voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
🚨 EUVD-2026-35799
📊 Score: 7.8/10 (CVSS v3.1)
📦 Product: Substance3D - Sampler
🏢 Vendor: Adobe
📅 Updated: 2026-06-09
📝 Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-35799
🚨 EUVD-2026-35798
📊 Score: 7.8/10 (CVSS v3.1)
📦 Product: Substance3D - Sampler
🏢 Vendor: Adobe
📅 Updated: 2026-06-09
📝 Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-35798
🚨 EUVD-2026-35797
📊 Score: 7.8/10 (CVSS v3.1)
📦 Product: Substance3D - Sampler
🏢 Vendor: Adobe
📅 Updated: 2026-06-09
📝 Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-35797
🚨 EUVD-2026-35794
📊 Score: 8.5/10 (CVSS v3.1)
📦 Product: SQLite
🏢 Vendor: SQLite
📅 Updated: 2026-06-09
📝 SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-35794
🚨 EUVD-2026-35793
📊 Score: 8.6/10 (CVSS v3.1)
📦 Product: FlashArray
🏢 Vendor: Everpure
📅 Updated: 2026-06-09
📝 A flaw exists in the FlashArray Purity management interface where an authenticated low-privileged user may, under specific conditions, access functionality beyond their assigned privileges.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-35793
🚨 EUVD-2026-35792
📊 Score: 8.7/10 (CVSS v3.1)
📦 Product: FlashArray, FlashArray
🏢 Vendor: Everpure
📅 Updated: 2026-06-09
📝 A flaw exists in FlashArray Purity where insufficient filtering of certain data paths could expose sensitive information to an authenticated user with low privileges.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-35792
🚨 EUVD-2026-35710
📊 Score: 5.4/10 (CVSS v3.1)
📦 Product: Adobe Experience Manager
🏢 Vendor: Adobe
📅 Updated: 2026-06-09
📝 Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields....
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-35710
Cyberpunk: El futuro ya es nuestro presente 🌐🔌
Alta Tecnología: IA avanzada, redes neuronales y realidad virtual inmersiva.
Baja Calidad de Vida: Megacorporaciones controlando datos, hacktivismo y brecha digital.
Ya no es solo literatura de ciencia ficción; es el reflejo exacto de nuestra lucha actual por la privacidad y la soberanía tecnológica.
#Cyberpunk #Hacking #AI #Privacy #Cybersecurity #SciFi #Technology #Mastodon
Anthropic’s too-scary-to-release AI hacking tool is actually coming out — kind of
Claude Fable 5 is Anthropic’s most capable public model yet, but it won’t find your zero-days.
https://www.androidauthority.com/claude-mythos-5-3676051/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
GM thinks EVs can help offset AI’s energy suck with vehicle-to-grid tech
At an event in San Francisco today, General Motors made a series of announcements around EV batteries, energy storage, and grid resiliency in the face of growing electricity demand from AI data centers. The automaker an…
https://www.theverge.com/transportation/946820/gm-energy-ev-v2g-storage-sodium-ion
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Possible Phishing 🎣
on: ⚠️hxxps[:]//nk-nitya[.]github[.]io/front_page_amazon/
🧬 Analysis at: https://urldna.io/scan/6a280e823b775000047a24ca
#cybersecurity #phishing #infosec #urldna #scam #infosec
#chrome extension SearchThatWeb seems malicious. Its #cybersecurity badness score is 89/100!
```json
{"id": "akimdaijebpdfojiohhimbebkdigkccj", "score": 89, "platform": "chrome", "name": "SearchThatWeb"}
```
🚨 EUVD-2026-35442
📊 Score: 6.2/10 (CVSS v3.1)
📦 Product: FortiPortal, FortiPortal, FortiPortal
🏢 Vendor: Fortinet
📅 Updated: 2026-06-09
📝 A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2.0 through 7.2.8, FortiPortal 7.0 all versions may allow attacker to improper access control via <insert attack vector here>
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-35442
🚨 EUVD-2026-35440
📊 Score: 10.0/10 (CVSS v3.1)
📦 Product: sentry, sentry, sentry
🏢 Vendor: Ivanti
📅 Updated: 2026-06-09
📝 An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-35440
Google Patches Chrome Zero-Day Exploited in the Wild Among 74 Security Fixes
Google released an emergency update for Chrome to patch 74 vulnerabilities, including a high-severity V8 zero-day (CVE-2026-11645) that is being actively exploited in the wild. The update addresses 17 critical flaws, mostly use-after-free memory corruption issues that allow remote code execution.
