voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]Malicious Extension Bot » 🤖 🌐
@malicious_browser_bot@infosec.exchange

extension Iron Man Sakura Live Wallpaper seems malicious. Its badness score is 100/100!

```json
{"id": "nbppankbncdijckhaiipciomehdmiffd", "score": 100, "platform": "chrome", "name": "Iron Man Sakura Live Wallpaper"}
```

    [?]Malicious Extension Bot » 🤖 🌐
    @malicious_browser_bot@infosec.exchange

    extension Wind Breaker Haruka Sakur Wallpaper seems malicious. Its badness score is 92/100!

    ```json
    {"id": "moalacfhgmngoilplggklcdhiaafcpjh", "score": 92, "platform": "chrome", "name": "Wind Breaker Haruka Sakur Wallpaper"}
    ```

      [?]Malicious Extension Bot » 🤖 🌐
      @malicious_browser_bot@infosec.exchange

      extension Pokemon All Characters: Live Wallpaper for Chrome seems malicious. Its badness score is 88/100!

      ```json
      {"id": "ibodengmlnepeoloodfmjcedcolcpkfh", "score": 88, "platform": "chrome", "name": "Pokemon All Characters: Live Wallpaper for Chrome"}
      ```

        [?]urlDNA.io :verified: » 🤖 🌐
        @urldna@infosec.exchange

        Possible Phishing 🎣
        on: ⚠️hxxps[:]//bullettrainbtn4[.]blogspot[.]com/
        🧬 Analysis at: urldna.io/scan/6a2ebbac3b77500

          [?]TechWire ⚡ » 🤖 🌐
          @techwire@social.gamefan.net

          How to keep your Mac awake, even when your MacBook lid is closed

          macOS is designed to put your Mac to sleep when it is not being used. That is usually exactly what you want. Sleep saves power, protects battery life, and keeps a MacBook from running when it is closed and stuffed in a …

          9to5mac.com/2026/06/12/how-to-

          [9to5Mac]

            [?]TheHackerWire » 🤖 🌐
            @thehackerwire@mastodon.social

            🟠 CVE-2026-53806 - High (8.8)

            OpenClaw before 2026.5.12 contains a shell option parsing vulnerability that allows combined POSIX shell flags to bypass exec revalidation checks. Attackers can exploit this by using combined shell options to execute inline shell content without i...

            🔗 thehackerwire.com/vulnerabilit

            CVE Alert: CVE-2026-53806

            Alt...CVE Alert: CVE-2026-53806

              [?]TheHackerWire » 🤖 🌐
              @thehackerwire@mastodon.social

              🟠 CVE-2026-53807 - High (8.8)

              OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that allows authenticated users to skip commands.allowFrom validation. Attackers can invoke affected callbacks to mark themselves as authoriz...

              🔗 thehackerwire.com/vulnerabilit

              CVE Alert: CVE-2026-53807

              Alt...CVE Alert: CVE-2026-53807

                [?]EUVD Bot » 🤖 🌐
                @EUVD_Bot@mastodon.social

                📊 EUVD Weekly CVSS Summary

                🟡 Average Score: 6.8/10 (Medium)
                📈 Vulnerabilities: 1413
                ⬇️ Min: 1.0 | ⬆️ Max: 10.0

                📅 Period: 2026-06-07 - 2026-06-13

                  [?]urlDNA.io :verified: » 🤖 🌐
                  @urldna@infosec.exchange

                  Possible Phishing 🎣
                  on: ⚠️hxxps[:]//hrccu[.]weebly[.]com/
                  🧬 Analysis at: urldna.io/scan/6a2e83743b77500

                    [?]TheHackerWire » 🤖 🌐
                    @thehackerwire@mastodon.social

                    🔴 CVE-2026-41005 - Critical (9)

                    Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signatures from the Identity Provider (authenticity) in two SAML flows: the OAuth 2.0 SAML2 bearer grant (token endpoint) and br...

                    🔗 thehackerwire.com/vulnerabilit

                    CVE Alert: CVE-2026-41005

                    Alt...CVE Alert: CVE-2026-41005

                      [?]The New Oil » 🤖 🌐
                      @thenewoil@mastodon.thenewoil.org

                      [?]Black Cat White Hat Security » 🌐
                      @BCWHQuiz@defcon.social

                      Assessments: Cybersecurity is the practice of protecting systems, networks, applications, and data from unauthorized access, cyberattacks, and malicious activities. By combining people, processes, and technology, cybersecurity safeguards the confidentiality, integrity, and availability of information across today's interconnected digital environment.

                      Link: blackcatwhitehatsecurity.com/t

                      Assessments: Cybersecurity is the practice of protecting systems, networks, applications, and data from unauthorized access, cyberattacks, and malicious activities. By combining people, processes, and technology, cybersecurity safeguards the confidentiality, integrity, and availability of information across today's interconnected digital environment.

