voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]EUVD Bot » 🤖 🌐
@EUVD_Bot@mastodon.social

🚨 EUVD-2026-36794

📊 Score: 8.6/10 (CVSS v3.1)
📦 Product: Discuz! X5.0
🏢 Vendor: Discuz!
📅 Updated: 2026-06-15

📝 Discuz! X5.0 releases 20260320 through 20260501 contain a local file inclusion vulnerability that allows authenticated administrators to execute arbitrary code by importing a specially crafted plugin configuration containing path traversal sequences in ...

🔗 euvd.enisa.europa.eu/vulnerabi

    [?]EUVD Bot » 🤖 🌐
    @EUVD_Bot@mastodon.social

    🚨 EUVD-2026-36791

    📊 Score: 6.8/10 (CVSS v3.1)
    📦 Product: Kiro IDE
    🏢 Vendor: aws
    📅 Updated: 2026-06-15

    📝 Incorrect default permissions in Kiro IDE on macOS and Linux before version 0.11.133 could expose the authentication token cache file to other local users or processes via world-readable permissions (0644) instead of owner-restricted permissions (0600).

    To r...

    🔗 euvd.enisa.europa.eu/vulnerabi

      [?]EUVD Bot » 🤖 🌐
      @EUVD_Bot@mastodon.social

      🚨 EUVD-2026-36791

      📊 Score: 6.8/10 (CVSS v3.1)
      📦 Product: Kiro IDE
      🏢 Vendor: aws
      📅 Updated: 2026-06-15

      📝 Incorrect default permissions in Kiro IDE on macOS and Linux before version 0.11.133 could expose the authentication token cache file to other local users or processes via world-readable permissions (0644) instead of owner-restricted permissions (0600).

      To r...

      🔗 euvd.enisa.europa.eu/vulnerabi

        [?]EUVD Bot » 🤖 🌐
        @EUVD_Bot@mastodon.social

        🚨 EUVD-2026-35549

        📊 Score: 7.5/10 (CVSS v3.1)
        📦 Product: .NET 9.0, Microsoft Visual Studio 2026 version 18.6, ASP.NET Core 9.0 (+4 more)
        🏢 Vendor: Microsoft
        📅 Updated: 2026-06-15

        📝 Microsoft Security Advisory CVE-2026-45591 – ASP.NET Core Denial of Service Vulnerability

        🔗 euvd.enisa.europa.eu/vulnerabi

          [?]deafnews » 🤖 🌐
          @deafnews@infosec.exchange

          [?]TechWire ⚡ » 🤖 🌐
          @techwire@social.gamefan.net

          Facebook is taking a page from Google’s playbook with these new features

          These features aim to enhance search on Facebook and give you more creative tools for stories.

          androidauthority.com/new-trio-

          [Android Authority]

            [?]TierraSapiens » 🤖 🌐
            @tierrasapiens@mastodon.social

            🖲️
            ⚫ The Beginning of the End of Social Engineering
            🔗 darkreading.com/cyberattacks-d

            AI-native operating systems are shifting the responsibility to stay vigilant against social engineering cyberattacks from the user onto the system itself.

              [?]TechWire ⚡ » 🤖 🌐
              @techwire@social.gamefan.net

              Xbox is closing down Hellblade creator Ninja Theory

              Xbox is closing down Ninja Theory, the studio behind the Hellblade series, a source tells The Verge. Staffers were told on a call on Monday about the closure, but they are hoping the studio will find a buyer. The closur…

              theverge.com/games/950204/xbox

              [The Verge]

                [?]urlDNA.io :verified: » 🤖 🌐
                @urldna@infosec.exchange

                Possible Phishing 🎣
                on: ⚠️hxxps[:]//docs[.]google[.]com/presentation/d/e/2PACX-1vSl13B9GhkcdICy__GwCkYk0sMjsO-8LY-iqawuhHaaZHIEZ0cjASzKC83QsHjQBn_iCLi66cyHIGJh/pub?start=false&loop=false&delayms=3000
                🧬 Analysis at: urldna.io/scan/6a2fe9573b77500

                  [?]TechWire ⚡ » 🤖 🌐
                  @techwire@social.gamefan.net

                  Facebook’s new AI Mode search gets its info from public posts

                  Your public Facebook posts could help inform AI-generated results in Meta's new AI Mode. When you search on Facebook, the "AI Mode" option will appear alongside the usual search modes like "People" and "Marketplace." It…

                  theverge.com/tech/950264/meta-

                  [The Verge]

                    [?]EUVD Bot » 🤖 🌐
                    @EUVD_Bot@mastodon.social

                    🚨 EUVD-2026-36732

                    📊 Score: 6.5/10 (CVSS v3.1)
                    📦 Product: Mattermost
                    🏢 Vendor: Mattermost
                    📅 Updated: 2026-06-15

                    📝 Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App which allows a malicious server owner to crash the application via including a script to call window.open on a very ...

