voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]N-gated Hacker News » 🤖 🌐
@ngate@mastodon.social

🚨Breaking news: gamers learn a tough lesson as their accounts get hijacked by evil wallpaper! 🎮🖼️ Remember, folks, not all downloadable content is meant to be downloaded. Also, kudos to for bravely stepping in to state the obvious. 🏆🔍
securelist.com/dozens-of-malic

    [?]TechWire ⚡ » 🤖 🌐
    @techwire@social.gamefan.net

    XREAL makes the Aura XR glasses official, but is still holding back a key detail

    XREAL leaves out the most important details for later this year.

    androidauthority.com/xreal-aur

    [Android Authority]

      [?]urlDNA.io :verified: » 🤖 🌐
      @urldna@infosec.exchange

      Possible Phishing 🎣
      on: ⚠️hxxps[:]//mijn[.]overheid[.]nl[.]berichtenbox[.]l1tjxkgmdqghekubdurkea68msnzfea6kx1u2q2s9pwpvurkzexb[.]luizmatoso[.]com[.]br
      🧬 Analysis at: urldna.io/scan/6a3148f23b77500

        [?]The New Oil » 🤖 🌐
        @thenewoil@mastodon.thenewoil.org

        [?]OTX Bot » 🤖 🌐
        @techbot@social.raytec.co

        Android Banker with Complete Device Takeover Capabilities

        A newly identified Android banking trojan named Rokarolla has been discovered, distributed through malicious websites masquerading as popular applications like TikTok or Google Chrome. The malware targets 217 distinct cryptocurrency and banking applications using 137 sophisticated commands for device control. Capabilities include harvesting lock screen credentials, exfiltrating contact lists and SMS data, deploying keyloggers, blocking calls, creating fraudulent screen overlays, and disabling Google Play Protect. The infection begins with a dropper impersonating Google Play Protect that installs a secondary payload. Rokarolla communicates with C2 infrastructure via HTTPS, uses overlays to steal banking credentials and device unlock patterns, silently monitors WhatsApp contacts, hijacks SMS and calls, manipulates clipboard content for cryptocurrency theft, and employs snapshot-based screen surveillance. It maintains persistence by hiding its icon, muting device audio, and keeping screens active indefinitely.

        Pulse ID: 6a315d684f0c09972ddea652
        Pulse Link: otx.alienvault.com/pulse/6a315
        Pulse Author: AlienVault
        Created: 2026-06-16 14:27:52

        Be advised, this data is unverified and should be considered preliminary. Always do further verification.

          [?]OTX Bot » 🤖 🌐
          @techbot@social.raytec.co

          Potemkin Loader & RMMProject The Anatomy of a ClickFix Attack

          A ClickFix social engineering attack on an unmonitored endpoint led to a multi-stage intrusion affecting over 11 hosts. The infection chain began with a malicious HTA payload that silently installed an MSI package containing Potemkin, a custom loader with a deterministic DGA. Potemkin delivered RMMProject, a 4.4 MB Lua-scriptable RAT featuring browser credential theft with Chrome App-Bound Encryption bypass, hidden-desktop remote control, and 15 distinct task types. The attacker deployed EtherRAT, a Node.js backdoor resolving C2 addresses from Ethereum blockchain, and established a Cloudflare tunnel for persistent access. Hands-on-keyboard activity included battling Windows Defender through AMSI patches, registry modifications, and service termination, followed by lateral movement via WMIExec and SMBExec to deploy malware across the network and reach the domain controller.

          Pulse ID: 6a315d670f9460fe003298a8
          Pulse Link: otx.alienvault.com/pulse/6a315
          Pulse Author: AlienVault
          Created: 2026-06-16 14:27:51

          Be advised, this data is unverified and should be considered preliminary. Always do further verification.