                      Alt...Assessments: Cybersecurity is the practice of protecting systems, networks, applications, and data from unauthorized access, cyberattacks, and malicious activities. By combining people, processes, and technology, cybersecurity safeguards the confidentiality, integrity, and availability of information across today's interconnected digital environment.

                        [?]ThreatNoir » 🌐
                        @threatnoir@infosec.exchange

                        ⚠️ CRITICAL: ‼️ CVE-2026-54420: LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn b...

                        CVE-2026-54420 is a critical symlink mishandling vulnerability in LiteSpeed cPanel plugin versions before 2.4.8 and LiteSpeed WHM Plugin versions before 5.3.2.0. Attackers with FTP or web shell access on CloudLinux/CageFS servers can exploit this flaw to escalate privileges or access sensitive file…

                        threatnoir.com/focus

                          [?]ThreatNoir » 🌐
                          @threatnoir@infosec.exchange

                          ⚠️ CRITICAL: Over 400 Arch Linux packages compromised to push rootkit, infostealer

                          A threat actor compromised over 400 packages in the Arch User Repository by injecting a Linux rootkit and infostealer into build scripts. The malware uses eBPF to achieve kernel-level persistence, hide processes, and exfiltrate credentials and access tokens. Any Arch Linux user who installed affect…

                          threatnoir.com/focus

                            [?]ThreatNoir » 🌐
                            @threatnoir@infosec.exchange

                            ⚠️ CRITICAL: China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade

                            China-linked Velvet Ant group has been backdooring PAM and OpenSSH binaries on Linux systems since at least 2016 to steal credentials and maintain persistent access while evading detection. Any Linux system running compromised login software is at risk of complete credential compromise and undetect…

                            threatnoir.com/focus

                              [?]TechWire ⚡ » 🤖 🌐
                              @techwire@social.gamefan.net

                              WhatsApp rolling out multi-account support more widely on iOS

                              WhatsApp is finally rolling out multi-account support on iPhone, bringing one of its most requested features to iOS. Here are the details.

                              9to5mac.com/2026/06/11/whatsap

                              [9to5Mac]

                                [?]CyberNetsecIO » 🌐
                                @netsecio@mastodon.social

                                📰 Splunk Scrambles to Patch Critical 9.8 CVSS Flaw Allowing Unauthenticated RCE

                                🚨 CRITICAL Splunk Enterprise flaw (CVE-2026-20253) allows unauthenticated RCE! CVSS 9.8. Attackers can execute code via an insecure PostgreSQL endpoint. On-premise versions 10.0.x and 10.2.x are vulnerable. Patch now!

                                🌐 cyber[.]netsecops[.]io

                                🔗 cyber.netsecops.io/articles/cr

                                  [?]CyberNetsecIO » 🌐
                                  @netsecio@mastodon.social

                                  📰 New Phishing Wave Uses Fake Browser Windows to Target Microsoft 365 Users

                                  ⚠️ New phishing attack targets Microsoft 365 users with 'Browser-in-the-Browser' (BitB) fakes. Attackers use realistic but fake login pop-ups to steal credentials. Stay vigilant!

                                  🌐 cyber[.]netsecops[.]io

                                  🔗 cyber.netsecops.io/articles/br

                                    [?]CyberNetsecIO » 🌐
                                    @netsecio@mastodon.social

                                    📰 Google Patches Fifth Actively Exploited Chrome Zero-Day of 2026

                                    ⚠️ Google patches its FIFTH Chrome zero-day this year! CVE-2026-11645 is a high-severity V8 bug actively exploited in the wild. Update your browser to version 149.0.7827.103+ immediately!

                                    🌐 cyber[.]netsecops[.]io

                                    🔗 cyber.netsecops.io/articles/go

                                      [?]CyberNetsecIO » 🌐
                                      @netsecio@mastodon.social

                                      📰 DHS Cyber Modernization Efforts Face Hurdles, GAO Report Finds

                                      A new GAO report finds that DHS cybersecurity modernization programs, while crucial, face major hurdles from rising costs, staffing shortages, and evolving threats. Sustained investment is needed to protect federal networks. 🏛️ #...

                                      🌐 cyber[.]netsecops[.]io

                                      🔗 cyber.netsecops.io/articles/dh

                                        [?]TechWire ⚡ » 🤖 🌐
                                        @techwire@social.gamefan.net

                                        Design resources for iOS 27, iPadOS 27, and macOS 27 Golden Gate now available

                                        Apple has released the Sketch files for three of the new systems it announced during WWDC26, alongside the updated App Icon Template in several file formats. Here are the details.

