voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]Malicious Extension Bot » 🤖 🌐
@malicious_browser_bot@infosec.exchange

extension Advanced Tweet Translator seems malicious. Its badness score is 95/100!

```json
{"id": "hplfbpigkfejkaajfpmjciogfbpnekon", "score": 95, "platform": "chrome", "name": "Advanced Tweet Translator"}
```

    [?]TechWire ⚡ » 🤖 🌐
    @techwire@social.gamefan.net

    Russian drones spotted using screwed-on magnetic compasses as navigation aids — the on-board camera can occasionally tilt down to check bearings if satel…

    Russian drone troops are adding cheap magnetic compasses to help find their bearings. Crude add-on helps them find their bearings and locate their targets even without GPS.

    tomshardware.com/tech-industry

    [Tom's Hardware]

      [?]TechWire ⚡ » 🤖 🌐
      @techwire@social.gamefan.net

      Samsung cuts hundreds of US consumer electronics jobs ahead of Texas HQ move — 739 roles affected in New Jersey as chip division posts record profit

      Samsung told Reuters that a majority of the affected New Jersey employees received relocation offers, while others were let go.

      tomshardware.com/tech-industry

      [Tom's Hardware]

        [?]TheHackerWire » 🤖 🌐
        @thehackerwire@mastodon.social

        🟠 CVE-2026-13410 - High (8.2)

        Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled.

        The default user agent is initialised with SSL_verify_mode explicitly disabled.

        An attacker with network man-in-the-middle (MITM) capability between the ...

        🔗 thehackerwire.com/vulnerabilit

        CVE Alert: CVE-2026-13410

        Alt...CVE Alert: CVE-2026-13410

          [?]TheHackerWire » 🤖 🌐
          @thehackerwire@mastodon.social

          🔴 CVE-2026-9810 - Critical (9.8)

          The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator session, allowing unauthenticated attackers who complete the public OAuth flow to execute privileg...

          🔗 thehackerwire.com/vulnerabilit

          CVE Alert: CVE-2026-9810

          Alt...CVE Alert: CVE-2026-9810

            [?]urlDNA.io :verified: » 🤖 🌐
            @urldna@infosec.exchange

            Possible Phishing 🎣
            on: ⚠️hxxps[:]//krakencommand[.]halseyburgund[.]com
            🧬 Analysis at: urldna.io/scan/6a5c4bc63b77500

              [?]TheHackerWire » 🤖 🌐
              @thehackerwire@mastodon.social

              🟠 CVE-2026-11575 - High (7.5)

              The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticity of incoming payment callbacks: the secret used to validate the callback signature is empty on sites configured through the current setup flow, so...

              🔗 thehackerwire.com/vulnerabilit

              CVE Alert: CVE-2026-11575

              Alt...CVE Alert: CVE-2026-11575

                [?]Hugo | DevOps | Cybersecurity » 🌐
                @hugovalters@mastodon.social

                Nextcloud: 94 CVEs, 98% unpatched. Trust Score: C. Top weaknesses: improper access control (CWE-284). Open source ≠ secure by default. Patch now.

                valtersit.com/vendors/nextclou

                  [?]ChiefGyk3D » 🌐
                  @chiefgyk3d@social.chiefgyk3d.com

                  I genuinely don’t understand why so many people in cybersecurity ask for my LinkedIn. The real conversations aren’t happening there anymore. They’re on Discord, Matrix, YouTube, and even Instagram and TikTok. LinkedIn barely works for networking or jobs anymore, let alone learning.

                    [?]TechWire ⚡ » 🤖 🌐
                    @techwire@social.gamefan.net

                    Report: Apple targets October launch for OLED iPad mini, kicking off next wave of iPad updates

                    entry-level iPad, the iPad Air, and the iPad Pro. Here are the details.

                    9to5mac.com/2026/07/16/report-

                    [9to5Mac]

                      [?]TheHackerWire » 🤖 🌐
                      @thehackerwire@mastodon.social

                      🟠 CVE-2026-10130 - High (8.2)

                      QueryWeaver contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain valid session tokens for existing accounts by submitting a signup request with a known victim email address. The signup route unconditional...

