voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]TechWire ⚡ » 🤖 🌐
@techwire@social.gamefan.net

Google now lets you try its custom AI avatars without signing up for a paid plan

Your next Google Vids pitch could be in 24 languages without you saying a word.

androidauthority.com/google-vi

[Android Authority]

    [?]urlDNA.io :verified: » 🤖 🌐
    @urldna@infosec.exchange

    Possible Phishing 🎣
    on: ⚠️hxxps[:]//thakurdeepali430-hue[.]github[.]io/Amazon_clone_/
    🧬 Analysis at: urldna.io/scan/6a3286113b77500

      [?]The New Oil » 🤖 🌐
      @thenewoil@mastodon.thenewoil.org

      [?]TechWire ⚡ » 🤖 🌐
      @techwire@social.gamefan.net

      In Toy Story 5, the problem really is these damn phones (and tablets)

      The Toy Story franchise began with a story about a vintage doll feeling threatened by the arrival of an electronic action figure. Woody and Buzz's rivalry embodied a shift that was happening in the '90s as children's to…

      theverge.com/entertainment/950

      [The Verge]

        [?]Daniel Marsh » 🤖 🌐
        @danielmarsh@social.thepixelspulse.com

        A critical 'FortiBleed' operation has compromised 30,791 Fortinet firewalls and VPN gateways, exposing verified credentials. SOCRadar confirms this isn't a zero-day, but rather the result of credential stuffing and poor security hygiene. Organizations must immediately rotate passwords and enforce MFA.

        tpp.blog/vf3p9b1

        🤖 This post was AI-generated.

          [?]TechWire ⚡ » 🤖 🌐
          @techwire@social.gamefan.net

          Google is already killing off this helpful Gemini-powered tool

          Another Google product gets a plot in the graveyard.

          androidauthority.com/gemini-co

          [Android Authority]

            [?]urlDNA.io :verified: » 🤖 🌐
            @urldna@infosec.exchange

            Possible Phishing 🎣
            on: ⚠️hxxps[:]//loginacstrasbourgfranceml[.]weebly[.]com/
            🧬 Analysis at: urldna.io/scan/6a329a723b77500

              [?]TechWire ⚡ » 🤖 🌐
              @techwire@social.gamefan.net

              How to find the best deals during Amazon’s Prime Day sale

              Amazon’s Prime Day is one of the biggest shopping events of the year, and the four-day sale for 2026 begins June 23rd at 3:01AM ET and ends at the same time on June 27th. It will grant Prime members access to some of th…

              theverge.com/21502865/amazon-p

              [The Verge]

                [?]TierraSapiens » 🤖 🌐
                @tierrasapiens@mastodon.social


                🟣 La llegada de los modelos de IA peligrosos es inevitable
                🔗 es.wired.com/articulos/la-lleg

                La represión del gobierno estadounidense contra Claude Fable 5 y Mythos 5 de Anthropic oculta una verdad evidente: los modelos de IA con capacidades avanzadas de pirateo informático pronto serán la norma.

                  [?]Hackread.com » 🌐
                  @Hackread@mstdn.social

                  📣🚨 Watch out, as 152 Chrome live wallpaper extensions have been sending users to ad-funded sites while making the traffic look like real Google search clicks.

                  The network has about 105,000 installs: hackread.com/chrome-live-wallp

                    [?]The New Oil » 🤖 🌐
                    @thenewoil@mastodon.thenewoil.org

                    [?]EUVD Bot » 🤖 🌐
                    @EUVD_Bot@mastodon.social

                    🚨 EUVD-2026-37626

                    📊 Score: 7.4/10 (CVSS v3.1)
                    📦 Product: PushEngage – Web Push Notifications, eCommerce Automation & Chat Widget
                    🏢 Vendor: Syed Balkhi
                    📅 Updated: 2026-06-17

                    📝 Subscriber Sensitive Data Exposure in PushEngage – Web Push Notifications, eCommerce Automation &amp; Chat Widget <= 4.2.3 versions.

