voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]TheHackerWire » 🤖 🌐
@thehackerwire@mastodon.social

🟠 CVE-2026-45012 - High (7.6)

ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 contain an authenticated server-side request forgery (SSRF) in the rich-text widget import flow. An authenticated user who can submit/edit rich-...

🔗 thehackerwire.com/vulnerabilit

CVE Alert: CVE-2026-45012

Alt...CVE Alert: CVE-2026-45012

    [?]TheHackerWire » 🤖 🌐
    @thehackerwire@mastodon.social

    🟠 CVE-2026-45013 - High (8.1)

    ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 have a password reset flow that constructs the reset URL using `req.hostname`, which is derived directly from the attacker-controlled HTTP `Host...

    🔗 thehackerwire.com/vulnerabilit

    CVE Alert: CVE-2026-45013

    Alt...CVE Alert: CVE-2026-45013

      [?]TechWire ⚡ » 🤖 🌐
      @techwire@social.gamefan.net

      We’ve cut Google enough slack for poor Pixel updates. Now it’s time to hold it accountable

      Pixel updates have been a mess, and it needs to stop!

      androidauthority.com/google-po

      [Android Authority]

        [?]TechWire ⚡ » 🤖 🌐
        @techwire@social.gamefan.net

        Phone battery draining fast? Malware is one of 8 possible factors - how to tell for sure

        No battery lasts forever. But it's often in your power to extend its life. Here's our checklist for identifying the causes of battery degradation - and how to fix each one.

        zdnet.com/article/phone-batter

        [ZDNet]

          [?]urlDNA.io :verified: » 🤖 🌐
          @urldna@infosec.exchange

          Possible Phishing 🎣
          on: ⚠️hxxp[:]//facebook-clone-rho-ten[.]vercel[.]app
          🧬 Analysis at: urldna.io/scan/6a2d1c363b77500

            [?]TechWire ⚡ » 🤖 🌐
            @techwire@social.gamefan.net

            The best thing about the Moto G Stylus 2026? It does what Google and Samsung won’t

            Not all older features are obsolete.

            androidauthority.com/moto-g-st

            [Android Authority]

              [?]urlDNA.io :verified: » 🤖 🌐
              @urldna@infosec.exchange

              Possible Phishing 🎣
              on: ⚠️hxxps[:]//035261[.]weebly[.]com
              🧬 Analysis at: urldna.io/scan/6a2cd5cf3b77500

                [?]TechWire ⚡ » 🤖 🌐
                @techwire@social.gamefan.net

                iOS 27 Adds New Drawing Tool to Your iPhone's Messages App

                The upcoming iOS 27 and macOS 27 Golden Gate updates expand drawing tools to more of Apple's built-in apps across the iPhone and Mac. In the Messages app on iOS 27, there is a new "Drawing" option in the app drawer, whi…

                macrumors.com/2026/06/12/ios-2

                [MacRumors]

                  [?]TechWire ⚡ » 🤖 🌐
                  @techwire@social.gamefan.net

                  Last Chance: Apple Card Sign-Up Promo Can Earn You Free AirPods Pro 3

                  Time is running out on the Apple Card sign-up promo that began last month. For three more days, you can effectively receive AirPods Pro 3 for free when you sign up for a new Apple Card, but there are some strings attach…

                  macrumors.com/2026/06/12/last-

                  [MacRumors]

                    [?]TheHackerWire » 🤖 🌐
                    @thehackerwire@mastodon.social

                    🔴 CVE-2026-46716 - Critical (9.9)

                    Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, a RoleMember user can create a scheduled cron task with Cover=CronCoverAll, Servers=[] and an arbitrary Com...

                    🔗 thehackerwire.com/vulnerabilit

                    CVE Alert: CVE-2026-46716

                    Alt...CVE Alert: CVE-2026-46716

                      [?]urlDNA.io :verified: » 🤖 🌐
                      @urldna@infosec.exchange

                      Possible Phishing 🎣
                      on: ⚠️hxxps[:]//forms[.]gle/Y1gQcJHZiBZLccMo8
                      🧬 Analysis at: urldna.io/scan/6a2c1efb3b77500

                        [?]TheHackerWire » 🤖 🌐
                        @thehackerwire@mastodon.social

                        🟠 CVE-2026-46717 - High (7.7)

                        Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, nezha's dashboard supports two user roles: RoleAdmin (Role==0) and RoleMember (Role==1). The notification r...

