voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
🚨 EUVD-2026-37899
📊 Score: 8.4/10 (CVSS v3.1)
📦 Product: Eclipse Theia
🏢 Vendor: Eclipse Foundation
📅 Updated: 2026-06-18
📝 In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded and could override or extend the AI agent's system prompts. An attacker could craft a malicious reposito...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-37899
🚨 EUVD-2026-37898
📊 Score: 8.4/10 (CVSS v3.1)
📦 Product: Eclipse Theia
🏢 Vendor: Eclipse Foundation
📅 Updated: 2026-06-18
📝 In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context without distinguishing them from system instructions. An attacker could craft a malicious repository with...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-37898
Klue Breach: Dormant OAuth Credential Opens Multi-Victim Door to Salesforce https://deafnews.it/en/article/klue-breach-dormant-oauth-credential-opens-multi-victim-door-to-salesforce #Cybersecurity
Google Calendar finally has more color options for events
There are now 24 default color options instead of 11, and you can select more via an RGB color picker. | Image: Google Running out of color options for events in Google Calendar shouldn't be an issue going forward. The …
https://www.theverge.com/tech/952123/google-calendar-event-color-options-expansion
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Galaxy Watch owners report that they can’t get certain apps to open
An app launch issue is affecting some Galaxy Watches.
https://www.androidauthority.com/samsung-galaxy-watch-app-launch-bug-3679071/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
🚨New ransom group blog post!🚨
Group name: qilin
Post title: ATCOM Outsourcing
Info: https://cti.fyi/groups/qilin.html
#ransomware #cti #threatintelligence #cybersecurity #infosec
📊 EUVD Monthly CVSS Summary
🟠 Average Score: 7.66/10 (High)
📈 Vulnerabilities: 694
⬇️ Min: 2.1 | ⬆️ Max: 10.0
📅 Period: 2026-05-19 - 2026-06-17
Possible Phishing 🎣
on: ⚠️hxxp[:]//amazon-clone-blue-nu[.]vercel[.]app
🧬 Analysis at: https://urldna.io/scan/6a33ad633b7750000991b726
#cybersecurity #phishing #infosec #urldna #scam #infosec
UK: More than one year later, HCRG is first notifying patients of a ransomware attack:
This is the one where they ran to the High Court in the UK to get injunctions that their lawyers sent to @amvinfe and me.
It seems they are first notifying patients now -- 16 months after the attack.
#healthsec #cybersecurity #incidentresponse #HCRG #injunction
#databreach #ransomware
No more lightbulbs, much more sports: Five predictions for Roku’s future
This is Lowpass by Janko Roettgers, a newsletter on the ever-evolving intersection of tech and entertainment, syndicated just for The Verge subscribers once a week. When Fox announced its acquisition of Roku earlier thi…
https://www.theverge.com/column/951850/fox-roku-predictions
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
🚨 EUVD-2026-37873
📊 Score: 5.9/10 (CVSS v3.1)
📦 Product: Bricksable for Bricks Builder
🏢 Vendor: Bricksable
📅 Updated: 2026-06-18
📝 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bricksable for Bricks Builder allows Stored XSS.
This issue affects Bricksable for Bricks Builder: from n/a through 1.6.83.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-37873
Elastic: 87 CVEs tracked, 95% unpatched. Trust Score: C. Top weaknesses in CWE-770 (resource mgmt). Even SIEM tools need patching. #Elastic #cybersecurity #infosec
Qilin Ransomware Group Claims Attack on Australian Tutoring Provider Kinetic Education
The Qilin ransomware group claimed responsibility for a cyberattack on Australian tutoring provider Kinetic Education, listing the company on its dark web leak site. The listing did not have any proof. The attack is not confirmed by the company.
****
#cybersecurity #infosec #incident #ransomware
https://beyondmachines.net/event_details/qilin-ransomware-group-claims-attack-on-australian-tutoring-provider-kinetic-education-h-5-m-o-k/gD2P6Ple2L
Apple Beats: Bluetooth Flaw Turns Headphones Into Spy Microphones https://deafnews.it/en/article/apple-beats-bluetooth-flaw-turns-headphones-into-spy-microphones #Cybersecurity
This Galaxy Z Fold 8 rival could put Ultra flagships to shame with its huge battery
The X Fold 6's battery will put conventional Ultra and Pro Max phones to shame.
https://www.androidauthority.com/vivo-galaxy-z-fold-8-rival-battery-size-3678904/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
I found 10k GitHub repositories distributing Trojan malware
https://orchidfiles.com/github-repositories-distributing-malware/
#HackerNews #malware #cybersecurity #GitHub #Trojan #repositories #threatintelligence #hacking
🎩 Wow, Sherlock! You discovered 10k malware-infested #GitHub #repositories just by Googling and #Binging. Next time, try using a magnifying glass 🔍—might find even more! 💀
https://orchidfiles.com/github-repositories-distributing-malware/ #Sherlock #Malware #Google #Cybersecurity #HackerNews #ngated
Security teams have no shortage of tools, but visibility remains a major challenge. ThreatAware’s $25 million funding round highlights growing interest in cyber asset management as a way to unify fragmented security operations, improve asset visibility and identify gaps that traditional security tools can miss.
