voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
🟠 CVE-2026-45012 - High (7.6)
ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 contain an authenticated server-side request forgery (SSRF) in the rich-text widget import flow. An authenticated user who can submit/edit rich-...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45012/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-45013 - High (8.1)
ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 have a password reset flow that constructs the reset URL using `req.hostname`, which is derived directly from the attacker-controlled HTTP `Host...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45013/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
We’ve cut Google enough slack for poor Pixel updates. Now it’s time to hold it accountable
Pixel updates have been a mess, and it needs to stop!
https://www.androidauthority.com/google-poor-pixel-updates-accountability-3661496/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Phone battery draining fast? Malware is one of 8 possible factors - how to tell for sure
No battery lasts forever. But it's often in your power to extend its life. Here's our checklist for identifying the causes of battery degradation - and how to fix each one.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
Possible Phishing 🎣
on: ⚠️hxxp[:]//facebook-clone-rho-ten[.]vercel[.]app
🧬 Analysis at: https://urldna.io/scan/6a2d1c363b77500007024a1d
#cybersecurity #phishing #infosec #urldna #scam #infosec
The best thing about the Moto G Stylus 2026? It does what Google and Samsung won’t
Not all older features are obsolete.
https://www.androidauthority.com/moto-g-stylus-2026-beats-google-samsung-how-3675524/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Possible Phishing 🎣
on: ⚠️hxxps[:]//035261[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a2cd5cf3b77500007024427
#cybersecurity #phishing #infosec #urldna #scam #infosec
iOS 27 Adds New Drawing Tool to Your iPhone's Messages App
The upcoming iOS 27 and macOS 27 Golden Gate updates expand drawing tools to more of Apple's built-in apps across the iPhone and Mac. In the Messages app on iOS 27, there is a new "Drawing" option in the app drawer, whi…
https://www.macrumors.com/2026/06/12/ios-27-macos-27-drawing-tools/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #MacRumors [MacRumors]
Last Chance: Apple Card Sign-Up Promo Can Earn You Free AirPods Pro 3
Time is running out on the Apple Card sign-up promo that began last month. For three more days, you can effectively receive AirPods Pro 3 for free when you sign up for a new Apple Card, but there are some strings attach…
https://www.macrumors.com/2026/06/12/last-chance-apple-card-airpods-pro-3-promo/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #MacRumors [MacRumors]
🔴 CVE-2026-46716 - Critical (9.9)
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, a RoleMember user can create a scheduled cron task with Cover=CronCoverAll, Servers=[] and an arbitrary Com...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-46716/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Possible Phishing 🎣
on: ⚠️hxxps[:]//forms[.]gle/Y1gQcJHZiBZLccMo8
🧬 Analysis at: https://urldna.io/scan/6a2c1efb3b77500008275bb8
#cybersecurity #phishing #infosec #urldna #scam #infosec
🟠 CVE-2026-46717 - High (7.7)
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, nezha's dashboard supports two user roles: RoleAdmin (Role==0) and RoleMember (Role==1). The notification r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-46717/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2025-7011 - High (7.8)
Heap out-of-bounds read vulnerability in Avast Antivirus when scanning a malformed zip file containing XML may allow Local Execution of Code or Denial-of-Service of the antivirus process.
This issue affects Avast Antivirus, AVG Antivirus, Norton ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-7011/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
OnyxC2 Malware Campaign Exploiting Fake Software Installers External Inbox CTIA
A Malware-as-a-Service (MaaS) campaign using OnyxC2 is being used by threat
actors to steal credentials and sensitive data from over 210 applications. The campaign delivers infostealer malware through fake software installers and
uses evasion techniques to enable financial fraud and unauthorized access to accounts, systems and crypto assets.
Pulse ID: 6a2ce2ef1e1556ace79c78b3
Pulse Link: https://otx.alienvault.com/pulse/6a2ce2ef1e1556ace79c78b3
Pulse Author: cryptocti
Created: 2026-06-13 04:56:15
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #FinancialFraud #InfoSec #InfoStealer #MaaS #Malware #MalwareAsAService #OTX #OpenThreatExchange #bot #cryptocti
#chrome extension Jedi Pikachu Live Wallpap seems malicious. Its #cybersecurity badness score is 96/100!