                        🔗 thehackerwire.com/vulnerabilit

                        CVE Alert: CVE-2026-46717

                        Alt...CVE Alert: CVE-2026-46717

                          [?]TheHackerWire » 🤖 🌐
                          @thehackerwire@mastodon.social

                          🟠 CVE-2025-7011 - High (7.8)

                          Heap out-of-bounds read vulnerability in Avast Antivirus when scanning a malformed zip file containing XML may allow Local Execution of Code or Denial-of-Service of the antivirus process.

                          This issue affects Avast Antivirus, AVG Antivirus, Norton ...

                          🔗 thehackerwire.com/vulnerabilit

                          CVE Alert: CVE-2025-7011

                          Alt...CVE Alert: CVE-2025-7011

                            [?]OTX Bot » 🤖 🌐
                            @techbot@social.raytec.co

                            OnyxC2 Malware Campaign Exploiting Fake Software Installers External Inbox CTIA

                            A Malware-as-a-Service (MaaS) campaign using OnyxC2 is being used by threat
                            actors to steal credentials and sensitive data from over 210 applications. The campaign delivers infostealer malware through fake software installers and
                            uses evasion techniques to enable financial fraud and unauthorized access to accounts, systems and crypto assets.

                            Pulse ID: 6a2ce2ef1e1556ace79c78b3
                            Pulse Link: otx.alienvault.com/pulse/6a2ce
                            Pulse Author: cryptocti
                            Created: 2026-06-13 04:56:15

                            Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                              [?]Malicious Extension Bot » 🤖 🌐
                              @malicious_browser_bot@infosec.exchange

                              extension Jedi Pikachu Live Wallpap seems malicious. Its badness score is 96/100!

                              ```json
                              {"id": "bdlholhlpkomooecbhclfnmjkilldepk", "score": 96, "platform": "chrome", "name": "Jedi Pikachu Live Wallpap"}
                              ```

                                [?]TechWire ⚡ » 🤖 🌐
                                @techwire@social.gamefan.net

                                macOS 27 Golden Gate Hands-On: Every Major New Feature

                                macOS 27 Golden Gate is in beta ahead of a fall release, and we thought we'd go over what's new for those who don't want to risk beta software on their Mac. macOS Golden Gate adds Siri AI, Liquid Glass updates, and mult…

                                macrumors.com/2026/06/12/macos

                                [MacRumors]

                                  [?]Marcus Adams » 🌐
                                  @gerowen@mastodon.social

                                  [?]TechWire ⚡ » 🤖 🌐
                                  @techwire@social.gamefan.net

                                  Apple's Limited-Edition 2026 'Close Your Rings' Watch Band Revealed

                                  Apple's employees who participated in the company's annual Close Your Rings Challenge have begun to receive a limited-edition Apple Watch band and a special enamel pin marking the 10th anniversary of the internal challe…

                                  macrumors.com/2026/06/12/apple

                                  [MacRumors]

                                    [?]urlDNA.io :verified: » 🤖 🌐
                                    @urldna@infosec.exchange

                                    Possible Phishing 🎣
                                    on: ⚠️hxxps[:]//docs[.]google[.]com/presentation/d/e/2PACX-1vRpOQ3fU5UADCUHiPhAylnm11pcxabNYywbRTPiK3YbgUdHxVWDIJ4CqnyLg3JJhhLVoxL41mL365Sx/pub?start=false&loop=false&delayms=3000
                                    🧬 Analysis at: urldna.io/scan/6a2c57603b77500

                                      [?]SquaredTech » 🌐
                                      @SquaredTech@mstdn.social

                                      🔐 Big news! US Govt. takes strict action as Export Control disables and worldwide 🌍 due to a reported jailbreak. This move has surely shaken up the tech world! 🚀 Stay tuned for more updates. Anthropic Claude Export Control: US Government Pulls Fable 5 and Mytho
                                      squaredtech.co/anthropic-claud

                                        [?]TechWire ⚡ » 🤖 🌐
                                        @techwire@social.gamefan.net

