voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]Hugo | DevOps | Cybersecurity » 🌐
@hugovalters@mastodon.social

Qualcomm: 144 CVEs, 2 critical/51 high, avg CVSS 7.4. 1 CISA KEV exploited in wild. 100% unpatched. Trust Score: D. Snapdragon chips in billions of devices—attack surface is massive.

valtersit.com/vendors/qualcomm/

    [?]Ivy Cyber » 🤖 🌐
    @ivycyber@privacysafe.social

    🛡️ news & tips across the

    “CBI is thrilled to host "The Problem with Personalization." A talk by UPenn Annenberg School of Comm. Prof. Joseph Turow. June 30th 1pm Central. Via Zoom. Register for this free event at the link. # media # privacy ...”

    mastodon.social/@JustCodeCultu

    🤖 via RSS feed. Not an endorsement.

      [?]TechWire ⚡ » 🤖 🌐
      @techwire@social.gamefan.net

      The best Lenovo laptops on sale for Prime Day: 8 models we've tested personally

      We've tested dozens of Lenovo laptops over the last year. These are the models we recommend - and they're all on sale for Amazon Prime Day.

      zdnet.com/article/best-early-l

      [ZDNet]

        [?]Daniel Marsh » 🤖 🌐
        @danielmarsh@social.thepixelspulse.com

        CISA has issued a critical directive: Federal agencies must patch a CVSS 10.0 Joomla Content Editor (JCE) plugin flaw (CVE-2026-48907) by Friday, June 19. This unauthenticated PHP code execution vulnerability is actively exploited, allowing attackers to deploy web shells and establish persistent access. Beyond patching, the article stresses the need for aggressive threat hunting to uncover hidden…

        tpp.blog/2di6vjo

        🤖 This post was AI-generated.

          [?]TechWire ⚡ » 🤖 🌐
          @techwire@social.gamefan.net

          Does your phone charge as fast as advertised? I measured the latest iPhone, Samsung, OnePlus

          Phone makers love to advertise fast-charging speeds. I tested three flagship phones with OEM and Anker chargers to see what their claims really mean.

          zdnet.com/article/i-tested-fas

          [ZDNet]

            [?]CTI.FYI » 🤖 🌐
            @CTI_FYI@infosec.exchange

            🚨New ransom group blog post!🚨

            Group name: incransom
            Post title: neuwoges.de
            Info: cti.fyi/groups/incransom.html

              [?]urlDNA.io :verified: » 🤖 🌐
              @urldna@infosec.exchange

              Possible Phishing 🎣
              on: ⚠️hxxps[:]//www[.]robiox[.]com[.]ps/games/131623223084840/Escape-Tsunami-For-Brainrots?privateServerLinkCode=15549057279258852747664498581439
              🧬 Analysis at: urldna.io/scan/6a327e423b77500

                [?]TechWire ⚡ » 🤖 🌐
                @techwire@social.gamefan.net

                There are hundreds of power banks on the market, but this one is the fastest at recharging

                ZDNET's latest Lab Award goes to the power bank that charged to 100% the fastest.

                zdnet.com/article/fastest-char

                [ZDNet]

                  [?]TierraSapiens » 🤖 🌐
                  @tierrasapiens@mastodon.social

                  🖲️
                  ⚫ Sweeping Credential-Harvesting Heist Compromises +30K Fortinet Devices
                  🔗 darkreading.com/cyberattacks-d

                  Attackers actively are targeting various sectors across nearly 200 countries and have already compiled a list of working credentials for tens of thousands of

                    [?]TechWire ⚡ » 🤖 🌐
                    @techwire@social.gamefan.net

                    I found 6 useful Amazon gadgets that are up to 68% off - including a $100 TV

                    Amazon is discounting its smart home prices ahead of Prime Day, and these deals on Echo, Ring, and other brands are actually worth your money.

                    zdnet.com/article/amazon-echo-

                    [ZDNet]

                      [?]urlDNA.io :verified: » 🤖 🌐
                      @urldna@infosec.exchange

                      Possible Phishing 🎣
                      on: ⚠️hxxps[:]//aasdghftryii556hdd73646yyyuijjdhyttegrvvfedrtsnjjksliojhhh[.]pages[.]dev/
                      🧬 Analysis at: urldna.io/scan/6a32f6753b77500

                        [?]EUVD Bot » 🤖 🌐
                        @EUVD_Bot@mastodon.social

                        🚨 EUVD-2026-37830

                        📊 Score: 8.2/10 (CVSS v3.1)
                        📦 Product: typebot.io
                        🏢 Vendor: baptisteArno
                        📅 Updated: 2026-06-17

                        📝 TypeBot is a chatbot builder tool. In versions prior to 3.17.2, SSRF validation is implemented by resolving a hostname once and checking whether the resolved IP belongs to a forbidden range allowing for DNS rebinding bypass. The root cause is a time-...

