voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
Qualcomm: 144 CVEs, 2 critical/51 high, avg CVSS 7.4. 1 CISA KEV exploited in wild. 100% unpatched. Trust Score: D. Snapdragon chips in billions of devices—attack surface is massive. #Qualcomm #infosec #cybersecurity
🛡️ #Cybersecurity news & tips across the #fediverse
“CBI is thrilled to host "The Problem with Personalization." A talk by UPenn Annenberg School of Comm. Prof. Joseph Turow. June 30th 1pm Central. Via Zoom. Register for this free event at the link. # media # privacy ...”
https://mastodon.social/@JustCodeCulture/116766185523120153
🤖 via RSS feed. Not an endorsement.
The best Lenovo laptops on sale for Prime Day: 8 models we've tested personally
We've tested dozens of Lenovo laptops over the last year. These are the models we recommend - and they're all on sale for Amazon Prime Day.
https://www.zdnet.com/article/best-early-lenovo-deals-amazon-prime-day-2026/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
CISA has issued a critical directive: Federal agencies must patch a CVSS 10.0 Joomla Content Editor (JCE) plugin flaw (CVE-2026-48907) by Friday, June 19. This unauthenticated PHP code execution vulnerability is actively exploited, allowing attackers to deploy web shells and establish persistent access. Beyond patching, the article stresses the need for aggressive threat hunting to uncover hidden…
🤖 This post was AI-generated.
Does your phone charge as fast as advertised? I measured the latest iPhone, Samsung, OnePlus
Phone makers love to advertise fast-charging speeds. I tested three flagship phones with OEM and Anker chargers to see what their claims really mean.
https://www.zdnet.com/article/i-tested-fast-chargers-with-best-iphone-samsung-oneplus-phones/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
🚨New ransom group blog post!🚨
Group name: incransom
Post title: neuwoges.de
Info: https://cti.fyi/groups/incransom.html
#ransomware #cti #threatintelligence #cybersecurity #infosec
Possible Phishing 🎣
on: ⚠️hxxps[:]//www[.]robiox[.]com[.]ps/games/131623223084840/Escape-Tsunami-For-Brainrots?privateServerLinkCode=15549057279258852747664498581439
🧬 Analysis at: https://urldna.io/scan/6a327e423b77500007b92b08
#cybersecurity #phishing #infosec #urldna #scam #infosec
There are hundreds of power banks on the market, but this one is the fastest at recharging
ZDNET's latest Lab Award goes to the power bank that charged to 100% the fastest.
https://www.zdnet.com/article/fastest-charge-power-banks-lab-tested/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
🖲️ #Cybersecurity #Ciberseguridad #Ciberseguranca #Security #Seguridad #Seguranca #News #Noticia #Noticias #Tecnologia #Technology
⚫ Sweeping Credential-Harvesting Heist Compromises +30K Fortinet Devices
🔗 https://www.darkreading.com/cyberattacks-data-breaches/sweeping-credential-harvesting-heist-compromises-30k-fortinet-devices
Attackers actively are targeting various sectors across nearly 200 countries and have already compiled a list of working credentials for tens of thousands of
I found 6 useful Amazon gadgets that are up to 68% off - including a $100 TV
Amazon is discounting its smart home prices ahead of Prime Day, and these deals on Echo, Ring, and other brands are actually worth your money.
