voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]urlDNA.io :verified: » 🤖 🌐
@urldna@infosec.exchange

Possible Phishing 🎣
on: ⚠️hxxps[:]//vnrdxap[.]web[.]app/?dt=156&qr=PICS
🧬 Analysis at: urldna.io/scan/6a36a4c23b77500

    [?]TechWire ⚡ » 🤖 🌐
    @techwire@social.gamefan.net

    Widow’s Bay creator explains finale twists, teases season 2 plans

    Apple TV aired the Widow’s Bay finale last night, and today in a new interview the show’s creator goes behind the scenes on the finale, the upcoming season 2, and more.

    9to5mac.com/2026/06/17/widows-

    [9to5Mac]

      [?]TechWire ⚡ » 🤖 🌐
      @techwire@social.gamefan.net

      iA Writer 8 brings Liquid Glass design, clear icon support, more

      iA Writer, the lightweight text editor for Apple devices, is out with a new Liquid Glass design-focused update for iPhone, iPad, and Mac.

      9to5mac.com/2026/06/17/ia-writ

      [9to5Mac]

        [?]urlDNA.io :verified: » 🤖 🌐
        @urldna@infosec.exchange

        Possible Phishing 🎣
        on: ⚠️hxxps[:]//gmxdexxvz[.]weebly[.]com
        🧬 Analysis at: urldna.io/scan/6a3680e33b77500

          [?]OTX Bot » 🤖 🌐
          @techbot@social.raytec.co

          Gravity SMTP Plugin API Key Exposure Flaw has been Patched

          Gravity SMTP has disclosed a vulnerability affecting its WordPress email plugin that could allow unauthenticated attackers to steal sensitive API keys and system data.

          Pulse ID: 6a3701f1be6f045440063e23
          Pulse Link: otx.alienvault.com/pulse/6a370
          Pulse Author: cryptocti
          Created: 2026-06-20 21:11:13

          Be advised, this data is unverified and should be considered preliminary. Always do further verification.

            [?]CyberNetsecIO » 🌐
            @netsecio@mastodon.social

            📰 New 'Gentlemen' Ransomware Uses EDR Killer Framework to Blindside Security Tools

            New 'The Gentlemen' ransomware is aggressively disabling security tools. ⚔️ It uses a multi-pronged 'GentleKiller' framework to terminate EDR/AV products before encryption. Ensure your tamper protection is on!

            🌐 cyber[.]netsecops[.]io

            🔗 cyber.netsecops.io/articles/ge

              [?]CyberNetsecIO » 🌐
              @netsecio@mastodon.social

              📰 New 'Agentjacking' Attack Turns AI Coding Assistants into Malicious Insiders

              🤖 HACKED: New 'Agentjacking' attack turns AI coding assistants into trojans. Attackers inject malicious commands into fake Sentry bug reports, tricking agents like Cursor & Claude into running them on a dev's machine.

              🌐 cyber[.]netsecops[.]io

              🔗 cyber.netsecops.io/articles/ag

                [?]CyberNetsecIO » 🌐
                @netsecio@mastodon.social

                📰 Hackers Actively Exploit Gravity SMTP Flaw (CVE-2026-4020) to Steal API Keys from 100K WordPress Sites

                📢 ATTENTION WordPress Admins: A flaw in the Gravity SMTP plugin (CVE-2026-4020) is being mass-exploited to steal API keys. 100K sites at risk. Update to v2.1.5 & rotate all email service credentials NOW!

                🌐 cyber[.]netsecops[.]io

                🔗 cyber.netsecops.io/articles/gr

                  [?]TechWire ⚡ » 🤖 🌐
                  @techwire@social.gamefan.net

                  Apple One is getting better in iOS 27, here’s what’s new

                  Apple One is getting better in iOS 27, with subscribers set to benefit from new features coming to bundled Apple services like iCloud+ and Apple Music. Here’s what’s new.

                  9to5mac.com/2026/06/17/apple-o

                  [9to5Mac]

                    [?]Hugo | DevOps | Cybersecurity » 🌐
                    @hugovalters@mastodon.social

                    Vim: 45 CVEs tracked — 4 critical/high, avg CVSS 5.0, max 9.2. 77% unpatched. Trust Score: C. Plugin risks rising.

                    valtersit.com/vendors/vim/

                      [?]The New Oil » 🤖 🌐
                      @thenewoil@mastodon.thenewoil.org

                      [?]The New Oil » 🤖 🌐
                      @thenewoil@mastodon.thenewoil.org

                      [?]EUVD Bot » 🤖 🌐
                      @EUVD_Bot@mastodon.social

                      🚨 EUVD-2026-38120

                      📊 Score: 6.9/10 (CVSS v3.1)
                      📦 Product: capgo
                      🏢 Vendor: Capgo
                      📅 Updated: 2026-06-20

                      📝 Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /replication endpoint that exposes internal PostgreSQL replication telemetry including slot names and WAL LSN positions. Attackers can access this endpoint without auth...

