voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
🚨Breaking news: gamers learn a tough lesson as their accounts get hijacked by evil wallpaper! 🎮🖼️ Remember, folks, not all downloadable content is meant to be downloaded. Also, kudos to #Kaspersky for bravely stepping in to state the obvious. 🏆🔍
https://securelist.com/dozens-of-malicious-wallpapers-found-on-steam-workshop/120186/ #gamersbeware #accountsecurity #malware #gamingnews #cybersecurity #HackerNews #ngated
XREAL makes the Aura XR glasses official, but is still holding back a key detail
XREAL leaves out the most important details for later this year.
https://www.androidauthority.com/xreal-aura-android-xr-glasses-3677874/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Possible Phishing 🎣
on: ⚠️hxxps[:]//mijn[.]overheid[.]nl[.]berichtenbox[.]l1tjxkgmdqghekubdurkea68msnzfea6kx1u2q2s9pwpvurkzexb[.]luizmatoso[.]com[.]br
🧬 Analysis at: https://urldna.io/scan/6a3148f23b77500006394e57
#cybersecurity #phishing #infosec #urldna #scam #infosec
Android Banker with Complete Device Takeover Capabilities
A newly identified Android banking trojan named Rokarolla has been discovered, distributed through malicious websites masquerading as popular applications like TikTok or Google Chrome. The malware targets 217 distinct cryptocurrency and banking applications using 137 sophisticated commands for device control. Capabilities include harvesting lock screen credentials, exfiltrating contact lists and SMS data, deploying keyloggers, blocking calls, creating fraudulent screen overlays, and disabling Google Play Protect. The infection begins with a dropper impersonating Google Play Protect that installs a secondary payload. Rokarolla communicates with C2 infrastructure via HTTPS, uses overlays to steal banking credentials and device unlock patterns, silently monitors WhatsApp contacts, hijacks SMS and calls, manipulates clipboard content for cryptocurrency theft, and employs snapshot-based screen surveillance. It maintains persistence by hiding its icon, muting device audio, and keeping screens active indefinitely.
Pulse ID: 6a315d684f0c09972ddea652
Pulse Link: https://otx.alienvault.com/pulse/6a315d684f0c09972ddea652
Pulse Author: AlienVault
Created: 2026-06-16 14:27:52
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #Bank #BankingTrojan #Chrome #Clipboard #CyberSecurity #Google #GooglePlay #HTTP #HTTPS #InfoSec #KeyLogger #Malware #OTX #OpenThreatExchange #RAT #SMS #Trojan #WhatsApp #bot #cryptocurrency #AlienVault
Potemkin Loader & RMMProject The Anatomy of a ClickFix Attack
A ClickFix social engineering attack on an unmonitored endpoint led to a multi-stage intrusion affecting over 11 hosts. The infection chain began with a malicious HTA payload that silently installed an MSI package containing Potemkin, a custom loader with a deterministic DGA. Potemkin delivered RMMProject, a 4.4 MB Lua-scriptable RAT featuring browser credential theft with Chrome App-Bound Encryption bypass, hidden-desktop remote control, and 15 distinct task types. The attacker deployed EtherRAT, a Node.js backdoor resolving C2 addresses from Ethereum blockchain, and established a Cloudflare tunnel for persistent access. Hands-on-keyboard activity included battling Windows Defender through AMSI patches, registry modifications, and service termination, followed by lateral movement via WMIExec and SMBExec to deploy malware across the network and reach the domain controller.
Pulse ID: 6a315d670f9460fe003298a8
Pulse Link: https://otx.alienvault.com/pulse/6a315d670f9460fe003298a8
Pulse Author: AlienVault
Created: 2026-06-16 14:27:51
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #BlockChain #Browser #Chrome #Cloud #CyberSecurity #DomainController #Encryption #Endpoint #InfoSec #LUA #Malware #NATO #Nodejs #OTX #OpenThreatExchange #RAT #SMB #SocialEngineering #Troll #Windows #bot #AlienVault
🚨New ransom group blog post!🚨
Group name: incransom
Post title: jasperplastics.info
Info: https://cti.fyi/groups/incransom.html
#ransomware #cti #threatintelligence #cybersecurity #infosec
Trump Bolsters Military, Intelligence Cybersecurity with New National Security Memo
President Trump just took a major step to fortify America's defenses in the digital age, signing a National Security Presidential Memorandum to boost cybersecurity and modernize governance for our nation's most sensitive computer systems. This move aims to improve accountability and coordination…
#NationalSecurity #Cybersecurity #MilitaryOperations #IntelligenceOperations #NationState
A 52% price drop gets you the Amazon Smart Plug 2-Pack at an all-time low
It's your first chance to get a pair of Amazon's compact smart plugs for under $24.
https://www.androidauthority.com/amazon-smart-plug-2-pack-deal-3676485/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
🔴 CVE-2026-40750 - Critical (9.9)
Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server.