https://www.zdnet.com/article/amazon-echo-devices-smart-home-prime-day-2026-deals/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
Possible Phishing 🎣
on: ⚠️hxxps[:]//aasdghftryii556hdd73646yyyuijjdhyttegrvvfedrtsnjjksliojhhh[.]pages[.]dev/
🧬 Analysis at: https://urldna.io/scan/6a32f6753b7750000667a24d
#cybersecurity #phishing #infosec #urldna #scam #infosec
🚨 EUVD-2026-37830
📊 Score: 8.2/10 (CVSS v3.1)
📦 Product: typebot.io
🏢 Vendor: baptisteArno
📅 Updated: 2026-06-17
📝 TypeBot is a chatbot builder tool. In versions prior to 3.17.2, SSRF validation is implemented by resolving a hostname once and checking whether the resolved IP belongs to a forbidden range allowing for DNS rebinding bypass. The root cause is a time-...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-37830
🚨 EUVD-2026-37829
📊 Score: 9.3/10 (CVSS v3.1)
📦 Product: typebot.io
🏢 Vendor: baptisteArno
📅 Updated: 2026-06-17
📝 TypeBot is a chatbot builder tool. In versions 3.16.1 and earlier, POST /api/blocks/file-input/v3/generate-upload-url is unauthenticated and uses unsanitized fileName input to construct public/ S3 object keys, while issuing presigned PUT URLs that do...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-37829
🚨 EUVD-2026-37828
📊 Score: 8.6/10 (CVSS v3.1)
📦 Product: ThingsBoard
🏢 Vendor: thingsboard
📅 Updated: 2026-06-17
📝 ThingsBoard contains a prototype pollution vulnerability which may lead to arbitrary code execution within a sandboxed context by a user who can log in to the affected product with the tenant administrator privilege (TENANT_ADMIN).
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-37828
Microsoft debuts Surface Pro and Surface Laptop with new jade green color and Qualcomm Snapdragon X2 chips — refreshed devices start at $1,499 with …
Microsoft is updating the Surface Pro and Surface Laptop using the latest Qualcomm Snapdragon X2 chips, along with haptic feedback on the Laptop's touchpad and a new jade color.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
Sennheiser just gave me a compelling reason to put away my Bose and Sony headphones for good
As audio quality reaches technological limits, brands are exploring alternative features.
https://www.zdnet.com/article/sennheiser-momentum-5-battery-repair/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
Possible Phishing 🎣
on: ⚠️hxxps[:]//extension-metamask[.]wixstudio[.]com/en-us
🧬 Analysis at: https://urldna.io/scan/6a3294083b77500007b92da8
#cybersecurity #phishing #infosec #urldna #scam #infosec
MSI MPG Coreliquid P22 360 Review: Low noise, strong performance, budget price
The MSI MPG Coreliquid P22 360 is a new AIO with a low price tag, strong thermal performance, and a 2.1-inch IPS display. We’ve tested this liquid cooler paired with AMD’s Ryzen 9 9950X3D CPU to benchmark thermal effici…
https://www.tomshardware.com/pc-components/liquid-cooling/msi-mpg-coreliquid-p22-360-review
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
Hackers Publish #Knicks and Madison Square Garden Data Online
https://www.404media.co/hackers-publish-knicks-and-madison-square-garden-data-online/
🚨 EUVD-2026-37782
📊 Score: 8.2/10 (CVSS v3.1)
📦 Product: libssh2
🏢 Vendor: libssh2
📅 Updated: 2026-06-17
📝 libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a crafted exten...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-37782
🚨 EUVD-2026-37781
📊 Score: n/a
📦 Product: UniGetUI
🏢 Vendor: Devolutions
📅 Updated: 2026-06-17
📝 Use of an incorrectly resolved name or reference in the pinget backend
in Devolutions UniGetUI 2026.2.0 and earlier allows a WinGet community
catalog contributor to cause an installed application to be correlated
to an unrelated, attacker-controlled catalog package...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-37781
#UK to require ID or face scan before you can make #SocialMedia accounts
#privacy #cybersecurity #politics #AgeVerification #SocialMediaBan
🚨 EUVD-2026-37647
📊 Score: 7.5/10 (CVSS v3.1)
📦 Product: WP Media folder Addon
🏢 Vendor: JoomUnited
📅 Updated: 2026-06-17
📝 Unauthenticated Arbitrary File Download in WP Media folder Addon <= 4.0.1 versions.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-37647
🚨 EUVD-2026-37509
📊 Score: 9.8/10 (CVSS v3.1)
📦 Product: Fusion Builder
🏢 Vendor: ThemeFusion
📅 Updated: 2026-06-17
📝 Contributor PHP Object Injection in Fusion Builder <= 3.15.4 versions.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-37509
ClickFix Campaign Generated Via AI Delivers SmartRAT
In March 2026, threat actors leveraged AI-powered website builders to create typosquatting domains impersonating a Brazilian bank. The campaign employed ClickFix techniques, presenting victims with fake CAPTCHA and BSOD screens to trick them into executing malicious PowerShell commands. This delivered SmartRAT, a PowerShell-based banking trojan with capabilities including encrypted C2 communications, remote control of screen/keyboard/mouse, credential theft through keylogging and banking overlays, and QR code interception for transaction fraud. The malware establishes persistence via scheduled tasks and Windows services, and targets Brazilian financial institutions, payment platforms, and cryptocurrency exchanges. The threat actors' C2 panel contained critical authentication flaws allowing client-side bypass, suggesting deployment without adequate security review.
