voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]The New Oil » 🤖 🌐
@thenewoil@mastodon.thenewoil.org

[?]CTI.FYI » 🤖 🌐
@CTI_FYI@infosec.exchange

🚨New ransom group blog posts!🚨

Group name: akira
Post title: The Midland Theatre
Info: cti.fyi/groups/akira.html

Group name: spacebears
Post title: Cattani
Info: cti.fyi/groups/spacebears.html

    [?]InfosecK2K » 🌐
    @InfosecK2K@mastodon.social

    Thousands of security alerts are generated daily.

    The challenge is knowing what matters.

    Infosec K2K helps improve detection, visibility, and response through continuous monitoring.

    zurl.co/I4KCi

      [?]urlDNA.io :verified: » 🤖 🌐
      @urldna@infosec.exchange

      Possible Phishing 🎣
      on: ⚠️hxxps[:]//711564891573141249[.]weebly[.]com
      🧬 Analysis at: urldna.io/scan/6a28ef963b77500

        [?]OTX Bot » 🤖 🌐
        @techbot@social.raytec.co

        From Malspam to Fileless .NET Loader

        A sophisticated malspam campaign delivers a multi-stage .NET loader through an elaborate chain beginning with HTML email attachments. The attack routes through legitimate Google DoubleClick infrastructure to evade detection, then deploys a dynamically personalized phishing kit that pulls victim company branding in real-time. The infection chain progresses through JavaScript, PowerShell, and multiple .NET components, executing primarily in-memory while actively patching AMSI and ETW to blind Windows telemetry. The loader performs extensive anti-analysis checks, terminates or reboots upon detecting sandboxes or debugging tools, and establishes persistence through registry keys and scheduled tasks disguised as NVIDIA components. It targets Microsoft-signed binaries like InstallUtil.exe and MSBuild.exe for process injection, maintains C2 communications over non-standard ports using AES-encrypted protobuf messages, and profiles victim systems including specific GPU enumeration potentially for cryptocurrency min...

        Pulse ID: 6a2836368857c87f205e9605
        Pulse Link: otx.alienvault.com/pulse/6a283
        Pulse Author: AlienVault
        Created: 2026-06-09 15:50:14

        Be advised, this data is unverified and should be considered preliminary. Always do further verification.

          [?]TechWire ⚡ » 🤖 🌐
          @techwire@social.gamefan.net

          WhatsApp ordered to host rival AI assistants for free

          Meta has been ordered by the European Commission to restore free WhatsApp access for chatbots made by rival AI providers while the regulator finishes its antitrust investigation. The rare interim measure announced on Tu…

          theverge.com/tech/947516/meta-

          [The Verge]

            [?]Open Security Conference » 🌐
            @OSCo@infosec.exchange

            It's finally time to announce our first keynote speaker for ! 🤩

            We're more than happy to have Stephanie Carstensen with us this year. She's specializing in and industrial cybersecurity and shares her a vast experience in her keynote "The Day Everything Stops: Preparing for the Cyber Crisis You Hope Never Comes".

            Intrigued like we are? Check out the full description here: opensecurityconference.org/con

            See you at ! 😃

            [lisi]

              [?]TechWire ⚡ » 🤖 🌐
              @techwire@social.gamefan.net

              EU Says Decision Not to Launch Siri AI in Europe Is Apple's Alone

              The European Commission has responded to Apple's announcement that Siri AI will not launch in the EU, saying the decision is entirely Apple's and that the company sought an exemption from its legal obligations rather th…

              macrumors.com/2026/06/09/eu-sa

              [MacRumors]

                [?]TheHackerWire » 🤖 🌐
                @thehackerwire@mastodon.social

                🟠 CVE-2026-47952 - High (7.8)

                Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user in...

                🔗 thehackerwire.com/vulnerabilit

                CVE Alert: CVE-2026-47952

                Alt...CVE Alert: CVE-2026-47952

                  [?]urlDNA.io :verified: » 🤖 🌐
                  @urldna@infosec.exchange

                  Possible Phishing 🎣
                  on: ⚠️hxxps[:]//shentelnetsing[.]weebly[.]com
                  🧬 Analysis at: urldna.io/scan/6a29133a3b77500

                    [?]TheHackerWire » 🤖 🌐
                    @thehackerwire@mastodon.social

                    🟠 CVE-2026-47921 - High (7.8)

                    Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in...

