voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]EUVD Bot » 🤖 🌐
@EUVD_Bot@mastodon.social

🚨 EUVD-2026-37899

📊 Score: 8.4/10 (CVSS v3.1)
📦 Product: Eclipse Theia
🏢 Vendor: Eclipse Foundation
📅 Updated: 2026-06-18

📝 In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded and could override or extend the AI agent's system prompts. An attacker could craft a malicious reposito...

🔗 euvd.enisa.europa.eu/vulnerabi

    [?]EUVD Bot » 🤖 🌐
    @EUVD_Bot@mastodon.social

    🚨 EUVD-2026-37898

    📊 Score: 8.4/10 (CVSS v3.1)
    📦 Product: Eclipse Theia
    🏢 Vendor: Eclipse Foundation
    📅 Updated: 2026-06-18

    📝 In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context without distinguishing them from system instructions. An attacker could craft a malicious repository with...

    🔗 euvd.enisa.europa.eu/vulnerabi

      [?]The New Oil » 🤖 🌐
      @thenewoil@mastodon.thenewoil.org

      [?]deafnews » 🤖 🌐
      @deafnews@infosec.exchange

      [?]TechWire ⚡ » 🤖 🌐
      @techwire@social.gamefan.net

      Google Calendar finally has more color options for events

      There are now 24 default color options instead of 11, and you can select more via an RGB color picker. | Image: Google Running out of color options for events in Google Calendar shouldn't be an issue going forward. The …

      theverge.com/tech/952123/googl

      [The Verge]

        [?]TechWire ⚡ » 🤖 🌐
        @techwire@social.gamefan.net

        Galaxy Watch owners report that they can’t get certain apps to open

        An app launch issue is affecting some Galaxy Watches.

        androidauthority.com/samsung-g

        [Android Authority]

          [?]CTI.FYI » 🤖 🌐
          @CTI_FYI@infosec.exchange

          🚨New ransom group blog post!🚨

          Group name: qilin
          Post title: ATCOM Outsourcing
          Info: cti.fyi/groups/qilin.html

            [?]EUVD Bot » 🤖 🌐
            @EUVD_Bot@mastodon.social

            📊 EUVD Monthly CVSS Summary

            🟠 Average Score: 7.66/10 (High)
            📈 Vulnerabilities: 694
            ⬇️ Min: 2.1 | ⬆️ Max: 10.0

            📅 Period: 2026-05-19 - 2026-06-17

              [?]urlDNA.io :verified: » 🤖 🌐
              @urldna@infosec.exchange

              Possible Phishing 🎣
              on: ⚠️hxxp[:]//amazon-clone-blue-nu[.]vercel[.]app
              🧬 Analysis at: urldna.io/scan/6a33ad633b77500

                [?]Dissent Doe :cupofcoffee: [She/Her] » 🌐
                @PogoWasRight@infosec.exchange

                UK: More than one year later, HCRG is first notifying patients of a ransomware attack:

                databreaches.net/2026/06/18/uk

                This is the one where they ran to the High Court in the UK to get injunctions that their lawyers sent to @amvinfe and me.

                It seems they are first notifying patients now -- 16 months after the attack.


                  [?]TechWire ⚡ » 🤖 🌐
                  @techwire@social.gamefan.net

                  No more lightbulbs, much more sports: Five predictions for Roku’s future

                  This is Lowpass by Janko Roettgers, a newsletter on the ever-evolving intersection of tech and entertainment, syndicated just for The Verge subscribers once a week. When Fox announced its acquisition of Roku earlier thi…

                  theverge.com/column/951850/fox

                  [The Verge]

                    [?]EUVD Bot » 🤖 🌐
                    @EUVD_Bot@mastodon.social

                    🚨 EUVD-2026-37873

                    📊 Score: 5.9/10 (CVSS v3.1)
                    📦 Product: Bricksable for Bricks Builder
                    🏢 Vendor: Bricksable
                    📅 Updated: 2026-06-18

                    📝 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bricksable for Bricks Builder allows Stored XSS.

                    This issue affects Bricksable for Bricks Builder: from n/a through 1.6.83.

