voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]EUVD Bot » 🤖 🌐
@EUVD_Bot@mastodon.social

🚨 EUVD-2026-38277

📊 Score: 8.1/10 (CVSS v3.1)
📦 Product: Storage Protect Client, Storage Protect Snapshot For Windows
🏢 Vendor: IBM
📅 Updated: 2026-06-22

📝 IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 could allow a remote attacker to bypass authentication due to the use of a hardcoded cred...

🔗 euvd.enisa.europa.eu/vulnerabi

    [?]EUVD Bot » 🤖 🌐
    @EUVD_Bot@mastodon.social

    🚨 EUVD-2026-38276

    📊 Score: 3.8/10 (CVSS v3.1)
    📦 Product: Mattermost, Mattermost
    🏢 Vendor: Mattermost
    📅 Updated: 2026-06-22

    📝 Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to validate bot targets when demoting users to guests which allows a lower-privileged administrator to degrade arbitrary bot accounts via the standard demote-user API.. Mattermo...

    🔗 euvd.enisa.europa.eu/vulnerabi

      [?]TechWire ⚡ » 🤖 🌐
      @techwire@social.gamefan.net

      Patreon CEO Jack Conte on supporting artists in the AI slop era

      Today, I’m talking with Jack Conte, the CEO of Patreon. Jack last joined me on the show almost exactly five years ago, in the summer of 2021, and a lot has changed on the internet and in the creator landscape since then…

      theverge.com/podcast/952607/pa

      [The Verge]

        [?]Neil Brown [he/him/his] » 🌐
        @neil@mastodon.neilzone.co.uk

        # Cybersecurity for the paranoid business traveller

        A great, practical blogpost, by @Edent, for people who are not James Bond.

        shkspr.mobi/blog/2026/06/cyber

          [?]TechWire ⚡ » 🤖 🌐
          @techwire@social.gamefan.net

          Apple’s latest AirTags are cheaper than ever for Prime Day

          It’s a small but rare discount. | Photo by Amelia Holowaty Krales / The Verge Prime Day has brought a number of Apple deals, but one of the most useful if you’re planning to travel over the July 4th weekend or later thi…

          theverge.com/gadgets/951987/ap

          [The Verge]

            [?]urlDNA.io :verified: » 🤖 🌐
            @urldna@infosec.exchange

            Possible Phishing 🎣
            on: ⚠️hxxps[:]//office365-service-c38bf0[.]webflow[.]io
            🧬 Analysis at: urldna.io/scan/6a38f3613b77500

              [?]TechWire ⚡ » 🤖 🌐
              @techwire@social.gamefan.net

              AMD releases FSR 4.1 upscaling for older graphics cards

              Assassin’s Creed Black Flag Resynced will have support for FSR 4.1 on day one. AMD is officially launching FSR Upscaling 4.1 for Radeon RX 7000-series GPUs today. The update means that computers with those older graphic…

              theverge.com/news/953664/amd-f

              [The Verge]

                [?]Negative PID SL » 🌐
                @negativepid@mastodon.social

                [?]eteryu » 🌐
                @eteryu@infosec.exchange

                Lekcja prywatności z Poznania. Czego uczy nas "afera" wokół Pyrkonu?

                W sieci zawrzało po wycinku z posiedzenia poznańskich urzędników. Zamiast jednak robić wir w szklance wody, warto spojrzeć na chłodne fakty.

                Prawdziwym źródłem danych dla brokerów informacji nie są urzędy miast, ale smartfony, które codziennie nosimy w kieszeniach, a dokładniej oprogramowanie, które sami na nich instalujemy.

                Zamiast liczyć na to, że obroni nas RODO, musimy wziąć sprawy we własne ręce. W artykule opisuję jak działają mechanizmy śledzenia, dlaczego oddajemy prywatność za zniżki u operatorów i jak za pomocą narzędzi takich jak @exodus odzyskać kontrolę nad telefonem.