                                        9to5mac.com/2026/06/11/design-

                                        [9to5Mac]

                                          [?]urlDNA.io :verified: » 🤖 🌐
                                          @urldna@infosec.exchange

                                          Possible Phishing 🎣
                                          on: ⚠️hxxps[:]//www[.]fenouxltd[.]com/M/men[.]html
                                          🧬 Analysis at: urldna.io/scan/6a2e89b63b77500

                                            [?]The New Oil » 🤖 🌐
                                            @thenewoil@mastodon.thenewoil.org

                                            [?]TechWire ⚡ » 🤖 🌐
                                            @techwire@social.gamefan.net

                                            Bipartisan lawmakers reintroduce bill to limit Big Tech gatekeeping, Apple shoots back

                                            After a bipartisan group of senators reintroduced the American Innovation and Choice Online Act (AICOA) today, reviving an effort that could have major implications for Big Tech if enacted into law, Apple issued a stron…

                                            9to5mac.com/2026/06/11/biparti

                                            [9to5Mac]

                                              [?]TechWire ⚡ » 🤖 🌐
                                              @techwire@social.gamefan.net

                                              Razer Kiyo V2 X Review: Auto-focus for life

                                              Razer's Kiyo V2 X is the most budget-friendly of its current webcam lineup; it records video at 1440p / 60 fps and features "speedy" auto-focus, a wide 80-degree field of view, and a smoothly integrated physical privacy…

                                              tomshardware.com/peripherals/w

                                              [Tom's Hardware]

                                                [?]TechWire ⚡ » 🤖 🌐
                                                @techwire@social.gamefan.net

                                                AI cryptomining network's 320,000 RTX 3090-class GPUs allegedly burn 112 megawatts of power on ‘zero useful AI computation’ — GPU rental costs jump 38%, but Pearl’s cards are doing random…

                                                A preprint claims Pearl’s AI mining network consumes 320,000 GPU-equivalents and 112 MW while producing no verified useful AI computation.

                                                tomshardware.com/tech-industry

                                                [Tom's Hardware]

                                                  [?]TheHackerWire » 🤖 🌐
                                                  @thehackerwire@mastodon.social

                                                  🟠 CVE-2026-50645 - High (7.5)

                                                  There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncontrolled resource consumption or a denial of service attack. Users are recommended to upgrade to v...

                                                  🔗 thehackerwire.com/vulnerabilit

                                                  CVE Alert: CVE-2026-50645

                                                  Alt...CVE Alert: CVE-2026-50645

                                                    [?]TheHackerWire » 🤖 🌐
                                                    @thehackerwire@mastodon.social

                                                    🔴 CVE-2026-12027 - Critical (9.6)

                                                    Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

                                                    🔗 thehackerwire.com/vulnerabilit

                                                    CVE Alert: CVE-2026-12027

                                                    Alt...CVE Alert: CVE-2026-12027

                                                      [?]EUVD Bot » 🤖 🌐
                                                      @EUVD_Bot@mastodon.social

                                                      🚨 EUVD-2026-36660

                                                      📊 Score: n/a
                                                      📦 Product: Config::IniFiles
                                                      🏢 Vendor: SHLOMIF
                                                      📅 Updated: 2026-06-14

                                                      📝 Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandle.

                                                      Config::IniFiles::_make_filehandle opens a filename argument with Perl's 2-arg open(), so a filename tha...

                                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                                        [?]EUVD Bot » 🤖 🌐
                                                        @EUVD_Bot@mastodon.social

                                                        🚨 EUVD-2026-36659

                                                        📊 Score: n/a
                                                        📦 Product: gd
                                                        🏢 Vendor: RURBAN
                                                        📅 Updated: 2026-06-14

                                                        📝 GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle.

                                                        GD::Image::_make_filehandle opens a filename argument with Perl's 2-arg open(), so a filename that begins or ends with a pipe ("| cmd", "...

                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                          [?]urlDNA.io :verified: » 🤖 🌐
                                                          @urldna@infosec.exchange

                                                          Possible Phishing 🎣
                                                          on: ⚠️hxxps[:]//zuwmbztn[.]firebaseapp[.]com
                                                          🧬 Analysis at: urldna.io/scan/6a2e436a3b77500

                                                            [?]TheHackerWire » 🤖 🌐
                                                            @thehackerwire@mastodon.social

                                                            🟠 CVE-2026-12012 - High (8.1)

                                                            Use after free in Network in Google Chrome prior to 149.0.7827.115 allowed an attacker in a privileged network position to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High)

                                                            🔗 thehackerwire.com/vulnerabilit

                                                            CVE Alert: CVE-2026-12012

                                                            Alt...CVE Alert: CVE-2026-12012

                                                              [?]The New Oil » 🤖 🌐
                                                              @thenewoil@mastodon.thenewoil.org

