voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]EUVD Bot » 🤖 🌐
@EUVD_Bot@mastodon.social

🚨 EUVD-2026-36103

📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: s2n-quic
🏢 Vendor: aws
📅 Updated: 2026-06-10

📝 Unbounded memory allocation in the CRYPTO frame reassembler in s2n-quic before 1.8.2 may allow an unauthenticated remote actor to cause a denial of service (degraded availability) by sending crafted QUIC Initial packets.

To remediate this issue, users should...

🔗 euvd.enisa.europa.eu/vulnerabi

    [?]EUVD Bot » 🤖 🌐
    @EUVD_Bot@mastodon.social

    🚨 EUVD-2026-36105

    📊 Score: n/a
    📦 Product: Metrics::Any::Adapter::DogStatsd
    🏢 Vendor: PEVANS
    📅 Updated: 2026-06-10

    📝 Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections.

    The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics,separated by newlines, to be sent per packet.

    Metrics::Any::Ada...

    🔗 euvd.enisa.europa.eu/vulnerabi

      [?]EUVD Bot » 🤖 🌐
      @EUVD_Bot@mastodon.social

      🚨 EUVD-2026-36104

      📊 Score: n/a
      📦 Product: Metrics::Any::Adapter::Statsd
      🏢 Vendor: PEVANS
      📅 Updated: 2026-06-10

      📝 Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric injections.

      The statsd protocol (and extensions) allow mutiple metrics,separated by newlines, to be sent per packet.

      The send method does not validate the con...

      🔗 euvd.enisa.europa.eu/vulnerabi

        [?]The New Oil » 🤖 🌐
        @thenewoil@mastodon.thenewoil.org

        [?]TechWire ⚡ » 🤖 🌐
        @techwire@social.gamefan.net

        Android 17 QPR1 Beta 4 is ready to share its latest bug fixes

        Hopefully these new builds are almost done sorting out glitches.

        androidauthority.com/android-1

        [Android Authority]

          [?]/G|T|R|O|N|I|X\ :python: :emacs: :nix: :linux: » 🌐
          @gtronix@infosec.exchange

          "CISA Tells US Agencies to Fix Security Bugs in as Little as 3 Days Thanks to AI Threats"

          "“Defenders cannot afford to take weeks to patch,” one Cybersecurity and Infrastructure Security Agency official warned on Wednesday."

          wired.com/story/cisa-ai-vulner

            [?]Hackread.com » 🌐
            @Hackread@mstdn.social

            📣🚫 The FBI has seized 13 fake consulting websites that officials say targeted U.S. clearance holders with paid research work designed to obtain sensitive government information.

            Read: hackread.com/fbi-seizes-china-

              [?]TechWire ⚡ » 🤖 🌐
              @techwire@social.gamefan.net

              Lenovo’s rugged ThinkTab X11 is finally available in the US

              Looking for a durable tablet? Lenovo's new ThinkTab X11 has made it to the US.

              androidauthority.com/lenovo-th

              [Android Authority]

                [?]urlDNA.io :verified: » 🤖 🌐
                @urldna@infosec.exchange

                Possible Phishing 🎣
                on: ⚠️hxxp[:]//netflix-clone-rust-five[.]vercel[.]app/
                🧬 Analysis at: urldna.io/scan/6a2959923b77500

                  [?]TechWire ⚡ » 🤖 🌐
                  @techwire@social.gamefan.net

                  You can just tell the Instagram algorithm what you want now

                  Instagram is going to let you tweak what its algorithm shows you on your main feed. With the Your Algorithm feature, "you can now see the topics we think you're interested in, and change them, across all the major parts…

                  theverge.com/tech/947898/meta-

                  [The Verge]

                    [?]EUVD Bot » 🤖 🌐
                    @EUVD_Bot@mastodon.social

                    🚨 EUVD-2026-36051

                    📊 Score: 6.9/10 (CVSS v3.1)
                    📦 Product: bsimvis
                    🏢 Vendor: MISP
                    📅 Updated: 2026-06-10

                    📝 A stored cross-site scripting vulnerability existed in MISP BSimVis tag rendering code. Several client-side rendering paths interpolated tag names, collection names, entity identifiers, cluster names, and tag metadata directly into HTML, HTML attributes, inline...