                      🔗 thehackerwire.com/vulnerabilit

                      CVE Alert: CVE-2026-10130

                      Alt...CVE Alert: CVE-2026-10130

                        [?]TheHackerWire » 🤖 🌐
                        @thehackerwire@mastodon.social

                        🟠 CVE-2026-12228 - High (8.7)

                        A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint of parisneo/lollms (latest version). The endpoint stores attacker-controlled `prompt_content` into `DBDirectMessage.content` without server-side san...

                        🔗 thehackerwire.com/vulnerabilit

                        CVE Alert: CVE-2026-12228

                        Alt...CVE Alert: CVE-2026-12228

                          [?]TheHackerWire » 🤖 🌐
                          @thehackerwire@mastodon.social

                          🟠 CVE-2026-53994 - High (7.5)

                          ProFTPD mod_sftp contains a heap-based buffer overflow reachable by an authenticated SFTP user. The fxp_packet_read() function accepts the attacker-supplied 32-bit big-endian SFTP packet length without a minimum sanity check. A value of 0 causes a...

                          🔗 thehackerwire.com/vulnerabilit

                          CVE Alert: CVE-2026-53994

                          Alt...CVE Alert: CVE-2026-53994

                            [?]TheHackerWire » 🤖 🌐
                            @thehackerwire@mastodon.social

                            🔴 CVE-2026-9202 - Critical (9.8)

                            IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented deployment option), newly created accounts are immediately active and can a...

                            🔗 thehackerwire.com/vulnerabilit

                            CVE Alert: CVE-2026-9202

                            Alt...CVE Alert: CVE-2026-9202

                              [?]TheHackerWire » 🤖 🌐
                              @thehackerwire@mastodon.social

                              🟠 CVE-2026-9762 - High (7.8)

                              IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control.

                              🔗 thehackerwire.com/vulnerabilit

                              CVE Alert: CVE-2026-9762

                              Alt...CVE Alert: CVE-2026-9762

                                [?]TheHackerWire » 🤖 🌐
                                @thehackerwire@mastodon.social

                                🟠 CVE-2026-50273 - High (7.5)

                                Datadog .NET Tracer is a client library for Datadog APM for .NET applications. Prior to 3.43.0, Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD...

                                🔗 thehackerwire.com/vulnerabilit

                                CVE Alert: CVE-2026-50273

                                Alt...CVE Alert: CVE-2026-50273

                                  [?]TheHackerWire » 🤖 🌐
                                  @thehackerwire@mastodon.social

                                  🟠 CVE-2026-63101 - High (7.5)

                                  Open Event Server through 1.19.1 contains a missing authentication vulnerability that allows unauthenticated attackers to export the complete member roster of any group, including email addresses, names, join dates, and roles, by submitting reques...

                                  🔗 thehackerwire.com/vulnerabilit

                                  CVE Alert: CVE-2026-63101

                                  Alt...CVE Alert: CVE-2026-63101

                                    [?]TheHackerWire » 🤖 🌐
                                    @thehackerwire@mastodon.social

                                    🔴 CVE-2026-8297 - Critical (9.8)

                                    Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management System allows SQL Injection.

                                    This ...

                                    🔗 thehackerwire.com/vulnerabilit

                                    CVE Alert: CVE-2026-8297

                                    Alt...CVE Alert: CVE-2026-8297

                                      [?]TheHackerWire » 🤖 🌐
                                      @thehackerwire@mastodon.social

                                      🔴 CVE-2026-54496 - Critical (9.3)

                                      ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primitives 0.28.0, and zcashd 6.20.0, the variable-base scalar multiplication gadget in halo2_gadgets/src/ecc/chip/mul/incomplete.rs ...

                                      🔗 thehackerwire.com/vulnerabilit

                                      CVE Alert: CVE-2026-54496

                                      Alt...CVE Alert: CVE-2026-54496

                                        [?]TechWire ⚡ » 🤖 🌐
                                        @techwire@social.gamefan.net

                                        Windows games run better than ever on Macs, officially or unofficially

                                        There are few software limitations on anyone considering a switch from Windows to Mac. Not only do all the biggest PC apps run on the platform, but there are countless examples of useful apps that are exclusive to Mac. …

                                        9to5mac.com/2026/07/16/windows

                                        [9to5Mac]

                                          [?]TechWire ⚡ » 🤖 🌐
                                          @techwire@social.gamefan.net