Read the full story: https://www.techfinitive.com/features/cyber-asset-management-why-threatawares-25m-bet-could-redefine-secops/
The traditional annual penetration test is increasingly out of step with today’s threat landscape. As attackers probe systems continuously, organisations are looking for more proactive approaches. Hadrian’s Nova platform reflects that shift, bringing AI-driven, on-demand penetration testing to help identify weaknesses before attackers do.
Read the full story: https://www.techfinitive.com/features/how-hadrians-nova-is-making-always-on-offense-a-security-baseline/
#AI #CISO #Cybersecurity #PenetrationTesting #VulnerabilityManagement
Looking forward to DEF CON 34. I’ll be part of Call Center Village this year, so there’s a good chance you’ll find me there. Feel free to say hi, I’ll have stickers. Just remember if you take photos, make sure everyone in frame has given permission first #DEFCON #CallCenterVillage #Cybersecurity
1/2
Google Vids is making it easier to create longer clips with Veo
It just got easier to create longer and better video clips in Google Vids.
https://www.androidauthority.com/google-vids-longer-clips-simultaneous-generations-3678940/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
🚨New ransom group blog post!🚨
Group name: akira
Post title: Apptricity
Info: https://cti.fyi/groups/akira.html
#ransomware #cti #threatintelligence #cybersecurity #infosec
Possible Phishing 🎣
on: ⚠️hxxp[:]//bafkreigbpzdt7rw6lfjs3tebur3rc7vcwgpc3ajljyikugl4kf6f3v7u5e[.]ipfs[.]dweb[.]link/
🧬 Analysis at: https://urldna.io/scan/6a339f313b77500007b94d25
#cybersecurity #phishing #infosec #urldna #scam #infosec
FortiBleed: 75.000 Fortinet-Firewalls weltweit kompromittiert
Den vorliegenden Daten zufolge wurden 73.932 eindeutige Firewall-URLs in 194 Ländern kompromittiert, was rund 21.632 betroffene Domains ergibt.
https://www.all-about-security.de/fortibleed-75-000-fortinet-firewalls-weltweit-kompromittiert/
YouTube is testing another Android redesign, and your muscle memory might hate it
YouTube could redesign the buttons on its Android app again.
https://www.androidauthority.com/youtube-ui-redesign-test-again-3678953/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
🚨 EUVD-2026-37854
📊 Score: 9.4/10 (CVSS v3.1)
📦 Product: Cotonti
🏢 Vendor: Cotonti
📅 Updated: 2026-06-18
📝 Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration rights handler. In system/admin/admin.rights.php, the rights update action ('a=update') modifies group access rights (including via cot_auth_add_...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-37854
🚨 EUVD-2026-37853
📊 Score: 8.7/10 (CVSS v3.1)
📦 Product: Cotonti
🏢 Vendor: Cotonti
📅 Updated: 2026-06-18
📝 Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration configuration handler. In system/admin/admin.config.php, the configuration update action ('a=update') processes POST data via cot_config_update_o...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-37853
🚨 EUVD-2026-37852
📊 Score: n/a
📦 Product: MagicForm
🏢 Vendor: Unknown
📅 Updated: 2026-06-18
📝 The MagicForm WordPress plugin through 0.1.3 does not properly validate the type of files uploaded through an unauthenticated AJAX action when a form's per-field extension allowlist is left empty, allowing unauthenticated attackers to upload PHP files and execute arbitra...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-37852
Possible Phishing 🎣
on: ⚠️hxxps[:]//metamaskwallet[.]to/
🧬 Analysis at: https://urldna.io/scan/6a3397923b77500007b94c68
#cybersecurity #phishing #infosec #urldna #scam #infosec
MariaDB Patches Critical Command Injection Flaws in Community Server
MariaDB released security updates for Community Server to fix four vulnerabilities, including a maximum-severity CVSS 10.0 flaw that allows arbitrary shell command execution via Galera Cluster components.
**Update your MariaDB clusters to the latest secure versions as soon as possible to fully block remote command execution. If you cannot patch right now, disable the wsrep_notify_cmd setting to stop the most dangerous exploit path. Ensure you check all active cluster environments, as this flaw specifically targets high-availability production systems running Galera Cluster.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/mariadb-patches-critical-command-injection-flaws-in-community-server-d-a-z-6-o/gD2P6Ple2L
CISA Adds Oracle PeopleSoft Zero-Day CVE-2026-35273 to KEV Catalog After Ransomware Gang Exploitation
#CyberSecurity
https://securebulletin.com/cisa-adds-oracle-peoplesoft-zero-day-cve-2026-35273-to-kev-catalog-after-ransomware-gang-exploitation/
Kodak Confirms Data Breach as ShinyHunters Claims 2.2 Million Customer Records Stolen
#CyberSecurity
https://securebulletin.com/kodak-confirms-data-breach-as-shinyhunters-claims-2-2-million-customer-records-stolen/
Android 17 is rolling out, but it’s missing the one feature I was really looking forward to
Improved gaming will have to wait a little longer.
https://www.androidauthority.com/android-17-update-missing-one-feature-i-really-wanted-3678527/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]