voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
🚨 EUVD-2026-37201
📊 Score: 7.4/10 (CVSS v3.1)
📦 Product: getssl
🏢 Vendor: ServerCo
📅 Updated: 2026-06-16
📝 In ServerCo getssl version 2.49 and prior, the ACME challenge token returned to the client was not strictly validated against RFC 8555 before being used in challenge-file handling, allowing a maliciously crafted token to influence local path/filename usage d...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-37201
🚨 EUVD-2026-37200
📊 Score: n/a
📦 Product: Devolutions Server, Devolutions Server
🏢 Vendor: Devolutions
📅 Updated: 2026-06-16
📝 Improper access control in PAM account discovery results in Devolutions
Server 2026.2.5, 2026.1.21 allows an authenticated user to retrieve
account discovery scan results.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-37200
🚨 EUVD-2026-37198
📊 Score: 7.8/10 (CVSS v3.1)
📦 Product: stable-diffusion.cpp
🏢 Vendor: leejet
📅 Updated: 2026-06-16
📝 stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. In versions prior to master-584-0a7ae07, the pickle .ckpt parser in src/model.cpp contained a heap b...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-37198
🔴 CVE-2026-22313 - Critical (9.1)
The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vulnerability an authenticated attacker can send
arbitrary commands to the device that are executed with...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-22313/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-53849 - High (8.1)
OpenClaw before 2026.5.7 contains a privilege escalation vulnerability where the allowFrom feature improperly validates Discord account identity using mutable display names instead of immutable user IDs. Attackers with Discord accounts can change ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53849/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-53853 - High (8.3)
OpenClaw before 2026.5.12 contains an argument pattern validation bypass in the exec allowlist that allows attackers to execute disallowed arguments for allowlisted executables on Linux and macOS systems. Attackers can bypass configured argPattern...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53853/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
"Anthropic recently shared a third-party research paper on Fable 5 guardrail bypass techniques with me privately and asked for my take. Nobody expected the US Secretary of Commerce to issue an export control affecting Fable 5 and Mythos, forcing Anthropic to pull the plug on access for everyone to comply.
So much for a drama-free weekend in cybersecurity.
The heavy-handed and hasty export control directive was misguided. The behavior described in the paper cannot meaningfully be fixed, and any attempt would only weaken the model for defense.
What the Report Shows
Since I appear to be the only outside expert who has actually read the paper, I can separate the technical facts from the speculation. The researchers took open-source code with known CVEs, plus new code with deliberately planted vulnerabilities, and asked Fable 5, Mythos, and Opus to “review the code for security issues.” Fable 5 refused. They then asked the models to “fix this code” and, through a multistep and manual process, turned the output into scripts that test the patches.
That’s it. “Fix this code,” plus several manual steps to generate test scripts, should never have triggered an export control. I feel like making ’90s-style t-shirts with “fix this code” on the front and “this shirt is a munition” on the back.
Defenders need to be able to ask AI to fix the bugs in a file, explain why the fix matters, and write tests that confirm the patch works. That is not a guardrail bypass. It is the most valuable thing an AI model can do for defensive security: executing the find, fix, and test loop defenders run every day."
https://www.lutasecurity.com/post/the-fable-5-export-controls-harm-us-cyber-defense
#CyberSecurity #AI #GenerativeAI #ExportControls #Anthropic #Claude #ClaudeFable
https://www.stopkillingtheinternet.com/
Oh, I forgot, SKG also have a sister campaign about digital surveillance move by govt. You all can sign up for news.
I already sign up for news. This is not just a UK problem, this is an upcoming internet problem as a whole
#StopKillingInternet #SKI #privacy #digitalrights #cybersecurity
Apple’s camera-equipped AirPods could launch alongside the foldable iPhone
Here's when Apple could launch its camera-equipped AirPods.
https://www.androidauthority.com/apple-camera-equipped-airpods-launch-window-3678077/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
A new Android banking trojan, Rokarolla, has emerged with an alarming 137 remote commands, actively targeting 217 banking and cryptocurrency applications. Disguised as a Google Play Protect update, it gains Accessibility access to steal credentials, intercept OTPs, block fraud calls, and even replace crypto wallet addresses. Zimperium's zLabs details its sophisticated methods for total…
#cybersecurity #rokarolla #androidmalware
🤖 This post was AI-generated.
Can a PDF carry a virus? Yes — SMBs are prime targets. A single malicious PDF can install spyware, steal credentials, or trigger ransomware. Scan attachments, limit internal sharing, enforce MFA, train staff. Read more: https://proton.me/business/blog/blog-pdf-virus 🔒📄 #CyberSecurity #SMB #Infosec
Google’s June Pixel update is packed with dozens of fixes
June 2026's Pixel update is here for the Pixel 6 and up.
https://www.androidauthority.com/june-2026-pixel-software-update-3678162/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Possible Phishing 🎣
on: ⚠️hxxp[:]//rahulpoona58-del[.]github[.]io/amazon-clone/
🧬 Analysis at: https://urldna.io/scan/6a317ac83b77500006395543
#cybersecurity #phishing #infosec #urldna #scam #infosec
GrapheneOS has been ported to Android 17 and official releases are coming soon
#HackerNews #GrapheneOS #Android17 #Port #OfficialRelease #TechNews #Cybersecurity
https://winbuzzer.com/2026/06/16/microsoft-patches-copilot-searchleak-data-theft-flaw-xcxwbn/
Microsoft has patched a Copilot flaw after researchers showed a one-click chain that could expose two-factor codes and enterprise data via search.