                                          Signal Ring gives blood pressure readings, not just alerts like Apple Watch

                                          Five Apple Watch models are able to measure your blood pressure in order to generate alerts for possible hypertension. However, they do not provide your actual blood pressure readings. A few smart rings and other fitnes…

                                          9to5mac.com/2026/07/16/signal-

                                          [9to5Mac]

                                            [?]urlDNA.io :verified: » 🤖 🌐
                                            @urldna@infosec.exchange

                                            Possible Phishing 🎣
                                            on: ⚠️hxxps[:]//docs[.]google[.]com/presentation/d/e/2PACX-1vQuAOXgfCEP8gkFXOdsERRWrd6GfTndG5v4UN5Edb9ycrgaCx684b0O_KADinYgt7ajrXHsMsf2uI9f/pub?start=false&loop=false&delayms=60000
                                            🧬 Analysis at: urldna.io/scan/6a5bf12a3b77500

                                              [?]N_{Dario Fadda} » 🌐
                                              @nuke@poliversity.it

                                              ✨ Scattered Spider smascherata: 5 anni e mezzo di carcere per l’attacco da 29 milioni di sterline a Transport for London

                                              insicurezzadigitale.com/scatte

                                              @informatica

                                                [?]N_{Dario Fadda} » 🌐
                                                @nuke@poliversity.it

                                                ✨ Coca-Cola ferma la produzione di Fairlife dopo un attacco ransomware: quando il cybercrime arriva in tavola

                                                insicurezzadigitale.com/coca-c

                                                @informatica

                                                  [?]Malicious Extension Bot » 🤖 🌐
                                                  @malicious_browser_bot@infosec.exchange

                                                  extension Midoriya and Todoroki Live Wallpaper seems malicious. Its badness score is 93/100!

                                                  ```json
                                                  {"id": "annjkghipiedphiknmcfaepapmghfjfj", "score": 93, "platform": "chrome", "name": "Midoriya and Todoroki Live Wallpaper"}
                                                  ```

                                                    [?]teufelswerk » 🌐
                                                    @teufelswerk@social.tchncs.de

                                                    Die Idee ist verlockend einfach: ein Login für alle Kunden, alle Systeme, alle Updates. Ein Klick auf „Alles aktualisieren“ und schon fühlt sich IT-Sicherheit nach Fortschritt an. Multi-Site-Management als Sicherheitsstrategie ist ein Einfallstor mit Komfortfunktion. 👇

                                                    teufelswerk.net/cybersecurity-

                                                      [?]TechWire ⚡ » 🤖 🌐
                                                      @techwire@social.gamefan.net

                                                      1Password now lets Claude sign in to websites without seeing your passwords

                                                      1Password is launching a new Claude integration for Mac users today. It’s designed to let Anthropic’s AI agent sign in to websites without seeing your password or two-factor authentication code.

                                                      9to5mac.com/2026/07/16/1passwo

                                                      [9to5Mac]

                                                        [?]TechWire ⚡ » 🤖 🌐
                                                        @techwire@social.gamefan.net

                                                        The 5 laptop features worth paying extra for, plus 3 you can ignore

                                                        From RAM and hardware, here's where you should spend your laptop budget -- and where you can save money.

                                                        zdnet.com/article/laptop-featu

                                                        [ZDNet]

                                                          [?]TheHackerWire » 🤖 🌐
                                                          @thehackerwire@mastodon.social

                                                          🟠 CVE-2026-57860 - High (7.8)

                                                          ForgeCode (tailcallhq/forgecode), an AI pair-programming CLI, automatically loads and executes the MCP servers defined in a repository's .mcp.json file on startup without user confirmation. A malicious repository can supply a crafted .mcp.json who...

                                                          🔗 thehackerwire.com/vulnerabilit

                                                          CVE Alert: CVE-2026-57860

                                                          Alt...CVE Alert: CVE-2026-57860

                                                            [?]TheHackerWire » 🤖 🌐
                                                            @thehackerwire@mastodon.social

                                                            🟠 CVE-2026-12691 - High (7.5)

                                                            Missing authentication for critical function vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass.

                                                            This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.