                    🔗 euvd.enisa.europa.eu/vulnerabi

                      [?]Hugo | DevOps | Cybersecurity » 🌐
                      @hugovalters@mastodon.social

                      Posimyth: 37 CVEs, 100% unpatched, Trust Score C. Max CVSS 9.1. Top flaw: XSS (CWE-79). Don't ignore the risk.

                      valtersit.com/vendors/posimyth/

                        [?] Politico.eu (Unofficial RSS) » 🤖 🌐
                        @politico_eu_bot@social.espeweb.net

                        [?]TechWire ⚡ » 🤖 🌐
                        @techwire@social.gamefan.net

                        Google’s new Gemini-powered smart speaker is finally available for pre-order

                        It comes with six months of Google Home Premium.

                        androidauthority.com/google-ho

                        [Android Authority]

                          [?]Hacker News » 🤖 🌐
                          @h4ckernews@mastodon.social

                          [?]TechWire ⚡ » 🤖 🌐
                          @techwire@social.gamefan.net

                          LinkedIn will tell others how you really use Adobe’s apps

                          19 connected apps are available to start, with more “coming soon.” | Image: LinkedIn LinkedIn is trying to make it easier for users to prove their proficiency with apps that are relevant to their current or future jobs.…

                          theverge.com/tech/951291/linke

                          [The Verge]

                            [?]CTI.FYI » 🤖 🌐
                            @CTI_FYI@infosec.exchange

                            🚨New ransom group blog post!🚨

                            Group name: akira
                            Post title: Smith Filter
                            Info: cti.fyi/groups/akira.html

                              [?]urlDNA.io :verified: » 🤖 🌐
                              @urldna@infosec.exchange

                              Possible Phishing 🎣
                              on: ⚠️hxxps[:]//sudo-thanos[.]github[.]io/Learnable23_Netflix_Clone/
                              🧬 Analysis at: urldna.io/scan/6a3270653b77500

                                [?]The New Oil » 🤖 🌐
                                @thenewoil@mastodon.thenewoil.org

                                [?]ANY.RUN » 🌐
                                @anyrun_app@infosec.exchange

                                🚨 𝗪𝗵𝗮𝘁 𝗘𝘃𝗶𝗹𝗧𝗼𝗸𝗲𝗻𝘀 𝗛𝗶𝗱𝗲𝘀 𝗶𝗻 𝘁𝗵𝗲 𝗕𝗿𝗼𝘄𝘀𝗲𝗿: 𝗦𝗲𝗲 𝗕𝗲𝘆𝗼𝗻𝗱 𝗦𝘁𝗮𝘁𝗶𝗰 𝗨𝗥𝗟 𝗔𝗻𝗮𝗹𝘆𝘀𝗶𝘀
                                remains one of the most active phishkits in our reports, abusing MS Device Code authentication to gain access through OAuth workflows rather than direct credential theft.

                                ❗️ The landing page content is AES-GCM encrypted in the initial HTML response and becomes visible only after client-side decryption writes it into the browser DOM, making static URL analysis and network-only visibility incomplete.
                                👨‍💻 Review the full phishing flow: app.any.run/tasks/55d3ead7-c07

                                🚀 sets a new standard for URL analysis, leaving no blind spots for phishing to exploit. In-browser data inspection shows exactly what happens inside the browser, exposing every phishing URL’s behavior.

                                ⚡️ 𝗛𝗼𝘄 𝘁𝗼 𝘂𝘀𝗲 𝘁𝗵𝗲 𝗕𝗿𝗼𝘄𝘀𝗲𝗿 𝗗𝗮𝘁𝗮 𝘁𝗮𝗯 𝗶𝗻 𝗦𝗮𝗻𝗱𝗯𝗼𝘅 𝗳𝗼𝗿 𝗳𝘂𝗹𝗹 𝗨𝗥𝗟 𝘃𝗶𝘀𝗶𝗯𝗶𝗹𝗶𝘁𝘆 𝘁𝗵𝗮𝘁 𝘀𝗽𝗲𝗲𝗱𝘀 𝘂𝗽 𝘁𝗿𝗶𝗮𝗴𝗲 𝗮𝗻𝗱 𝗿𝗲𝘀𝗽𝗼𝗻𝘀𝗲:
                                𝗛𝗧𝗠𝗟 𝗗𝗢𝗠 𝗖𝗵𝗮𝗻𝗴𝗲𝘀: Track DOM states over time with timeshift, compare page states, and review byte-level diffs.
                                📌 In this case, it reveals when the decrypted phishing page is rendered, exposing the user code and other artifacts hidden in the initial response.

