voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
Inside the FortiBleed Open Directory: A Technical Analysis of What the Attacker Left Behind
An exposed attacker server has unveiled FortiBleed, a large-scale credential-compromise campaign targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways globally. This operation involved credential harvesting through reuse, brute force, and hash cracking using a distributed GPU infrastructure with approximately 36 rented GPUs via Hashtopolis. The exposed directory contained 319 files revealing scanning tools, cracking infrastructure, credential databases, post-exploitation toolkits, and active VPN configurations. While initially reported as affecting 21,632 domains, analysis of the attacker's own tooling reveals only 918 organizations showed evidence of internal network compromise, with merely 148 confirmed cases where credentials were fully cracked. The operation ultimately aimed to sell initial access to compromised networks, with victims spanning 194 countries, predominantly India, United States, and Taiwan.
Pulse ID: 6a358eb86925d602f0cf5600
Pulse Link: https://otx.alienvault.com/pulse/6a358eb86925d602f0cf5600
Pulse Author: AlienVault
Created: 2026-06-19 18:47:20
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BruteForce #CredentialHarvesting #CyberSecurity #India #InfoSec #OTX #OpenThreatExchange #RAT #RCE #SSL #UnitedStates #VPN #bot #AlienVault
Threat Actors Weaponizing RAR Archives to Target Thailand's Healthcare Sector
An active malware campaign is targeting Thailand's healthcare sector, including Ministry of Health personnel and affiliated organizations. The operation leverages healthcare-themed spear-phishing lures distributed through malicious RAR archives containing obfuscated batch scripts and executable payloads. The infection chain employs multiple stages of obfuscation, GitHub-hosted payload delivery, and persistence mechanisms. The final payload is a Python-based information stealer designed to harvest browser credentials, session data, and cookies, with exfiltration attempts through Telegram Bot API. The campaign demonstrates sophisticated tradecraft including Rouki-obfuscated batch loaders, Startup folder persistence, and bundled Python interpreters. Active operational window spans from April to June 2026, with all samples uploaded from Thailand.
Pulse ID: 6a3551ceb394e391f2a341f1
Pulse Link: https://otx.alienvault.com/pulse/6a3551ceb394e391f2a341f1
Pulse Author: AlienVault
Created: 2026-06-19 14:27:26
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Cookies #CyberSecurity #GitHub #Healthcare #InfoSec #Malware #OTX #OpenThreatExchange #Phishing #Python #RAT #SMS #SpearPhishing #Telegram #Thailand #UK #bot #AlienVault
Cloud Security: A Practical Guide to Protecting Data, Identity and Workloads - https://www.redpacketsecurity.com/cloud-security-a-practical-guide-to-protecting-data-identity-and-workloads-3/
Possible Phishing 🎣
on: ⚠️hxxps[:]//bbghhjhfgfggh[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a3889363b77500005326aea
#cybersecurity #phishing #infosec #urldna #scam #infosec
🛡️ #Cybersecurity news & tips across the #fediverse
“Meta is testing face-recognition software for its smart glasses app, built with Rank One, a surveillance-tech supplier tied to Pentagon use. 🤖
It is developed for internal use in Meta’s smart glasses app and uses biome...”
https://mastodon.social/@knoppix95/116788307611822429
🤖 via RSS feed. Not an endorsement.
Sundar Pichai on ‘California optimism’ & doing hard, exciting work at 2026 Stanford Commencement Address
Alphabet and Google CEO Sundar Pichai today gave the commencement speech to Stanford University’s Class of 2026.