                        🔗 euvd.enisa.europa.eu/vulnerabi

                          [?]EUVD Bot » 🤖 🌐
                          @EUVD_Bot@mastodon.social

                          🚨 EUVD-2026-37829

                          📊 Score: 9.3/10 (CVSS v3.1)
                          📦 Product: typebot.io
                          🏢 Vendor: baptisteArno
                          📅 Updated: 2026-06-17

                          📝 TypeBot is a chatbot builder tool. In versions 3.16.1 and earlier, POST /api/blocks/file-input/v3/generate-upload-url is unauthenticated and uses unsanitized fileName input to construct public/ S3 object keys, while issuing presigned PUT URLs that do...

                          🔗 euvd.enisa.europa.eu/vulnerabi

                            [?]EUVD Bot » 🤖 🌐
                            @EUVD_Bot@mastodon.social

                            🚨 EUVD-2026-37828

                            📊 Score: 8.6/10 (CVSS v3.1)
                            📦 Product: ThingsBoard
                            🏢 Vendor: thingsboard
                            📅 Updated: 2026-06-17

                            📝 ThingsBoard contains a prototype pollution vulnerability which may lead to arbitrary code execution within a sandboxed context by a user who can log in to the affected product with the tenant administrator privilege (TENANT_ADMIN).

                            🔗 euvd.enisa.europa.eu/vulnerabi

                              [?]TechWire ⚡ » 🤖 🌐
                              @techwire@social.gamefan.net

                              Microsoft debuts Surface Pro and Surface Laptop with new jade green color and Qualcomm Snapdragon X2 chips — refreshed devices start at $1,499 with …

                              Microsoft is updating the Surface Pro and Surface Laptop using the latest Qualcomm Snapdragon X2 chips, along with haptic feedback on the Laptop's touchpad and a new jade color.

                              tomshardware.com/laptops/micro

                              [Tom's Hardware]

                                [?]TechWire ⚡ » 🤖 🌐
                                @techwire@social.gamefan.net

                                Sennheiser just gave me a compelling reason to put away my Bose and Sony headphones for good

                                As audio quality reaches technological limits, brands are exploring alternative features.

                                zdnet.com/article/sennheiser-m

                                [ZDNet]

                                  [?]urlDNA.io :verified: » 🤖 🌐
                                  @urldna@infosec.exchange

                                  Possible Phishing 🎣
                                  on: ⚠️hxxps[:]//extension-metamask[.]wixstudio[.]com/en-us
                                  🧬 Analysis at: urldna.io/scan/6a3294083b77500

                                    [?]TechWire ⚡ » 🤖 🌐
                                    @techwire@social.gamefan.net

                                    MSI MPG Coreliquid P22 360 Review: Low noise, strong performance, budget price

                                    The MSI MPG Coreliquid P22 360 is a new AIO with a low price tag, strong thermal performance, and a 2.1-inch IPS display. We’ve tested this liquid cooler paired with AMD’s Ryzen 9 9950X3D CPU to benchmark thermal effici…

                                    tomshardware.com/pc-components

                                    [Tom's Hardware]

                                      [?]The New Oil » 🤖 🌐
                                      @thenewoil@mastodon.thenewoil.org

                                      [?]EUVD Bot » 🤖 🌐
                                      @EUVD_Bot@mastodon.social

                                      🚨 EUVD-2026-37782

                                      📊 Score: 8.2/10 (CVSS v3.1)
                                      📦 Product: libssh2
                                      🏢 Vendor: libssh2
                                      📅 Updated: 2026-06-17

                                      📝 libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a crafted exten...

                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                        [?]EUVD Bot » 🤖 🌐
                                        @EUVD_Bot@mastodon.social

                                        🚨 EUVD-2026-37781

                                        📊 Score: n/a
                                        📦 Product: UniGetUI
                                        🏢 Vendor: Devolutions
                                        📅 Updated: 2026-06-17

                                        📝 Use of an incorrectly resolved name or reference in the pinget backend
                                        in Devolutions UniGetUI 2026.2.0 and earlier allows a WinGet community
                                        catalog contributor to cause an installed application to be correlated
                                        to an unrelated, attacker-controlled catalog package...

                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                          [?]The New Oil » 🤖 🌐
                                          @thenewoil@mastodon.thenewoil.org

                                          [?]EUVD Bot » 🤖 🌐
                                          @EUVD_Bot@mastodon.social

                                          🚨 EUVD-2026-37647

                                          📊 Score: 7.5/10 (CVSS v3.1)
                                          📦 Product: WP Media folder Addon
                                          🏢 Vendor: JoomUnited
                                          📅 Updated: 2026-06-17

                                          📝 Unauthenticated Arbitrary File Download in WP Media folder Addon <= 4.0.1 versions.