                    🔗 euvd.enisa.europa.eu/vulnerabi

                      [?]BeyondMachines :verified: » 🤖 🌐
                      @beyondmachines1@infosec.exchange

                      Miasma Worm Compromises 73 Microsoft GitHub Repositories in Supply Chain Attack

                      Microsoft disabled 73 GitHub repositories after the Miasma worm compromised developer credentials to inject password-stealing malware into Azure and AI development tools. The supply chain attack exploited OIDC tokens to bypass security scanners and harvest cloud identities and CI/CD secrets.

                      **If you build or deploy software using Azure Functions, GitHub Actions, or the Durable Task tools, stop using floating version tags like @v1 and switch to a safe deployment method check the as Azure CLI, Azure DevOps, or Zip Deploy for possible compromise and loading of the libraries in the affected period. If you did load them, rotate secrets immediately.**

                      beyondmachines.net/event_detai

                        [?]TechWire ⚡ » 🤖 🌐
                        @techwire@social.gamefan.net

                        The AirPods Pro 3 are $179, their best-ever price

                        AirPods Pro 3 | Photo by Amelia Holowaty Krales / The Verge Ahead of Prime Day, the Apple AirPods 3 wireless earbuds have hit their lowest price so far. Originally $249 (though commonly selling somewhere between $200 an…

                        theverge.com/gadgets/947719/ai

                        [The Verge]

                          [?]CyberNetsecIO » 🌐
                          @netsecio@mastodon.social

                          📰 Microsoft's Record-Breaking June Patch Tuesday: Over 200 Flaws and Three Zero-Days Patched

                          🚨 Microsoft's June 2026 Patch Tuesday is a record-breaker, fixing over 200 flaws, 33 critical RCEs, and 3 zero-days. A potentially wormable kernel bug (CVE-2026-45657) requires immediate patching. ⚠️

                          🌐 cyber[.]netsecops[.]io

                          🔗 cyber.netsecops.io/articles/mi

                            [?]CyberNetsecIO » 🌐
                            @netsecio@mastodon.social

                            📰 Energy Sector in Crosshairs: 66% of APT Campaigns Target Utilities, Report Finds

                            🚨 New report: Global energy sector is the top target for nation-state hackers. 66% of all APT campaigns in the last 3 months hit energy & utilities, with actors from China, Russia & North Korea leading the charge. ⚡️

                            🌐 cyber[.]netsecops[.]io

                            🔗 cyber.netsecops.io/articles/en

                              [?]CyberNetsecIO » 🌐
                              @netsecio@mastodon.social

                              📰 Ivanti Patches Critical Sentry Flaws Allowing Root-Level RCE

                              ⚠️ CRITICAL: Ivanti patches two severe flaws in Sentry, including a root-level unauthenticated RCE (CVE-2026-10520). Technical details are public, exploitation risk is high. Patch immediately!

                              🌐 cyber[.]netsecops[.]io

                              🔗 cyber.netsecops.io/articles/iv

                                [?]CyberNetsecIO » 🌐
                                @netsecio@mastodon.social

                                📰 ICS Patch Tuesday: Siemens, Schneider, Phoenix Contact Release Critical Advisories

                                🔌 ICS Patch Tuesday: Siemens, Schneider Electric, and Phoenix Contact release critical advisories for flaws in industrial products, including protection relays, network gear, and EV chargers.

                                🌐 cyber[.]netsecops[.]io

                                🔗 cyber.netsecops.io/articles/ic

                                  [?]CyberNetsecIO » 🌐
                                  @netsecio@mastodon.social

                                  📰 Infostealer Malware Poses Critical Supply Chain Risk to U.S. Defense Sector

                                  New Flashpoint report: Infostealer malware is a critical threat to the US defense sector. Attackers are bypassing defenses by simply logging in with stolen credentials, creating a massive supply chain risk. 🛡️

                                  🌐 cyber[.]netsecops[.]io

                                  🔗 cyber.netsecops.io/articles/in

                                    [?]CyberNetsecIO » 🌐
                                    @netsecio@mastodon.social

                                    📰 OT Cybersecurity Becomes a Board-Level Priority, Fortinet Report Finds

                                    Report: OT security is now a board-level concern. Over 50% of orgs now place OT under the CISO, up from 16% in 2022, as maturity rises and cyber-physical risks gain executive attention. 🏭

                                    🌐 cyber[.]netsecops[.]io

                                    🔗 cyber.netsecops.io/articles/ot

                                      [?]CyberNetsecIO » 🌐
                                      @netsecio@mastodon.social

                                      📰 Active Exploitation of Critical PAN-OS Auth Bypass (CVE-2026-0257) Detected in the Wild

                                      ⚠️ Active Exploitation Alert! Unidentified actors are exploiting PAN-OS auth bypass CVE-2026-0257 to access GlobalProtect VPNs. CISA KEV listed. Patch or apply mitigations immediately to prevent unauthorized access.