                                        How to See Which Mac Apps Will Stop Working After macOS Golden Gate

                                        Apple is phasing out support for Rosetta 2, which is a feature that allows Intel-based apps to run on Apple silicon Macs. Rosetta is going to stop working for most apps in macOS 28, and when that happens, apps that use …

                                        macrumors.com/2026/06/12/macos

                                        [MacRumors]

                                          [?]TheHackerWire » 🤖 🌐
                                          @thehackerwire@mastodon.social

                                          🟠 CVE-2025-14098 - High (7.8)

                                          Heap buffer out-of-bounds write vulnerability due to integer overflow in Avira Antivirus engine when scanning a malformed MS-DOS executable file may allow Local Execution of Code or Denial-of-Service of the antivirus engine process.

                                          This issue af...

                                          🔗 thehackerwire.com/vulnerabilit

                                          CVE Alert: CVE-2025-14098

                                          Alt...CVE Alert: CVE-2025-14098

                                            [?]urlDNA.io :verified: » 🤖 🌐
                                            @urldna@infosec.exchange

                                            Possible Phishing 🎣
                                            on: ⚠️hxxps[:]//mejillones-a01ce[.]web[.]app/
                                            🧬 Analysis at: urldna.io/scan/6a2c7b113b77500

                                              [?]EUVD Bot » 🤖 🌐
                                              @EUVD_Bot@mastodon.social

                                              🚨 EUVD-2026-36634

                                              📊 Score: 4.6/10 (CVSS v3.1)
                                              📦 Product: Allegra
                                              🏢 Vendor: Allegra
                                              📅 Updated: 2026-06-12

                                              📝 Allegra downloadAttachment Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to execute arbitrary script on affected installations of Allegra. User interaction is required to exploit this vulnerability in th...

                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                [?]EUVD Bot » 🤖 🌐
                                                @EUVD_Bot@mastodon.social

                                                🚨 EUVD-2026-36633

                                                📊 Score: 6.5/10 (CVSS v3.1)
                                                📦 Product: Allegra
                                                🏢 Vendor: Allegra
                                                📅 Updated: 2026-06-12

                                                📝 Allegra exportReport Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Allegra. Authentication is required to exploit this vulnerability.

                                                The s...

                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                  [?]TheHackerWire » 🤖 🌐
                                                  @thehackerwire@mastodon.social

                                                  🟠 CVE-2026-53831 - High (8.3)

                                                  OpenClaw before 2026.5.18 contains a policy enforcement vulnerability in system.run safe-bin allowlist validation that allows shell expansion to modify command interpretation on POSIX nodes. Authenticated operators can exploit shell metacharacters...

                                                  🔗 thehackerwire.com/vulnerabilit

                                                  CVE Alert: CVE-2026-53831

                                                  Alt...CVE Alert: CVE-2026-53831

                                                    [?]TheHackerWire » 🤖 🌐
                                                    @thehackerwire@mastodon.social

                                                    🟠 CVE-2026-53832 - High (7.7)

                                                    OpenClaw before 2026.5.18 contains an identity header validation vulnerability allowing local same-host callers to forge trusted-proxy identity headers. Attackers with access to the proxy-facing Gateway port can supply forged identity headers to a...

                                                    🔗 thehackerwire.com/vulnerabilit

                                                    CVE Alert: CVE-2026-53832

                                                    Alt...CVE Alert: CVE-2026-53832

                                                      [?]TheHackerWire » 🤖 🌐
                                                      @thehackerwire@mastodon.social

                                                      🟠 CVE-2026-53833 - High (7.7)

                                                      OpenClaw before 2026.4.29 contains an authorization bypass vulnerability in the QQBot streaming command that allows authenticated senders to mutate configuration without explicit allowFrom restrictions. Attackers can modify QQBot streaming configu...

                                                      🔗 thehackerwire.com/vulnerabilit

                                                      CVE Alert: CVE-2026-53833

                                                      Alt...CVE Alert: CVE-2026-53833

                                                        [?]Malicious Extension Bot » 🤖 🌐
                                                        @malicious_browser_bot@infosec.exchange

                                                        extension Ai Assistant Sidebar seems malicious. Its badness score is 85/100!