This issue affects Kids Online Store: from n/a through 0.8.9.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-40750/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🚨 EUVD-2026-37063
📊 Score: 8.6/10 (CVSS v3.1)
📦 Product: NPort W2150A/W2250A Series, NPort W2150A-W4/W2250A-W4 Series
🏢 Vendor: Moxa
📅 Updated: 2026-06-16
📝 A stack-based buffer overflow vulnerability has been found in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and earlier. This vulnerability stems from insufficient input validation of user-supplied input i...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-37063
🚨 EUVD-2026-37062
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: NPort W2150A-W4/W2250A-W4 Series, NPort W2150A/W2250A Series
🏢 Vendor: Moxa
📅 Updated: 2026-06-16
📝 A format string vulnerability has been found in the "alias" parameter of the Serial Param configuration page in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and prior. This vulnerability stems from insuff...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-37062
Possible Phishing 🎣
on: ⚠️hxxp[:]//leia-santander[.]vercel[.]app
🧬 Analysis at: https://urldna.io/scan/6a30ee413b775000082876b5
#cybersecurity #phishing #infosec #urldna #scam #infosec
🟠 CVE-2026-39581 - High (8.5)
Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-39581/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🔴 CVE-2026-49772 - Critical (9.3)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allows Blind SQL Injection.
This issue affects The Events Calendar: from 6.15.12 through 6.16.2.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49772/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Infinite Campus data breach affects 137,000 school staff accounts
The ShinyHunters extortion gang stole personal information from more than 137,000 school staff accounts in a Salesforce data theft attack that targeted the widely used Infinite Campus K-12 student information system
#Salesforce #InfiniteCampus #education #security #cybersecurity #hackers #hacking #hacked
Autodesk: 191 CVEs, 95% unpatched. Avg CVSS 7.71. Trust Score: C. Design tools are a growing attack surface. #Autodesk #infosec #cybersecurity
Vertex AI SDK: Cross-Tenant Bucket Squatting Enabled RCE https://deafnews.it/en/article/vertex-ai-sdk-cross-tenant-bucket-squatting-enabled-rce #Cybersecurity
Lenovo’s next tablet has a thick speaker bump and an upgraded kickstand
A large speaker bump on the back of the Tab Plus Gen 2 contributes to the tablet’s upgraded sound. | Photo: Sean Hollister / The Verge Lenovo announced a new version of its chonky speaker-filled Tab Plus tablet that onc…
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Apple’s weird anti-nausea dots cured my car sickness
I'll just work from the car, I thought. But after a few minutes of staring at my screen on quick mountain switchbacks I could feel the first signs of cold, coagulated nausea bubbling up from that sweaty place in my gut.…
https://www.theverge.com/tech/942854/apple-vehicle-motion-cues-review-really-work
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Possible Phishing 🎣
on: ⚠️hxxps[:]//leagueaflegends[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a310a483b775000063945d9
#cybersecurity #phishing #infosec #urldna #scam #infosec
HaveIBeenPwned ergänzt seine Datenbank um 124 Mio. Passwörter — offenbar aus Stealer-Logs. Herkunft unklar; Risiko durch Credential‑Stuffing bleibt hoch. Nutzer sollten Passwörter prüfen, ändern und 2FA aktivieren. https://www.golem.de/news/mit-malware-erbeutet-124-millionen-neue-passwoerter-bei-haveibeenpwned-2606-209825.html 🔐🧾 #CyberSecurity #Datenschutz
SpaceX is officially buying Cursor for $60 billion
Days after its massive IPO, SpaceX says it is spending $60 billion to buy Cursor - a bet designed to help Elon Musk's sprawling rocket / AI / social media behemoth win over lucrative enterprise customers and close the g…
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
A June 2026 stealer‑logs breach added 56.3M emails & 124M passwords to HIBP; compromised passwords are now in Pwned Passwords. Change reused passwords, enable 2FA, and use a password manager. Check if you’re affected: https://haveibeenpwned.com/Breach/June2026StealerLogs 🔐📢 #DataBreach #CyberSecurity
🚨 EUVD-2025-210165
📊 Score: n/a
📦 Product: Nokia SR Linux, Nokia SR Linux, Nokia SR Linux
🏢 Vendor: Nokia
📅 Updated: 2026-06-16
📝 Nokia SR Linux is vulnerable to a local privilege escalation vulnerability. Successful exploitation of this vulnerability may allow an authenticated user to execute arbitrary commands with superuser privilege.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-210165
Microsoft Lets connectivity.office.com TLS Certificate Expire, Breaking Enterprise Microsoft 365 Diagnostics
#CyberSecurity
https://securebulletin.com/microsoft-lets-connectivity-office-com-tls-certificate-expire-breaking-enterprise-microsoft-365-diagnostics/
Possible Phishing 🎣
on: ⚠️hxxps[:]//netflix-clone-zeta-nine[.]vercel[.]app
🧬 Analysis at: https://urldna.io/scan/6a30b5ec3b77500006393ceb
#cybersecurity #phishing #infosec #urldna #scam #infosec
Microsoft Patches Critical SearchLeak Vulnerability in Copilot Enterprise
Microsoft patched a critical vulnerability in Copilot Enterprise (CVE-2026-42824) that allowed attackers to steal sensitive organizational data via a single-click link. The flaw chained prompt injection with web vulnerabilities to silently steal emails, files, and MFA codes through Bing.
