voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]TechWire ⚡ » 🤖 🌐
@techwire@social.gamefan.net

Nearly a million passports and photo IDs were left unprotected on the public internet

Typing a few letters and numbers into my web browser, I find myself gaping at the identity documents of complete strangers. The passport of a young woman from Germany. The passport of a man from Spain with glasses resti…

theverge.com/tech/947157/passp

[The Verge]

    [?]TheHackerWire » 🤖 🌐
    @thehackerwire@mastodon.social

    🟠 CVE-2026-49218 - High (7.5)

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing check in the DCM decoder could result in an image with invalid dimensions and that could cause crash...

    🔗 thehackerwire.com/vulnerabilit

    CVE Alert: CVE-2026-49218

    Alt...CVE Alert: CVE-2026-49218

      [?]EUVD Bot » 🤖 🌐
      @EUVD_Bot@mastodon.social

      🚨 EUVD-2026-36165

      📊 Score: 9.6/10 (CVSS v3.1)
      📦 Product: boxlite
      🏢 Vendor: boxlite-ai
      📅 Updated: 2026-06-10

      📝 Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior to version 0.9.0, Boxlite allows users to specify the OCI image used by containers in the sand...

      🔗 euvd.enisa.europa.eu/vulnerabi

        [?]urlDNA.io :verified: » 🤖 🌐
        @urldna@infosec.exchange

        Possible Phishing 🎣
        on: ⚠️hxxps[:]//shentelcommunicatiionsserverupgrade[.]weebly[.]com
        🧬 Analysis at: urldna.io/scan/6a29fa9c3b77500

          [?]TechWire ⚡ » 🤖 🌐
          @techwire@social.gamefan.net

          Apple’s new Siri AI knows when to shut up

          Apple's new Siri AI is finally here, and so far, it seems like it works. I have access and have been messing around with it, and my biggest impression so far is that Siri AI is quite curt - which I mean as a compliment.…

          theverge.com/tech/948155/apple

          [The Verge]

            [?]TheHackerWire » 🤖 🌐
            @thehackerwire@mastodon.social

            🔴 CVE-2026-46695 - Critical (10)

            Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior to version 0.9.0, Boxlite does not restrict the kernel capabilities available inside t...

            🔗 thehackerwire.com/vulnerabilit

            CVE Alert: CVE-2026-46695

            Alt...CVE Alert: CVE-2026-46695

              [?]TheHackerWire » 🤖 🌐
              @thehackerwire@mastodon.social

              🔴 CVE-2026-46703 - Critical (9.6)

              Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior to version 0.9.0, Boxlite allows users to specify the OCI image used by containers in ...

              🔗 thehackerwire.com/vulnerabilit

              CVE Alert: CVE-2026-46703

              Alt...CVE Alert: CVE-2026-46703

                [?]TheHackerWire » 🤖 🌐
                @thehackerwire@mastodon.social

                🟠 CVE-2026-42305 - High (8.8)

                Dulwich is a pure-Python implementation of the Git file formats and protocols. Versions starting with 0.10.0 and prior to 1.2.5 have an arbitrary file write leading to remote code execution when cloning or checking out a malicious Git repository o...

                🔗 thehackerwire.com/vulnerabilit

                CVE Alert: CVE-2026-42305

                Alt...CVE Alert: CVE-2026-42305

                  [?]deafnews » 🤖 🌐
                  @deafnews@infosec.exchange

                  ASUS MyASUS: SYSTEM Privilege Escalation Disclosed After 98 Days, Patch Link Remains Circular deafnews.it/en/article/asus-my

                    [?]TechWire ⚡ » 🤖 🌐
                    @techwire@social.gamefan.net

                    Framework delays its first Laptop 13 Pro shipments by a month

                    The Framework Laptop 13 Pro is delayed. The new 13-inch Framework flagship was set to launch in June, but shipments from the first batch are now expected in July - and there's still a chance some shipments could slip to…

                    theverge.com/gadgets/948044/fr

                    [The Verge]

                      [?]Malicious Extension Bot » 🤖 🌐
                      @malicious_browser_bot@infosec.exchange

                      extension Ocean Floor seems malicious. Its badness score is 85/100!