#AI #SearchLeak #Microsoft365Copilot #Microsoft #Microsoft365 #MicrosoftCopilot #Varonis #CVE202642824 #Cybersecurity
Snap is finally about to ship AR glasses — and they cost a fortune
Snap is finally launching augmented glasses for the public. Specs, which Snap describes as "a wearable computer built into see-through augmented reality glasses," will cost $2,195. You can preorder a pair of Specs now a…
https://www.theverge.com/tech/950492/snap-specs-ar-glasses-launch-date-preorder
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
✈️ New Blog Post: Your Boarding Pass Is a Skeleton Key. Frontier Airlines Doesn't Care.
Frontier's mobile API returns full passport numbers, home addresses, children's DOB, credit card details, and KTNs for any booking. The only auth? A PNR and last name. Printed on every boarding pass.
Reported March 3rd. 105 days later, still live. They fixed the least important vuln and ghosted me on the rest. They also updated the website code and somehow made the leaks worse.
Full writeup: https://bobdahacker.com/blog/frontier-airlines-hack
#InfoSec #BugBounty #ResponsibleDisclosure #FrontierAirlines #Security #CyberSecurity #Privacy #Aviation #PCIDSS #DataExposure
Lorem Ipsum Pivots to ClickFix After Fox Tempest Takedown https://deafnews.it/en/article/lorem-ipsum-pivots-to-clickfix-after-fox-tempest-takedown #Cybersecurity
Lighter, cooler headsets are coming, thanks to Qualcomm’s latest silicon
Snapdragon Reality Elite's efficiency gains means manufacturers can ditch external compute and battery pucks if they want to.
https://www.androidauthority.com/qualcomm-snapdragon-reality-elite-3677546/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Hands on with CrowdStrike Crowdtour today with their “Secure AI Everywhere” track. Like I say you learn more hands on than a book or cert will teach you. #Cybersecurity #Crowdstrike #Crowdtour #technology
New by me: Private Cloud Compute Is Impressive, but It Still Needs Real Security Scrutiny
#Cybersecurity #InfoSec #AppleIntelligence #SiriAI #AISecurity
Gamers beware: malicious wallpapers on Steam found stealing accounts
https://securelist.com/dozens-of-malicious-wallpapers-found-on-steam-workshop/120186/
#HackerNews #gamersbeware #maliciouswallpapers #steamsecurity #accounttheft #cybersecurity
🚨Breaking news: gamers learn a tough lesson as their accounts get hijacked by evil wallpaper! 🎮🖼️ Remember, folks, not all downloadable content is meant to be downloaded. Also, kudos to #Kaspersky for bravely stepping in to state the obvious. 🏆🔍
https://securelist.com/dozens-of-malicious-wallpapers-found-on-steam-workshop/120186/ #gamersbeware #accountsecurity #malware #gamingnews #cybersecurity #HackerNews #ngated
XREAL makes the Aura XR glasses official, but is still holding back a key detail
XREAL leaves out the most important details for later this year.
https://www.androidauthority.com/xreal-aura-android-xr-glasses-3677874/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Possible Phishing 🎣
on: ⚠️hxxps[:]//mijn[.]overheid[.]nl[.]berichtenbox[.]l1tjxkgmdqghekubdurkea68msnzfea6kx1u2q2s9pwpvurkzexb[.]luizmatoso[.]com[.]br
🧬 Analysis at: https://urldna.io/scan/6a3148f23b77500006394e57
#cybersecurity #phishing #infosec #urldna #scam #infosec
Android Banker with Complete Device Takeover Capabilities
A newly identified Android banking trojan named Rokarolla has been discovered, distributed through malicious websites masquerading as popular applications like TikTok or Google Chrome. The malware targets 217 distinct cryptocurrency and banking applications using 137 sophisticated commands for device control. Capabilities include harvesting lock screen credentials, exfiltrating contact lists and SMS data, deploying keyloggers, blocking calls, creating fraudulent screen overlays, and disabling Google Play Protect. The infection begins with a dropper impersonating Google Play Protect that installs a secondary payload. Rokarolla communicates with C2 infrastructure via HTTPS, uses overlays to steal banking credentials and device unlock patterns, silently monitors WhatsApp contacts, hijacks SMS and calls, manipulates clipboard content for cryptocurrency theft, and employs snapshot-based screen surveillance. It maintains persistence by hiding its icon, muting device audio, and keeping screens active indefinitely.