**You don't need to do anything to patch this flaw. Make a note of it for vendor evaluation. As an extra precaution, educate your users to avoid clicking links with long, complex query parameters, and have your security team watch for unusual Copilot Search URLs containing encoded HTML tags.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/microsoft-patches-critical-searchleak-vulnerability-in-copilot-enterprise-t-p-3-7-1/gD2P6Ple2L
#chrome extension Agent Pocket seems malicious. Its #cybersecurity badness score is 98/100!
```json
{"id": "acejnkocmhhdeepejldlchcpcokmomia", "score": 98, "platform": "chrome", "name": "Agent Pocket"}
```
#chrome extension Secure Password Generator seems malicious. Its #cybersecurity badness score is 87/100!
```json
{"id": "idfihpinagmbpjoonfkekcnflihfibeg", "score": 87, "platform": "chrome", "name": "Secure Password Generator"}
```
#chrome extension Chatgpt For Google seems malicious. Its #cybersecurity badness score is 96/100!
```json
{"id": "apoolaigpomccfpofkhcbfniogicjiai", "score": 96, "platform": "chrome", "name": "Chatgpt For Google"}
```
CVE-2026-48558: Critical SimpleHelp Auth Bypass Exposes 14,000 RMM Servers to Unauthenticated Access
#CyberSecurity
https://securebulletin.com/cve-2026-48558-critical-simplehelp-auth-bypass-exposes-14000-rmm-servers-to-unauthenticated-access/
Malware on Steam Workshop: Animated Wallpapers Steal Credentials https://deafnews.it/en/article/malware-on-steam-workshop-animated-wallpapers-steal-credentials #Cybersecurity
CVE-2026-20262: Cisco Catalyst SD-WAN vManage Zero-Day Actively Exploited in Enterprise Attacks
#CyberSecurity
https://securebulletin.com/cve-2026-20262-cisco-catalyst-sd-wan-vmanage-zero-day-actively-exploited-in-enterprise-attacks/
I spent 48 hours comparing Siri AI to Gemini — and Apple really impressed me
Siri AI isn't perfect, but it's off to a solid start.
https://www.androidauthority.com/siri-ai-vs-gemini-hands-on-comparison-3677330/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
CVE-2026-54420: LiteSpeed cPanel Plugin Zero-Day Actively Exploited to Escalate Privileges to Root
#CyberSecurity
https://securebulletin.com/cve-2026-54420-litespeed-cpanel-plugin-zero-day-actively-exploited-to-escalate-privileges-to-root/
Breaking: Galaxy S26 series gets third One UI 9 beta release with major bug fixes
The Android 17-based update brings critical display, camera, and stability patches.
https://www.androidauthority.com/samsung-galaxy-s26-one-ui-9-beta-3-3677792/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Possible Phishing 🎣
on: ⚠️hxxps[:]//merenciano[.]net/serviciodecorreo/login/
🧬 Analysis at: https://urldna.io/scan/6a3102963b77500008287724
#cybersecurity #phishing #infosec #urldna #scam #infosec
Why I’d never buy an Android phone with 8GB RAM in 2026
8GB used to be plenty, but now these phones are already obsolete.
https://www.androidauthority.com/dont-buy-8gb-ram-android-phone-2026-3676313/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]