voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
🚨 EUVD-2026-36549
📊 Score: 5.1/10 (CVSS v3.1)
📦 Product: MISP
🏢 Vendor: MISP
📅 Updated: 2026-06-12
📝 An improper authorization vulnerability in MISP allowed an authenticated organization administrator to access or modify user settings belonging to site administrator accounts within the same organization. The affected access-control checks scoped administrative ac...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-36549
🚨 EUVD-2026-36548
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: actual
🏢 Vendor: actualbudget
📅 Updated: 2026-06-12
📝 Actual is an open-source personal finance application. Prior to version 26.5.0, several endpoints are affected by a path traversal vulnerability. Version 26.5.0 fixes the issue.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-36548
🚨 EUVD-2026-36546
📊 Score: 6.3/10 (CVSS v3.1)
📦 Product: koel
🏢 Vendor: koel
📅 Updated: 2026-06-12
📝 Koel is a free, open-source music streaming solution. Prior to version 9.7.1, Koel contains a Server-Side Request Forgery (SSRF) vulnerability in the radio station creation endpoint (POST /api/radio/stations). The url field validation rules are declared without th...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-36546
🚨 EUVD-2026-36545
📊 Score: 7.7/10 (CVSS v3.1)
📦 Product: koel
🏢 Vendor: koel
📅 Updated: 2026-06-12
📝 Koel is a free, open-source music streaming solution. Prior to version 9.3.5, Koel validates the podcast feed URL via the SafeUrl rule (DNS resolution + public IP check), but the individual episode <enclosure url="..."> values extracted from the RSS XML are stored...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-36545
🚨 EUVD-2026-36544
📊 Score: 8.7/10 (CVSS v3.1)
📦 Product: agenticmail
🏢 Vendor: agenticmail
📅 Updated: 2026-06-12
📝 AgenticMail gives AI agents real email addresses and phone numbers. Prior to version 0.9.27, @agenticmail/mcp exposes a Streamable HTTP transport when started with --http or MCP_HTTP=1. In that mode, the /mcp endpoint accepts requests without any HTT...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-36544
🚨 EUVD-2026-36543
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: actual
🏢 Vendor: actualbudget
📅 Updated: 2026-06-12
📝 Actual is a local-first personal finance tool. The `POST /openid/config` endpoint in Actual Budget's sync-server versions <= 26.4.0 exposes the full OpenID Connect configuration—including the OAuth2 `client_secret`—to any caller who knows the bootstrap p...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-36543
Ready for the trails? Strava just dropped a massive hiking update
Strava's new update focuses on upgrading your next hike.
https://www.androidauthority.com/strava-new-hiking-features-3677280/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
#chrome extension Yoda Vs Pikachu Battle Li seems malicious. Its #cybersecurity badness score is 98/100!
```json
{"id": "kmmdmkjgkonecmjmgffhkompeccbocak", "score": 98, "platform": "chrome", "name": "Yoda Vs Pikachu Battle Li"}
```
#chrome extension Ciao seems malicious. Its #cybersecurity badness score is 87/100!
```json
{"id": "icodfpiopeekhmcjohmglciaipnlobmi", "score": 87, "platform": "chrome", "name": "Ciao"}
```
#chrome extension Bmw I7 Neon Red Cyberpunk seems malicious. Its #cybersecurity badness score is 98/100!
```json
{"id": "jonfhhejejpomjihccjdknlpfjjggohd", "score": 98, "platform": "chrome", "name": "Bmw I7 Neon Red Cyberpunk"}
```
Get 32GB of DDR5 RAM for only $255 in this 2-item combo from Newegg — just $514.99 gets you Corsair Vengeance RGB RAM and a Gigab…
Newegg slashes ~$185 off this 2-item combo, dropping the RAM to an affordable $255 - just $514.99 gets you a solid Gigabyte X870 motherboards, and 32GB of RAM in this incredible Newegg combo deal.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
Possible Phishing 🎣
on: ⚠️hxxps[:]//bcuyee-epxrss0653-7ehf[.]weebly[.]com/
🧬 Analysis at: https://urldna.io/scan/6a2c3b193b77500008275f5e
#cybersecurity #phishing #infosec #urldna #scam #infosec
Xbox will pay five times more for memory and storage in 2027 than it did two years ago — CEO Asha Sharma admits there's an unsustainable hardware gap that 'cannot continue'
The next-gen Xbox Helix is looking in trouble due to surging memory and storage costs that are forcing even a giant like Microsoft to bend down.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
🚨 EUVD-2026-36435
📊 Score: 7.5/10 (CVSS v3.1)
📦 Product: netty
🏢 Vendor: netty
📅 Updated: 2026-06-12
📝 Netty is a network application framework for development of protocol servers and clients. NoQuicTokenHandler is the tokenHandler used when the application does not set one. Prior to version 4.2.15.Final, its writeToken() returns false (server will not send Retry...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-36435
🚨 EUVD-2026-36432
📊 Score: 7.5/10 (CVSS v3.1)
📦 Product: netty, netty
🏢 Vendor: netty
📅 Updated: 2026-06-12
📝 Netty is a network application framework for development of protocol servers and clients. In netty-codec-haproxy prior to versions 4.1.135.Final and 4.2.15.Final, when decoding a PP2_TYPE_SSL TLV, HAProxyMessage.readNextTLV() first calls `header.retainedS...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-36432
🟠 CVE-2026-50085 - High (8.6)
The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's HiveMQ broker without authentication. This is an instance of "CWE-306: Missing Authentication for Critical Function" and has an...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-50085/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🔴 CVE-2026-50086 - Critical (10)