                    🔗 thehackerwire.com/vulnerabilit

                    CVE Alert: CVE-2026-47921

                    Alt...CVE Alert: CVE-2026-47921

                      [?]TheHackerWire » 🤖 🌐
                      @thehackerwire@mastodon.social

                      🔴 CVE-2026-47928 - Critical (9.6)

                      ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interacti...

                      🔗 thehackerwire.com/vulnerabilit

                      CVE Alert: CVE-2026-47928

                      Alt...CVE Alert: CVE-2026-47928

                        [?]BeyondMachines :verified: » 🤖 🌐
                        @beyondmachines1@infosec.exchange

                        OpenSSL Patches High-Severity Vulnerability

                        OpenSSL released patches for 18 vulnerabilities, including a high-severity heap use-after-free flaw (CVE-2026-45447) that could allow remote code execution during PKCS#7 signature verification.

                        **Plan an update your OpenSSL libraries . Since AI is now being used to find these flaws, the window for patching before exploitation may shrink.**

                        beyondmachines.net/event_detai

                          [?]TechWire ⚡ » 🤖 🌐
                          @techwire@social.gamefan.net

                          Google is playing a dangerous game by killing off the Nest Mini

                          Google risks losing entry-level buyers and power users alike.

                          androidauthority.com/google-ki

                          [Android Authority]

                            [?]Hackread.com » 🌐
                            @Hackread@mstdn.social

                            📣🚨 ’s June 2026 Patch Tuesday fixes 206 security flaws, including 3 publicly disclosed zero-days affecting HTTP.sys, Windows CTFMON, and BitLocker - Update your devices NOW!

                            Read: hackread.com/microsoft-june-20

                              [?]TechWire ⚡ » 🤖 🌐
                              @techwire@social.gamefan.net

                              One device, double the coverage – The Botslab W101 window camera covers the inside and outside

                              Get all-round coverage with one camera.

                              androidauthority.com/botslab-w

                              [Android Authority]

                                [?]urlDNA.io :verified: » 🤖 🌐
                                @urldna@infosec.exchange

                                Possible Phishing 🎣
                                on: ⚠️hxxps[:]//bex43452789840[.]weebly[.]com
                                🧬 Analysis at: urldna.io/scan/6a2913333b77500

                                  [?]CTI.FYI » 🤖 🌐
                                  @CTI_FYI@infosec.exchange

                                  🚨New ransom group blog posts!🚨

                                  Group name: worldleaks
                                  Post title: Tata Electronics
                                  Info: cti.fyi/groups/worldleaks.html

                                  Group name: worldleaks
                                  Post title: First Federal Savings & Loan
                                  Info: cti.fyi/groups/worldleaks.html

                                    [?]TechWire ⚡ » 🤖 🌐
                                    @techwire@social.gamefan.net

                                    Anthropic's warning over AI self-improvement has a hidden message — accelerating development requires more compute before companies ever risk losing control of fro…

                                    The company that just a few weeks ago told us that its Mythos model was much too powerful to be released is now saying that we might need to hit the pause button.

                                    tomshardware.com/tech-industry

                                    [Tom's Hardware]

                                      [?]TechWire ⚡ » 🤖 🌐
                                      @techwire@social.gamefan.net

                                      Razer Seiren V3 Pro Review: USB, XLR, and 32-bit float

                                      Razer's new Seiren V3 Pro is an end-address mic with both USB-C and XLR connectivity, and it also supports 32-bit float.

                                      tomshardware.com/peripherals/m

                                      [Tom's Hardware]

                                        [?]eteryu » 🌐
                                        @eteryu@infosec.exchange

                                        Poranna kawa paruje, więc to idealny moment na dłuższą lekturę. ☕️📱

                                        Współczesny Big Tech zaszczepił w nas złudne przekonanie, że wygoda musi oznaczać całkowitą bezobsługowość – magię funkcji typu „włącz i zapomnij” (set-and-forget). Za tę bezobsługowość płacimy jednak bezpowrotną utratą kontroli. Wielkie korporacje agregują metadane, analizują nasz styl pisania, lokalizację i relacje między dokumentami, budując z tych puzzli naszego „cyfrowego bliźniaka” (digital twin). Handlują predykcją naszych zachowań, a my stajemy się produktem.