**One more huge emergency patch for Chrome and Chromium-based browsers (Edge, Opera, Brave, Vivaldi...). Don't delay, it addresses a critical, actively exploited zero-day flaw and 17 other critical vulnerabilities. Updating the browser is easy, all your tabs reopen after the patch, so ensure automatic updates are enabled and restart immediately to minimize your exposure.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/google-patches-chrome-zero-day-exploited-in-the-wild-among-74-security-fixes-i-m-s-z-p/gD2P6Ple2L
🎉 Welcome to the #future of #AI, where Claude Fable 5 is so "state-of-the-art" that it's practically an overachieving intern on steroids who forgot to read the #cybersecurity manual! 🤖🔐 As usual, we've made sure it's so "safe" for general use that you can almost feel the safety through the screen... or not. 😂
https://www.anthropic.com/news/claude-fable-5-mythos-5 #Overachiever #SafeTech #HackerNews #ngated
WIRED - The Latest in Technology, Science, Culture and Business [Unofficial] » 🌐
@wired.com@web.brid.gy
Anthropic is releasing Claude Mythos 5 to trusted organizations and Claude Fable 5 to the public, a version it says can’t be used for cyberattacks.
The Legend of Zelda: Ocarina of Time is getting a remake for the Switch 2
Nintendo announced a remake of The Legend of Zelda: Ocarina of Time during its Nintendo Direct presentation on Tuesday. It will launch sometime in 2026 on Nintendo Switch 2. More details will be announced "in the future…
https://www.theverge.com/games/945745/nintendo-zelda-ocarina-of-time-remake-direct-june-2026
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Habr » 🤖 🌐
@habr@zhub.link
Когда AI ошибается уверенно
Это третья глава серии про AI Innovation Lab — исследовательскую площадку, где я строю AI-augmented SOC: систему из шести AI агентов, которая следит за корпоративной инфраструктурой, расследует инциденты и предлагает действия. В этой главе я подключил к платформе внешнюю разведку угроз — и во время первого же теста AI уверенно предложил отключить операционный аккаунт, через который работает сама система защиты. Аргументация выглядела профессионально. Rule ID, MITRE-техники, количество алертов. Я почти согласился. История не про баг. История про то, почему уверенный AI опаснее неуверенного — и как с этим жить.
https://habr.com/ru/articles/1045636/
#ai #enterpriseai #cio #ciso #digitaltransformation #cybersecurity #кибербезопасность #информационная_безопасность
🚨New ransom group blog post!🚨
Group name: chaos
Post title: airespring.com
Info: https://cti.fyi/groups/chaos.html
#ransomware #cti #threatintelligence #cybersecurity #infosec
Meta will use your activity on other websites to personalize your feeds
Meta is planning to use the data shared by other businesses to personalize your feed and its AI responses. In a blog post on Tuesday, Meta explains that it already uses your off-platform activity, like the games you pla…
https://www.theverge.com/tech/946744/meta-website-activity-personalize-feeds
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Possible Phishing 🎣
on: ⚠️hxxps[:]//www[.]robiox[.]com[.]py/users/411804676273/profile
🧬 Analysis at: https://urldna.io/scan/6a2816103b775000047a25b2
#cybersecurity #phishing #infosec #urldna #scam #infosec
#Microsoft Hacked to Deliver #Malware to #Claude and #Gemini Users
https://www.404media.co/microsoft-hacked-to-deliver-malware-to-claude-and-gemini-users/
Hello fediverse, I have a question.