                                                        ```json
                                                        {"id": "cimdidfalaihjffeflblihcahdmlomca", "score": 85, "platform": "chrome", "name": "Ai Assistant Sidebar"}
                                                        ```

                                                          [?]TechWire ⚡ » 🤖 🌐
                                                          @techwire@social.gamefan.net

                                                          What's New in the iOS 27 Photos App

                                                          The Photos app is one of a handful of apps that Apple paid extra attention to in iOS 27. It has multiple improvements to performance, and several quality-of-life upgrades. There are also new AI photo editing tools that …

                                                          macrumors.com/guide/ios-27-pho

                                                          [MacRumors]

                                                            [?]TechWire ⚡ » 🤖 🌐
                                                            @techwire@social.gamefan.net

                                                            Apple Criticizes U.S. Antitrust Bill That Targets the App Store

                                                            United States Senators Chuck Grassley and Amy Klobuchar this week reintroduced the American Innovation and Choice Online Act (AICOA) that targets major tech companies like Apple, and Apple is not happy to see it back. T…

                                                            macrumors.com/2026/06/11/apple

                                                            [MacRumors]

                                                              [?]urlDNA.io :verified: » 🤖 🌐
                                                              @urldna@infosec.exchange

                                                              Possible Phishing 🎣
                                                              on: ⚠️hxxps[:]//docs[.]google[.]com/presentation/d/e/2PACX-1vR2chhBTn9RgXNHHEslF1GPW2_Xq1L817ySV-xekMwhupZOWUh_3n68nV4f23l5FLSy8ZMur-MkhLFh/pub
                                                              🧬 Analysis at: urldna.io/scan/6a2c3b2b3b77500

                                                                [?]Tim Green » 🤖 🌐
                                                                @rawveg@me.dm

                                                                AI tools are increasingly weaponised for coercive control and abuse, with consumer devices and generative tech being exploited at scale. Legal standards and tech design must evolve to match this growing crisis.
                                                                Discover more at smarterarticles.co.uk/ai-and-t

                                                                  [?]Graham Perrin » 🌐
                                                                  @grahamperrin@mastodon.bsd.cafe

                                                                  "TLDR: depthfirst’s production autonomous security agent discovered 21 zero-day vulnerabilities in FFmpeg, after intensive security analysis by Google and Anthropic. Moving beyond theoretical analysis, our agent produces concrete, reproducible PoC inputs to confirm its findings at a fraction of the costs ($1k vs. $10k). Several of the findings had been sitting latent for 15 to 20 years. We explored the exploitability of the issues and developed a PoC demonstrating a RCE exploit primitive."

                                                                  Also:

                                                                  ― <news.ycombinator.com/item?id=4>
                                                                  ― <thehackernews.com/2026/06/ai-a> via <reddit.com/r/cybersecurity/com>

                                                                    [?]TechWire ⚡ » 🤖 🌐
                                                                    @techwire@social.gamefan.net

                                                                    Valve just imported 13 tons of VR headsets in one day

                                                                    On June 10th, the German container ship Posen docked in Los Angeles after a two-week voyage from Shanghai. As Valve watcher Brad Lynch notes, it was almost certainly carrying the first mass production shipments of the S…

                                                                    theverge.com/news/949517/valve

                                                                    [The Verge]

                                                                      [?]Marcus Adams » 🌐
                                                                      @gerowen@mastodon.social

                                                                      This is one reason I don't like, or recommend, adding third party repos to any distribution.

                                                                      Title: Arch Linux's AUR Sees More Than 400 Packages Compromised With Malware

                                                                      Link: phoronix.com/news/Arch-Linux-A

                                                                        [?]Marcus Adams » 🌐
                                                                        @gerowen@mastodon.social

                                                                        Follow-up; it got hammered.

                                                                        Quote:

                                                                        Even at 1,579 packages listed, that final update noted, it's a "list containing many (but not all) of the affected packages". Ouch.

                                                                        Title: Arch Now Believes Malware Incident Under Control: More Than 1,500 Affected Packages

                                                                        Link: phoronix.com/news/Arch-Linux-A

                                                                          [?]AI6YR Ben » 🌐
                                                                          @ai6yr@m.ai6yr.org

                                                                          Oh, good thing it's so hard to install packages in Arch Linux, I hadn't yet loaded AUR 🤪

                                                                          bleepingcomputer.com/news/secu

                                                                            Back to top - More...