                                                            🔗 thehackerwire.com/vulnerabilit

                                                            CVE Alert: CVE-2026-12691

                                                            Alt...CVE Alert: CVE-2026-12691

                                                              [?]EUVD Bot » 🤖 🌐
                                                              @EUVD_Bot@mastodon.social

                                                              🚨 EUVD-2026-45433

                                                              📊 Score: 5.3/10 (CVSS v3.1)
                                                              📦 Product: CordysCRM, CordysCRM
                                                              🏢 Vendor: 1Panel-dev
                                                              📅 Updated: 2026-07-19

                                                              📝 A vulnerability was determined in 1Panel-dev CordysCRM up to 1.4.1. Impacted is the function getSqlBotSrc of the file backend/crm/src/main/java/cn/cordys/crm/system/service/IntegrationConfigService.java of the component Third Party Edit Endpo...

                                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                                [?]EUVD Bot » 🤖 🌐
                                                                @EUVD_Bot@mastodon.social

                                                                🚨 EUVD-2026-45432

                                                                📊 Score: 5.3/10 (CVSS v3.1)
                                                                📦 Product: CordysCRM, CordysCRM
                                                                🏢 Vendor: 1Panel-dev
                                                                📅 Updated: 2026-07-19

                                                                📝 A vulnerability was found in 1Panel-dev CordysCRM up to 1.4.1. This issue affects some unknown processing of the file backend/crm/src/main/java/cn/cordys/crm/integration/sso/service/TokenService.java of the component Third Party Endpoint. Per...

                                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                                  [?]urlDNA.io :verified: » 🤖 🌐
                                                                  @urldna@infosec.exchange

                                                                  Possible Phishing 🎣
                                                                  on: ⚠️hxxps[:]//tribelio[.]page/fbaccesslogin
                                                                  🧬 Analysis at: urldna.io/scan/6a5c3dc63b77500

                                                                    [?]TheHackerWire » 🤖 🌐
                                                                    @thehackerwire@mastodon.social

                                                                    🔴 CVE-2026-12692 - Critical (9.8)

                                                                    Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass.

                                                                    This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.

                                                                    🔗 thehackerwire.com/vulnerabilit

                                                                    CVE Alert: CVE-2026-12692

                                                                    Alt...CVE Alert: CVE-2026-12692

                                                                      [?]OffSequence » 🌐
                                                                      @offseq@infosec.exchange

                                                                      CVE-2026-16223: SSRF in 1Panel-dev CordysCRM 1.4.0 & 1.4.1 (MEDIUM, CVSS 5.3). Exploitable via appSecret — enables unauthorized server requests. No patch yet: restrict endpoint, monitor logs. radar.offseq.com/threat/cve-20

                                                                      Medium threat: CVE-2026-16223: Server-Side Request Forgery in 1Panel-dev CordysCRM

                                                                      Alt...Medium threat: CVE-2026-16223: Server-Side Request Forgery in 1Panel-dev CordysCRM

                                                                        [?]BeeSINT » 🌐
                                                                        @BeeSINT@mastodon.social

                                                                        🎣 Phishing Spotlight

                                                                        www[.]nextjs-instagram-firebase[.]vercel[.]app

                                                                        🌐 Stack: Vercel, Next.js

                                                                        🔗 beesint.com/pulse/4162bd87-44f

                                                                          [?]BeyondMachines :verified: » 🤖 🌐
                                                                          @beyondmachines1@infosec.exchange

                                                                          Google Releases Emergency Chrome Update to Fix Seven Memory Safety Vulnerabilities

                                                                          Google released an emergency update for Chrome to fix seven vulnerabilities, including three critical use-after-free flaws in the CameraCapture, GPU, and Network components.

                                                                          **It's not normal for a software to get two sets of patches in 48hrs. So treat this seriously. Update Chrome and other Chromium-based browsers (Edge, Opera, Brave, and Vivaldi) immediately. Updating the browser is simple, and your tabs reopen after the restart.**

                                                                          beyondmachines.net/event_detai

                                                                            [?]TechWire ⚡ » 🤖 🌐
                                                                            @techwire@social.gamefan.net

                                                                            5 overlooked ways to use Samsung’s Secure Folder that have completely changed my Galaxy phone

                                                                            It's not just for keeping secrets.

                                                                            androidauthority.com/samsung-s

                                                                            [Android Authority]

                                                                              [?]Taran Rampersad » 🌐
                                                                              @knowprose@mastodon.social

                                                                              [?]r1cksec » 🌐
                                                                              @r1cksec@infosec.exchange

                                                                              ProxyWatch is a real-time process and network behavior monitor for detecting proxy activity, tunnels, C2 sessions, beacons, and lateral movement.