Pulse ID: 6a315d684f0c09972ddea652
Pulse Link: https://otx.alienvault.com/pulse/6a315d684f0c09972ddea652
Pulse Author: AlienVault
Created: 2026-06-16 14:27:52
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #Bank #BankingTrojan #Chrome #Clipboard #CyberSecurity #Google #GooglePlay #HTTP #HTTPS #InfoSec #KeyLogger #Malware #OTX #OpenThreatExchange #RAT #SMS #Trojan #WhatsApp #bot #cryptocurrency #AlienVault
Potemkin Loader & RMMProject The Anatomy of a ClickFix Attack
A ClickFix social engineering attack on an unmonitored endpoint led to a multi-stage intrusion affecting over 11 hosts. The infection chain began with a malicious HTA payload that silently installed an MSI package containing Potemkin, a custom loader with a deterministic DGA. Potemkin delivered RMMProject, a 4.4 MB Lua-scriptable RAT featuring browser credential theft with Chrome App-Bound Encryption bypass, hidden-desktop remote control, and 15 distinct task types. The attacker deployed EtherRAT, a Node.js backdoor resolving C2 addresses from Ethereum blockchain, and established a Cloudflare tunnel for persistent access. Hands-on-keyboard activity included battling Windows Defender through AMSI patches, registry modifications, and service termination, followed by lateral movement via WMIExec and SMBExec to deploy malware across the network and reach the domain controller.
Pulse ID: 6a315d670f9460fe003298a8
Pulse Link: https://otx.alienvault.com/pulse/6a315d670f9460fe003298a8
Pulse Author: AlienVault
Created: 2026-06-16 14:27:51
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #BlockChain #Browser #Chrome #Cloud #CyberSecurity #DomainController #Encryption #Endpoint #InfoSec #LUA #Malware #NATO #Nodejs #OTX #OpenThreatExchange #RAT #SMB #SocialEngineering #Troll #Windows #bot #AlienVault
🚨New ransom group blog post!🚨
Group name: incransom
Post title: jasperplastics.info
Info: https://cti.fyi/groups/incransom.html
#ransomware #cti #threatintelligence #cybersecurity #infosec
Trump Bolsters Military, Intelligence Cybersecurity with New National Security Memo
President Trump just took a major step to fortify America's defenses in the digital age, signing a National Security Presidential Memorandum to boost cybersecurity and modernize governance for our nation's most sensitive computer systems. This move aims to improve accountability and coordination…
#NationalSecurity #Cybersecurity #MilitaryOperations #IntelligenceOperations #NationState
A 52% price drop gets you the Amazon Smart Plug 2-Pack at an all-time low
It's your first chance to get a pair of Amazon's compact smart plugs for under $24.
https://www.androidauthority.com/amazon-smart-plug-2-pack-deal-3676485/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
🔴 CVE-2026-40750 - Critical (9.9)
Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server.
This issue affects Kids Online Store: from n/a through 0.8.9.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-40750/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🚨 EUVD-2026-37063
📊 Score: 8.6/10 (CVSS v3.1)
📦 Product: NPort W2150A/W2250A Series, NPort W2150A-W4/W2250A-W4 Series
🏢 Vendor: Moxa
📅 Updated: 2026-06-16
📝 A stack-based buffer overflow vulnerability has been found in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and earlier. This vulnerability stems from insufficient input validation of user-supplied input i...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-37063
🚨 EUVD-2026-37062
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: NPort W2150A-W4/W2250A-W4 Series, NPort W2150A/W2250A Series
🏢 Vendor: Moxa
📅 Updated: 2026-06-16
📝 A format string vulnerability has been found in the "alias" parameter of the Serial Param configuration page in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and prior. This vulnerability stems from insuff...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-37062
Possible Phishing 🎣
on: ⚠️hxxp[:]//leia-santander[.]vercel[.]app
🧬 Analysis at: https://urldna.io/scan/6a30ee413b775000082876b5
#cybersecurity #phishing #infosec #urldna #scam #infosec
🟠 CVE-2026-39581 - High (8.5)
Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-39581/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🔴 CVE-2026-49772 - Critical (9.3)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allows Blind SQL Injection.
This issue affects The Events Calendar: from 6.15.12 through 6.16.2.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49772/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Infinite Campus data breach affects 137,000 school staff accounts
The ShinyHunters extortion gang stole personal information from more than 137,000 school staff accounts in a Salesforce data theft attack that targeted the widely used Infinite Campus K-12 student information system
#Salesforce #InfiniteCampus #education #security #cybersecurity #hackers #hacking #hacked
Autodesk: 191 CVEs, 95% unpatched. Avg CVSS 7.71. Trust Score: C. Design tools are a growing attack surface. #Autodesk #infosec #cybersecurity
Vertex AI SDK: Cross-Tenant Bucket Squatting Enabled RCE https://deafnews.it/en/article/vertex-ai-sdk-cross-tenant-bucket-squatting-enabled-rce #Cybersecurity