voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
#chrome extension Lunethwatch seems malicious. Its #cybersecurity badness score is 89/100!
```json
{"id": "ogkhkgoakclmbjbhbdpbapmjflflmhnc", "score": 89, "platform": "chrome", "name": "Lunethwatch"}
```
T1 Phone PR firm is ‘not assisting Trump Mobile any further’
Where's the Trump phone? We're going to keep talking about it every week. We don't have the phones we preordered yet, but this week we received unexpected news from Trump Mobile's media relations manager. If you've been…
https://www.theverge.com/gadgets/952274/t1-phone-pr-firm-not-assisting-trump-mobile-any-further
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Possible Phishing 🎣
on: ⚠️hxxp[:]//login[.]credits-center[.]com/
🧬 Analysis at: https://urldna.io/scan/6a34d4a73b7750000554b973
#cybersecurity #phishing #infosec #urldna #scam #infosec
✨ Operation Endgame abbatte SocGholish: 100 server offline e 15.000 siti risanati nell’operazione contro Evil Corp
#CyberSecurity
https://insicurezzadigitale.com/operation-endgame-abbatte-socgholish-100-server-offline-e-15-000-siti-risanati-nelloperazione-contro-evil-corp/
✨ LLMjacking si evolve: server Ollama esposti diventano il cervello di uno strumento di hacking autonomo, catturato in sviluppo da Sysdig
#CyberSecurity
https://insicurezzadigitale.com/llmjacking-si-evolve-server-ollama-esposti-diventano-il-cervello-di-uno-strumento-di-hacking-autonomo-catturato-in-sviluppo-da-sysdig/
Scammers in China sell $222 RTX 4090 with fake GPU die made out of plastic instead of real silicon — marked with 2030 production dates, the card didn't even have working VRAM
Nvidia dupes keep getting more sophisticated as time goes on, with the latest example using a plastic die instead of real silicon on an RTX 4090.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
🚨 EUVD-2026-37996
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: 2Download Connector for 2DL Hosted Checkout
🏢 Vendor: 2download
📅 Updated: 2026-06-19
📝 The 2Download Connector for 2DL Hosted Checkout plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 0.1.5. This is due to the plugin not properly verifying that a user is autho...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-37996
🚨 EUVD-2026-37995
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: STRABL – A checkout solution
🏢 Vendor: strablengineering
📅 Updated: 2026-06-19
📝 The STRABL – A checkout solution plugin for WordPress is vulnerable to Missing Authentication in all versions up to and including 4.5. The plugin registers a REST API webhook endpoint at /wp-json/strabl/webhook/order with a per...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-37995
🚨 EUVD-2026-37979
📊 Score: 5.9/10 (CVSS v3.1)
📦 Product: Armeria
🏢 Vendor: LY Corporation
📅 Updated: 2026-06-19
📝 A vulnerability has been identified in armeria-xds versions 1.38.0 through 1.39.0, where DataSourceStream in the xDS module can resolve control-plane-supplied filenames and environment variables without restriction, allowing a compromised or semi-trus...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-37979
Cisco Patches Critical Root RCE and Credential Theft Flaws in ISE
Cisco patched a critical root RCE vulnerability (CVE-2026-20181) and a high-severity information disclosure flaw (CVE-2026-20190) in its Identity Services Engine. These vulnerabilities allow authenticated root access or theft of hashed credentials.
**Make sure your Cisco ISE and ISE-PIC systems are isolated from the internet and reachable only from trusted management networks. Apply the latest patches immediately (ISE 3.3 Patch 11, 3.4 Patch 6, or 3.5 Patch 3) and for the 3.5 command-execution fix, request the hotfix from Cisco TAC now. Don't wait for Patch 4 in August 2026.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/cisco-patches-critical-root-rce-and-credential-theft-flaws-in-ise-o-v-f-q-7/gD2P6Ple2L
Operation FlutterBridge: The FlutterShell macOS Backdoor
FlutterShell is a macOS backdoor campaign active from December 2025 to March 2026, identified as cluster CL-CRI-1089 under Operation FlutterBridge. The threat actors deliberately misused the Flutter framework to deliver malware through malvertising campaigns on Google and YouTube. The malware employs a two-component architecture: a thin Mach-O launcher and a large Flutter payload dylib. Across three generations, the operators rotated Apple Developer certificates, implemented progressive Dart obfuscation, and renamed bridge commands to evade detection. The backdoor uses a WKWebView to load attacker-controlled JavaScript from C2 servers, implementing a conditional execution model where commands are delivered at runtime via a JavaScript-to-native bridge called flutterInvoke. The primary impact includes Chrome browser hijacking to inject sinterfumesco[.]com as the default search provider and persistent infection through silent Sparkle framework updates.