                      ```json
                      {"id": "lflpoohnikdcjjphblgklcdepmdppodc", "score": 85, "platform": "chrome", "name": "Ocean Floor"}
                      ```

                        [?]Malicious Extension Bot » 🤖 🌐
                        @malicious_browser_bot@infosec.exchange

                        extension Mint Glacier – Clean Mini seems malicious. Its badness score is 100/100!

                        ```json
                        {"id": "gnmnagcjdnfkcccmegohnfmnieikhnon", "score": 100, "platform": "chrome", "name": "Mint Glacier \u2013 Clean Mini"}
                        ```

                          [?]Malicious Extension Bot » 🤖 🌐
                          @malicious_browser_bot@infosec.exchange

                          extension Orchid Bloom seems malicious. Its badness score is 86/100!

                          ```json
                          {"id": "ikbhljpedngpgfdbmekdbjcpfkdcloej", "score": 86, "platform": "chrome", "name": "Orchid Bloom"}
                          ```

                            [?]David Hollingworth [Sometimes Bond, sometimes Broughton] » 🌐
                            @David_Hollingworth@mastodon.social

                            2019 - the hacker, not the year - is at it again.

                            Not only have they compromised a whole mess of customer data of a WA publisher, but it looks like they were sending unauthorised emails while they were in the network.

                            Seems to be a regular part of their playbook, and even yours truly has gotten some attention from them. It's always odd to find a cyber criminal in your inbox...

                            cyberdaily.au/security/13728-e

                              [?]urlDNA.io :verified: » 🤖 🌐
                              @urldna@infosec.exchange

                              Possible Phishing 🎣
                              on: ⚠️hxxps[:]//135461223[.]site/no/405/9b9f2577-cd35-401b-82b9-3b393263e811/732538/x
                              🧬 Analysis at: urldna.io/scan/6a2959833b77500

                                [?]TechWire ⚡ » 🤖 🌐
                                @techwire@social.gamefan.net

                                Bluesky is getting ‘communities’

                                Bluesky will be getting "communities," which will function as smaller spaces where you can "go deeper and hang out with people who care about the same stuff" sometime this year, according to head of product Alex Benzer.…

                                theverge.com/tech/948215/blues

                                [The Verge]

                                  [?]The New Oil » 🤖 🌐
                                  @thenewoil@mastodon.thenewoil.org

                                  [?]EUVD Bot » 🤖 🌐
                                  @EUVD_Bot@mastodon.social

                                  🚨 EUVD-2026-36112

                                  📊 Score: 6.9/10 (CVSS v3.1)
                                  📦 Product: snappy
                                  🏢 Vendor: KnpLabs
                                  📅 Updated: 2026-06-10

                                  📝 Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.7.0, there is a SSRF and local file read vulnerability via the xsl-style-sheet option. This issue has been patched in version 1.7.0.

                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                    [?]EUVD Bot » 🤖 🌐
                                    @EUVD_Bot@mastodon.social

                                    🚨 EUVD-2026-36111

                                    📊 Score: 7.5/10 (CVSS v3.1)
                                    📦 Product: snappy
                                    🏢 Vendor: KnpLabs
                                    📅 Updated: 2026-06-10

                                    📝 Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.7.1, on POSIX, escapeshellarg(‘/usr/bin/wkhtmltopdf’) returns the literal string ‘/usr/bin/wkhtmltopdf’ with the single-quote characters inclu...

                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                      [?]EUVD Bot » 🤖 🌐
                                      @EUVD_Bot@mastodon.social

                                      🚨 EUVD-2026-36109

                                      📊 Score: 8.4/10 (CVSS v3.1)
                                      📦 Product: atril, atril
                                      🏢 Vendor: mate-desktop
                                      📅 Updated: 2026-06-10

                                      📝 Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execution as the ...

                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                        [?]urlDNA.io :verified: » 🤖 🌐
                                        @urldna@infosec.exchange

                                        Possible Phishing 🎣
                                        on: ⚠️hxxps[:]//1sh[.]co/e3c9dfb6#amVubnlAbG5wLmNvLnVr
                                        🧬 Analysis at: urldna.io/scan/6a296e073b77500

                                          [?]EUVD Bot » 🤖 🌐
                                          @EUVD_Bot@mastodon.social

                                          🚨 EUVD-2026-36110

                                          📊 Score: 8.8/10 (CVSS v3.1)
                                          📅 Updated: 2026-06-10

                                          📝 A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled...

                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                            [?]EUVD Bot » 🤖 🌐
                                            @EUVD_Bot@mastodon.social

                                            🚨 EUVD-2026-36108

                                            📊 Score: n/a
                                            📦 Product: Chrome
                                            🏢 Vendor: Google
                                            📅 Updated: 2026-06-10

                                            📝 Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit type confusion via a crafted HTML page. (Chromium security severity: High)

                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                              [?]EUVD Bot » 🤖 🌐
                                              @EUVD_Bot@mastodon.social

                                              🚨 EUVD-2026-36106

                                              📊 Score: 6.5/10 (CVSS v3.1)
                                              📦 Product: Metrics::Any::Adapter::SignalFx
                                              🏢 Vendor: PEVANS
                                              📅 Updated: 2026-06-10

                                              📝 Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric injections.

                                              The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics,separated by newlines, to be sent per packet.

                                              Metr...

                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                [?]EUVD Bot » 🤖 🌐
                                                @EUVD_Bot@mastodon.social

                                                🚨 EUVD-2026-36107

                                                📊 Score: 5.4/10 (CVSS v3.1)
                                                📦 Product: Symantec Endpoint Protection CleanWipe Removal Tool
                                                🏢 Vendor: Broadcom
                                                📅 Updated: 2026-06-10

                                                📝 CleanWipe Removal Tool (macOS), prior to 16.0.0.65, may be susceptible to an Local Privilege Escalation vulnerability, which is a type of issue whereby an attacker with limited privilege access on an affected syst...

                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                  [?]EUVD Bot » 🤖 🌐
                                                  @EUVD_Bot@mastodon.social

                                                  🚨 EUVD-2026-36103

                                                  📊 Score: 6.9/10 (CVSS v3.1)
                                                  📦 Product: s2n-quic
                                                  🏢 Vendor: aws
                                                  📅 Updated: 2026-06-10

                                                  📝 Unbounded memory allocation in the CRYPTO frame reassembler in s2n-quic before 1.8.2 may allow an unauthenticated remote actor to cause a denial of service (degraded availability) by sending crafted QUIC Initial packets.

                                                  To remediate this issue, users should...

                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                    [?]EUVD Bot » 🤖 🌐
                                                    @EUVD_Bot@mastodon.social

                                                    🚨 EUVD-2026-36105

                                                    📊 Score: n/a
                                                    📦 Product: Metrics::Any::Adapter::DogStatsd
                                                    🏢 Vendor: PEVANS
                                                    📅 Updated: 2026-06-10

                                                    📝 Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections.

                                                    The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics,separated by newlines, to be sent per packet.

                                                    Metrics::Any::Ada...

                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                      [?]EUVD Bot » 🤖 🌐
                                                      @EUVD_Bot@mastodon.social

                                                      🚨 EUVD-2026-36104

                                                      📊 Score: n/a
                                                      📦 Product: Metrics::Any::Adapter::Statsd
                                                      🏢 Vendor: PEVANS
                                                      📅 Updated: 2026-06-10

                                                      📝 Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric injections.

                                                      The statsd protocol (and extensions) allow mutiple metrics,separated by newlines, to be sent per packet.

                                                      The send method does not validate the con...

                                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                                        [?]The New Oil » 🤖 🌐
                                                        @thenewoil@mastodon.thenewoil.org

                                                        [?]TechWire ⚡ » 🤖 🌐
                                                        @techwire@social.gamefan.net

                                                        Android 17 QPR1 Beta 4 is ready to share its latest bug fixes

                                                        Hopefully these new builds are almost done sorting out glitches.

                                                        androidauthority.com/android-1

                                                        [Android Authority]

                                                          [?]/G|T|R|O|N|I|X\ :python: :emacs: :nix: :linux: » 🌐
                                                          @gtronix@infosec.exchange

                                                          "CISA Tells US Agencies to Fix Security Bugs in as Little as 3 Days Thanks to AI Threats"

                                                          "“Defenders cannot afford to take weeks to patch,” one Cybersecurity and Infrastructure Security Agency official warned on Wednesday."

                                                          wired.com/story/cisa-ai-vulner

                                                            [?]Hackread.com » 🌐
                                                            @Hackread@mstdn.social

                                                            📣🚫 The FBI has seized 13 fake consulting websites that officials say targeted U.S. clearance holders with paid research work designed to obtain sensitive government information.

                                                            Read: hackread.com/fbi-seizes-china-

                                                              [?]TechWire ⚡ » 🤖 🌐
                                                              @techwire@social.gamefan.net

                                                              Lenovo’s rugged ThinkTab X11 is finally available in the US

                                                              Looking for a durable tablet? Lenovo's new ThinkTab X11 has made it to the US.

                                                              androidauthority.com/lenovo-th

                                                              [Android Authority]

                                                                [?]urlDNA.io :verified: » 🤖 🌐
                                                                @urldna@infosec.exchange

                                                                Possible Phishing 🎣
                                                                on: ⚠️hxxp[:]//netflix-clone-rust-five[.]vercel[.]app/
                                                                🧬 Analysis at: urldna.io/scan/6a2959923b77500

                                                                  [?]TechWire ⚡ » 🤖 🌐
                                                                  @techwire@social.gamefan.net

                                                                  You can just tell the Instagram algorithm what you want now

                                                                  Instagram is going to let you tweak what its algorithm shows you on your main feed. With the Your Algorithm feature, "you can now see the topics we think you're interested in, and change them, across all the major parts…

                                                                  theverge.com/tech/947898/meta-

                                                                  [The Verge]

                                                                    [?]EUVD Bot » 🤖 🌐
                                                                    @EUVD_Bot@mastodon.social

                                                                    🚨 EUVD-2026-36051

                                                                    📊 Score: 6.9/10 (CVSS v3.1)
                                                                    📦 Product: bsimvis
                                                                    🏢 Vendor: MISP
                                                                    📅 Updated: 2026-06-10

                                                                    📝 A stored cross-site scripting vulnerability existed in MISP BSimVis tag rendering code. Several client-side rendering paths interpolated tag names, collection names, entity identifiers, cluster names, and tag metadata directly into HTML, HTML attributes, inline...

                                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                                      [?]BeyondMachines :verified: » 🤖 🌐
                                                                      @beyondmachines1@infosec.exchange

                                                                      Miasma Worm Compromises 73 Microsoft GitHub Repositories in Supply Chain Attack

                                                                      Microsoft disabled 73 GitHub repositories after the Miasma worm compromised developer credentials to inject password-stealing malware into Azure and AI development tools. The supply chain attack exploited OIDC tokens to bypass security scanners and harvest cloud identities and CI/CD secrets.

                                                                      **If you build or deploy software using Azure Functions, GitHub Actions, or the Durable Task tools, stop using floating version tags like @v1 and switch to a safe deployment method check the as Azure CLI, Azure DevOps, or Zip Deploy for possible compromise and loading of the libraries in the affected period. If you did load them, rotate secrets immediately.**

                                                                      beyondmachines.net/event_detai

                                                                        [?]TechWire ⚡ » 🤖 🌐
                                                                        @techwire@social.gamefan.net

                                                                        The AirPods Pro 3 are $179, their best-ever price

                                                                        AirPods Pro 3 | Photo by Amelia Holowaty Krales / The Verge Ahead of Prime Day, the Apple AirPods 3 wireless earbuds have hit their lowest price so far. Originally $249 (though commonly selling somewhere between $200 an…

                                                                        theverge.com/gadgets/947719/ai

                                                                        [The Verge]

                                                                          [?]CyberNetsecIO » 🌐
                                                                          @netsecio@mastodon.social

                                                                          📰 Microsoft's Record-Breaking June Patch Tuesday: Over 200 Flaws and Three Zero-Days Patched

                                                                          🚨 Microsoft's June 2026 Patch Tuesday is a record-breaker, fixing over 200 flaws, 33 critical RCEs, and 3 zero-days. A potentially wormable kernel bug (CVE-2026-45657) requires immediate patching. ⚠️

                                                                          🌐 cyber[.]netsecops[.]io

                                                                          🔗 cyber.netsecops.io/articles/mi

                                                                            [?]CyberNetsecIO » 🌐
                                                                            @netsecio@mastodon.social

                                                                            📰 Energy Sector in Crosshairs: 66% of APT Campaigns Target Utilities, Report Finds

                                                                            🚨 New report: Global energy sector is the top target for nation-state hackers. 66% of all APT campaigns in the last 3 months hit energy & utilities, with actors from China, Russia & North Korea leading the charge. ⚡️

                                                                            🌐 cyber[.]netsecops[.]io

                                                                            🔗 cyber.netsecops.io/articles/en

                                                                              Back to top - More...