voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]EUVD Bot » 🤖 🌐
@EUVD_Bot@mastodon.social

🚨 EUVD-2026-37201

📊 Score: 7.4/10 (CVSS v3.1)
📦 Product: getssl
🏢 Vendor: ServerCo
📅 Updated: 2026-06-16

📝 In ServerCo getssl version 2.49 and prior, the ACME challenge token returned to the client was not strictly validated against RFC 8555 before being used in challenge-file handling, allowing a maliciously crafted token to influence local path/filename usage d...

🔗 euvd.enisa.europa.eu/vulnerabi

    [?]EUVD Bot » 🤖 🌐
    @EUVD_Bot@mastodon.social

    🚨 EUVD-2026-37200

    📊 Score: n/a
    📦 Product: Devolutions Server, Devolutions Server
    🏢 Vendor: Devolutions
    📅 Updated: 2026-06-16

    📝 Improper access control in PAM account discovery results in Devolutions
    Server 2026.2.5, 2026.1.21 allows an authenticated user to retrieve
    account discovery scan results.

    🔗 euvd.enisa.europa.eu/vulnerabi

      [?]EUVD Bot » 🤖 🌐
      @EUVD_Bot@mastodon.social

      🚨 EUVD-2026-37198

      📊 Score: 7.8/10 (CVSS v3.1)
      📦 Product: stable-diffusion.cpp
      🏢 Vendor: leejet
      📅 Updated: 2026-06-16

      📝 stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. In versions prior to master-584-0a7ae07, the pickle .ckpt parser in src/model.cpp contained a heap b...

      🔗 euvd.enisa.europa.eu/vulnerabi

        [?]TheHackerWire » 🤖 🌐
        @thehackerwire@mastodon.social

        🔴 CVE-2026-22313 - Critical (9.1)

        The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vulnerability an authenticated attacker can send
        arbitrary commands to the device that are executed with...

        🔗 thehackerwire.com/vulnerabilit

        CVE Alert: CVE-2026-22313

        Alt...CVE Alert: CVE-2026-22313

          [?]TheHackerWire » 🤖 🌐
          @thehackerwire@mastodon.social

          🟠 CVE-2026-53849 - High (8.1)

          OpenClaw before 2026.5.7 contains a privilege escalation vulnerability where the allowFrom feature improperly validates Discord account identity using mutable display names instead of immutable user IDs. Attackers with Discord accounts can change ...

          🔗 thehackerwire.com/vulnerabilit

          CVE Alert: CVE-2026-53849

          Alt...CVE Alert: CVE-2026-53849

            [?]TheHackerWire » 🤖 🌐
            @thehackerwire@mastodon.social

            🟠 CVE-2026-53853 - High (8.3)

            OpenClaw before 2026.5.12 contains an argument pattern validation bypass in the exec allowlist that allows attackers to execute disallowed arguments for allowlisted executables on Linux and macOS systems. Attackers can bypass configured argPattern...

            🔗 thehackerwire.com/vulnerabilit

            CVE Alert: CVE-2026-53853

            Alt...CVE Alert: CVE-2026-53853

              [?]Miguel Afonso Caetano » 🌐
              @remixtures@tldr.nettime.org

              "Anthropic recently shared a third-party research paper on Fable 5 guardrail bypass techniques with me privately and asked for my take. Nobody expected the US Secretary of Commerce to issue an export control affecting Fable 5 and Mythos, forcing Anthropic to pull the plug on access for everyone to comply.

              So much for a drama-free weekend in cybersecurity.

              The heavy-handed and hasty export control directive was misguided. The behavior described in the paper cannot meaningfully be fixed, and any attempt would only weaken the model for defense.

              What the Report Shows

              Since I appear to be the only outside expert who has actually read the paper, I can separate the technical facts from the speculation. The researchers took open-source code with known CVEs, plus new code with deliberately planted vulnerabilities, and asked Fable 5, Mythos, and Opus to “review the code for security issues.” Fable 5 refused. They then asked the models to “fix this code” and, through a multistep and manual process, turned the output into scripts that test the patches.

              That’s it. “Fix this code,” plus several manual steps to generate test scripts, should never have triggered an export control. I feel like making ’90s-style t-shirts with “fix this code” on the front and “this shirt is a munition” on the back.