                                      🌐 cyber[.]netsecops[.]io

                                      🔗 cyber.netsecops.io/articles/ac

                                        [?]CyberNetsecIO » 🌐
                                        @netsecio@mastodon.social

                                        📰 Google Patches Fifth Actively Exploited Chrome Zero-Day of 2026

                                        ⚠️ Google patches its FIFTH Chrome zero-day this year! CVE-2026-11645 is a high-severity V8 bug actively exploited in the wild. Update your browser to version 149.0.7827.103+ immediately!

                                        🌐 cyber[.]netsecops[.]io

                                        🔗 cyber.netsecops.io/articles/go

                                          [?]TechWire ⚡ » 🤖 🌐
                                          @techwire@social.gamefan.net

                                          The Social Reckoning trailer gives us our first look at Jeremy Strong as Zuck

                                          Over 15 years after David Fincher and Aaron Sorkin's The Social Network premiered in theaters, Sony has released the first trailer for The Social Reckoning ahead of its theatrical release on October 9th. The follow-up t…

                                          theverge.com/entertainment/947

                                          [The Verge]

                                            [?]urlDNA.io :verified: » 🤖 🌐
                                            @urldna@infosec.exchange

                                            Possible Phishing 🎣
                                            on: ⚠️hxxps[:]//ledhggt-vbhdgg[.]pages[.]dev/index[.]htm
                                            🧬 Analysis at: urldna.io/scan/6a2951d23b77500

                                              [?]The New Oil » 🤖 🌐
                                              @thenewoil@mastodon.thenewoil.org

                                              [?]Recon InfoSec » 🌐
                                              @recon_infosec@infosec.exchange

                                              Looking forward to learning about Mobile Forensics and FOSS with @b1n2h3x tomorrow during at 12:30pm CT!

                                              Join us by registering at thursdef.com

                                                [?]TechWire ⚡ » 🤖 🌐
                                                @techwire@social.gamefan.net

                                                Xbox exploring ‘radically different’ console business models

                                                The RAMageddon crisis has got Microsoft rethinking its Xbox console hardware business. Xbox CEO Asha Sharma and Xbox strategy chief Matthew Ball have both revealed this week that Microsoft is reevaluating plans for its …

                                                theverge.com/news/947537/micro

                                                [The Verge]

                                                  [?]TheHackerWire » 🤖 🌐
                                                  @thehackerwire@mastodon.social

                                                  🟠 CVE-2026-47914 - High (7.8)

                                                  Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in...

                                                  🔗 thehackerwire.com/vulnerabilit

                                                  CVE Alert: CVE-2026-47914

                                                  Alt...CVE Alert: CVE-2026-47914

                                                    [?]Kevin Dominik Korte » 🌐
                                                    @kdkorte@fosstodon.org

                                                    It seems that, between the vibe coding and rush-to-market plays, most companies have forgotten about these unimportant details like software engineering or cybersecurity. Who could have foreseen that this would come back to bite us big time?

                                                      [?]EUVD Bot » 🤖 🌐
                                                      @EUVD_Bot@mastodon.social

                                                      🚨 EUVD-2026-36000

                                                      📊 Score: n/a
                                                      📦 Product: Slate Digital Connect
                                                      🏢 Vendor: Slate Digital LLC
                                                      📅 Updated: 2026-06-10

                                                      📝 Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.privileged.helper.tool2. The helper validates connecting XPC clients by...

                                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                                        [?]EUVD Bot » 🤖 🌐
                                                        @EUVD_Bot@mastodon.social

                                                        🚨 EUVD-2026-36002

                                                        📊 Score: n/a
                                                        📦 Product: Slate Digital Connect
                                                        🏢 Vendor: Slate Digital LLC
                                                        📅 Updated: 2026-06-10

                                                        📝 Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.privileged.helper.tool2. The helper validates connecting XPC clients by...

                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                          [?]EUVD Bot » 🤖 🌐
                                                          @EUVD_Bot@mastodon.social

                                                          🚨 EUVD-2026-36001

                                                          📊 Score: 2.0/10 (CVSS v3.1)
                                                          📦 Product: canarytokens, canarytokens
                                                          🏢 Vendor: Thinkst Applied Research
                                                          📅 Updated: 2026-06-10

                                                          📝 An HTML injection vulnerability in the "fetch links" email sent by Thinkst Applied Research Canarytokens, enabling Interface Manipulation, Cross-Site Scripting (XSS) in emails clients that render HTML emails.