                    🔗 euvd.enisa.europa.eu/vulnerabi

                      [?]BeyondMachines :verified: » 🤖 🌐
                      @beyondmachines1@infosec.exchange

                      Caldwell Sutter Capital Discloses Data Breach Following Third-Party Vendor Cyberattack

                      Caldwell Sutter Capital disclosed a data breach affecting 663 individuals after a cyberattack on its third-party software provider, FoxTrot LLC, exposed Social Security numbers and financial account details.

                      ****

                      beyondmachines.net/event_detai

                        [?]TechWire ⚡ » 🤖 🌐
                        @techwire@social.gamefan.net

                        Google Earth’s hidden flight simulator is taking off globally

                        Google Earth's hidden flying Easter egg is not much of a secret anymore.

                        androidauthority.com/google-ea

                        [Android Authority]

                          [?]Hacker News » 🤖 🌐
                          @h4ckernews@mastodon.social

                          [?]Hacker News » 🤖 🌐
                          @h4ckernews@mastodon.social

                          Bots flooded my anti-bot startup with 55,000 fake signups

                          humaverify.com/blog/anatomy-of

                          -signups -news

                            [?]TechWire ⚡ » 🤖 🌐
                            @techwire@social.gamefan.net

                            Xbox turmoil continues with a studio closure and executive departures

                            Last week, Xbox boss Asha Sharma sent a memo warning of an Xbox "reset" ahead of expected layoffs, and today, Kotaku reported that Xbox plans to shut down Compulsion Games, the studio behind South of Midnight. Since tak…

                            theverge.com/games/949964/xbox

                            [The Verge]

                              [?]urlDNA.io :verified: » 🤖 🌐
                              @urldna@infosec.exchange

                              Possible Phishing 🎣
                              on: ⚠️hxxps[:]//block-filogenx[.]gitbook[.]io/us/
                              🧬 Analysis at: urldna.io/scan/6a2f78dc3b77500

                                [?]OTX Bot » 🤖 🌐
                                @techbot@social.raytec.co

                                OptinMonster supply chain attack hits 1.2 million sites

                                An active supply-chain attack targeted over 1.2 million WordPress sites using OptinMonster, TrustPulse, and PushEngage plugins operated by Awesome Motive. Attackers injected malicious JavaScript into legitimate files served through Awesome Motive's CDN endpoints. The malware activates when a logged-in administrator accesses the site, creating backdoor admin accounts (developer_api1 and randomized dev_xxxxxx accounts) and installing a self-hiding PHP plugin. The backdoor provides unauthenticated code execution through a web shell and eval endpoint. Stolen credentials are exfiltrated to tidio.cc, a lookalike domain mimicking the legitimate tidio.com. The breach likely originated from compromised Awesome Motive servers or their BunnyNet CDN account. The campaign began in late April 2026 and remained active through mid-June, affecting OptinMonster (over 1 million installations), TrustPulse, and PushEngage users.

                                Pulse ID: 6a2ec0e674b2d14b332499fa
                                Pulse Link: otx.alienvault.com/pulse/6a2ec
                                Pulse Author: AlienVault
                                Created: 2026-06-14 14:55:34

                                Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                  [?]OTX Bot » 🤖 🌐
                                  @techbot@social.raytec.co

                                  How 23 Browser Extensions Silently Monetize ~758,000 Users' Searches

                                  SearchJack represents a coordinated campaign comprising 23 deceptive Chrome browser extensions that silently hijack users' default search engines, redirecting queries through monetization middleware before delivering results. These extensions masquerade as various productivity tools, satellite imagery viewers, maps, and news readers while their actual purpose is generating search affiliate revenue. The campaign affects approximately 758,000 users across 22 unique publishers and leverages at least 8 distinct monetization brokers, primarily routing traffic through Yahoo Hosted Search affiliate programs. The extensions employ manifest-only wrappers using chrome_settings_overrides to hijack search settings, with some implementing runtime obfuscation to evade static analysis. Several extensions feature false privacy claims, anomalous review patterns, and anonymous publishers with fictional corporate identities, enabling operators to monetize user search behavior while maintaining zero accountability.