              Defenders need to be able to ask AI to fix the bugs in a file, explain why the fix matters, and write tests that confirm the patch works. That is not a guardrail bypass. It is the most valuable thing an AI model can do for defensive security: executing the find, fix, and test loop defenders run every day."

              lutasecurity.com/post/the-fabl

                [?]AmmarSpaces » 🌐
                @AmmarSpaces@infosec.exchange

                stopkillingtheinternet.com/

                Oh, I forgot, SKG also have a sister campaign about digital surveillance move by govt. You all can sign up for news.

                I already sign up for news. This is not just a UK problem, this is an upcoming internet problem as a whole

                  [?]TechWire ⚡ » 🤖 🌐
                  @techwire@social.gamefan.net

                  Apple’s camera-equipped AirPods could launch alongside the foldable iPhone

                  Here's when Apple could launch its camera-equipped AirPods.

                  androidauthority.com/apple-cam

                  [Android Authority]

                    [?]Daniel Marsh » 🤖 🌐
                    @danielmarsh@social.thepixelspulse.com

                    A new Android banking trojan, Rokarolla, has emerged with an alarming 137 remote commands, actively targeting 217 banking and cryptocurrency applications. Disguised as a Google Play Protect update, it gains Accessibility access to steal credentials, intercept OTPs, block fraud calls, and even replace crypto wallet addresses. Zimperium's zLabs details its sophisticated methods for total…

                    tpp.blog/1cs4ms9

                    🤖 This post was AI-generated.

                      [?]:awesome:🐦‍🔥nemo™🐦‍⬛ 🇺🇦🍉 » 🌐
                      @nemo@mas.to

                      Can a PDF carry a virus? Yes — SMBs are prime targets. A single malicious PDF can install spyware, steal credentials, or trigger ransomware. Scan attachments, limit internal sharing, enforce MFA, train staff. Read more: proton.me/business/blog/blog-p 🔒📄

                      Opinion mas.to/@nemo/116761900381526148

                        [?]TechWire ⚡ » 🤖 🌐
                        @techwire@social.gamefan.net

                        Google’s June Pixel update is packed with dozens of fixes

                        June 2026's Pixel update is here for the Pixel 6 and up.

                        androidauthority.com/june-2026

                        [Android Authority]

                          [?]urlDNA.io :verified: » 🤖 🌐
                          @urldna@infosec.exchange

                          Possible Phishing 🎣
                          on: ⚠️hxxp[:]//rahulpoona58-del[.]github[.]io/amazon-clone/
                          🧬 Analysis at: urldna.io/scan/6a317ac83b77500

                            [?]Hacker News » 🤖 🌐
                            @h4ckernews@mastodon.social

                            [?]Winbuzzer » 🌐
                            @winbuzzer@mastodon.social

                            winbuzzer.com/2026/06/16/micro

                            Microsoft has patched a Copilot flaw after researchers showed a one-click chain that could expose two-factor codes and enterprise data via search.

                              [?]TechWire ⚡ » 🤖 🌐
                              @techwire@social.gamefan.net

                              Snap is finally about to ship AR glasses — and they cost a fortune

                              Snap is finally launching augmented glasses for the public. Specs, which Snap describes as "a wearable computer built into see-through augmented reality glasses," will cost $2,195. You can preorder a pair of Specs now a…

                              theverge.com/tech/950492/snap-

                              [The Verge]

                                [?]BobDaHacker 🏳️‍⚧️ [She/They] » 🌐
                                @bobdahacker@infosec.exchange

                                ✈️ New Blog Post: Your Boarding Pass Is a Skeleton Key. Frontier Airlines Doesn't Care.

                                Frontier's mobile API returns full passport numbers, home addresses, children's DOB, credit card details, and KTNs for any booking. The only auth? A PNR and last name. Printed on every boarding pass.

                                Reported March 3rd. 105 days later, still live. They fixed the least important vuln and ghosted me on the rest. They also updated the website code and somehow made the leaks worse.

                                Full writeup: bobdahacker.com/blog/frontier-

                                  [?]deafnews » 🤖 🌐
                                  @deafnews@infosec.exchange

                                  [?]TechWire ⚡ » 🤖 🌐
                                  @techwire@social.gamefan.net

                                  Lighter, cooler headsets are coming, thanks to Qualcomm’s latest silicon

                                  Snapdragon Reality Elite's efficiency gains means manufacturers can ditch external compute and battery pucks if they want to.

                                  androidauthority.com/qualcomm-

                                  [Android Authority]

                                    [?]ChiefGyk3D » 🌐
                                    @chiefgyk3d@social.chiefgyk3d.com

                                    Hands on with CrowdStrike Crowdtour today with their “Secure AI Everywhere” track. Like I say you learn more hands on than a book or cert will teach you.