                                                                              github.com/In3x0rabl3/Proxywat

                                                                                [?]TierraSapiens » 🤖 🌐
                                                                                @tierrasapiens@mastodon.social

                                                                                🖲️
                                                                                ⚫ Gold Eagle Clearinghouse Targets Security Gap, But How Is Unclear
                                                                                🔗 darkreading.com/vulnerabilitie

                                                                                The White House launched Gold Eagle to coordinate vulnerability response in a new AI world, but multiple questions linger over how it's being implemented.

                                                                                  [?]TechWire ⚡ » 🤖 🌐
                                                                                  @techwire@social.gamefan.net

                                                                                  Apple adds new 36-month financing options for iPad purchases

                                                                                  Apple has added new financing options for cellular iPad purchases. As of today, you can buy cellular iPads directly from Apple with 36-month financing from AT&T and Verizon.

                                                                                  9to5mac.com/2026/07/15/apple-a

                                                                                  [9to5Mac]

                                                                                    [?]TechWire ⚡ » 🤖 🌐
                                                                                    @techwire@social.gamefan.net

                                                                                    9to5Mac Daily: July 15, 2026 – iOS 27 public beta is here

                                                                                    Listen to a recap of the top stories of the day from 9to5Mac. 9to5Mac Daily is available on iTunes and Apple’s Podcasts app, Stitcher, TuneIn, Google Play, or through our dedicated RSS feed for Overcast and other podcas…

                                                                                    9to5mac.com/2026/07/15/daily-j

                                                                                    [9to5Mac]

                                                                                      [?]TechWire ⚡ » 🤖 🌐
                                                                                      @techwire@social.gamefan.net

                                                                                      Report: How an email mistake derailed talks between Apple and OpenAI ahead of the lawsuit

                                                                                      NBC News reports that talks between Apple and OpenAI over alleged trade secret theft broke down after an outside lawyer for Apple mistakenly emailed the wrong OpenAI employee and confused their interactions. Here are th…

                                                                                      9to5mac.com/2026/07/15/report-

                                                                                      [9to5Mac]

                                                                                        [?]TechWire ⚡ » 🤖 🌐
                                                                                        @techwire@social.gamefan.net

                                                                                        Report: Apple looking into buying chip startups to strengthen its AI infrastructure

                                                                                        The Information reports that Apple has been in talks with bankers and semiconductor startups as it explores acquisitions to strengthen its AI server capabilities. Here are the details.

                                                                                        9to5mac.com/2026/07/15/report-

                                                                                        [9to5Mac]

                                                                                          [?]TechWire ⚡ » 🤖 🌐
                                                                                          @techwire@social.gamefan.net

                                                                                          Deals: Apple Watch Series 11 $130 off, AirPods, M5 MacBook Air, iPhone 17 Pro, HomeKit lamp, Bose, more

                                                                                          Alongside the ongoing $50 price drop on AirPods Pro 3 and the up to $130 off Apple Watch Series 11, today’s 9to5Toys Lunch Break is headlined by Amazon re-stocking select M5 MacBook Air models at $150 off and the Amazon…

                                                                                          9to5mac.com/2026/07/15/deals-a

                                                                                          [9to5Mac]

                                                                                            [?]Negative PID SL » 🌐
                                                                                            @negativepid@mastodon.social

                                                                                            [?]Avoca » 🌐
                                                                                            @avoca@gladtech.social

                                                                                            [?]TechWire ⚡ » 🤖 🌐
                                                                                            @techwire@social.gamefan.net

                                                                                            Suno now lets iPhone users generate songs directly in iMessage

                                                                                            Starting today, iPhone users who have the Suno app installed can generate songs from the Messages app using text or voice prompts. Here are the details.

                                                                                            9to5mac.com/2026/07/15/suno-no

                                                                                            [9to5Mac]

                                                                                              [?]urlDNA.io :verified: » 🤖 🌐
                                                                                              @urldna@infosec.exchange

                                                                                              Possible Phishing 🎣
                                                                                              on: ⚠️hxxps[:]//bit[.]ly/4cTSQ9w
                                                                                              🧬 Analysis at: urldna.io/scan/6a5c295b3b77500

                                                                                                Back to top - More...