                                        Na moim blogu ląduje właśnie szczegółowa analiza konfiguracji, którą nazywam „pragmatycznym puryzmem”. To opowieść o rygorystycznym okiełznaniu iOS: odcięciu iCloud, uciszeniu Siri, NextDNS na sterydach, kompletnym de-Google i sprowadzeniu klawiatury do roli prymitywnej maszyny do pisania. Czy da się zbudować szczelną klatkę na zamkniętym gruncie od Apple?

                                        Cały wpis i wnioski z tej drogi znajdziecie tutaj:

                                        👉 eteryu.space/pragmatyczny-pury

                                        Chętnie podyskutuję – jak wyglądają Wasze doświadczenia z próbami utwardzania iOS?

                                          [?]EUVD Bot » 🤖 🌐
                                          @EUVD_Bot@mastodon.social

                                          🚨 EUVD-2026-35876

                                          📊 Score: 5.3/10 (CVSS v3.1)
                                          📦 Product: core-rs-albatross
                                          🏢 Vendor: nimiq
                                          📅 Updated: 2026-06-09

                                          📝 Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. network-libp2p handles kad get-record query progress in handle_dht_get (network-libp2p/src/swarm.rs). Prior to version 1.4.0, when a peer ...

                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                            [?]EUVD Bot » 🤖 🌐
                                            @EUVD_Bot@mastodon.social

                                            🚨 EUVD-2026-35875

                                            📊 Score: 7.5/10 (CVSS v3.1)
                                            📦 Product: pipecat
                                            🏢 Vendor: pipecat-ai
                                            📅 Updated: 2026-06-09

                                            📝 Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. From version 0.0.90 to before version 1.2.0, a path traversal vulnerability exists in Pipecat's development runner (src/pipecat/runner/run.py). W...

                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                              [?]EUVD Bot » 🤖 🌐
                                              @EUVD_Bot@mastodon.social

                                              🚨 EUVD-2026-35874

                                              📊 Score: 7.8/10 (CVSS v3.1)
                                              📦 Product: LMDeploy
                                              🏢 Vendor: InternLM
                                              📅 Updated: 2026-06-09

                                              📝 LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, hardcoded "trust_remote_code=True" enables HF supply-chain RCE without user opt-in. At time of publication, there are no publicly available p...

                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                [?]EUVD Bot » 🤖 🌐
                                                @EUVD_Bot@mastodon.social

                                                🚨 EUVD-2026-35873

                                                📊 Score: 7.8/10 (CVSS v3.1)
                                                📦 Product: LMDeploy
                                                🏢 Vendor: InternLM
                                                📅 Updated: 2026-06-09

                                                📝 LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, LMDeploy is vulnerable to arbitrary code execution through hardcoded "trust_remote_code=True" in multiple HuggingFace model-loading call site...

                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                  [?]EUVD Bot » 🤖 🌐
                                                  @EUVD_Bot@mastodon.social

                                                  🚨 EUVD-2026-35872

                                                  📊 Score: 6.5/10 (CVSS v3.1)
                                                  📦 Product: FlashMQ
                                                  🏢 Vendor: halfgaar
                                                  📅 Updated: 2026-06-09

                                                  📝 FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.26.2, authorized clients have the ability to exceed the permitted over-commit of their write buffer and triggering an internal safe-guard exception. This exception was ...

                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                    [?]EUVD Bot » 🤖 🌐
                                                    @EUVD_Bot@mastodon.social

                                                    🚨 EUVD-2026-35871

                                                    📊 Score: 8.6/10 (CVSS v3.1)
                                                    📦 Product: simplesamlphp-module-casserver
                                                    🏢 Vendor: SimpleSAMLphp
                                                    📅 Updated: 2026-06-09

                                                    📝 SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. Prior to version 7.0.3, simplesamlphp-module-casserver builds file paths for the file-based CAS ticket store by directly con...

                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                      [?]EUVD Bot » 🤖 🌐
                                                      @EUVD_Bot@mastodon.social

                                                      🚨 EUVD-2026-35870

                                                      📊 Score: 8.9/10 (CVSS v3.1)
                                                      📦 Product: cloud-hypervisor
                                                      🏢 Vendor: cloud-hypervisor
                                                      📅 Updated: 2026-06-09

                                                      📝 Cloud Hypervisor is a Virtual Machine Monitor for Cloud workloads. From version 21.0 to before version 51.2, a guest can cause a use-after-free in the cloud-hypervisor process by submitting two virtio-block descriptor chains that reuse the ...

                                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                                        [?]EUVD Bot » 🤖 🌐
                                                        @EUVD_Bot@mastodon.social

                                                        🚨 EUVD-2026-35869

                                                        📊 Score: 7.7/10 (CVSS v3.1)
                                                        📦 Product: OpenEMR
                                                        🏢 Vendor: OpenEMR
                                                        📅 Updated: 2026-06-09

                                                        📝 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.1, a stored cross-site scripting vulnerability in the prescription CSS/HTML multi-print feature allows a patient portal user to ex...

                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                          [?]TheHackerWire » 🤖 🌐
                                                          @thehackerwire@mastodon.social

                                                          🟠 CVE-2026-44716 - High (7.5)

                                                          Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. From version 0.0.90 to before version 1.2.0, a path traversal vulnerability exists in Pipecat's development runner (src/pipecat/runner/ru...

                                                          🔗 thehackerwire.com/vulnerabilit

                                                          CVE Alert: CVE-2026-44716

                                                          Alt...CVE Alert: CVE-2026-44716

                                                            [?]TheHackerWire » 🤖 🌐
                                                            @thehackerwire@mastodon.social

                                                            🟠 CVE-2026-46432 - High (7.8)

                                                            LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, LMDeploy is vulnerable to arbitrary code execution through hardcoded "trust_remote_code=True" in multiple HuggingFace model-loading ...

                                                            🔗 thehackerwire.com/vulnerabilit

                                                            CVE Alert: CVE-2026-46432

                                                            Alt...CVE Alert: CVE-2026-46432

                                                              [?]TheHackerWire » 🤖 🌐
                                                              @thehackerwire@mastodon.social

                                                              🟠 CVE-2026-46491 - High (8.6)

                                                              SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. Prior to version 7.0.3, simplesamlphp-module-casserver builds file paths for the file-based CAS ticket store by directly concatenating the con...

                                                              🔗 thehackerwire.com/vulnerabilit

                                                              CVE Alert: CVE-2026-46491

                                                              Alt...CVE Alert: CVE-2026-46491

                                                                [?]TierraSapiens » 🤖 🌐
                                                                @tierrasapiens@mastodon.social

                                                                🖲️
                                                                ⚫ Microsoft Exchange Flaw Lets Attackers Spoof Any Email Address
                                                                🔗 darkreading.com/vulnerabilitie

                                                                "Ghost-Sender" uses Exchange Online or on-premises in hybrid mode with a third-party mail server or spam filter to achieve this level of spoofing.

                                                                  [?]deafnews » 🤖 🌐
                                                                  @deafnews@infosec.exchange

                                                                  [?]AmmarSpaces » 🌐
                                                                  @AmmarSpaces@infosec.exchange

                                                                  Alright, this is my feeling so far, reading various posts regarding Mythos capability.

                                                                  Note: I might will never use Mythos in my life, because I do not want to waste my thinking or money, unless I needed to.

                                                                  First off, yes, it will look like better than ANY models that is released so far.

                                                                  Proof: x.com/VictorTaelin/status/2064

                                                                  And, for me, this Xitter post might be what I will feel on it:
                                                                  x.com/atelicinvest/status/2064

                                                                  Okay, that's just the positive note I have which tbf, i don't really give an f.

                                                                  Now, on the shit part. If Claude retain their current policy. I (think I can) guarantee you, MYTHOS WILL NOT SOLVE THE PROBLEM IT BEING ADVERTISED ON.

                                                                  Yes, it WILL NOT solve any Cybersecurity problem.