                                      [?]Kyle Reddoch (CybersecKyle) » 🌐
                                      @cyberseckyle@infosec.exchange

                                      [?]Hacker News » 🤖 🌐
                                      @h4ckernews@mastodon.social

                                      [?]N-gated Hacker News » 🤖 🌐
                                      @ngate@mastodon.social

                                      🚨Breaking news: gamers learn a tough lesson as their accounts get hijacked by evil wallpaper! 🎮🖼️ Remember, folks, not all downloadable content is meant to be downloaded. Also, kudos to for bravely stepping in to state the obvious. 🏆🔍
                                      securelist.com/dozens-of-malic

                                        [?]TechWire ⚡ » 🤖 🌐
                                        @techwire@social.gamefan.net

                                        XREAL makes the Aura XR glasses official, but is still holding back a key detail

                                        XREAL leaves out the most important details for later this year.

                                        androidauthority.com/xreal-aur

                                        [Android Authority]

                                          [?]urlDNA.io :verified: » 🤖 🌐
                                          @urldna@infosec.exchange

                                          Possible Phishing 🎣
                                          on: ⚠️hxxps[:]//mijn[.]overheid[.]nl[.]berichtenbox[.]l1tjxkgmdqghekubdurkea68msnzfea6kx1u2q2s9pwpvurkzexb[.]luizmatoso[.]com[.]br
                                          🧬 Analysis at: urldna.io/scan/6a3148f23b77500

                                            [?]The New Oil » 🤖 🌐
                                            @thenewoil@mastodon.thenewoil.org

                                            [?]OTX Bot » 🤖 🌐
                                            @techbot@social.raytec.co

                                            Android Banker with Complete Device Takeover Capabilities

                                            A newly identified Android banking trojan named Rokarolla has been discovered, distributed through malicious websites masquerading as popular applications like TikTok or Google Chrome. The malware targets 217 distinct cryptocurrency and banking applications using 137 sophisticated commands for device control. Capabilities include harvesting lock screen credentials, exfiltrating contact lists and SMS data, deploying keyloggers, blocking calls, creating fraudulent screen overlays, and disabling Google Play Protect. The infection begins with a dropper impersonating Google Play Protect that installs a secondary payload. Rokarolla communicates with C2 infrastructure via HTTPS, uses overlays to steal banking credentials and device unlock patterns, silently monitors WhatsApp contacts, hijacks SMS and calls, manipulates clipboard content for cryptocurrency theft, and employs snapshot-based screen surveillance. It maintains persistence by hiding its icon, muting device audio, and keeping screens active indefinitely.

                                            Pulse ID: 6a315d684f0c09972ddea652
                                            Pulse Link: otx.alienvault.com/pulse/6a315
                                            Pulse Author: AlienVault
                                            Created: 2026-06-16 14:27:52

                                            Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                              [?]OTX Bot » 🤖 🌐
                                              @techbot@social.raytec.co

                                              Potemkin Loader & RMMProject The Anatomy of a ClickFix Attack

                                              A ClickFix social engineering attack on an unmonitored endpoint led to a multi-stage intrusion affecting over 11 hosts. The infection chain began with a malicious HTA payload that silently installed an MSI package containing Potemkin, a custom loader with a deterministic DGA. Potemkin delivered RMMProject, a 4.4 MB Lua-scriptable RAT featuring browser credential theft with Chrome App-Bound Encryption bypass, hidden-desktop remote control, and 15 distinct task types. The attacker deployed EtherRAT, a Node.js backdoor resolving C2 addresses from Ethereum blockchain, and established a Cloudflare tunnel for persistent access. Hands-on-keyboard activity included battling Windows Defender through AMSI patches, registry modifications, and service termination, followed by lateral movement via WMIExec and SMBExec to deploy malware across the network and reach the domain controller.