Pulse ID: 6a34874a01c1f77a4c242d5b
Pulse Link: https://otx.alienvault.com/pulse/6a34874a01c1f77a4c242d5b
Pulse Author: AlienVault
Created: 2026-06-19 00:03:22
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Browser #Chrome #CyberSecurity #Google #InfoSec #Java #JavaScript #Mac #MacOS #Malvertising #Malware #OTX #OpenThreatExchange #RAT #Troll #YouTube #bot #AlienVault
4 security upgrades in Android 17 you didn’t know about, but will be glad to have
Forget App Bubbles, Android 17 is all about tougher security.
https://www.androidauthority.com/android-17-security-upgrades-3679016/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
A massive credential leak, dubbed FortiBleed, has compromised nearly 74,000 Fortinet firewall and VPN devices globally, prompting an urgent warning from CISA. Security researchers discovered plaintext passwords and critical business intelligence circulating, enabling highly targeted attacks against major corporations and government agencies. This incident highlights how overlooked updates and exposed…
#cybersecurity #cisa #fortinet
🤖 This post was AI-generated.
Apple's WebKit Rules Reportedly Cost iOS Users Almost 30% Browser Performance
Microsoft engineers have published benchmark results showing that a Chromium-based browser using its own rendering engine scores 28.6% higher than Safari on Apple's own Speedometer 3.1 performance test on iOS. Kyle Pflu…
https://www.macrumors.com/2026/06/17/webkit-rule-costs-ios-users-browser-performance/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #MacRumors [MacRumors]
Possible Phishing 🎣
on: ⚠️hxxps[:]//sonic999[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a34c6aa3b7750000554b83d
#cybersecurity #phishing #infosec #urldna #scam #infosec
Popa: From Sourcing to Distribution
An Android proxyware SDK named Popa enrolls consumer devices including phones, tablets, and streaming boxes into a commercial residential proxy network. Operating since at least 2020, Popa and its variants (Loopop, Neupop, and Moneytiser) are distributed inside consumer streaming, IPTV, and utility applications. The SDK begins relaying third-party traffic at host-app launch without displaying informed-consent prompts in analyzed samples. Multiple variants communicate directly with NetNut SDK endpoints, sharing operational infrastructure and telemetry. Controlled testing showed traffic from Popa-enrolled devices egressing through NetNut's commercial gateway. The SDK uses encrypted Google Drive files to resolve relay servers in later versions. Analysis of over 20 publishers revealed significant links to piracy-related applications, with none observed requesting user consent despite later builds including this capability.
Pulse ID: 6a3447ad5cdebd92116d1c01
Pulse Link: https://otx.alienvault.com/pulse/6a3447ad5cdebd92116d1c01
Pulse Author: AlienVault
Created: 2026-06-18 19:31:57
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #CyberSecurity #Endpoint #Google #InfoSec #OTX #OpenThreatExchange #Proxy #RAT #Troll #bot #AlienVault
CVE Alert: CVE-2026-47633 - Microsoft - Microsoft Cost Management - https://www.redpacketsecurity.com/cve-alert-cve-2026-47633-microsoft-microsoft-cost-management/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-47633 #microsoft #microsoft-cost-management
CVE Alert: CVE-2026-25865 - Yandex - Punto Switcher - https://www.redpacketsecurity.com/cve-alert-cve-2026-25865-yandex-punto-switcher/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-25865 #yandex #punto-switcher
CVE Alert: CVE-2026-55203 - haproxy - haproxy - https://www.redpacketsecurity.com/cve-alert-cve-2026-55203-haproxy-haproxy/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-55203 #haproxy #
CVE Alert: CVE-2026-56076 - PraisonAI - PraisonAI - https://www.redpacketsecurity.com/cve-alert-cve-2026-56076-praisonai-praisonai/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-56076 #praisonai #
CVE Alert: CVE-2026-32174 - Microsoft - Azure AI Bot Service - https://www.redpacketsecurity.com/cve-alert-cve-2026-32174-microsoft-azure-ai-bot-service/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-32174 #microsoft #azure-ai-bot-service
CVE Alert: CVE-2026-56075 - PraisonAI - PraisonAI - https://www.redpacketsecurity.com/cve-alert-cve-2026-56075-praisonai-praisonai/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-56075 #praisonai #
CVE Alert: CVE-2026-56078 - PraisonAI - PraisonAI - https://www.redpacketsecurity.com/cve-alert-cve-2026-56078-praisonai-praisonai/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-56078 #praisonai #
This all-new OnePlus phone could deliver three days of battery life
OnePlus also says the battery should last for seven years before dropping to 80% effective capacity.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Virtual Private Networks (VPNs): Security Benefits, Risks, and Hardening Steps - https://www.redpacketsecurity.com/virtual-private-networks-vpns-security-benefits-risks-and-hardening-steps/