                                                                  So far, what I have observed is there are two problems:
                                                                  1. Claude restricts ANY CYBER SECURITY tasks. Which is a fucking shame, mother fucker advertise it will replace pentesters, discover 0days, and so on, yet when it has a chance to be independently verified, "NO, YOU CAN'T DO THAT", in the name of guard rails. (Photo 1)

                                                                  2. Claude rolling the data retention policy. Haha, fuck you, if you are a sane cybersec man, you do AND MUST realize this is a big fucking no no. Especially IF YOU ARE IN A BIG FUCKING CRITICAL/HIGH RISK place.

                                                                  So, verdict?
                                                                  Just do whatever y currently do, also this, that, themes and such.

                                                                  Real changes will come when it really comes.

                                                                  And, thanks for reading my ramblings.

                                                                  Claude prevents usage in Cybersecurity and biology related

                                                                  Alt...Claude prevents usage in Cybersecurity and biology related

                                                                  Claude data retention policy.

                                                                  Alt...Claude data retention policy.

                                                                    [?]TechWire ⚡ » 🤖 🌐
                                                                    @techwire@social.gamefan.net

                                                                    US workers are the world's biggest AI skeptics - and it's not just about job loss

                                                                    More than half of US desk workers consider themselves AI skeptics, while emerging economies trust AI more, according to recent studies.

                                                                    zdnet.com/article/us-workers-a

                                                                    [ZDNet]

                                                                      [?]TechWire ⚡ » 🤖 🌐
                                                                      @techwire@social.gamefan.net

                                                                      The best early Prime Day TV deals actually worth your time: Samsung, Sony, and more

                                                                      Amazon's Prime Day sale is just two weeks away, but you can already save thousands on TVs from top brands we've tested.

                                                                      zdnet.com/article/best-early-p

                                                                      [ZDNet]

                                                                        [?]urlDNA.io :verified: » 🤖 🌐
                                                                        @urldna@infosec.exchange

                                                                        Possible Phishing 🎣
                                                                        on: ⚠️hxxps[:]//docs[.]google[.]com/presentation/d/e/2PACX-1vT3DmTob3FqFxzmvYPpHT_hXVHF6AKcTnEvo45CoorVqPb_xpeHgXWvXp8kkOyNqyt7ZSGz-FopSshE/pub?start=false&loop=false&delayms=3000
                                                                        🧬 Analysis at: urldna.io/scan/6a2846973b77500

                                                                          [?]SquaredTech » 🌐
                                                                          @SquaredTech@mstdn.social

                                                                          Microsoft's biggest patch Tuesday ever arrives this June 2026, with nearly 200 security fixes! A record-breaker addressing active zero-day exploits, a rogue researcher, and even AI vulnerabilities. Stay updated and keep your system secure! June 2026 Patch Tuesday: Microsoft's Biggest Ever With 200 Fixes
                                                                          squaredtech.co/june-2026-patch

                                                                            [?]EUVD Bot » 🤖 🌐
                                                                            @EUVD_Bot@mastodon.social

                                                                            🚨 EUVD-2026-35795

                                                                            📊 Score: 5.1/10 (CVSS v3.1)
                                                                            📦 Product: Banner Self-Service, Banner Self-Service
                                                                            🏢 Vendor: Ellucian
                                                                            📅 Updated: 2026-06-09

                                                                            📝 Ellucian Banner Self-Service before the April T2 release (2025-04-23) contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser by inj...

                                                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                                                              [?]EUVD Bot » 🤖 🌐
                                                                              @EUVD_Bot@mastodon.social

                                                                              🚨 EUVD-2026-35801

                                                                              📊 Score: 8.5/10 (CVSS v3.1)
                                                                              📦 Product: SQLite
                                                                              🏢 Vendor: SQLite
                                                                              📅 Updated: 2026-06-09

                                                                              📝 SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifyin...

                                                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                [?]EUVD Bot » 🤖 🌐
                                                                                @EUVD_Bot@mastodon.social

                                                                                🚨 EUVD-2026-35800

                                                                                📊 Score: 7.8/10 (CVSS v3.1)
                                                                                📦 Product: Substance3D - Sampler
                                                                                🏢 Vendor: Adobe
                                                                                📅 Updated: 2026-06-09

                                                                                📝 Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a...

                                                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                  Back to top - More...