                      🔗 euvd.enisa.europa.eu/vulnerabi

                        [?]EUVD Bot » 🤖 🌐
                        @EUVD_Bot@mastodon.social

                        🚨 EUVD-2026-38119

                        📊 Score: 6.0/10 (CVSS v3.1)
                        📦 Product: Flowise
                        🏢 Vendor: Flowise
                        📅 Updated: 2026-06-20

                        📝 Flowise before 3.1.2 contains a mass assignment vulnerability in the PUT /api/v1/user endpoint that allows authenticated users to directly modify the credential field without validation. Attackers can bypass password change verification and session invalidat...

                        🔗 euvd.enisa.europa.eu/vulnerabi

                          [?]EUVD Bot » 🤖 🌐
                          @EUVD_Bot@mastodon.social

                          🚨 EUVD-2026-38118

                          📊 Score: 6.9/10 (CVSS v3.1)
                          📦 Product: Flowise
                          🏢 Vendor: Flowise
                          📅 Updated: 2026-06-20

                          📝 Flowise before 3.0.13 contains an information exposure vulnerability in the POST /api/v1/account/forgot-password endpoint that returns full user objects including PII to unauthenticated attackers. An attacker can enumerate valid email addresses and harvest s...

                          🔗 euvd.enisa.europa.eu/vulnerabi

                            [?]EUVD Bot » 🤖 🌐
                            @EUVD_Bot@mastodon.social

                            🚨 EUVD-2026-38117

                            📊 Score: 6.9/10 (CVSS v3.1)
                            📦 Product: capgo
                            🏢 Vendor: Cap-go
                            📅 Updated: 2026-06-20

                            📝 Cap-go capgo before 12.128.2 contains an authorization bypass in several Supabase PostgREST RPC functions (get_app_metrics, get_global_metrics, get_total_metrics) that are granted to the anon role without enforcing org membership or permission checks. An unauth...

                            🔗 euvd.enisa.europa.eu/vulnerabi

                              [?]EUVD Bot » 🤖 🌐
                              @EUVD_Bot@mastodon.social

                              🚨 EUVD-2026-38116

                              📊 Score: 6.9/10 (CVSS v3.1)
                              📦 Product: capgo
                              🏢 Vendor: Capgo
                              📅 Updated: 2026-06-20

                              📝 Capgo before 12.128.2 fails to enforce a maximum value on the minimum password length field in its password policy configuration. An authenticated organization administrator can set an extremely large numeric value (e.g., billions of characters) as the minimum p...

                              🔗 euvd.enisa.europa.eu/vulnerabi

                                [?]EUVD Bot » 🤖 🌐
                                @EUVD_Bot@mastodon.social

                                🚨 EUVD-2026-38115

                                📊 Score: 5.3/10 (CVSS v3.1)
                                📦 Product: capgo
                                🏢 Vendor: Capgo
                                📅 Updated: 2026-06-20

                                📝 Capgo before 12.128.2 contains a server-side request forgery vulnerability in webhook URL validation that allows loopback and internal addresses. Organization admins can configure webhooks pointing to localhost or 127.0.0.1, and when triggered, the backend perfo...

                                🔗 euvd.enisa.europa.eu/vulnerabi

                                  [?]EUVD Bot » 🤖 🌐
                                  @EUVD_Bot@mastodon.social

                                  🚨 EUVD-2026-38114

                                  📊 Score: 6.9/10 (CVSS v3.1)
                                  📦 Product: capgo
                                  🏢 Vendor: Capgo
                                  📅 Updated: 2026-06-20

                                  📝 Capgo before 12.128.2 fails to strip EXIF metadata including GPS geolocation data from uploaded images, allowing information disclosure. Attackers can download uploaded images and extract precise latitude and longitude coordinates revealing user physical locatio...