https://9to5google.com/2026/06/14/sundar-pichai-2026-stanford/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Google [9to5Google]
🚨 EUVD-2026-38208
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: Central Dogma
🏢 Vendor: LY Corporation
📅 Updated: 2026-06-22
📝 A vulnerability has been identified in centraldogma-server-auth-shiro versions prior to 0.84.0, where the SearchFirstActiveDirectoryRealm substitutes the login username into an LDAP search filter without neutralizing LDAP filter metacharacters, ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-38208
🚨 EUVD-2026-38207
📊 Score: 9.4/10 (CVSS v3.1)
📦 Product: Central Dogma
🏢 Vendor: LY Corporation
📅 Updated: 2026-06-22
📝 A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. This def...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-38207
🚨 EUVD-2026-38206
📊 Score: 8.8/10 (CVSS v3.1)
📦 Product: Central Dogma
🏢 Vendor: LY Corporation
📅 Updated: 2026-06-22
📝 A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verify remote host keys for git+ssh:// connections, allowing an on-path attacker to perform man-in-the-middl...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-38206
🚨 EUVD-2026-38205
📊 Score: 7.1/10 (CVSS v3.1)
📦 Product: Armoury Crate
🏢 Vendor: ASUS
📅 Updated: 2026-06-22
📝 A permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/write operations or cause a system crash (BSOD) by bypassing the validation mechanism.Refer to the '
Security Update for Armoury Crate ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-38205
Investigating domains and websites with OSINT #negativepid #digitalInvestigations #OSINT #cybersecurity #AI #tech #onlineInvestigations #robotics #cyberpsychology #cybercrime https://negativepid.blog/investigating-domains-and-websites-with-osint/?utm_source=mastodon&utm_medium=social&utm_campaign=fedica-Negative-PID-Blog
Google ads tease next Pixel Drop with Screen Reactions and Gemini Omni [Video]
We’re due for Google’s next Pixel Drop and, thanks to some early ads, we now know that Screen Reactions and some Gemini Omni-powered features will be a part of this next update.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Google [9to5Google]
Possible Phishing 🎣
on: ⚠️hxxps[:]//ilotbetzipeg1li1itch[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a38ad173b77500005326e2e
#cybersecurity #phishing #infosec #urldna #scam #infosec
These are the best new MacBook deals currently: June 2026 Buyer’s Guide
In the era of Apple Silicon, MacBooks are more affordable than ever. Nowadays, you can buy a MacBook Air with 512GB of storage and 16GB of memory for $1099 directly from Apple, when such a configuration would’ve cost $1…
https://9to5mac.com/2026/06/21/best-new-macbook-deals-right-now-june-2026/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
Nothing’s latest teaser may have just revealed the Nothing Phone 4b
After canceling CMF plans, Nothing may be getting ready to launch a new budget phone.
https://www.androidauthority.com/nothing-phone-4b-teaser-3679702/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Possible Phishing 🎣
on: ⚠️hxxp[:]//amazonbylio[.]vercel[.]app
🧬 Analysis at: https://urldna.io/scan/6a386cfe3b77500002390de8
#cybersecurity #phishing #infosec #urldna #scam #infosec
Roku is being bought out by Fox for $22 billion
Fox has announced its intention to buy Roku in a deal valued at $22 billion.
https://9to5google.com/2026/06/15/roku-is-being-bought-out-by-fox-for-22-billion/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Google [9to5Google]
Galaxy Z Fold 8 ‘Wide’ reportedly has a stronger inner display than the ‘Ultra’
According to a new report, Samsung’s upcoming Galaxy Z Fold 8, the one otherwise known as “Wide,” will have better inner display ultra-thin glass than the device known as “Ultra.”
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Google [9to5Google]
Possible Phishing 🎣
on: ⚠️hxxps[:]//facebook-clone-rho-ten[.]vercel[.]app
🧬 Analysis at: https://urldna.io/scan/6a386d183b7750000532685c
#cybersecurity #phishing #infosec #urldna #scam #infosec
Google Chrome’s next update will mark the end of popular ad blockers
Google Chrome’s move to Manifest V3 for extensions is closing its final loophole and, with it, bringing the end of many ad blocker tools.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Google [9to5Google]
🛡️ #Cybersecurity news & tips across the #fediverse
“https:// lemmy.zip/post/66542364 # Google # reCaptcha # enshittification # privacy # surveillance # technology”
https://mastodon.online/@jonsnow/116788030087067076
🤖 via RSS feed. Not an endorsement.
