-62241 - Critical (9.1)
clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as the default in .env.example. Because GET /api/v1/scans returns scan records containing userId value...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62241/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-62386 - High (7.5)
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens through the ?token= URL query parameter on every API route (JwtAuthenticator::extractBearerToken fallback). Because tokens are embedded in URLs, they are lo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62386/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🖲️ #Cybersecurity #Ciberseguridad #Ciberseguranca #Security #Seguridad #Seguranca #News #Noticia #Noticias #Tecnologia #Technology
⚫ Inc Ransomware Exploits SonicWall SMA Zero-Days
🔗 https://www.darkreading.com/vulnerabilities-threats/inc-ransomware-exploits-sonicwall-sma-zero-days
When chained together, the two vulnerabilities allow threat actors to gain root-level capabilities on SonicWall's mobile access appliances.
🟠 CVE-2026-16221 - High (7.5)
Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL parser, used by fetch, und...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16221/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack