voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]urlDNA.io :verified: » 🤖 🌐
@urldna@infosec.exchange

Possible Phishing 🎣
on: ⚠️hxxps[:]//api[.]19966991[.]xyz/
🧬 Analysis at: urldna.io/scan/6a2aa3673b77500

    [?]EUVD Bot » 🤖 🌐
    @EUVD_Bot@mastodon.social

    🚨 EUVD-2026-36304

    📊 Score: 8.5/10 (CVSS v3.1)
    📦 Product: Idira Endpoint Privilege Manager
    🏢 Vendor: CyberArk Software, a Palo Alto Networks Company
    📅 Updated: 2026-06-11

    📝 Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in secu...

    🔗 euvd.enisa.europa.eu/vulnerabi

      [?]EUVD Bot » 🤖 🌐
      @EUVD_Bot@mastodon.social

      🚨 EUVD-2026-36303

      📊 Score: 8.1/10 (CVSS v3.1)
      📦 Product: SolidInvoice
      🏢 Vendor: SolidInvoice
      📅 Updated: 2026-06-11

      📝 SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, the company logo upload feature accepts any file type without validation. An authenticated administrator can upload an SVG file containing embedded JavaScript. This script ...

      🔗 euvd.enisa.europa.eu/vulnerabi

        [?]EUVD Bot » 🤖 🌐
        @EUVD_Bot@mastodon.social

        🚨 EUVD-2026-36302

        📊 Score: 6.0/10 (CVSS v3.1)
        📦 Product: CodexBar
        🏢 Vendor: steipete
        📅 Updated: 2026-06-11

        📝 CodexBar before 0.33.0 contains a credential forwarding vulnerability that allows network-adjacent attackers to intercept sensitive credentials by issuing cross-origin or HTTP-downgrade redirects to the shared ProviderHTTPClient transport. Attackers can re...

        🔗 euvd.enisa.europa.eu/vulnerabi

          [?]EUVD Bot » 🤖 🌐
          @EUVD_Bot@mastodon.social

          🚨 EUVD-2026-36301

          📊 Score: 8.1/10 (CVSS v3.1)
          📦 Product: SolidInvoice
          🏢 Vendor: SolidInvoice
          📅 Updated: 2026-06-11

          📝 SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authenticate all REST API requests are stored as plaintext strings in the api_tokens database table. Any attacker who obtains read access to the database...

          🔗 euvd.enisa.europa.eu/vulnerabi

            [?]TechWire ⚡ » 🤖 🌐
            @techwire@social.gamefan.net

            The best Sam's Club deals to compete with Prime Day (including half off membership)

            You may want to check Sam's Club first before filling your Amazon cart this Prime Day.

            zdnet.com/article/best-early-a

            [ZDNet]

              [?]ABC Feeds » 🤖 🌐
              @abcfeeds@rssfeed.media

              Amex ordered to compensate man whose ex accessed his data
              By Charlotte Grieve

              Australia's privacy commissioner has threatened a complainant with legal action to prevent the full disclosure of the findings of a long-running investigation into American Express's information security, which found widespread technology failures.

              abc.net.au/news/2026-06-12/pri

                [?]TechWire ⚡ » 🤖 🌐
                @techwire@social.gamefan.net

                Best Buy has better gaming deals right now than Amazon's early Prime Day sale

                Disappointed in Amazon's selection of gaming deals ahead of the Prime Day 2026 sale? Best Buy has you covered.

                zdnet.com/article/best-buy-gam

                [ZDNet]

                  [?]urlDNA.io :verified: » 🤖 🌐
                  @urldna@infosec.exchange

                  Possible Phishing 🎣
                  on: ⚠️hxxps[:]//blog[.]porta-nuova[.]ch/wp-login[.]php?redirect_to=hxxps%3A%2F%2Fblog[.]porta-nuova[.]ch%2Fwp-admin%2Fcomment[.]php%3Faction%3Dspam%26c%3D102&reauth=1
                  🧬 Analysis at: urldna.io/scan/6a2ae99b3b77500

                    [?]TechWire ⚡ » 🤖 🌐
                    @techwire@social.gamefan.net

                    Have Pokémon Go players been unwittingly training military combat drones?

                    Report paints an uncomfortable picture of how player-submitted data may end up being used.

                    androidauthority.com/pokemon-g

                    [Android Authority]

                      [?]The New Oil » 🤖 🌐
                      @thenewoil@mastodon.thenewoil.org

                      [?]TheHackerWire » 🤖 🌐
                      @thehackerwire@mastodon.social

                      🟠 CVE-2026-53777 - High (8.1)

                      Perry before 0.5.1159 contains a path traversal vulnerability that allows a malicious build server to write arbitrary content to any location writable by the running process by supplying unsanitized path components in the artifact_name field of Ar...

                      🔗 thehackerwire.com/vulnerabilit

                      CVE Alert: CVE-2026-53777

                      Alt...CVE Alert: CVE-2026-53777

                        [?]TechWire ⚡ » 🤖 🌐
                        @techwire@social.gamefan.net

                        Waymo introduces $30-a-month premium tier for riders who want faster pickups

                        Uber One, meet Waymo Premier. The robotaxi operator announced a new $29.99-a-month premium tier for riders who want a more elevated and exclusive autonomous experience. The invite-only membership service is aimed at Way…

                        theverge.com/transportation/94

                        [The Verge]

                          [?]TheHackerWire » 🤖 🌐
                          @thehackerwire@mastodon.social

                          🔴 CVE-2026-11839 - Critical (9.9)

                          Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows Upload a Web Shell to a Web Server.

                          This issue affects Rotaban: from V2026.06.002 before V2026.06.003.

                          🔗 thehackerwire.com/vulnerabilit

                          CVE Alert: CVE-2026-11839

                          Alt...CVE Alert: CVE-2026-11839

                            [?]TheHackerWire » 🤖 🌐
                            @thehackerwire@mastodon.social

                            🔴 CVE-2026-38581 - Critical (9.8)

                            SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attackers to execute arbitrary SQL commands via the idFormMain parameter to /substudy/ezform.php (line 14) and the id parameter (line 49). The parameters a...

                            🔗 thehackerwire.com/vulnerabilit

                            CVE Alert: CVE-2026-38581

                            Alt...CVE Alert: CVE-2026-38581

                              [?]TheHackerWire » 🤖 🌐
                              @thehackerwire@mastodon.social

                              🟠 CVE-2026-6552 - High (8.7)

                              GitLab has remediated an issue in GitLab EE affecting all versions from 15.5 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with group Owner role to take over ano...

                              🔗 thehackerwire.com/vulnerabilit

                              CVE Alert: CVE-2026-6552

                              Alt...CVE Alert: CVE-2026-6552

                                [?]BeyondMachines :verified: » 🤖 🌐
                                @beyondmachines1@infosec.exchange

                                Langflow AI Platform Targeted by Active Remote Code Execution Exploits

                                Attackers are actively exploiting a high-severity path traversal vulnerability (CVE-2026-5027) in the Langflow AI platform to achieve unauthenticated remote code execution.

                                **If you're running Langflow, make sure it's isolated from the public internet. Then update ASAP to version 1.10.0 and disable the default auto-login setting. Treat these platforms as high-value targets—they hold the keys to your proprietary data and LLM integrations.**

                                beyondmachines.net/event_detai

                                  [?]deafnews » 🤖 🌐
                                  @deafnews@infosec.exchange

                                  Europol and DOJ Dismantle AudiA6: A Critical Hub for Ransomware Money Laundering Smashed deafnews.it/en/article/europol

                                    [?]TechWire ⚡ » 🤖 🌐
                                    @techwire@social.gamefan.net

                                    A warrantless wiretap law is about to expire — but surveillance networks aren’t actually ‘going dark’

                                    Congress has failed to pass a three-week extension of Section 702 of the Foreign Intelligence Surveillance Act (FISA), with the House voting 218-198 against reauthorizing the controversial warrantless wiretapping author…

                                    theverge.com/tech/948451/fisa-

                                    [The Verge]

                                      [?]Malicious Extension Bot » 🤖 🌐
                                      @malicious_browser_bot@infosec.exchange

                                      extension Wellshared Ai seems malicious. Its badness score is 85/100!

                                      ```json
                                      {"id": "ajeffabgdodbbdngakbpafbggnoegdjd", "score": 85, "platform": "chrome", "name": "Wellshared Ai"}
                                      ```

                                        [?]Ben Schorr :donor: » 🌐
                                        @bschorr@infosec.exchange

                                        Your irregular reminder to get your Microsoft updates installed. Especially important this month.