                Cały artykuł: 👇
                eteryu.space/lekcja-prywatnosc

                Screen z video udostępnionego przez Autorów.

                Alt...Screen z video udostępnionego przez Autorów.

                [?]EUVD Bot » 🤖 🌐
                @EUVD_Bot@mastodon.social

                🚨 EUVD-2026-38225

                📊 Score: 9.4/10 (CVSS v3.1)
                📦 Product: MISP
                🏢 Vendor: MISP
                📅 Updated: 2026-06-22

                📝 Multiple MISP core controllers and model capture paths accepted client-controlled request fields such as primary keys (id) and ownership/scope foreign keys (event_id, org_id, user_id, sharing_group_id, galaxy_cluster_uuid, organisation_uuid, and related nested obj...

                🔗 euvd.enisa.europa.eu/vulnerabi

                  [?]EUVD Bot » 🤖 🌐
                  @EUVD_Bot@mastodon.social

                  🚨 EUVD-2026-38224

                  📊 Score: n/a
                  📦 Product: Net::Statsite::Client
                  🏢 Vendor: JASEI
                  📅 Updated: 2026-06-22

                  📝 Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections.

                  Net::Statsite::Client is a client for the statsite protocol, which is a variant of statsd.

                  Newlines are not removed from metric names, allowing metric injections.

                  Values are not s...

                  🔗 euvd.enisa.europa.eu/vulnerabi

                    [?]urlDNA.io :verified: » 🤖 🌐
                    @urldna@infosec.exchange

                    Possible Phishing 🎣
                    on: ⚠️hxxps[:]//doctorssserver[.]weebly[.]com
                    🧬 Analysis at: urldna.io/scan/6a38ad123b77500

                      [?]gtbarry » 🌐
                      @gtbarry@mastodon.social

                      Massive breach spills credentials for thousands of sensitive networks

                      Researchers have uncovered a massive breach of Fortinet firewalls that has given Russian-speaking attackers near-unrestricted access to some of the world’s largest and most powerful organizations, including Oracle, Chevron, Lenovo, Federal Express, a NATO defense contractor, and Fortinet itself.

                      arstechnica.com/security/2026/

                        [?]TechWire ⚡ » 🤖 🌐
                        @techwire@social.gamefan.net

                        Nothing just designed its most wanted phone ever, but it isn’t for sale

                        This Nothing phone's got everything.

                        androidauthority.com/nothing-d

                        [Android Authority]

                          [?]Hugo | DevOps | Cybersecurity » 🌐
                          @hugovalters@mastodon.social

                          Lunary-ai: 69 CVEs, 18 critical, avg CVSS 7.69. 100% unpatched. Trust Score: D. AI monitoring tool needs patching NOW.

                          valtersit.com/vendors/lunary-a

                            [?]deafnews » 🤖 🌐
                            @deafnews@infosec.exchange

                            [?]TechWire ⚡ » 🤖 🌐
                            @techwire@social.gamefan.net

                            The Galaxy S27 Pro could inherit one of the Ultra’s best display features

                            Samsung might finally stop gatekeeping its best screen tech.

                            androidauthority.com/samsung-g

                            [Android Authority]

                              [?]AllAboutSecurity » 🌐
                              @allaboutsecurity@mastodon.social

                              Firefox KI-Funktion ermöglichte E-Mail-Diebstahl per Prompt-Injection

                              Ein manipulierter Seitentitel reichte aus, um den KI-Assistenten in Firefox dazu zu bringen, E-Mail-Daten auszulesen und an einen Angreifer zu übermitteln – ohne sichtbares Zutun des Nutzers.