[Update: US too]Google kicks off World Cup hype with new ‘Chrome Dino FC’ Android figure [Gallery]
To celebrate the World Cup 2026, Google has quietly dropped a clever new limited-edition “Chrome Dino FC” Android figurine on its merchandise store.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Google [9to5Google]
Amazon AWS: 55 CVEs, 98% unpatched, Trust Score C. 18 critical/high flaws. Top weaknesses: CWE-89 (SQL injection) & CWE-78 (OS command injection). Cloud dominance ≠ secure defaults. Fix your attack surface. #AWS #cybersecurity #infosec
systemd 261: Software TPM and Native Installer Rewrite the Rules https://deafnews.it/en/article/systemd-261-software-tpm-and-native-installer-rewrite-the-rules #Cybersecurity
Google sues cybercrime network that used Gemini for financial scams
Google has filed a lawsuit against a cybercrime organization that was using Gemini to power its financial scams, while Google is also pushing for stricter laws that are more relevant to an AI era.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Google [9to5Google]
Possible Phishing 🎣
on: ⚠️hxxps[:]//btconectupgradewirelessvoicemail017[.]weebly[.]com/
🧬 Analysis at: https://urldna.io/scan/6a3812453b77500005325f4b
#cybersecurity #phishing #infosec #urldna #scam #infosec
Gemini 3.5 Flash lands on Google’s Android coding rankings, but it’s 3x the cost for slower performance
Google has released another set of benchmark results to determine the best AI models for Android coding, along with how much each model costs per token. Google’s Gemini 3.5 Flash is easily the most resource-intensive in…
https://9to5google.com/2026/06/12/gemini-3-5-flash-on-googles-android-coding-rankings/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Google [9to5Google]
Deals: Google Pixel 10 Pro up to $420 off, 512GB Galaxy S26+ $400 off, up to $875 off Windows laptops/desktops,…
Today’s 9to5Toys Lunch Break is headlined by the mid-range 256GB Google Pixel 10 Pro at up to $420 off alongside a sizable collection of Father’s Day Google deals you can browse through. We also have a huge $400 price d…
https://9to5google.com/2026/06/12/deals-google-pixel-10-pro-galaxy-s26-windows-laptops/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Google [9to5Google]
🚨 EUVD-2026-38204
📊 Score: 4.8/10 (CVSS v3.1)
📦 Product: Browserbase
📅 Updated: 2026-06-21
📝 A security flaw has been discovered in Browserbase up to 20260526. This impacts an unknown function of the component Autobrowse Trace Artifact Handler. The manipulation results in incorrect default permissions. The attack requires a local approach. The exploit has been re...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-38204
🚨 EUVD-2026-38203
📊 Score: 4.8/10 (CVSS v3.1)
📦 Product: langflow, langflow, langflow (+1 more)
🏢 Vendor: langflow-ai
📅 Updated: 2026-06-21
📝 A vulnerability was identified in langflow-ai langflow up to 1.9.3. This affects an unknown function of the component Bundle URL Loader. The manipulation leads to code injection. The attack needs to be performed locally. Th...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-38203
🚨 EUVD-2026-38202
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Flowise, Flowise, Flowise
🏢 Vendor: FlowiseAI
📅 Updated: 2026-06-21
📝 A vulnerability was determined in FlowiseAI Flowise up to 3.1.2. The impacted element is an unknown function of the file packages/components/nodes/documentloaders/S3/S3.ts of the component S3 Document Loader. Executing a manipulation can ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-38202
🚨 EUVD-2026-38201
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: coolify
🏢 Vendor: coollabsio
📅 Updated: 2026-06-21
📝 A vulnerability has been found in coollabsio coolify 4.0.0. Impacted is an unknown function of the component Image Name Handler. Such manipulation leads to os command injection. The attack may be performed from remote. The vendor was contacted early about...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-38201