```json
{"id": "bdlholhlpkomooecbhclfnmjkilldepk", "score": 96, "platform": "chrome", "name": "Jedi Pikachu Live Wallpap"}
```
macOS 27 Golden Gate Hands-On: Every Major New Feature
macOS 27 Golden Gate is in beta ahead of a fall release, and we thought we'd go over what's new for those who don't want to risk beta software on their Mac. macOS Golden Gate adds Siri AI, Liquid Glass updates, and mult…
https://www.macrumors.com/2026/06/12/macos-golden-gate-hands-on/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #MacRumors [MacRumors]
Apple's Limited-Edition 2026 'Close Your Rings' Watch Band Revealed
Apple's employees who participated in the company's annual Close Your Rings Challenge have begun to receive a limited-edition Apple Watch band and a special enamel pin marking the 10th anniversary of the internal challe…
https://www.macrumors.com/2026/06/12/apple-watch-close-your-rings-band/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #MacRumors [MacRumors]
Possible Phishing 🎣
on: ⚠️hxxps[:]//docs[.]google[.]com/presentation/d/e/2PACX-1vRpOQ3fU5UADCUHiPhAylnm11pcxabNYywbRTPiK3YbgUdHxVWDIJ4CqnyLg3JJhhLVoxL41mL365Sx/pub?start=false&loop=false&delayms=3000
🧬 Analysis at: https://urldna.io/scan/6a2c57603b7750000702386f
#cybersecurity #phishing #infosec #urldna #scam #infosec
🔐 Big news! US Govt. takes strict action as #AnthropicClaude Export Control disables #Fable5 and #Mythos5 worldwide 🌍 due to a reported jailbreak. This move has surely shaken up the tech world! 🚀 Stay tuned for more updates. #CyberSecurity #TechNews #ExportControl Anthropic Claude Export Control: US Government Pulls Fable 5 and Mytho
https://www.squaredtech.co/anthropic-claude-export-control-us-government-pulls-fable-5-and-mytho?fsp_sid=11915
How to See Which Mac Apps Will Stop Working After macOS Golden Gate
Apple is phasing out support for Rosetta 2, which is a feature that allows Intel-based apps to run on Apple silicon Macs. Rosetta is going to stop working for most apps in macOS 28, and when that happens, apps that use …
https://www.macrumors.com/2026/06/12/macos-golden-gate-rosetta-support/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #MacRumors [MacRumors]
🟠 CVE-2025-14098 - High (7.8)
Heap buffer out-of-bounds write vulnerability due to integer overflow in Avira Antivirus engine when scanning a malformed MS-DOS executable file may allow Local Execution of Code or Denial-of-Service of the antivirus engine process.
This issue af...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-14098/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Possible Phishing 🎣
on: ⚠️hxxps[:]//mejillones-a01ce[.]web[.]app/
🧬 Analysis at: https://urldna.io/scan/6a2c7b113b77500004ebbbb7
#cybersecurity #phishing #infosec #urldna #scam #infosec
🚨 EUVD-2026-36634
📊 Score: 4.6/10 (CVSS v3.1)
📦 Product: Allegra
🏢 Vendor: Allegra
📅 Updated: 2026-06-12
📝 Allegra downloadAttachment Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to execute arbitrary script on affected installations of Allegra. User interaction is required to exploit this vulnerability in th...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-36634
🚨 EUVD-2026-36633
📊 Score: 6.5/10 (CVSS v3.1)
📦 Product: Allegra
🏢 Vendor: Allegra
📅 Updated: 2026-06-12
📝 Allegra exportReport Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Allegra. Authentication is required to exploit this vulnerability.