                              all-about-security.de/firefox-

                                [?]CTI.FYI » 🤖 🌐
                                @CTI_FYI@infosec.exchange

                                🚨New ransom group blog post!🚨

                                Group name: qilin
                                Post title: Central Bank of Libya
                                Info: cti.fyi/groups/qilin.html

                                  [?]urlDNA.io :verified: » 🤖 🌐
                                  @urldna@infosec.exchange

                                  Possible Phishing 🎣
                                  on: ⚠️hxxps[:]//wewewecodesadwewesadwe[.]weebly[.]com
                                  🧬 Analysis at: urldna.io/scan/6a38bb223b77500

                                    [?]The New Oil » 🤖 🌐
                                    @thenewoil@mastodon.thenewoil.org

                                    [?]TechWire ⚡ » 🤖 🌐
                                    @techwire@social.gamefan.net

                                    Wyze’s new smart scale can break down your body composition for less than $80

                                    Seven months after introducing its $119.98 Ultra BodyScan smart scale, Wyze announced a cheaper $79.98 alternative available today that makes a few compromises to shave $40 off the price. There's no Wi-Fi, but you can s…

                                    theverge.com/tech/952512/wyze-

                                    [The Verge]

                                      [?]Hacker News » 🤖 🌐
                                      @h4ckernews@mastodon.social

                                      [?]EUVD Bot » 🤖 🌐
                                      @EUVD_Bot@mastodon.social

                                      🚨 EUVD-2025-210296

                                      📊 Score: n/a
                                      📦 Product: Apache Atlas
                                      🏢 Vendor: Apache Software Foundation
                                      📅 Updated: 2026-06-22

                                      📝 An authenticated user can perform XSS.

                                      This issue affects Apache Atlas versions 2.4.0 and earlier.

                                      Users are recommended to upgrade to version 2.5.0, which fixes the issue.

                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                        [?]EUVD Bot » 🤖 🌐
                                        @EUVD_Bot@mastodon.social

                                        🚨 EUVD-2026-38219

                                        📊 Score: 7.5/10 (CVSS v3.1)
                                        📦 Product: Apache NiFi
                                        🏢 Vendor: Apache Software Foundation
                                        📅 Updated: 2026-06-22

                                        📝 Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates addit...

                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                          [?]EUVD Bot » 🤖 🌐
                                          @EUVD_Bot@mastodon.social

                                          🚨 EUVD-2026-38218

                                          📊 Score: 2.3/10 (CVSS v3.1)
                                          📦 Product: Apache NiFi
                                          🏢 Vendor: Apache Software Foundation
                                          📅 Updated: 2026-06-22

                                          📝 Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to submit proposed configuration properties. The proposed properties override current configur...

                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                            [?]EUVD Bot » 🤖 🌐
                                            @EUVD_Bot@mastodon.social

                                            🚨 EUVD-2026-38217

                                            📊 Score: 5.2/10 (CVSS v3.1)
                                            📦 Product: Apache NiFi
                                            🏢 Vendor: Apache Software Foundation
                                            📅 Updated: 2026-06-22

                                            📝 Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 allows for injecting SQL commands using crafted naming. Manual quoted boundaries added in Apache NiFi 1.8.0 nar...

                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                              [?]EUVD Bot » 🤖 🌐
                                              @EUVD_Bot@mastodon.social

                                              🚨 EUVD-2026-38216

                                              📊 Score: 6.3/10 (CVSS v3.1)
                                              📦 Product: Apache NiFi
                                              🏢 Vendor: Apache Software Foundation
                                              📅 Updated: 2026-06-22

                                              📝 Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an alternative to the standard Host header without validating the values provided. Apache NiFi 1.6.0 introduced a con...

                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                [?]EUVD Bot » 🤖 🌐
                                                @EUVD_Bot@mastodon.social

                                                🚨 EUVD-2025-210295

                                                📊 Score: n/a
                                                📦 Product: Apache Doris MCP Server
                                                🏢 Vendor: Apache Software Foundation
                                                📅 Updated: 2026-06-22

                                                📝 Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name is directly interpolated into a SQL query, and the query is executed without passing the caller's authorization con...