Possible Phishing 🎣
on: ⚠️hxxps[:]//netflix-clone-taupe-ten[.]vercel[.]app
🧬 Analysis at: https://urldna.io/scan/6a386d0b3b7750000532683c
#cybersecurity #phishing #infosec #urldna #scam #infosec
Nothing Ear (3a) reportedly in the pipeline with new colors and a lower price tag
Nothing Ear (3) launched earlier this year as a solid pair of wireless earbuds, but it’s also been hard to beat the budget-focused Nothing Ear (a) from 2024. But, apparently, Nothing is giving it a shot with the first N…
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Google [9to5Google]
Cybercrime logistics: the hosting infrastructure #negativepid #digitalInvestigations #OSINT #cybersecurity #AI #tech #onlineInvestigations #robotics #cyberpsychology #cybercrime https://negativepid.blog/cybercrime-logistics-the-hosting-infrastructure/?utm_source=mastodon&utm_medium=social&utm_campaign=fedica-Negative-PID-Blog
The Pixel punches way above its weight in the smartphone space [Video]
Despite a single-digit market share in practically every global region, Google still has a fairly strong foothold in the smartphone space with the Pixel, but why?
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Google [9to5Google]
Possible Phishing 🎣
on: ⚠️hxxps[:]//emailsecurityactivation[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a3882e93b77500005326a59
#cybersecurity #phishing #infosec #urldna #scam #infosec
Google’s official Pixel Watch bands are as low as $5 right now
Google’s Fitbit Air might be sweeping the fitness landscape right now — I, for one, think it’s an excellent tracker at its core — but for plenty of Android users, you just can’t swap sway from a real smartwatch. If you’…
https://9to5google.com/2026/06/12/googles-official-pixel-watch-bands-are-as-low-as-5-right-now/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Google [9to5Google]
Anatomy of a modern OneDrive phishing attack #negativepid #digitalInvestigations #OSINT #cybersecurity #AI #tech #onlineInvestigations #robotics #cyberpsychology #cybercrime https://negativepid.blog/anatomy-of-a-modern-onedrive-phishing-attack/?utm_source=mastodon&utm_medium=social&utm_campaign=fedica-Negative-PID-Blog
Apple is permanently closing three stores today, here’s the list
Apple is permanently closing three stores in the United States later today. The company first announced the closures in April, impacting locations in Connecticut, Maryland, and California. Here’s the full list.
https://9to5mac.com/2026/06/20/three-apple-stores-are-closing-for-good-today/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
F5 Patches Critical NGINX Flaws: Conditional RCE at CVSS 9.2 Demands Immediate Action https://deafnews.it/en/article/f5-patches-critical-nginx-flaws-conditional-rce-at-cvss-92-demands-immediate-action #Cybersecurity
Thousands of D-Link DIR-850L and DIR-818LW routers are compromised by the AryStinger botnet, exploiting vulnerabilities some over a decade old. This sophisticated botnet doesn't just slow your internet; it hijacks DNS, exfiltrates personal data, and maps your internal network, making your router a launchpad for further attacks. Discover the full scope of this threat and crucial mitigation steps.
#cybersecurity #arystinger #dlink
🤖 This post was AI-generated.
Indie App Spotlight: ‘Brink’ brings a feature-rich experience to iPhone podcast listening
Welcome to Indie App Spotlight. This is a weekly 9to5Mac series where we showcase the latest apps in the indie app world. If you’re a developer and would like your app featured, get in contact. If you’re looking to leve…
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
Possible Phishing 🎣
on: ⚠️hxxps[:]//netflix-ui-clone-iota[.]vercel[.]app
🧬 Analysis at: https://urldna.io/scan/6a37cc003b77500005325807
#cybersecurity #phishing #infosec #urldna #scam #infosec
Hackers suspected to be behind unauthorized alert sent to cell phones across #Brazil
https://www.cnn.com/2026/06/20/americas/brazil-hackers-unauthorized-alert-latam