                                                              [?]SquaredTech » 🌐
                                                              @SquaredTech@mstdn.social

                                                              US Gov has issued a critical alert! A Chinese group has reportedly exploited an Anthropic jailbreak to access Claude. Shockingly, Anthropic has declined to patch it prior to export controls. Stay informed, stay safe! 🚨🔒 Anthropic Jailbreak Warning: US Gov Alert Over Chinese Access
                                                              squaredtech.co/anthropic-jailb

                                                                [?]Hugo | DevOps | Cybersecurity » 🌐
                                                                @hugovalters@mastodon.social

                                                                Ubiquiti: 47 CVEs, avg CVSS 7.99. 100% unpatched. Trust Score: D. Critical flaws in UniFi & AmpliFi. Patch or risk exposure.

                                                                valtersit.com/vendors/ubiquiti/

                                                                  [?]TechWire ⚡ » 🤖 🌐
                                                                  @techwire@social.gamefan.net

                                                                  US government warned Anthropic that Chinese group had accessed model, but firm 'refused' to fix Fable 5 jailbreak before US export controls — Anthropic defended its decision by saying…

                                                                  David Sacks said the US government warned Anthropic that Claude Fable 5 had been jailbroken and that CEO Dario Amodei refused to fix the flaw.

                                                                  tomshardware.com/tech-industry

                                                                  [Tom's Hardware]

                                                                    [?]Daniel Marsh » 🤖 🌐
                                                                    @danielmarsh@social.thepixelspulse.com

                                                                    Ezekiel Dean Potter, a former IT specialist, waged a 21-month cyber war on Saydel School District after his termination, exploiting credentials that were never revoked. His actions, including deleting administrator accounts and disrupting classes, underscore the catastrophic real-world impact of neglected offboarding procedures and continuous access management. A…

                                                                    tpp.blog/15fn1cq

                                                                    🤖 This post was AI-generated.

                                                                      [?]TechWire ⚡ » 🤖 🌐
                                                                      @techwire@social.gamefan.net

                                                                      AMD taunts Apple's MacBook Neo for failing to run 75% of top PC games — Only 5 out of the 20 top PC games …

                                                                      AMD is reminding folks not to buy a MacBook, even if it's as good of a deal as the Neo, if you primarily want to game on it. Instead, AMD's own budget laptops can run all the modern titles you want, with a small caveat.

                                                                      tomshardware.com/laptops/macbo

                                                                      [Tom's Hardware]

                                                                        [?]urlDNA.io :verified: » 🤖 🌐
                                                                        @urldna@infosec.exchange

                                                                        Possible Phishing 🎣
                                                                        on: ⚠️hxxps[:]//sanvik05[.]github[.]io/amazon-homepage-clone/
                                                                        🧬 Analysis at: urldna.io/scan/6a2e43923b77500

                                                                          [?]The New Oil » 🤖 🌐
                                                                          @thenewoil@mastodon.thenewoil.org

                                                                          [?]TechWire ⚡ » 🤖 🌐
                                                                          @techwire@social.gamefan.net

                                                                          OpenAI hit with sweeping probe from massive coalition of 42 US state attorneys general just days after reported IPO filing — subpoena ta…

                                                                          State attorneys general have opened a broad investigation into OpenAI, subpoenaing documents on ads, user retention, data handling, minors, health data, model behavior, and safety policies.

                                                                          tomshardware.com/tech-industry

                                                                          [Tom's Hardware]

                                                                            [?]Malicious Extension Bot » 🤖 🌐
                                                                            @malicious_browser_bot@infosec.exchange

                                                                            extension Breezy Beach Live Wallpaper seems malicious. Its badness score is 98/100!

                                                                            ```json
                                                                            {"id": "dfnmijehfiknkcddjpchgaikklmocfhi", "score": 98, "platform": "chrome", "name": "Breezy Beach Live Wallpaper"}
                                                                            ```

                                                                              [?]urlDNA.io :verified: » 🤖 🌐
                                                                              @urldna@infosec.exchange

                                                                              Possible Phishing 🎣
                                                                              on: ⚠️hxxps[:]//0393761[.]weebly[.]com
                                                                              🧬 Analysis at: urldna.io/scan/6a2e210f3b77500

                                                                                [?]TechWire ⚡ » 🤖 🌐
                                                                                @techwire@social.gamefan.net

                                                                                Apple hinted at three new products this week with fall launches rumored

                                                                                Apple’s WWDC announcements for iOS 27 and macOS Golden Gate were packed with hints about new hardware, including three new products expected to launch this fall.

                                                                                9to5mac.com/2026/06/11/apple-h

                                                                                [9to5Mac]

                                                                                  Back to top - More...