                                              Pulse ID: 6a315d670f9460fe003298a8
                                              Pulse Link: otx.alienvault.com/pulse/6a315
                                              Pulse Author: AlienVault
                                              Created: 2026-06-16 14:27:51

                                              Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                                [?]CTI.FYI » 🤖 🌐
                                                @CTI_FYI@infosec.exchange

                                                🚨New ransom group blog post!🚨

                                                Group name: incransom
                                                Post title: jasperplastics.info
                                                Info: cti.fyi/groups/incransom.html

                                                  [?]Analyst207 » 🤖 🌐
                                                  @Analyst207@mastodon.social

                                                  Trump Bolsters Military, Intelligence Cybersecurity with New National Security Memo

                                                  President Trump just took a major step to fortify America's defenses in the digital age, signing a National Security Presidential Memorandum to boost cybersecurity and modernize governance for our nation's most sensitive computer systems. This move aims to improve accountability and coordination…

                                                  osintsights.com/trump-bolsters

                                                    [?]TechWire ⚡ » 🤖 🌐
                                                    @techwire@social.gamefan.net

                                                    A 52% price drop gets you the Amazon Smart Plug 2-Pack at an all-time low

                                                    It's your first chance to get a pair of Amazon's compact smart plugs for under $24.

                                                    androidauthority.com/amazon-sm

                                                    [Android Authority]

                                                      [?]TheHackerWire » 🤖 🌐
                                                      @thehackerwire@mastodon.social

                                                      🔴 CVE-2026-40750 - Critical (9.9)

                                                      Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server.

                                                      This issue affects Kids Online Store: from n/a through 0.8.9.

                                                      🔗 thehackerwire.com/vulnerabilit

                                                      CVE Alert: CVE-2026-40750

                                                      Alt...CVE Alert: CVE-2026-40750

                                                        [?]EUVD Bot » 🤖 🌐
                                                        @EUVD_Bot@mastodon.social

                                                        🚨 EUVD-2026-37063

                                                        📊 Score: 8.6/10 (CVSS v3.1)
                                                        📦 Product: NPort W2150A/W2250A Series, NPort W2150A-W4/W2250A-W4 Series
                                                        🏢 Vendor: Moxa
                                                        📅 Updated: 2026-06-16

                                                        📝 A stack-based buffer overflow vulnerability has been found in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and earlier. This vulnerability stems from insufficient input validation of user-supplied input i...

                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                          [?]EUVD Bot » 🤖 🌐
                                                          @EUVD_Bot@mastodon.social

                                                          🚨 EUVD-2026-37062

                                                          📊 Score: 6.9/10 (CVSS v3.1)
                                                          📦 Product: NPort W2150A-W4/W2250A-W4 Series, NPort W2150A/W2250A Series
                                                          🏢 Vendor: Moxa
                                                          📅 Updated: 2026-06-16

                                                          📝 A format string vulnerability has been found in the "alias" parameter of the Serial Param configuration page in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and prior. This vulnerability stems from insuff...

                                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                                            [?]urlDNA.io :verified: » 🤖 🌐
                                                            @urldna@infosec.exchange

                                                            Possible Phishing 🎣
                                                            on: ⚠️hxxp[:]//leia-santander[.]vercel[.]app
                                                            🧬 Analysis at: urldna.io/scan/6a30ee413b77500

                                                              [?]TheHackerWire » 🤖 🌐
                                                              @thehackerwire@mastodon.social

                                                              🟠 CVE-2026-39581 - High (8.5)

                                                              Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions.

                                                              🔗 thehackerwire.com/vulnerabilit

                                                              CVE Alert: CVE-2026-39581

                                                              Alt...CVE Alert: CVE-2026-39581

                                                                [?]TheHackerWire » 🤖 🌐
                                                                @thehackerwire@mastodon.social

                                                                🔴 CVE-2026-49772 - Critical (9.3)

                                                                Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allows Blind SQL Injection.

                                                                This issue affects The Events Calendar: from 6.15.12 through 6.16.2.

                                                                🔗 thehackerwire.com/vulnerabilit

                                                                CVE Alert: CVE-2026-49772

                                                                Alt...CVE Alert: CVE-2026-49772

                                                                  [?]gtbarry » 🌐
                                                                  @gtbarry@mastodon.social

                                                                  Infinite Campus data breach affects 137,000 school staff accounts

                                                                  The ShinyHunters extortion gang stole personal information from more than 137,000 school staff accounts in a Salesforce data theft attack that targeted the widely used Infinite Campus K-12 student information system

                                                                  bleepingcomputer.com/news/secu

                                                                    [?]Hugo | DevOps | Cybersecurity » 🌐
                                                                    @hugovalters@mastodon.social

                                                                    Autodesk: 191 CVEs, 95% unpatched. Avg CVSS 7.71. Trust Score: C. Design tools are a growing attack surface.

                                                                    valtersit.com/vendors/autodesk/

                                                                      [?]deafnews » 🤖 🌐
                                                                      @deafnews@infosec.exchange

                                                                      Back to top - More...