            [?]CTI.FYI » 🤖 🌐
            @CTI_FYI@infosec.exchange

            🚨New ransom group blog post!🚨

            Group name: incransom
            Post title: jasperplastics.info
            Info: cti.fyi/groups/incransom.html

              [?]Analyst207 » 🤖 🌐
              @Analyst207@mastodon.social

              Trump Bolsters Military, Intelligence Cybersecurity with New National Security Memo

              President Trump just took a major step to fortify America's defenses in the digital age, signing a National Security Presidential Memorandum to boost cybersecurity and modernize governance for our nation's most sensitive computer systems. This move aims to improve accountability and coordination…

              osintsights.com/trump-bolsters

                [?]TechWire ⚡ » 🤖 🌐
                @techwire@social.gamefan.net

                A 52% price drop gets you the Amazon Smart Plug 2-Pack at an all-time low

                It's your first chance to get a pair of Amazon's compact smart plugs for under $24.

                androidauthority.com/amazon-sm

                [Android Authority]

                  [?]TheHackerWire » 🤖 🌐
                  @thehackerwire@mastodon.social

                  🔴 CVE-2026-40750 - Critical (9.9)

                  Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server.

                  This issue affects Kids Online Store: from n/a through 0.8.9.

                  🔗 thehackerwire.com/vulnerabilit

                  CVE Alert: CVE-2026-40750

                  Alt...CVE Alert: CVE-2026-40750

                    [?]EUVD Bot » 🤖 🌐
                    @EUVD_Bot@mastodon.social

                    🚨 EUVD-2026-37063

                    📊 Score: 8.6/10 (CVSS v3.1)
                    📦 Product: NPort W2150A/W2250A Series, NPort W2150A-W4/W2250A-W4 Series
                    🏢 Vendor: Moxa
                    📅 Updated: 2026-06-16

                    📝 A stack-based buffer overflow vulnerability has been found in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and earlier. This vulnerability stems from insufficient input validation of user-supplied input i...

                    🔗 euvd.enisa.europa.eu/vulnerabi

                      [?]EUVD Bot » 🤖 🌐
                      @EUVD_Bot@mastodon.social

                      🚨 EUVD-2026-37062

                      📊 Score: 6.9/10 (CVSS v3.1)
                      📦 Product: NPort W2150A-W4/W2250A-W4 Series, NPort W2150A/W2250A Series
                      🏢 Vendor: Moxa
                      📅 Updated: 2026-06-16

                      📝 A format string vulnerability has been found in the "alias" parameter of the Serial Param configuration page in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and prior. This vulnerability stems from insuff...

                      🔗 euvd.enisa.europa.eu/vulnerabi

                        [?]urlDNA.io :verified: » 🤖 🌐
                        @urldna@infosec.exchange

                        Possible Phishing 🎣
                        on: ⚠️hxxp[:]//leia-santander[.]vercel[.]app
                        🧬 Analysis at: urldna.io/scan/6a30ee413b77500

                          [?]TheHackerWire » 🤖 🌐
                          @thehackerwire@mastodon.social

                          🟠 CVE-2026-39581 - High (8.5)

                          Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions.

                          🔗 thehackerwire.com/vulnerabilit

                          CVE Alert: CVE-2026-39581

                          Alt...CVE Alert: CVE-2026-39581

                            [?]TheHackerWire » 🤖 🌐
                            @thehackerwire@mastodon.social

                            🔴 CVE-2026-49772 - Critical (9.3)

                            Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allows Blind SQL Injection.

                            This issue affects The Events Calendar: from 6.15.12 through 6.16.2.

                            🔗 thehackerwire.com/vulnerabilit

                            CVE Alert: CVE-2026-49772

                            Alt...CVE Alert: CVE-2026-49772

                              [?]gtbarry » 🌐
                              @gtbarry@mastodon.social

                              Infinite Campus data breach affects 137,000 school staff accounts

                              The ShinyHunters extortion gang stole personal information from more than 137,000 school staff accounts in a Salesforce data theft attack that targeted the widely used Infinite Campus K-12 student information system

                              bleepingcomputer.com/news/secu

                                [?]Hugo | DevOps | Cybersecurity » 🌐
                                @hugovalters@mastodon.social

                                Autodesk: 191 CVEs, 95% unpatched. Avg CVSS 7.71. Trust Score: C. Design tools are a growing attack surface.

                                valtersit.com/vendors/autodesk/

                                  [?]deafnews » 🤖 🌐
                                  @deafnews@infosec.exchange

                                  [?]TechWire ⚡ » 🤖 🌐
                                  @techwire@social.gamefan.net

                                  Lenovo’s next tablet has a thick speaker bump and an upgraded kickstand

                                  A large speaker bump on the back of the Tab Plus Gen 2 contributes to the tablet’s upgraded sound. | Photo: Sean Hollister / The Verge Lenovo announced a new version of its chonky speaker-filled Tab Plus tablet that onc…

                                  theverge.com/tech/949617/lenov

                                  [The Verge]

                                    [?]TechWire ⚡ » 🤖 🌐
                                    @techwire@social.gamefan.net

                                    Apple’s weird anti-nausea dots cured my car sickness

                                    I'll just work from the car, I thought. But after a few minutes of staring at my screen on quick mountain switchbacks I could feel the first signs of cold, coagulated nausea bubbling up from that sweaty place in my gut.…

                                    theverge.com/tech/942854/apple

                                    [The Verge]

                                      [?]urlDNA.io :verified: » 🤖 🌐
                                      @urldna@infosec.exchange

                                      Possible Phishing 🎣
                                      on: ⚠️hxxps[:]//leagueaflegends[.]weebly[.]com
                                      🧬 Analysis at: urldna.io/scan/6a310a483b77500

                                        [?]The New Oil » 🤖 🌐
                                        @thenewoil@mastodon.thenewoil.org

                                        [?]:awesome:🐦‍🔥nemo™🐦‍⬛ 🇺🇦🍉 » 🌐
                                        @nemo@mas.to

                                        HaveIBeenPwned ergänzt seine Datenbank um 124 Mio. Passwörter — offenbar aus Stealer-Logs. Herkunft unklar; Risiko durch Credential‑Stuffing bleibt hoch. Nutzer sollten Passwörter prüfen, ändern und 2FA aktivieren. golem.de/news/mit-malware-erbe 🔐🧾

                                          [?]TechWire ⚡ » 🤖 🌐
                                          @techwire@social.gamefan.net

                                          SpaceX is officially buying Cursor for $60 billion

                                          Days after its massive IPO, SpaceX says it is spending $60 billion to buy Cursor - a bet designed to help Elon Musk's sprawling rocket / AI / social media behemoth win over lucrative enterprise customers and close the g…

                                          theverge.com/ai-artificial-int

                                          [The Verge]

                                            [?]:awesome:🐦‍🔥nemo™🐦‍⬛ 🇺🇦🍉 » 🌐
                                            @nemo@mas.to

                                            A June 2026 stealer‑logs breach added 56.3M emails & 124M passwords to HIBP; compromised passwords are now in Pwned Passwords. Change reused passwords, enable 2FA, and use a password manager. Check if you’re affected: haveibeenpwned.com/Breach/June 🔐📢

                                              [?]EUVD Bot » 🤖 🌐
                                              @EUVD_Bot@mastodon.social

                                              🚨 EUVD-2025-210165

                                              📊 Score: n/a
                                              📦 Product: Nokia SR Linux, Nokia SR Linux, Nokia SR Linux
                                              🏢 Vendor: Nokia
                                              📅 Updated: 2026-06-16

                                              📝 Nokia SR Linux is vulnerable to a local privilege escalation vulnerability. Successful exploitation of this vulnerability may allow an authenticated user to execute arbitrary commands with superuser privilege.

                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                [?]N_{Dario Fadda} » 🌐
                                                @nuke@poliversity.it

                                                Microsoft Lets connectivity.office.com TLS Certificate Expire, Breaking Enterprise Microsoft 365 Diagnostics

                                                securebulletin.com/microsoft-l

                                                  [?]urlDNA.io :verified: » 🤖 🌐
                                                  @urldna@infosec.exchange

                                                  Possible Phishing 🎣
                                                  on: ⚠️hxxps[:]//netflix-clone-zeta-nine[.]vercel[.]app
                                                  🧬 Analysis at: urldna.io/scan/6a30b5ec3b77500

                                                    [?]BeyondMachines :verified: » 🤖 🌐
                                                    @beyondmachines1@infosec.exchange

                                                    Microsoft Patches Critical SearchLeak Vulnerability in Copilot Enterprise

                                                    Microsoft patched a critical vulnerability in Copilot Enterprise (CVE-2026-42824) that allowed attackers to steal sensitive organizational data via a single-click link. The flaw chained prompt injection with web vulnerabilities to silently steal emails, files, and MFA codes through Bing.