                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                    [?]EUVD Bot » 🤖 🌐
                                    @EUVD_Bot@mastodon.social

                                    🚨 EUVD-2025-210289

                                    📊 Score: 5.1/10 (CVSS v3.1)
                                    📦 Product: Flowise
                                    🏢 Vendor: Flowise
                                    📅 Updated: 2026-06-20

                                    📝 Flowise before 3.0.8 contains a cross-site scripting (XSS) vulnerability caused by insufficient input filtering in chat messages and custom agent functions. An attacker can inject malicious JavaScript by sending an iframe payload (e.g., <iframe src="javasc...

                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                      [?]EUVD Bot » 🤖 🌐
                                      @EUVD_Bot@mastodon.social

                                      🚨 EUVD-2026-38113

                                      📊 Score: 2.3/10 (CVSS v3.1)
                                      📦 Product: capgo
                                      🏢 Vendor: Capgo
                                      📅 Updated: 2026-06-20

                                      📝 Capgo before 12.128.2 uses ILIKE pattern matching instead of exact matching for app_id lookup in the preview subdomain resolver, allowing underscore characters in app_id to act as SQL wildcards. Attackers can create apps with app_ids differing by one character a...

                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                        [?]EUVD Bot » 🤖 🌐
                                        @EUVD_Bot@mastodon.social

                                        🚨 EUVD-2026-38112

                                        📊 Score: 2.3/10 (CVSS v3.1)
                                        📦 Product: nuxt, nuxt
                                        🏢 Vendor: nuxt
                                        📅 Updated: 2026-06-20

                                        📝 Nuxt before 4.4.7 (and the 3.x branch before 3.21.7) contains a cross-site scripting vulnerability in the NoScript component that writes slot content to innerHTML without escaping. Attackers can inject malicious scripts through untrusted data in NoScript slo...

                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                          [?]EUVD Bot » 🤖 🌐
                                          @EUVD_Bot@mastodon.social

                                          🚨 EUVD-2024-55642

                                          📊 Score: 9.3/10 (CVSS v3.1)
                                          📦 Product: Flowise
                                          🏢 Vendor: Flowise
                                          📅 Updated: 2026-06-20

                                          📝 Flowise before 2.1.4 allows configuration to be injected into the Chainflow during execution via the overrideConfig option, supported in both the frontend web integration and the backend Prediction API. Because this feature is enabled by default with no allo...

                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                            [?]TechWire ⚡ » 🤖 🌐
                                            @techwire@social.gamefan.net

                                            This Sunday’s Apple Watch Activity Challenge celebrates International Day of Yoga

                                            On June 21, Apple Watch users will be able to earn a special badge and animated iMessage stickers by completing Apple’s International Day of Yoga Challenge. Here’s how to get them.

                                            9to5mac.com/2026/06/16/this-su

                                            [9to5Mac]

                                              [?]TechWire ⚡ » 🤖 🌐
                                              @techwire@social.gamefan.net

                                              Eugene Levy’s Apple TV travel series is coming back for season 4

                                              Following a successful third season, where Eugene Levy went around the world to cross off several items on his bucket list, Apple TV confirmed today that ‘The Reluctant Traveler with Eugene Levy’ has been renewed for 8 …

                                              9to5mac.com/2026/06/16/eugene-

                                              [9to5Mac]

                                                [?]urlDNA.io :verified: » 🤖 🌐
                                                @urldna@infosec.exchange

                                                Possible Phishing 🎣
                                                on: ⚠️hxxps[:]//jasonalex02041992-coder[.]github[.]io/testing/
                                                🧬 Analysis at: urldna.io/scan/6a36b2b73b77500

                                                  [?]The New Oil » 🤖 🌐
                                                  @thenewoil@mastodon.thenewoil.org

                                                  [?]TechWire ⚡ » 🤖 🌐
                                                  @techwire@social.gamefan.net

                                                  MyFitnessPal adds AI-powered Coach for personalized nutrition guidance

                                                  MyFitnessPal is adding a new AI-powered coaching experience that turns users’ food logs, goals, meals, and habits into personalized nutrition guidance. Here are the details.

                                                  9to5mac.com/2026/06/16/myfitne

                                                  [9to5Mac]

                                                    [?]Negative PID SL » 🌐
                                                    @negativepid@mastodon.social

                                                    [?]ChiefGyk3D » 🌐
                                                    @chiefgyk3d@social.chiefgyk3d.com

                                                    Want to *really* get Linux? Forget the books – it's all about diving in! 💻 This short explores how to immerse yourself in the system, starting with a fun cybersecurity project. Check it out!