The s...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-36633
🟠 CVE-2026-53831 - High (8.3)
OpenClaw before 2026.5.18 contains a policy enforcement vulnerability in system.run safe-bin allowlist validation that allows shell expansion to modify command interpretation on POSIX nodes. Authenticated operators can exploit shell metacharacters...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53831/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-53832 - High (7.7)
OpenClaw before 2026.5.18 contains an identity header validation vulnerability allowing local same-host callers to forge trusted-proxy identity headers. Attackers with access to the proxy-facing Gateway port can supply forged identity headers to a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53832/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-53833 - High (7.7)
OpenClaw before 2026.4.29 contains an authorization bypass vulnerability in the QQBot streaming command that allows authenticated senders to mutate configuration without explicit allowFrom restrictions. Attackers can modify QQBot streaming configu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53833/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
#chrome extension Ai Assistant Sidebar seems malicious. Its #cybersecurity badness score is 85/100!
```json
{"id": "cimdidfalaihjffeflblihcahdmlomca", "score": 85, "platform": "chrome", "name": "Ai Assistant Sidebar"}
```
What's New in the iOS 27 Photos App
The Photos app is one of a handful of apps that Apple paid extra attention to in iOS 27. It has multiple improvements to performance, and several quality-of-life upgrades. There are also new AI photo editing tools that …
https://www.macrumors.com/guide/ios-27-photos-app/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #MacRumors [MacRumors]
Apple Criticizes U.S. Antitrust Bill That Targets the App Store
United States Senators Chuck Grassley and Amy Klobuchar this week reintroduced the American Innovation and Choice Online Act (AICOA) that targets major tech companies like Apple, and Apple is not happy to see it back. T…
https://www.macrumors.com/2026/06/11/apple-aicoa-reintroduction-criticism/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #MacRumors [MacRumors]
Possible Phishing 🎣
on: ⚠️hxxps[:]//docs[.]google[.]com/presentation/d/e/2PACX-1vR2chhBTn9RgXNHHEslF1GPW2_Xq1L817ySV-xekMwhupZOWUh_3n68nV4f23l5FLSy8ZMur-MkhLFh/pub
🧬 Analysis at: https://urldna.io/scan/6a2c3b2b3b77500008275f7a
#cybersecurity #phishing #infosec #urldna #scam #infosec
Tim Green » 🤖 🌐
@rawveg@me.dm
AI tools are increasingly weaponised for coercive control and abuse, with consumer devices and generative tech being exploited at scale. Legal standards and tech design must evolve to match this growing crisis.
Discover more at https://smarterarticles.co.uk/ai-and-the-abusers-toolkit-when-connection-becomes-control
#HumanInTheLoop #DigitalSafety #AIethics #Cybersecurity
"TLDR: depthfirst’s production autonomous security agent discovered 21 zero-day vulnerabilities in FFmpeg, after intensive security analysis by Google and Anthropic. Moving beyond theoretical analysis, our agent produces concrete, reproducible PoC inputs to confirm its findings at a fraction of the costs ($1k vs. $10k). Several of the findings had been sitting latent for 15 to 20 years. We explored the exploitability of the issues and developed a PoC demonstrating a RCE exploit primitive."
Also:
― <https://news.ycombinator.com/item?id=48510046#48510834>
― <https://thehackernews.com/2026/06/ai-agent-uncovers-21-zero-days-in.html> via <https://www.reddit.com/r/cybersecurity/comments/1tys5z7/ai_agent_uncovers_21_zerodays_in_ffmpeg_chrome/>
…
Valve just imported 13 tons of VR headsets in one day
On June 10th, the German container ship Posen docked in Los Angeles after a two-week voyage from Shanghai. As Valve watcher Brad Lynch notes, it was almost certainly carrying the first mass production shipments of the S…
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
This is one reason I don't like, or recommend, adding third party repos to any #Linux distribution.
Title: Arch Linux's AUR Sees More Than 400 Packages Compromised With Malware
Link: https://www.phoronix.com/news/Arch-Linux-AUR-400-Compromised
Follow-up; it got hammered.
Quote:
Even at 1,579 packages listed, that final update noted, it's a "list containing many (but not all) of the affected packages". Ouch.
Title: Arch #Linux Now Believes Malware Incident Under Control: More Than 1,500 Affected Packages
Link: https://www.phoronix.com/news/Arch-Linux-AUR-More-Than-1500