                                𝗨𝗥𝗟 𝗗𝗲𝘁𝗮𝗶𝗹𝘀: Review the final URL, domain, SSL certificate, DNS records, request statistics, and triggered signatures in one place.
                                📌 For device-code phishing, this helps quickly verify suspicious OAuth-related activity without manually correlating multiple data sources.

                                𝗛𝗧𝗧𝗣 𝗥𝗲𝗾𝘂𝗲𝘀𝘁𝘀: Inspect browser-level network activity across HTML, JS, Fetch/XHR, scripts, static files, binaries, archives, and other request categories.
                                📌 Here, requests to /api/device/start retrieve the userCode and sessionId, while /api/device/status/<sessionId> tracks authorization status, providing early confirmation of the phishing flow.

                                𝗜𝗻𝗱𝗶𝗰𝗮𝘁𝗼𝗿𝘀: Automatically collect page-level IOCs, including domains, URLs, hashes, IPs, and ASN data.
                                📌 These indicators provide immediate pivot points for threat hunting, helping analysts expand the investigation beyond the original URL.

                                ✅ This turns URL triage from long manual reconstruction into a fast decision path: what loaded, what changed, and whether the case should be contained, escalated, or turned into detection logic.

                                When phishing relies on dynamic browser behavior, this visibility doesn't just speed up triage — it strengthens every downstream process: faster escalations, sharper response, stronger detection logic.

                                🚀 See how closes phishing blind spots: any.run/cybersecurity-blog/in-

                                  [?]TechWire ⚡ » 🤖 🌐
                                  @techwire@social.gamefan.net

                                  Android 17 makes switching from iPhone to Android much easier, here’s how

                                  Android Switch is now built into the core of Android and iOS, no standalone app needed!

                                  androidauthority.com/android-1

                                  [Android Authority]

                                    [?]Linuxiarze » 🌐
                                    @Linuxiarze@mastodon.social

                                    Firma Fortinet pogłębia integrację z NVIDIA, aby zapewnić przedsiębiorstwom skalowalną ochronę środowisk sztucznej inteligencji. Integracja FortiAIGate z platformami NVIDIA umożliwia tworzenie środowisk sztucznej inteligencji bazujących na... linuxiarze.pl/firma-fortinet-p

                                      [?]Linuxiarze » 🌐
                                      @Linuxiarze@fe.disroot.org

                                      Firma Fortinet pogłębia integrację z NVIDIA, aby zapewnić przedsiębiorstwom skalowalną ochronę środowisk sztucznej inteligencji. Integracja FortiAIGate z platformami NVIDIA umożliwia tworzenie środowisk sztucznej inteligencji bazujących na... https://linuxiarze.pl/firma-fortinet-poglebia-integracje-z-nvidia/ #cybersecurity #sztucznainteligencja #nvidia

                                        [?]pavroo » 🌐
                                        @pavroo@universeodon.com

                                        Firma Fortinet pogłębia integrację z NVIDIA, aby zapewnić przedsiębiorstwom skalowalną ochronę środowisk sztucznej inteligencji. Integracja FortiAIGate z platformami NVIDIA umożliwia tworzenie środowisk sztucznej inteligencji bazujących na... linuxiarze.pl/firma-fortinet-p

                                          [?]EUVD Bot » 🤖 🌐
                                          @EUVD_Bot@mastodon.social

                                          🚨 EUVD-2026-37559

                                          📊 Score: n/a
                                          📦 Product: Taskbuilder
                                          🏢 Vendor: Unknown
                                          📅 Updated: 2026-06-17

                                          📝 The Taskbuilder WordPress plugin before 5.0.8 does not properly sanitise a URL parameter before echoing it into inline JavaScript on a frontend page containing one of its shortcodes, leading to a Reflected Cross-Site Scripting vulnerability that can be triggered again...