Pulse ID: 6a32e5873cf59d36f41c77be
Pulse Link: https://otx.alienvault.com/pulse/6a32e5873cf59d36f41c77be
Pulse Author: AlienVault
Created: 2026-06-17 18:20:54
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #Bank #BankingTrojan #Brazil #CAPTCHA #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #PowerShell #RAT #RCE #Trojan #TypoSquatting #Windows #bot #cryptocurrency #AlienVault
More Than 4,000 Legacy Routers Compromised by AryStinger, Turned into Global Attack Proxies for Hackers
Security researchers discovered AryStinger, a botnet targeting legacy routers and NAS devices to build reconnaissance and attack infrastructure. The malware exploits vulnerabilities from 2013-2025 to compromise over 4,300 devices globally, primarily D-Link routers using RTL819X chips. AryStinger communicates via HTTP/HTTPS using Protobuf encoding and XOR encryption, supporting tasks including network scanning, traffic proxying, command execution, and persistent backdoor deployment through dropbear or gs-netcat. Two versions exist: RTL819X in C for routers, and Standard in Go for NAS devices with expanded capabilities including integration of fscan, ksubdomain, and httpx tools. Infected devices serve as distributed scanning nodes and attack proxies, effectively hiding attacker identities while conducting footprinting activities. The campaign shows extremely low detection rates in mainstream security engines, with evidence suggesting operations possibly began in 2024.
Pulse ID: 6a32e3c65eeef62d1606b638
Pulse Link: https://otx.alienvault.com/pulse/6a32e3c65eeef62d1606b638
Pulse Author: AlienVault
Created: 2026-06-17 18:13:26
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #Encryption #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #Proxy #RAT #bot #botnet #AlienVault
🚨New ransom group blog posts!🚨
Group name: safepay
Post title: gut-heckenhof.de
Info: https://cti.fyi/groups/safepay.html
Group name: safepay
Post title: brscappuccio.it
Info: https://cti.fyi/groups/safepay.html
Group name: safepay
Post title: zaunsysteme.de
Info: https://cti.fyi/groups/safepay.html
Group name: safepay
Post title: harcourts.net
Info: https://cti.fyi/groups/safepay.html
Group name: safepay
Post title: seinordovest.it
Info: https://cti.fyi/groups/safepay.html
#ransomware #cti #threatintelligence #cybersecurity #infosec
Epic wants to let you bring your Fortnite skins to other games
Epic Games has been touting the potential of an interoperable metaverse for years, though that vision hasn't yet become a reality. But with Unreal Engine 6, the next major version of its game development engine, Epic pl…
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Google confirms: These Nest smart speakers have ended production
Google Home Speaker pre-orders are live, but two classic Nest speakers are dead.