                                                    youtube.com/watch?v=-vMKXkxWpWQ

                                                    🔴 LIVE

                                                    Alt...🔴 LIVE

                                                      [?]TechWire ⚡ » 🤖 🌐
                                                      @techwire@social.gamefan.net

                                                      Toy Story has the right take on tech

                                                      Hi, friends! Welcome to Installer No. 133, your guide to the best and Verge-iest stuff in the world. (If you're new here, welcome, happy belated Juneteenth, and also you can read all the old editions at the Installer ho…

                                                      theverge.com/tech/952547/toy-s

                                                      [The Verge]

                                                        [?]TechWire ⚡ » 🤖 🌐
                                                        @techwire@social.gamefan.net

                                                        Intel and AMD's new ACE CPU extensions bring an efficient AI-oriented instruction set to x86 — a new design makes matrix multiplication more power- and density-efficient

                                                        ACE CPU extensions bring an efficient AI-oriented instruction set to x86 — new design makes matrix multiplication more power- and density-efficient

                                                        tomshardware.com/pc-components

                                                        [Tom's Hardware]

                                                          [?]urlDNA.io :verified: » 🤖 🌐
                                                          @urldna@infosec.exchange

                                                          Possible Phishing 🎣
                                                          on: ⚠️hxxps[:]//dferyrdsii[.]weebly[.]com/
                                                          🧬 Analysis at: urldna.io/scan/6a3618183b77500

                                                            [?]ChiefGyk3D » 🌐
                                                            @chiefgyk3d@social.chiefgyk3d.com

                                                            It is wild how many people in cybersecurity treat SASE/ZTNA and WireGuard or OpenVPN as interchangeable. It is not just “moving trust to a vendor”—NetBird can be self-hosted. If you do not understand SASE, stop arguing and start studying.

                                                              [?]TechWire ⚡ » 🤖 🌐
                                                              @techwire@social.gamefan.net

                                                              Microsoft just gave Outlook for Mac an ‘app-wide’ Liquid Glass update

                                                              Microsoft Outlook should now look more at home on the Mac with today’s “app-wide” Liquid Glass update.

                                                              9to5mac.com/2026/06/16/microso

                                                              [9to5Mac]

                                                                [?]TechWire ⚡ » 🤖 🌐
                                                                @techwire@social.gamefan.net

                                                                Apple just released new AirPods Pro 3 firmware, more

                                                                Apple has just released new firmware for users of AirPods Pro 3 and AirPods Pro 2. Here’s how you can install the latest update.

                                                                9to5mac.com/2026/06/16/apple-j

                                                                [9to5Mac]

                                                                  [?]urlDNA.io :verified: » 🤖 🌐
                                                                  @urldna@infosec.exchange

                                                                  Possible Phishing 🎣
                                                                  on: ⚠️hxxps[:]//netflix-clone-mauve-beta[.]vercel[.]app
                                                                  🧬 Analysis at: urldna.io/scan/6a3642313b77500

                                                                    [?]Hugo | DevOps | Cybersecurity » 🌐
                                                                    @hugovalters@mastodon.social

                                                                    Parse Server: 70 CVEs, AVG CVSS 7.4, Max 10. 100% unpatched. Trust Score: D. Authentication and injection flaws rampant. Open source doesn't mean immune.

                                                                    valtersit.com/vendors/parse-se

                                                                      [?]TierraSapiens » 🤖 🌐
                                                                      @tierrasapiens@mastodon.social

                                                                      🖲️
                                                                      ⚫ Salesforce Data Thefts Continue via Klue App Compromise
                                                                      🔗 darkreading.com/cyberattacks-d

                                                                      Klue's Battlecards is now the third integrated application that has been compromised to steal customers' Salesforce data, and victims include Huntress, the cybersecurity vendor.

                                                                        [?]TechWire ⚡ » 🤖 🌐
                                                                        @techwire@social.gamefan.net

                                                                        Love NotebookLM but hate giving Google your data? I found a great open-source alternative

                                                                        Open Notebook works a lot like NotebookLM, but it can hook up to both cloud and local AI models.

                                                                        androidauthority.com/notebookl

                                                                        [Android Authority]

                                                                          [?]TechWire ⚡ » 🤖 🌐
                                                                          @techwire@social.gamefan.net

                                                                          The best 3D scanners 2026 — the top performing models we've benchmarked

                                                                          We help you find the best 3D scanners for high accuracy, portability, and more.

                                                                          tomshardware.com/3d-printing/t

                                                                          [Tom's Hardware]

                                                                            Back to top - More...