                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                            [?]EUVD Bot » 🤖 🌐
                                            @EUVD_Bot@mastodon.social

                                            🚨 EUVD-2026-37509

                                            📊 Score: 9.8/10 (CVSS v3.1)
                                            📦 Product: Fusion Builder
                                            🏢 Vendor: ThemeFusion
                                            📅 Updated: 2026-06-17

                                            📝 Contributor PHP Object Injection in Fusion Builder <= 3.15.4 versions.

                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                              [?]OTX Bot » 🤖 🌐
                                              @techbot@social.raytec.co

                                              ClickFix Campaign Generated Via AI Delivers SmartRAT

                                              In March 2026, threat actors leveraged AI-powered website builders to create typosquatting domains impersonating a Brazilian bank. The campaign employed ClickFix techniques, presenting victims with fake CAPTCHA and BSOD screens to trick them into executing malicious PowerShell commands. This delivered SmartRAT, a PowerShell-based banking trojan with capabilities including encrypted C2 communications, remote control of screen/keyboard/mouse, credential theft through keylogging and banking overlays, and QR code interception for transaction fraud. The malware establishes persistence via scheduled tasks and Windows services, and targets Brazilian financial institutions, payment platforms, and cryptocurrency exchanges. The threat actors' C2 panel contained critical authentication flaws allowing client-side bypass, suggesting deployment without adequate security review.

                                              Pulse ID: 6a32e5873cf59d36f41c77be
                                              Pulse Link: otx.alienvault.com/pulse/6a32e
                                              Pulse Author: AlienVault
                                              Created: 2026-06-17 18:20:54

                                              Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                                [?]OTX Bot » 🤖 🌐
                                                @techbot@social.raytec.co

                                                More Than 4,000 Legacy Routers Compromised by AryStinger, Turned into Global Attack Proxies for Hackers

                                                Security researchers discovered AryStinger, a botnet targeting legacy routers and NAS devices to build reconnaissance and attack infrastructure. The malware exploits vulnerabilities from 2013-2025 to compromise over 4,300 devices globally, primarily D-Link routers using RTL819X chips. AryStinger communicates via HTTP/HTTPS using Protobuf encoding and XOR encryption, supporting tasks including network scanning, traffic proxying, command execution, and persistent backdoor deployment through dropbear or gs-netcat. Two versions exist: RTL819X in C for routers, and Standard in Go for NAS devices with expanded capabilities including integration of fscan, ksubdomain, and httpx tools. Infected devices serve as distributed scanning nodes and attack proxies, effectively hiding attacker identities while conducting footprinting activities. The campaign shows extremely low detection rates in mainstream security engines, with evidence suggesting operations possibly began in 2024.

                                                Pulse ID: 6a32e3c65eeef62d1606b638
                                                Pulse Link: otx.alienvault.com/pulse/6a32e
                                                Pulse Author: AlienVault
                                                Created: 2026-06-17 18:13:26

                                                Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                                  [?]CTI.FYI » 🤖 🌐
                                                  @CTI_FYI@infosec.exchange

                                                  🚨New ransom group blog posts!🚨

                                                  Group name: safepay
                                                  Post title: gut-heckenhof.de
                                                  Info: cti.fyi/groups/safepay.html

                                                  Group name: safepay
                                                  Post title: brscappuccio.it
                                                  Info: cti.fyi/groups/safepay.html

                                                  Group name: safepay
                                                  Post title: zaunsysteme.de
                                                  Info: cti.fyi/groups/safepay.html

                                                  Group name: safepay
                                                  Post title: harcourts.net
                                                  Info: cti.fyi/groups/safepay.html

                                                  Group name: safepay
                                                  Post title: seinordovest.it
                                                  Info: cti.fyi/groups/safepay.html

                                                    [?]TechWire ⚡ » 🤖 🌐
                                                    @techwire@social.gamefan.net

                                                    Epic wants to let you bring your Fortnite skins to other games

                                                    Epic Games has been touting the potential of an interoperable metaverse for years, though that vision hasn't yet become a reality. But with Unreal Engine 6, the next major version of its game development engine, Epic pl…

                                                    theverge.com/games/951785/epic

                                                    [The Verge]

                                                      [?]TechWire ⚡ » 🤖 🌐
                                                      @techwire@social.gamefan.net

                                                      Google confirms: These Nest smart speakers have ended production

                                                      Google Home Speaker pre-orders are live, but two classic Nest speakers are dead.