🟠 CVE-2026-12044 - High (8.8)
SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ... IS ''`` for a user-supplied description field. The Jinja templates for Domains (and their constraints), Foreign Tables, Languages, and Event Triggers, plus the V...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12044/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Sayonara, SocGholish: Operation Endgame Disrupts Major Cybercrime Operation
Pulse ID: 6a34cbbc7e4b5194d30dc276
Pulse Link: https://otx.alienvault.com/pulse/6a34cbbc7e4b5194d30dc276
Pulse Author: Tr1sa111
Created: 2026-06-19 04:55:24
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberCrime #CyberSecurity #InfoSec #OTX #OpenThreatExchange #RAT #SocGholish #bot #Tr1sa111
Okendo Reviews Supply Chain Attack
Pulse ID: 6a34cbc32e5c3ef69d3a9fda
Pulse Link: https://otx.alienvault.com/pulse/6a34cbc32e5c3ef69d3a9fda
Pulse Author: Tr1sa111
Created: 2026-06-19 04:55:31
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #SupplyChain #bot #Tr1sa111
May 2026 Infostealer Trend Report
Pulse ID: 6a34cbb532c82b2bc8fcf275
Pulse Link: https://otx.alienvault.com/pulse/6a34cbb532c82b2bc8fcf275
Pulse Author: Tr1sa111
Created: 2026-06-19 04:55:17
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #InfoStealer #OTX #OpenThreatExchange #bot #Tr1sa111
Operation Endgame vs. SocGholish Fake Updates
Pulse ID: 6a34cba974f9e6df17b34f2b
Pulse Link: https://otx.alienvault.com/pulse/6a34cba974f9e6df17b34f2b
Pulse Author: Tr1sa111
Created: 2026-06-19 04:55:05
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #FakeUpdates #InfoSec #OTX #OpenThreatExchange #RAT #SocGholish #bot #Tr1sa111
GitBait: Phishing targeting the Mexican financial sector
Pulse ID: 6a34cba1798c13e7d298b759
Pulse Link: https://otx.alienvault.com/pulse/6a34cba1798c13e7d298b759
Pulse Author: Tr1sa111
Created: 2026-06-19 04:54:57
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Mexican #OTX #OpenThreatExchange #Phishing #bot #Tr1sa111
Interpol: $40 Billion Scam Economy in Asia, Cybercrime Tops 30% of All Crime https://deafnews.it/en/article/interpol-40-billion-scam-economy-in-asia-cybercrime-tops-30-of-all-crime #Cybersecurity
Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign
Pulse ID: 6a34cb9726e209e5c156ae25
Pulse Link: https://otx.alienvault.com/pulse/6a34cb9726e209e5c156ae25
Pulse Author: Tr1sa111
Created: 2026-06-19 04:54:47
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Malvertising #OTX #OpenThreatExchange #bot #Tr1sa111
Twitter Feed - nextronresearch - 17-06-2026
Pulse ID: 6a34cb876d27b0b85ae34466
Pulse Link: https://otx.alienvault.com/pulse/6a34cb876d27b0b85ae34466
Pulse Author: Tr1sa111
Created: 2026-06-19 04:54:31
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #Twitter #bot #Tr1sa111
From package to postinstall payload: Inside the Mastra npm supply chain compromise
Pulse ID: 6a34cb8f55b5585c6ad763cf
Pulse Link: https://otx.alienvault.com/pulse/6a34cb8f55b5585c6ad763cf
Pulse Author: Tr1sa111
Created: 2026-06-19 04:54:39
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #SupplyChain #bot #Tr1sa111
Klue Integration Abused in Salesforce Data Theft | Threat Spotlight
Pulse ID: 6a34cb7f1611bbfeceb58197
Pulse Link: https://otx.alienvault.com/pulse/6a34cb7f1611bbfeceb58197
Pulse Author: Tr1sa111
Created: 2026-06-19 04:54:23
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DataTheft #InfoSec #OTX #OpenThreatExchange #RAT #RCE #bot #Tr1sa111
Crypto Clipper uses Tor and worm-like propagation for persistence and control
Pulse ID: 6a34cb768b57470189224185
Pulse Link: https://otx.alienvault.com/pulse/6a34cb768b57470189224185
Pulse Author: Tr1sa111
Created: 2026-06-19 04:54:14
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #Worm #bot #Tr1sa111
Save a whopping 62% on this 8-port multi-Gigabit 2.5G Ethernet switch in Amazon's Early Prime Day sale — upgrade your home network for just $49
Add more ports to your network setup with this unmanaged multi-Gigabit switch for just $49.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
Defensive lessons from an exposed ICS/IoT honeypot: keep OT protocols private, block egress, kill default credentials, segment networks, and log behaviour. https://hackernoon.com/building-a-fake-solar-plant-for-cybersecurity-research-part-3 #cybersecurity
Save a huge 85% on a two-year Surfshark VPN subscription for your home or office and grab three extra months free — huge…
This Surfshark One 2-year VPN deal is now just $75.33, giving you a huge $436.32 saving compared to a standard monthly subscription, with three months extra thrown in for free to keep you protected online.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
Possible Phishing 🎣
on: ⚠️hxxps[:]//t[.]co/3wB8JWip2I
🧬 Analysis at: https://urldna.io/scan/6a3424333b77500007b95f21
#cybersecurity #phishing #infosec #urldna #scam #infosec