                                  Pulse ID: 6a30130a4f8994fe9cb1c31a
                                  Pulse Link: otx.alienvault.com/pulse/6a301
                                  Pulse Author: AlienVault
                                  Created: 2026-06-15 14:58:18

                                  Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                    [?]OTX Bot » 🤖 🌐
                                    @techbot@social.raytec.co

                                    Analysis of APT37 NarwhalRAT Leveraging MS-Themed Phishing and Dead-drop C2

                                    A sophisticated Python-based RAT targeting Korean users through spear phishing emails disguised as Microsoft security alerts. The attack chain employs LNK files embedded in ZIP archives, BAT-based obfuscation, and multi-stage loaders culminating in NarwhalRAT deployment. This advanced malware features keylogging, screen capture, microphone recording, and USB data collection capabilities. It utilizes a dual C2 infrastructure combining Korean relay servers (daehoat.com, novel21.co.kr) with pCloud API as a dead-drop resolver. The malware creates encrypted configuration files, implements anti-VM techniques, and establishes persistence through scheduled tasks. It operates as a manually-controlled RAT with selective function activation via C2 commands, employing in-memory execution to evade file-based detection.

                                    Pulse ID: 6a30130ad416e33ebf9e9417
                                    Pulse Link: otx.alienvault.com/pulse/6a301
                                    Pulse Author: AlienVault
                                    Created: 2026-06-15 14:58:18

                                    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                      [?]OTX Bot » 🤖 🌐
                                      @techbot@social.raytec.co

                                      Travel Phishing and Cyber Attacks are Surging in 2026, Growing 122% over the last 3 years: How Cybercriminals Are Targeting Travelers in 2026

                                      The hospitality and travel sector experienced a dramatic surge in cyberattacks, with organizations facing an average of 2,291 weekly attacks in May 2026, representing a 24% year-over-year increase and a cumulative 122% rise since 2023. Cybercriminals registered 47,318 travel-related domains in May 2026 alone, with one in every 112 classified as malicious or suspicious. Three coordinated bulk-registration campaigns were identified, including sequential hotel-lure domains, American Express and Lloyds Travel Choice impersonations, and widespread Fora Travel brand abuse across 108 TLDs. Active phishing operations target major platforms including Booking.com, Airbnb, and Skyscanner through lookalike domains designed to harvest credentials and payment information. These attacks deliberately intensify during peak summer booking season when travelers are distracted and eager for deals, exploiting the industry's high volume of personal and financial data processing.

                                      Pulse ID: 6a3011d19f2792eabf15cde0
                                      Pulse Link: otx.alienvault.com/pulse/6a301
                                      Pulse Author: AlienVault
                                      Created: 2026-06-15 14:53:05

                                      Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                        [?]OTX Bot » 🤖 🌐
                                        @techbot@social.raytec.co

                                        Inside OnyxC2: The New Stealer Targeting 210 Apps

                                        OnyxC2 emerged in early 2026 as a malware-as-a-service stealer sold on cybercrime networks for $250 monthly. The platform includes a web panel, payload builder, and tiered pricing structure with refund guarantees. Written in C++ with assembly for direct syscalls, it targets approximately 210 applications across nine categories: 45 browsers, 109 extensions including 2FA tools, 5 password managers, 17 cryptocurrency wallets, 11 FTP clients, 5 email clients, and VPN/messaging applications. The stealer achieves 99% detection evasion through mutated builds and delivers via DLL sideloading using signed binaries. Higher tiers unlock remote access capabilities including HVNC, LSASS dumping, reverse SOCKS5 proxy, keylogging, and reverse shell. Distribution occurs through fake installers delivered as password-protected archives, with C2 communication over Cloudflare-fronted HTTPS to akmuniverstall.top.

                                        Pulse ID: 6a301309d410a2c508c138d4
                                        Pulse Link: otx.alienvault.com/pulse/6a301
                                        Pulse Author: AlienVault
                                        Created: 2026-06-15 14:58:17

                                        Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                          [?]Steve Loughran » 🌐
                                          @stevel@hachyderm.io

                                          Claude Opus is so good at generating triage reports explaining how reported CVE vulnerabilities are nothing of the sort that I really wish people should send their reports through it before posting to security lists. Save us all time

                                            [?]OTX Bot » 🤖 🌐
                                            @techbot@social.raytec.co

                                            The Devil, Eight Million Emails, and a Whole Lot of Milk | Phishing Stager Exposed

                                            On May 15, 2026, Huntress agents detected an intrusion where threat actors compromised a terminal server to stage a massive phishing campaign rather than deploy ransomware. The attacker used legitimate bulk email software (Gammadyne Mailer) with a project file named 'dracii' (Romanian for 'the devils') and six recipient lists containing 8,894,920 email addresses. Operating from Romanian IP addresses, the actor impersonated UK pharmacy chain Boots through a fake customer satisfaction survey designed to harvest personal and payment card data. The phishing kit was hosted on a compromised Bolivian government website (ipelc.gob.bo), which Huntress reported to Bolivia's national CSIRT. The campaign used direct-to-MX delivery to bypass mail relays, with the mailer configured to send from 666 threads simultaneously. Evidence suggests this Romanian operator has been running multiple UK-targeting campaigns since at least July 2025, rotating between retail, tax, and cryptocurrency themes.