                                                      androidauthority.com/nest-audi

                                                      [Android Authority]

                                                        [?]N_{Dario Fadda} » 🌐
                                                        @nuke@poliversity.it

                                                        ✨ Supply chain attack su Uncanny Automator Pro: build backdoorata v7.3.0.5 distribuita a migliaia di siti WordPress

                                                        insicurezzadigitale.com/supply

                                                        @informatica

                                                          [?]urlDNA.io :verified: » 🤖 🌐
                                                          @urldna@infosec.exchange

                                                          Possible Phishing 🎣
                                                          on: ⚠️hxxps[:]//sportbetng247[.]weebly[.]com/
                                                          🧬 Analysis at: urldna.io/scan/6a330af73b77500

                                                            [?]TechWire ⚡ » 🤖 🌐
                                                            @techwire@social.gamefan.net

                                                            VSCO launches Studio Pro mobile photo editing app and plans $500 per year subscription

                                                            VSCO is taking on Adobe with a new Studio Pro editing app rolling out today on iOS and coming to macOS later this year, as Bloomberg reports. At launch, the app offers tools for batch editing, style matching from a refe…

                                                            theverge.com/tech/951863/vsco-

                                                            [The Verge]

                                                              [?]OTX Bot » 🤖 🌐
                                                              @techbot@social.raytec.co

                                                              140+ npm Packages Compromised in Coordinated Supply Chain Attack

                                                              More than 140 Mastra npm packages were compromised through a supply chain attack that injected a typosquatted dependency called easy-day-js. A single npm account published malicious versions within a short timeframe, affecting packages including @mastra/core with over 918K weekly downloads. The attack executes during npm install via a postinstall hook, deploying a two-stage payload. The first stage disables TLS validation and downloads a second-stage implant that installs cross-platform persistence on Windows, macOS, and Linux. This implant functions as a command-and-control client that steals cryptocurrency wallet inventories from 166+ browser extensions, harvests browser history, and can execute arbitrary code sent by operators. The malicious code executes before developers import packages, compromising systems during installation.

                                                              Pulse ID: 6a32a359d57a0d5d5999e35f
                                                              Pulse Link: otx.alienvault.com/pulse/6a32a
                                                              Pulse Author: AlienVault
                                                              Created: 2026-06-17 13:38:33

                                                              Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                                                [?]OTX Bot » 🤖 🌐
                                                                @techbot@social.raytec.co

                                                                From emerging threat to top-tier ransomware-as-a-service: The evolution of INC ransomware

                                                                INC has evolved from an emerging ransomware-as-a-service operation into one of the most active groups in 2026, claiming over 800 victims since 2023. The disruption of LockBit and BlackCat's shutdown created opportunities for INC to expand as affiliates migrated. Both Windows and Linux/ESXi encryptors have been rewritten in Rust, enabling cross-platform development and increasing analysis complexity. Recent incidents reveal updated tooling, including a modified credential dumper targeting newer Veeam backup deployments with support for salted DPAPI encryption. INC's influence extends beyond its operations; following the 2024 source code sale for $300,000, related families like Lynx and Sinobi emerged. United States organizations account for over 65% of victims, with legal services, manufacturing, construction, technology, and healthcare among the most targeted sectors.

                                                                Pulse ID: 6a32a34570e116fb4e3621e7
                                                                Pulse Link: otx.alienvault.com/pulse/6a32a
                                                                Pulse Author: AlienVault
                                                                Created: 2026-06-17 13:38:13

                                                                Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                                                  [?]Hacker News » 🤖 🌐
                                                                  @h4ckernews@mastodon.social

                                                                  [?]The New Oil » 🤖 🌐
                                                                  @thenewoil@mastodon.thenewoil.org

                                                                  [?]The New Oil » 🤖 🌐
                                                                  @thenewoil@mastodon.thenewoil.org

                                                                  [?]urlDNA.io :verified: » 🤖 🌐
                                                                  @urldna@infosec.exchange

                                                                  Possible Phishing 🎣
                                                                  on: ⚠️hxxps[:]//api[.]timeforsurveys[.]com/s/63BZGFSVBWSFCDX7Y9/584dd8/90eab167-7429-489f-99f6-ce86e8d0d81a
                                                                  🧬 Analysis at: urldna.io/scan/6a3277ef3b77500

                                                                    [?]Hackread.com » 🌐
                                                                    @Hackread@mstdn.social

                                                                    📣🚨 attack exposes Fortinet firewall credentials in 194 countries, with researchers linking the dataset to nearly 74,000 firewall URLs and 21,000+ affected domains.

                                                                    Read: hackread.com/fortibleed-attack

                                                                      [?]TechWire ⚡ » 🤖 🌐
                                                                      @techwire@social.gamefan.net

                                                                      Pokémon Champions has brought the battle to Android and iOS

                                                                      TCPI is celebrating the launch by giving you a free Raichu and mega stones.

                                                                      androidauthority.com/pokemon-c

                                                                      [Android Authority]

                                                                        Back to top - More...