The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing key without authentication. This is an instance of "CWE-306: Missing Authentication for Critical Function" and "CWE-327: Use of a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-50086/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Malware developers added nuclear and biological weapons text to to their spyware
https://twitter.com/jsrailton/status/2064661778978533571
#HackerNews #malware #cybersecurity #spyware #threats #hacking #news
🟠 CVE-2026-50087 - High (8.2)
The Aqara IAM/SSO gateway (gw-builder.aqara.com) exhibits a cross-origin request sharing vulnerability, which is an instance of "CWE-942: Permissive Cross-domain Policy with Untrusted Domains," and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-50087/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
👾 So, some *evil geniuses* decided to hide their #malware behind a nuclear apocalypse script just to dodge AI scans. 🤖🚫 Because nothing says "don't look here" like invoking world-ending doom. But hey, at least it's an efficient way to give AI a panic attack. 😅🍿
https://twitter.com/jsrailton/status/2064661778978533571 #evilgenius #AIhacks #nuclearapocalypse #cybersecurity #panicattack #HackerNews #ngated
A trillion dollars is a stupid amount of money
Elon Musk is now officially the world's first trillionaire. That is a colossal amount of wealth (and by proxy, power) for one individual to have. Its scale - a thousand times more than a billion - is difficult to fathom…
https://www.theverge.com/tech/948917/elon-musk-trillionaire-how-much-visualization
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
🚨New ransom group blog posts!🚨
Group name: dragonforce
Post title: Cheoy Lee Shipyards
Info: https://cti.fyi/groups/dragonforce.html
Group name: dragonforce
Post title: Al Ishrak Contracting
Info: https://cti.fyi/groups/dragonforce.html
#ransomware #cti #threatintelligence #cybersecurity #infosec
🚨New ransom group blog posts!🚨
Group name: dragonforce
Post title: Cheoy Lee Shipyards
Info: https://cti.fyi/groups/dragonforce.html
Group name: dragonforce
Post title: Al Ishrak Contracting
Info: https://cti.fyi/groups/dragonforce.html
#ransomware #cti #threatintelligence #cybersecurity #infosec
New by me: Security Signal Weekly: June 6-12, 2026
https://www.kylereddoch.me/blog/security-signal-weekly-june-6-12-2026/
Siri is good now??
You'd be forgiven for thinking this day would never come. Siri has spent a decade and half somewhere between "sort of useful at a few things" and "utterly disastrous, why did I even try, can it honestly not even set a t…
https://www.theverge.com/podcast/949079/siri-ai-good-vergecast
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Possible Phishing 🎣
on: ⚠️hxxps[:]//njitfinancialaid[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a2bd8af3b77500008275281
#cybersecurity #phishing #infosec #urldna #scam #infosec
Google TV’s World Cup hub brings live matches, highlights, and analysis together
Google TV just turned its Sports page into a World Cup command center.
https://www.androidauthority.com/google-tv-world-cup-3677238/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
The 12GB Retroid Pocket 6 is back, at the cost of storage
This model has less storage than the original 12GB variant, though.
https://www.androidauthority.com/retroid-pocket-6-12gb-of-ram-back-3677137/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Summer Upgrade Week
The sun is out, the sky is clear. It’s time to get outside and disconnect — from work, at least. This summer, we’re looking at all the ways to upgrade our free time indoors and out, from smart lights for the backyard to…
https://www.theverge.com/tech/942658/summer-upgrade-week-2026
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
🚨 EUVD-2026-36411
📊 Score: 7.0/10 (CVSS v3.1)
📦 Product: UC-1200A Series
🏢 Vendor: Moxa
📅 Updated: 2026-06-12
📝 A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial computers and controllers. This vulnerability represents an incomplete remediation of CVE-2026-0714. The firmware introduced TPM2 pa...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-36411
🚨 EUVD-2026-36410
📊 Score: 9.3/10 (CVSS v3.1)
📦 Product: iRM-TSi410X
🏢 Vendor: IEI Integration Corp
📅 Updated: 2026-06-12
📝 The
iRM-IEI Remote Management developed by IEI Integration Corp has a Hardcoded Credentials vulnerability, allowing unauthenticated remote attackers to exploit hard-coded credentials to gain administrative privileges on the database.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-36410
🚨 EUVD-2026-36409
📊 Score: 7.9/10 (CVSS v3.1)
📦 Product: iRM-TSi410X
🏢 Vendor: IEI Integration Corp
📅 Updated: 2026-06-12
📝 The iRM-IEI Remote Management developed by IEI Integration Corp has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to exploit a specific functionality to obtain partial system configuration information.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-36409
Possible Phishing 🎣
on: ⚠️hxxps[:]//mxx8855[.]net/
🧬 Analysis at: https://urldna.io/scan/6a2b927f3b77500008274a96
#cybersecurity #phishing #infosec #urldna #scam #infosec
Marvell: 55 CVEs, 96% unpatched. 4 critical, avg CVSS 7.78. Trust Score: D. Hardware security gaps can’t be ignored. #Marvell #cybersecurity #infosec
BLUERABBIT Malware Targets Windows Systems Through Ransomware and Disk Wiping Operations
Pulse ID: 6a2bfc6dbd90a378348e85f2
Pulse Link: https://otx.alienvault.com/pulse/6a2bfc6dbd90a378348e85f2
Pulse Author: cryptocti
Created: 2026-06-12 12:32:45
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RansomWare #Windows #bot #cryptocti