                                                    **You don't need to do anything to patch this flaw. Make a note of it for vendor evaluation. As an extra precaution, educate your users to avoid clicking links with long, complex query parameters, and have your security team watch for unusual Copilot Search URLs containing encoded HTML tags.**

                                                    beyondmachines.net/event_detai

                                                      [?]Malicious Extension Bot » 🤖 🌐
                                                      @malicious_browser_bot@infosec.exchange

                                                      extension Agent Pocket seems malicious. Its badness score is 98/100!

                                                      ```json
                                                      {"id": "acejnkocmhhdeepejldlchcpcokmomia", "score": 98, "platform": "chrome", "name": "Agent Pocket"}
                                                      ```

                                                        [?]Malicious Extension Bot » 🤖 🌐
                                                        @malicious_browser_bot@infosec.exchange

                                                        extension Secure Password Generator seems malicious. Its badness score is 87/100!

                                                        ```json
                                                        {"id": "idfihpinagmbpjoonfkekcnflihfibeg", "score": 87, "platform": "chrome", "name": "Secure Password Generator"}
                                                        ```

                                                          [?]Malicious Extension Bot » 🤖 🌐
                                                          @malicious_browser_bot@infosec.exchange

                                                          extension Chatgpt For Google seems malicious. Its badness score is 96/100!

                                                          ```json
                                                          {"id": "apoolaigpomccfpofkhcbfniogicjiai", "score": 96, "platform": "chrome", "name": "Chatgpt For Google"}
                                                          ```

                                                            [?]N_{Dario Fadda} » 🌐
                                                            @nuke@poliversity.it

                                                            CVE-2026-48558: Critical SimpleHelp Auth Bypass Exposes 14,000 RMM Servers to Unauthenticated Access

                                                            securebulletin.com/cve-2026-48

                                                              [?]deafnews » 🤖 🌐
                                                              @deafnews@infosec.exchange

                                                              [?]N_{Dario Fadda} » 🌐
                                                              @nuke@poliversity.it

                                                              CVE-2026-20262: Cisco Catalyst SD-WAN vManage Zero-Day Actively Exploited in Enterprise Attacks

                                                              securebulletin.com/cve-2026-20

                                                                [?]TechWire ⚡ » 🤖 🌐
                                                                @techwire@social.gamefan.net

                                                                I spent 48 hours comparing Siri AI to Gemini — and Apple really impressed me

                                                                Siri AI isn't perfect, but it's off to a solid start.

                                                                androidauthority.com/siri-ai-v

                                                                [Android Authority]

                                                                  [?]N_{Dario Fadda} » 🌐
                                                                  @nuke@poliversity.it

                                                                  CVE-2026-54420: LiteSpeed cPanel Plugin Zero-Day Actively Exploited to Escalate Privileges to Root

                                                                  securebulletin.com/cve-2026-54

                                                                    [?]TechWire ⚡ » 🤖 🌐
                                                                    @techwire@social.gamefan.net

                                                                    Breaking: Galaxy S26 series gets third One UI 9 beta release with major bug fixes

                                                                    The Android 17-based update brings critical display, camera, and stability patches.

                                                                    androidauthority.com/samsung-g

                                                                    [Android Authority]

                                                                      [?]urlDNA.io :verified: » 🤖 🌐
                                                                      @urldna@infosec.exchange

                                                                      Possible Phishing 🎣
                                                                      on: ⚠️hxxps[:]//merenciano[.]net/serviciodecorreo/login/
                                                                      🧬 Analysis at: urldna.io/scan/6a3102963b77500

                                                                        [?]TechWire ⚡ » 🤖 🌐
                                                                        @techwire@social.gamefan.net

                                                                        Why I’d never buy an Android phone with 8GB RAM in 2026

                                                                        8GB used to be plenty, but now these phones are already obsolete.

                                                                        androidauthority.com/dont-buy-

                                                                        [Android Authority]

                                                                          Back to top - More...