                                        Microsoft patches record 206 Windows bugs in June update - and 3 are zero days zdnet.com/article/microsofts-j

                                          [?]urlDNA.io :verified: » 🤖 🌐
                                          @urldna@infosec.exchange

                                          Possible Phishing 🎣
                                          on: ⚠️hxxps[:]//admin-index-mail-dex[.]weebly[.]com/
                                          🧬 Analysis at: urldna.io/scan/6a2abf783b77500

                                            [?]The New Oil » 🤖 🌐
                                            @thenewoil@mastodon.thenewoil.org

                                            [?]TechWire ⚡ » 🤖 🌐
                                            @techwire@social.gamefan.net

                                            Cash App’s new mobile network doesn’t sound like a very good deal

                                            Cash App Mobile's service is pricier than other popular MVNOs.

                                            androidauthority.com/cash-app-

                                            [Android Authority]

                                              [?]WIRED - The Latest in Technology, Science, Culture and Business [Unofficial] » 🌐
                                              @wired.com@web.brid.gy

                                              Signal Alums Reveal ‘Encrypted Spaces,’ a System for Making Private Collaboration Apps

                                              The new open-source project could serve as the basis for a future of apps with features as complex as Slack, Discord, or Google Docs—but with added protection against surveillance.

                                              Signal Alums Reveal ‘Encrypted Spaces,’ a System for Making Private Collaboration Apps

                                              Alt...Signal Alums Reveal ‘Encrypted Spaces,’ a System for Making Private Collaboration Apps

                                              [?]TechWire ⚡ » 🤖 🌐
                                              @techwire@social.gamefan.net

                                              I used the Motorola Edge (2026) and Pixel 10a, and I think Google should be worried

                                              A proper mid-range showdown between two solid phones.

                                              androidauthority.com/motorola-

                                              [Android Authority]

                                                [?]Daniel Marsh » 🤖 🌐
                                                @danielmarsh@social.thepixelspulse.com

                                                Langflow's CVE-2026-5027, a path traversal flaw, is now actively exploited, enabling remote code execution. This incident follows a pattern of critical vulnerabilities, including those linked to the Iranian threat group MuddyWater, raising serious questions about the project's secure development lifecycle.

                                                tpp.blog/1dx8b10

                                                🤖 This post was AI-generated.

                                                  [?]Hackread.com » 🌐
                                                  @Hackread@mstdn.social

                                                  New findings show hackers are using fake Claude Code guides and AI-themed PDFs to spread AsyncRAT malware on Windows devices.

                                                  Read: hackread.com/hackers-fake-clau

                                                    [?]Linuxiarze » 🌐
                                                    @Linuxiarze@mastodon.social

                                                    Dobrze naoliwiona machina oszustw. Tak cyberprzestępcy wykorzystują Mistrzostwa Świata FIFA 2026.Już dziś miliony kibiców na całym świecie zasiądą przed telewizorami, żeby śledzić transmisję meczów i dzielić się... linuxiarze.pl/dobrze-naoliwion

                                                    mundial 2026

                                                    Alt...mundial 2026

                                                      [?]Linuxiarze » 🌐
                                                      @Linuxiarze@fe.disroot.org

                                                      Dobrze naoliwiona machina oszustw. Tak cyberprzestępcy wykorzystują Mistrzostwa Świata FIFA 2026.Już dziś miliony kibiców na całym świecie zasiądą przed telewizorami, żeby śledzić transmisję meczów i dzielić się... https://linuxiarze.pl/dobrze-naoliwiona-machina-oszustw/ #cybersecurity #cyberattack #mundial2026

                                                        [?]pavroo » 🌐
                                                        @pavroo@universeodon.com

                                                        Dobrze naoliwiona machina oszustw. Tak cyberprzestępcy wykorzystują Mistrzostwa Świata FIFA 2026.Już dziś miliony kibiców na całym świecie zasiądą przed telewizorami, żeby śledzić transmisję meczów i dzielić się... linuxiarze.pl/dobrze-naoliwion

                                                        mundial 2026

                                                        Alt...mundial 2026

                                                          [?]urlDNA.io :verified: » 🤖 🌐
                                                          @urldna@infosec.exchange

                                                          Possible Phishing 🎣
                                                          on: ⚠️hxxps[:]//rewsdhjkkjfd[.]weebly[.]com
                                                          🧬 Analysis at: urldna.io/scan/6a2a3a893b77500

                                                            Back to top - More...