                    🔗 euvd.enisa.europa.eu/vulnerabi

                      [?]Hugo | DevOps | Cybersecurity » 🌐
                      @hugovalters@mastodon.social

                      Elastic: 87 CVEs tracked, 95% unpatched. Trust Score: C. Top weaknesses in CWE-770 (resource mgmt). Even SIEM tools need patching.

                      valtersit.com/vendors/elastic/

                        [?]BeyondMachines :verified: » 🤖 🌐
                        @beyondmachines1@infosec.exchange

                        Qilin Ransomware Group Claims Attack on Australian Tutoring Provider Kinetic Education

                        The Qilin ransomware group claimed responsibility for a cyberattack on Australian tutoring provider Kinetic Education, listing the company on its dark web leak site. The listing did not have any proof. The attack is not confirmed by the company.

                        ****

                        beyondmachines.net/event_detai

                          [?]deafnews » 🤖 🌐
                          @deafnews@infosec.exchange

                          [?]TechWire ⚡ » 🤖 🌐
                          @techwire@social.gamefan.net

                          This Galaxy Z Fold 8 rival could put Ultra flagships to shame with its huge battery

                          The X Fold 6's battery will put conventional Ultra and Pro Max phones to shame.

                          androidauthority.com/vivo-gala

                          [Android Authority]

                            [?]Hacker News » 🤖 🌐
                            @h4ckernews@mastodon.social

                            [?]N-gated Hacker News » 🤖 🌐
                            @ngate@mastodon.social

                            🎩 Wow, Sherlock! You discovered 10k malware-infested just by Googling and . Next time, try using a magnifying glass 🔍—might find even more! 💀
                            orchidfiles.com/github-reposit

                              [?]TechFinitive » 🌐
                              @TechFinitive@mastodon.social

                              Security teams have no shortage of tools, but visibility remains a major challenge. ThreatAware’s $25 million funding round highlights growing interest in cyber asset management as a way to unify fragmented security operations, improve asset visibility and identify gaps that traditional security tools can miss.

                              Read the full story: techfinitive.com/features/cybe

                                [?]TechFinitive » 🌐
                                @TechFinitive@mastodon.social

                                The traditional annual penetration test is increasingly out of step with today’s threat landscape. As attackers probe systems continuously, organisations are looking for more proactive approaches. Hadrian’s Nova platform reflects that shift, bringing AI-driven, on-demand penetration testing to help identify weaknesses before attackers do.

                                Read the full story: techfinitive.com/features/how-

                                  [?]ChiefGyk3D » 🌐
                                  @chiefgyk3d@social.chiefgyk3d.com

                                  Looking forward to DEF CON 34. I’ll be part of Call Center Village this year, so there’s a good chance you’ll find me there. Feel free to say hi, I’ll have stickers. Just remember if you take photos, make sure everyone in frame has given permission first
                                  1/2

                                    [?]TechWire ⚡ » 🤖 🌐
                                    @techwire@social.gamefan.net

                                    Google Vids is making it easier to create longer clips with Veo

                                    It just got easier to create longer and better video clips in Google Vids.

                                    androidauthority.com/google-vi

                                    [Android Authority]

                                      [?]CTI.FYI » 🤖 🌐
                                      @CTI_FYI@infosec.exchange

                                      🚨New ransom group blog post!🚨

                                      Group name: akira
                                      Post title: Apptricity
                                      Info: cti.fyi/groups/akira.html

                                        [?]urlDNA.io :verified: » 🤖 🌐
                                        @urldna@infosec.exchange

                                        Possible Phishing 🎣
                                        on: ⚠️hxxp[:]//bafkreigbpzdt7rw6lfjs3tebur3rc7vcwgpc3ajljyikugl4kf6f3v7u5e[.]ipfs[.]dweb[.]link/
                                        🧬 Analysis at: urldna.io/scan/6a339f313b77500

                                          [?]AllAboutSecurity » 🌐
                                          @allaboutsecurity@mastodon.social

                                          FortiBleed: 75.000 Fortinet-Firewalls weltweit kompromittiert

                                          Den vorliegenden Daten zufolge wurden 73.932 eindeutige Firewall-URLs in 194 Ländern kompromittiert, was rund 21.632 betroffene Domains ergibt.