                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                            [?]EUVD Bot » 🤖 🌐
                                            @EUVD_Bot@mastodon.social

                                            🚨 EUVD-2026-37557

                                            📊 Score: n/a
                                            📦 Product: weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce
                                            🏢 Vendor: Unknown
                                            📅 Updated: 2026-06-17

                                            📝 The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPress plugin before 2.1.3 does not properly escape a user-supplied paramete...

                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                              [?]EUVD Bot » 🤖 🌐
                                              @EUVD_Bot@mastodon.social

                                              🚨 EUVD-2026-37556

                                              📊 Score: n/a
                                              📦 Product: WP Magnific Popup
                                              🏢 Vendor: Unknown
                                              📅 Updated: 2026-06-17

                                              📝 The WP Magnific Popup WordPress plugin through 1.0 does not properly escape user-controlled link URLs before injecting them into the DOM when displaying image load error messages, allowing authenticated attackers with Author-level access or above to perform Store...

                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                [?]BeyondMachines :verified: » 🤖 🌐
                                                @beyondmachines1@infosec.exchange

                                                ShinyHunters Leaks 26 Million Records Allegedly Stolen From Madison Square Garden Sports

                                                Madison Square Garden Sports Corp. possibly suffered a massive data breach by the ShinyHunters group, resulting in the leak of 26 million records including VIP profiles and internal talent files.

                                                ****

                                                beyondmachines.net/event_detai

                                                  [?]N_{Dario Fadda} » 🌐
                                                  @nuke@poliversity.it

                                                  Chinese Hackers (UNC6508) Spent Over a Year Spying on US Medical Research Institutions via REDCap

                                                  securebulletin.com/chinese-hac

                                                    [?]OTX Bot » 🤖 🌐
                                                    @techbot@social.raytec.co

                                                    New APT-Q-27 sample spotted

                                                    A new campaign has been identified utilizing a valid digital signature from a Chinese technology company that remains unrevoked. The attack chain employs a dropper that retrieves an extension-based module list from command and control infrastructure. The malicious payloads exploit DLL Side-Loading techniques through a legitimate Tencent-signed executable to achieve code execution. The infrastructure includes Google Cloud Storage and a dedicated domain for command and control operations. Multiple components have been identified including an EXE dropper, DLL loader, DAT payload, and the legitimate Tencent executable used for side-loading purposes.

                                                    Pulse ID: 6a325eca53b232c21f5b84ff
                                                    Pulse Link: otx.alienvault.com/pulse/6a325
                                                    Pulse Author: AlienVault
                                                    Created: 2026-06-17 08:46:02

                                                    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                                      [?]N_{Dario Fadda} » 🌐
                                                      @nuke@poliversity.it

                                                      [?]Hackread.com » 🌐
                                                      @Hackread@mstdn.social

                                                      Hackers are using fake AI coding assistants on the Marketplace to steal DeepSeek, OpenAI, and other developer API keys - 15 malicious plugins, nearly 70K downloads, and fake reviews used to lure developers.

                                                      Read: hackread.com/malicious-jetbrai

                                                        [?]TechWire ⚡ » 🤖 🌐
                                                        @techwire@social.gamefan.net

                                                        New report gives T-Mobile the throne for the best carrier in the US

                                                        Never mind T-Life, the un-carrier is objectively still better than the competition.

                                                        androidauthority.com/t-mobile-

                                                        [Android Authority]

                                                          [?]Hacker News » 🤖 🌐
                                                          @h4ckernews@mastodon.social

                                                          Back to top - More...