                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                  [?]urlDNA.io :verified: » 🤖 🌐
                                                  @urldna@infosec.exchange

                                                  Possible Phishing 🎣
                                                  on: ⚠️hxxp[:]//facebook-clone-kappa-ten[.]vercel[.]app
                                                  🧬 Analysis at: urldna.io/scan/6a38f35d3b77500

                                                    [?]jbz » 🌐
                                                    @jbz@indieweb.social

                                                    🛃 After Recent AUR Security Scare, Yay 13.0 Adds New Review and Automation Features linuxiac.com/yay-13-0-adds-new

                                                      [?]BeyondMachines :verified: » 🤖 🌐
                                                      @beyondmachines1@infosec.exchange

                                                      libssh2 Vulnerabilities Enable Remote Code Execution and Denial of Service

                                                      libssh2 disclosed two vulnerabilities, including a critical out-of-bounds write (CVE-2026-55200) and a high-severity denial of service (CVE-2026-55199), affecting versions up to 1.11.1. These flaws allow malicious servers to execute code on connecting clients or cause resource exhaustion.

                                                      **Plan to update libssh2 to a patched build as soon as a fixed release is available. In the meantime audit your tools (curl/libcurl, PHP ssh2 extension, monitoring utilities, IoT firmware) for the vulnerable library versions up to 1.11.1. Only connect to SSH servers you trust and isolate sensitive management interfaces so they're reachable from trusted networks only, since a malicious server can now attack your client.**

                                                      beyondmachines.net/event_detai

                                                        [?]BeeSINT » 🌐
                                                        @BeeSINT@mastodon.social

                                                        🎣 Phishing Spotlight

                                                        Active phishing domain detected in the wild:
                                                        mail[.]my-iapple-lost[.]us

                                                        🔗 beesint.com/pulse/b58e3a00-db4

                                                          [?]TechWire ⚡ » 🤖 🌐
                                                          @techwire@social.gamefan.net

                                                          What’s new in Android’s June 2026 Google System Updates: WhatsApp backups

                                                          The monthly “Google System Release Notes” primarily detail what’s new in Play services, Play Store, and Play system update across Android phones/tablets, Wear OS, Google/Android TV, Auto, and PC. Some features apply to …

                                                          9to5google.com/2026/06/15/june

                                                          [9to5Google]

                                                            [?]deafnews » 🤖 🌐
                                                            @deafnews@infosec.exchange

                                                            [?]TechWire ⚡ » 🤖 🌐
                                                            @techwire@social.gamefan.net

                                                            I gamed on 2026’s best Snapdragon and Exynos flagship phones — and the benchmarks lied

                                                            Exynos vs Snapdragon vs Tensor vs Dimensity go head to head in real games

                                                            androidauthority.com/snapdrago

                                                            [Android Authority]

                                                              [?]SquaredTech » 🌐
                                                              @SquaredTech@mstdn.social

                                                              🚨Attention Crypto Users🚨 Microsoft warns of a new threat! CryptoBandits malware is lurking around, spreading through USB shortcuts to steal your seed phrases and wallet addresses. Make sure you're protecting your assets. Know more about how it works. 💻🔒💰 CryptoBandits Malware Uses USB Drives to Steal Crypto Wallets
                                                              squaredtech.co/cryptobandits-m

                                                                [?]urlDNA.io :verified: » 🤖 🌐
                                                                @urldna@infosec.exchange

                                                                Possible Phishing 🎣
                                                                on: ⚠️hxxps[:]//login[.]steampowered[.]com[.]ru
                                                                🧬 Analysis at: urldna.io/scan/6a38f36a3b77500

                                                                  [?]TechWire ⚡ » 🤖 🌐
                                                                  @techwire@social.gamefan.net

                                                                  Survey says Google could be making a huge mistake with its smart home product line

                                                                  Only 2% of respondents are committed to upgrading to the new Home Speaker.

                                                                  androidauthority.com/google-ki

                                                                  [Android Authority]

                                                                    Back to top - More...