                                                          This issue ...

                                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                                            [?]jbz » 🌐
                                                            @jbz@indieweb.social

                                                            ☣️ Miasma worms its way onto GitHub as attack kit goes open source

                                                            “It is a full supply chain attack toolkit that allows the operator to execute various attacks via stolen credentials against arbitrary or targeted packages on public registries (PyPI, npm, RubyGems), JFrog Artifactory, GitHub repositories and GitHub Actions, AI coding tools config poisoning, SSH based lateral movement and other attack vectors,”

                                                            theregister.com/cyber-crime/20

                                                            Alt...a man draws a dumpster fire with the words it 's a dumpster fire below him

                                                              [?]urlDNA.io :verified: » 🤖 🌐
                                                              @urldna@infosec.exchange

                                                              Possible Phishing 🎣
                                                              on: ⚠️hxxps[:]//wbxnscorroen1[.]weebly[.]com
                                                              🧬 Analysis at: urldna.io/scan/6a2927b03b77500

                                                                [?]The New Oil » 🤖 🌐
                                                                @thenewoil@mastodon.thenewoil.org

                                                                [?]gtbarry » 🌐
                                                                @gtbarry@mastodon.social

                                                                Meta to take legal action against Israeli spyware firm NSO, foils phishing attacks

                                                                Meta said its WhatsApp messaging service disrupted new spear phishing attempts linked to NSO, an entity blacklisted by the U.S. government for engaging in activities that are contrary to the national security or foreign policy interests.

                                                                yahoo.com/news/us/articles/met

                                                                  [?]BeyondMachines :verified: » 🤖 🌐
                                                                  @beyondmachines1@infosec.exchange

                                                                  SAP June 2026 Security Patch Day: Critical Fixes for NetWeaver and Commerce Cloud

                                                                  SAP's June 2026 Patch Day addresses 15 vulnerabilities, including four critical flaws in NetWeaver and Commerce Cloud that allow authentication bypass and remote code execution.

                                                                  **If you are using SAP products, prioritize patching SAP NetWeaver AS, SAP NetWeaver Application Server ABAP, and SAP Commerce Cloud. Then review the rest of the issues.
                                                                  Where possible, make sure all systems are isolated from the internet and accessible from trusted networks only.**

                                                                  beyondmachines.net/event_detai

                                                                    [?]Hugo | DevOps | Cybersecurity » 🌐
                                                                    @hugovalters@mastodon.social

                                                                    Nextcloud: 94 CVEs, 98% unpatched, Trust Score C. 1 critical (CVSS 9.7), top flaws: access control & info leaks. Open-source ≠ secure. Patch now.

                                                                    valtersit.com/vendors/nextclou

                                                                      [?]TechWire ⚡ » 🤖 🌐
                                                                      @techwire@social.gamefan.net

                                                                      Insta360’s latest camera takes a shot at DJI’s dual-lens Osmo Pocket 4P

                                                                      Insta360 has entered the pocket vlogging camera market with an impressive first product.

                                                                      androidauthority.com/insta360-

                                                                      [Android Authority]

                                                                        [?]TierraSapiens » 🤖 🌐
                                                                        @tierrasapiens@mastodon.social

                                                                        🖲️
                                                                        ⚫ Blame AI: Patch Tuesday Hits Record 206 CVEs
                                                                        🔗 darkreading.com/vulnerabilitie

                                                                        Voluminous patch updates could soon be the norm, as artificial intelligence accelerates the speed and scale of vulnerability discovery.

                                                                          [?]TechWire ⚡ » 🤖 🌐
                                                                          @techwire@social.gamefan.net

                                                                          Smartphones are finally getting Nvidia DLSS-style tech — and I’m ready for the ‘fake frames’

                                                                          Would you trade fake frames for longer battery life and less heat?

                                                                          androidauthority.com/arm-neura

                                                                          [Android Authority]

                                                                            [?]urlDNA.io :verified: » 🤖 🌐
                                                                            @urldna@infosec.exchange

                                                                            Possible Phishing 🎣
                                                                            on: ⚠️hxxps[:]//courrielweb-videotron-login-layout-iwc-static-fr-html[.]weebly[.]com
                                                                            🧬 Analysis at: urldna.io/scan/6a2921583b77500

                                                                              Back to top - More...