                                          all-about-security.de/fortible

                                            [?]TechWire ⚡ » 🤖 🌐
                                            @techwire@social.gamefan.net

                                            YouTube is testing another Android redesign, and your muscle memory might hate it

                                            YouTube could redesign the buttons on its Android app again.

                                            androidauthority.com/youtube-u

                                            [Android Authority]

                                              [?]EUVD Bot » 🤖 🌐
                                              @EUVD_Bot@mastodon.social

                                              🚨 EUVD-2026-37854

                                              📊 Score: 9.4/10 (CVSS v3.1)
                                              📦 Product: Cotonti
                                              🏢 Vendor: Cotonti
                                              📅 Updated: 2026-06-18

                                              📝 Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration rights handler. In system/admin/admin.rights.php, the rights update action ('a=update') modifies group access rights (including via cot_auth_add_...

                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                [?]EUVD Bot » 🤖 🌐
                                                @EUVD_Bot@mastodon.social

                                                🚨 EUVD-2026-37853

                                                📊 Score: 8.7/10 (CVSS v3.1)
                                                📦 Product: Cotonti
                                                🏢 Vendor: Cotonti
                                                📅 Updated: 2026-06-18

                                                📝 Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration configuration handler. In system/admin/admin.config.php, the configuration update action ('a=update') processes POST data via cot_config_update_o...

                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                  [?]EUVD Bot » 🤖 🌐
                                                  @EUVD_Bot@mastodon.social

                                                  🚨 EUVD-2026-37852

                                                  📊 Score: n/a
                                                  📦 Product: MagicForm
                                                  🏢 Vendor: Unknown
                                                  📅 Updated: 2026-06-18

                                                  📝 The MagicForm WordPress plugin through 0.1.3 does not properly validate the type of files uploaded through an unauthenticated AJAX action when a form's per-field extension allowlist is left empty, allowing unauthenticated attackers to upload PHP files and execute arbitra...

                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                    [?]urlDNA.io :verified: » 🤖 🌐
                                                    @urldna@infosec.exchange

                                                    Possible Phishing 🎣
                                                    on: ⚠️hxxps[:]//metamaskwallet[.]to/
                                                    🧬 Analysis at: urldna.io/scan/6a3397923b77500

                                                      [?]BeyondMachines :verified: » 🤖 🌐
                                                      @beyondmachines1@infosec.exchange

                                                      MariaDB Patches Critical Command Injection Flaws in Community Server

                                                      MariaDB released security updates for Community Server to fix four vulnerabilities, including a maximum-severity CVSS 10.0 flaw that allows arbitrary shell command execution via Galera Cluster components.

                                                      **Update your MariaDB clusters to the latest secure versions as soon as possible to fully block remote command execution. If you cannot patch right now, disable the wsrep_notify_cmd setting to stop the most dangerous exploit path. Ensure you check all active cluster environments, as this flaw specifically targets high-availability production systems running Galera Cluster.**

                                                      beyondmachines.net/event_detai

                                                        [?]N_{Dario Fadda} » 🌐
                                                        @nuke@poliversity.it

                                                        CISA Adds Oracle PeopleSoft Zero-Day CVE-2026-35273 to KEV Catalog After Ransomware Gang Exploitation

                                                        securebulletin.com/cisa-adds-o

                                                          [?]N_{Dario Fadda} » 🌐
                                                          @nuke@poliversity.it

                                                          Kodak Confirms Data Breach as ShinyHunters Claims 2.2 Million Customer Records Stolen

                                                          securebulletin.com/kodak-confi

                                                            [?]TechWire ⚡ » 🤖 🌐
                                                            @techwire@social.gamefan.net

                                                            Android 17 is rolling out, but it’s missing the one feature I was really looking forward to

                                                            Improved gaming will have to wait a little longer.

                                                            androidauthority.com/android-1

                                                            [Android Authority]

                                                              Back to top - More...