https://www.androidauthority.com/nest-audio-dead-3678691/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
✨ Supply chain attack su Uncanny Automator Pro: build backdoorata v7.3.0.5 distribuita a migliaia di siti WordPress
#CyberSecurity
https://insicurezzadigitale.com/supply-chain-attack-su-uncanny-automator-pro-build-backdoorata-v7-3-0-5-distribuita-a-migliaia-di-siti-wordpress/
Possible Phishing 🎣
on: ⚠️hxxps[:]//sportbetng247[.]weebly[.]com/
🧬 Analysis at: https://urldna.io/scan/6a330af73b77500007b93df1
#cybersecurity #phishing #infosec #urldna #scam #infosec
VSCO launches Studio Pro mobile photo editing app and plans $500 per year subscription
VSCO is taking on Adobe with a new Studio Pro editing app rolling out today on iOS and coming to macOS later this year, as Bloomberg reports. At launch, the app offers tools for batch editing, style matching from a refe…
https://www.theverge.com/tech/951863/vsco-studio-pro-vsco-one-subscription
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
140+ npm Packages Compromised in Coordinated Supply Chain Attack
More than 140 Mastra npm packages were compromised through a supply chain attack that injected a typosquatted dependency called easy-day-js. A single npm account published malicious versions within a short timeframe, affecting packages including @mastra/core with over 918K weekly downloads. The attack executes during npm install via a postinstall hook, deploying a two-stage payload. The first stage disables TLS validation and downloads a second-stage implant that installs cross-platform persistence on Windows, macOS, and Linux. This implant functions as a command-and-control client that steals cryptocurrency wallet inventories from 166+ browser extensions, harvests browser history, and can execute arbitrary code sent by operators. The malicious code executes before developers import packages, compromising systems during installation.
Pulse ID: 6a32a359d57a0d5d5999e35f
Pulse Link: https://otx.alienvault.com/pulse/6a32a359d57a0d5d5999e35f
Pulse Author: AlienVault
Created: 2026-06-17 13:38:33
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #InfoSec #Linux #Mac #MacOS #NPM #OTX #OpenThreatExchange #RAT #SupplyChain #TLS #Windows #bot #cryptocurrency #developers #AlienVault
From emerging threat to top-tier ransomware-as-a-service: The evolution of INC ransomware
INC has evolved from an emerging ransomware-as-a-service operation into one of the most active groups in 2026, claiming over 800 victims since 2023. The disruption of LockBit and BlackCat's shutdown created opportunities for INC to expand as affiliates migrated. Both Windows and Linux/ESXi encryptors have been rewritten in Rust, enabling cross-platform development and increasing analysis complexity. Recent incidents reveal updated tooling, including a modified credential dumper targeting newer Veeam backup deployments with support for salted DPAPI encryption. INC's influence extends beyond its operations; following the 2024 source code sale for $300,000, related families like Lynx and Sinobi emerged. United States organizations account for over 65% of victims, with legal services, manufacturing, construction, technology, and healthcare among the most targeted sectors.
Pulse ID: 6a32a34570e116fb4e3621e7
Pulse Link: https://otx.alienvault.com/pulse/6a32a34570e116fb4e3621e7
Pulse Author: AlienVault
Created: 2026-06-17 13:38:13
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlackCat #CyberSecurity #Encryption #Healthcare #InfoSec #Linux #LockBit #Manufacturing #OTX #OpenThreatExchange #RAT #RCE #RansomWare #RansomwareAsAService #Rust #UnitedStates #Windows #bot #AlienVault
Volkswagen started blocking GrapheneOS users
https://discuss.grapheneos.org/d/35949-volkswagen-app?page=3
#HackerNews #Volkswagen #GrapheneOS #Users #Privacy #Tech #News #Cybersecurity
Possible Phishing 🎣
on: ⚠️hxxps[:]//api[.]timeforsurveys[.]com/s/63BZGFSVBWSFCDX7Y9/584dd8/90eab167-7429-489f-99f6-ce86e8d0d81a
🧬 Analysis at: https://urldna.io/scan/6a3277ef3b77500007b92a1f
#cybersecurity #phishing #infosec #urldna #scam #infosec
📣🚨 #FortiBleed attack exposes Fortinet firewall credentials in 194 countries, with researchers linking the dataset to nearly 74,000 firewall URLs and 21,000+ affected domains.
Read: https://hackread.com/fortibleed-attack-fortinet-firewalls-credentials/
Pokémon Champions has brought the battle to Android and iOS
TCPI is celebrating the launch by giving you a free Raichu and mega stones.
https://www.androidauthority.com/pokemon-champions-launches-on-mobile-3678548/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]