Which country in south east asia region that still and potentially still in near future respecting individual privacy OR the very least has a strong community in Cybersecurity?
From what I see so far, it is either Malaysia or Singapore that has strong cybersecurity community.
This is just for future preference.
Thanks in advance
🚨 EUVD-2026-35397
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: TYPO3 CMS, TYPO3 CMS
🏢 Vendor: TYPO3
📅 Updated: 2026-06-09
📝 Backend users were able to move records to a different page without having edit permissions on the source page. This issue affects TYPO3 CMS versions 13.0.0-13.4.31 and 14.0.0-14.3.3.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-35397
🚨 EUVD-2026-35396
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: TYPO3 CMS, TYPO3 CMS, TYPO3 CMS (+2 more)
🏢 Vendor: TYPO3
📅 Updated: 2026-06-09
📝 Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they were not authorized to modify. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.51, 12.0.0...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-35396
🚨 EUVD-2026-35395
📊 Score: 5.1/10 (CVSS v3.1)
📦 Product: TYPO3 CMS, TYPO3 CMS
🏢 Vendor: TYPO3
📅 Updated: 2026-06-09
📝 Editors with access to create or modify page content were able to include HTML markup in page titles that were stored in the search index without sanitization. When displayed in frontend search results via the Indexed Search plugin, these titles w...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-35395
🚨 EUVD-2026-35394
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: TYPO3 CMS, TYPO3 CMS, TYPO3 CMS (+2 more)
🏢 Vendor: TYPO3
📅 Updated: 2026-06-09
📝 Applications that use GeneralUtility::sanitizeLocalUrl to allow only local URLs are vulnerable to open redirect attacks if the URL is used after it has passed the aforementioned sanitization checks. This enables attackers to r...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-35394
🚨 EUVD-2026-35393
📊 Score: 7.6/10 (CVSS v3.1)
📦 Product: TYPO3 CMS, TYPO3 CMS, TYPO3 CMS (+2 more)
🏢 Vendor: TYPO3
📅 Updated: 2026-06-09
📝 Backend users with file write permissions were able to upload form definition files with mixed-case extensions (e.g., .FORM.YAML) to bypass the Form Framework's upload restriction. Maliciously crafted form definition files can...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-35393
🚨 EUVD-2026-35392
📊 Score: 7.2/10 (CVSS v3.1)
📦 Product: TYPO3 CMS, TYPO3 CMS, TYPO3 CMS (+2 more)
🏢 Vendor: TYPO3
📅 Updated: 2026-06-09
📝 Non-privileged backend users with file mount access were able to perform write operations (move, delete, rename) on folders representing the root of an active file mount due to missing authorization restrictions. This issue af...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-35392
🚨 EUVD-2026-35391
📊 Score: 7.6/10 (CVSS v3.1)
📦 Product: TYPO3 CMS, TYPO3 CMS, TYPO3 CMS (+2 more)
🏢 Vendor: TYPO3
📅 Updated: 2026-06-09
📝 Backend users with access to the Form Framework were able to use files not ending in .form.yaml as form definitions, which were processed without denying the incorrect file extension. Maliciously crafted form definition files ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-35391
Oxford University discloses data breach after careers platform hack
The University of Oxford disclosed a new data breach last week after being informed by its third-party provider, Group GTI, that its CareerConnect career services platform had been compromised.
#Oxford #CareerConnect #databreach #security #cybersecurity #hackers #hacking #hacked
Moodle: 81 CVEs, 100% unpatched. Trust Score: C. Top weaknesses: Missing Authorization (CWE-862) & XSS (CWE-79). Open-source LMS, critical data at risk. #Moodle #infosec #cybersecurity
Possible Phishing 🎣
on: ⚠️hxxps[:]//absoluteprintgroup[.]com
🧬 Analysis at: https://urldna.io/scan/6a27e4433b775000075579bf
#cybersecurity #phishing #infosec #urldna #scam #infosec