                                            Pulse ID: 6a3011d0c31292cdb59fd70b
                                            Pulse Link: otx.alienvault.com/pulse/6a301
                                            Pulse Author: AlienVault
                                            Created: 2026-06-15 14:53:04

                                            Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                              [?]TechWire ⚡ » 🤖 🌐
                                              @techwire@social.gamefan.net

                                              Why Anthropic suddenly pulled Fable 5 and Mythos 5 for everyone

                                              Claude Fable 5 and Mythos 5 are gone. The reason? A US government directive.

                                              zdnet.com/article/why-anthropi

                                              [ZDNet]

                                                [?]EUVD Bot » 🤖 🌐
                                                @EUVD_Bot@mastodon.social

                                                🚨 EUVD-2026-36705

                                                📊 Score: 7.1/10 (CVSS v3.1)
                                                📦 Product: Wertheim SafeController Family 65000 Hardware for VAULT ROOMS (Safe Deposit Locker System - Microcontroller)
                                                🏢 Vendor: Wertheim GmbH
                                                📅 Updated: 2026-06-15

                                                📝 The Wertheim SafeController Family 65000, Controller 65000 - AssemblyVersion 6.11.8130.22319, uses weak custom cryptographic algorithms with hard-coded...

                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                  [?]EUVD Bot » 🤖 🌐
                                                  @EUVD_Bot@mastodon.social

                                                  🚨 EUVD-2026-36704

                                                  📊 Score: 8.6/10 (CVSS v3.1)
                                                  📦 Product: Wertheim SafeController 5400 Hardware for VAULT ROOMS (Safe Deposit Locker System - Microcontroller)
                                                  🏢 Vendor: Wertheim GmbH
                                                  📅 Updated: 2026-06-15

                                                  📝 The Wertheim SafeController 5400, Controller 5400 - AssemblyVersion 6.11.8130.22320, uses RS-485 communication between the server and the microcontroller witho...

                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                    [?]gtbarry » 🌐
                                                    @gtbarry@mastodon.social

                                                    Nearly a million passports and photo IDs were left unprotected on the public internet

                                                    Nefos had no meaningful level of security. A secret key for the Stripe payments platform was sitting inside the app in plain text - exposing profiles with their phone number, home address, passport, and weed preferences

                                                    theverge.com/tech/947157/passp

                                                      [?]Hugo | DevOps | Cybersecurity » 🌐
                                                      @hugovalters@mastodon.social

                                                      Portabilis: 100 CVEs, 99% unpatched. Avg CVSS 4.3, max 6.3. Trust Score: C. Top weakness: XSS (CWE-79). Educational systems at risk.

                                                      valtersit.com/vendors/portabil

                                                        [?]TechWire ⚡ » 🤖 🌐
                                                        @techwire@social.gamefan.net

                                                        Fox just made a $22 billion play for your TV screen by buying Roku

                                                        The blockbuster acquisition merges Tubi and The Roku Channel into a free streaming giant behind only YouTube and Netflix.

                                                        androidauthority.com/fox-roku-

                                                        [Android Authority]

                                                          [?]deafnews » 🤖 🌐
                                                          @deafnews@infosec.exchange

                                                          [?]Scott Wilson 🌈 [he/him/his] » 🌐
                                                          @scottwilson@infosec.exchange

                                                          RE: infosec.exchange/@deafnews/116

                                                          Whew! I was worried Instructure (Canvas) was feeling all alone. Now all the education platforms have been breached! 🤡

                                                            [?]TechWire ⚡ » 🤖 🌐
                                                            @techwire@social.gamefan.net

                                                            Marshall Emberton II price slashed to just $99.99 in early Prime Day deal

                                                            Thirty-plus hours of Marshall sound now costs under $100 in the Prime Day runup.

                                                            androidauthority.com/marshall-

                                                            [Android Authority]

                                                              [?]ANY.RUN » 🌐
                                                              @anyrun_app@infosec.exchange

                                                              🚨 Stealer is more than a password thief.

                                                              This fast-growing MaaS steals browser sessions, auth tokens, and password manager data, helping attackers bypass MFA and compromise business accounts.

                                                              🎯 Learn how it works and how to defend against it: any.run/malware-trends/remus/?

                                                                [?]urlDNA.io :verified: » 🤖 🌐
                                                                @urldna@infosec.exchange

                                                                Possible Phishing 🎣
                                                                on: ⚠️hxxps[:]//mailtelsu7[.]weebly[.]com/
                                                                🧬 Analysis at: urldna.io/scan/6a2ff10a3b77500

                                                                  Back to top - More...