voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]TechWire ⚡ » 🤖 🌐
@techwire@social.gamefan.net

Opera gains ground among iPhone users in the US and UK

Opera says its iOS browser saw monthly active users grow 93% in the UK and 50% in the US during Q2 2026 compared with the same period last year. Here are the details.

9to5mac.com/2026/07/14/opera-g

[9to5Mac]

    [?]Malicious Extension Bot » 🤖 🌐
    @malicious_browser_bot@infosec.exchange

    extension Purple Sunset Live Wallpaper seems malicious. Its badness score is 93/100!

    ```json
    {"id": "npofmnnbidppdfjnfdcjicgmhhmahepm", "score": 93, "platform": "chrome", "name": "Purple Sunset Live Wallpaper"}
    ```

      [?]Malicious Extension Bot » 🤖 🌐
      @malicious_browser_bot@infosec.exchange

      extension Naruto Uzumaki Flaming Live Wallpaper New Tab seems malicious. Its badness score is 85/100!

      ```json
      {"id": "ichfadkdnkechpkpebiikjcfkhkljmji", "score": 85, "platform": "chrome", "name": "Naruto Uzumaki Flaming Live Wallpaper New Tab"}
      ```

        [?]Malicious Extension Bot » 🤖 🌐
        @malicious_browser_bot@infosec.exchange

        extension Blackpink Anime Wallpapers Gameograf seems malicious. Its badness score is 98/100!

        ```json
        {"id": "delpahkmccgedaocoganaaligaljchli", "score": 98, "platform": "chrome", "name": "Blackpink Anime Wallpapers Gameograf"}
        ```

          [?]EUVD Bot » 🤖 🌐
          @EUVD_Bot@mastodon.social

          🚨 EUVD-2026-45409

          📊 Score: 6.3/10 (CVSS v3.1)
          📦 Product: PicoClaw, PicoClaw, PicoClaw (+7 more)
          🏢 Vendor: Sipeed
          📅 Updated: 2026-07-18

          📝 A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. The impacted element is an unknown function of the file web/backend/middleware/access_control.go of the component First Run Setup. Performing a manipulation of the arg...

          🔗 euvd.enisa.europa.eu/vulnerabi

            [?]EUVD Bot » 🤖 🌐
            @EUVD_Bot@mastodon.social

            🚨 EUVD-2026-45408

            📊 Score: 5.3/10 (CVSS v3.1)
            📦 Product: PicoClaw, PicoClaw, PicoClaw (+7 more)
            🏢 Vendor: Sipeed
            📅 Updated: 2026-07-18

            📝 A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. The affected element is the function handleMessageReceive of the file pkg/channels/feishu/feishu_64.go of the component Group Message Handler. Such manip...

            🔗 euvd.enisa.europa.eu/vulnerabi

              [?]EUVD Bot » 🤖 🌐
              @EUVD_Bot@mastodon.social

              🚨 EUVD-2026-45407

              📊 Score: 5.3/10 (CVSS v3.1)
              📦 Product: PicoClaw, PicoClaw, PicoClaw (+7 more)
              🏢 Vendor: Sipeed
              📅 Updated: 2026-07-18

              📝 A weakness has been identified in Sipeed PicoClaw up to 0.2.9. Impacted is the function isPrivateOrRestrictedIP of the file pkg/tools/integration/web.go of the component web_fetch. This manipulation causes server-side request fo...

              🔗 euvd.enisa.europa.eu/vulnerabi

                [?]EUVD Bot » 🤖 🌐
                @EUVD_Bot@mastodon.social

                🚨 EUVD-2026-45406

                📊 Score: 5.3/10 (CVSS v3.1)
                📦 Product: PicoClaw, PicoClaw, PicoClaw (+7 more)
                🏢 Vendor: Sipeed
                📅 Updated: 2026-07-18

                📝 A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This issue affects the function dispatchIncoming of the file pkg/channels/wecom/wecom.go of the component Group Message Handler. The manipulation results in inc...

                🔗 euvd.enisa.europa.eu/vulnerabi

                  [?]EUVD Bot » 🤖 🌐
                  @EUVD_Bot@mastodon.social

                  🚨 EUVD-2026-45405

                  📊 Score: 8.8/10 (CVSS v3.1)
                  📦 Product: QueryWeaver, QueryWeaver
                  🏢 Vendor: FalkorDB
                  📅 Updated: 2026-07-18

                  📝 QueryWeaver contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain valid session tokens for existing accounts by submitting a signup request with a known victim email address. The signup route uncond...

                  🔗 euvd.enisa.europa.eu/vulnerabi

                    [?]TechWire ⚡ » 🤖 🌐
                    @techwire@social.gamefan.net

                    iOS 27: My favorite new iPhone features (other than AI)

                    The iOS 27 public beta is here, and the headlining changes are Siri AI and the array of new Apple Intelligence features. However, the update also includes plenty of non-AI features. Here are a few of my favorite iOS 27 …

                    9to5mac.com/2026/07/14/ios-27-

                    [9to5Mac]

                      [?]urlDNA.io :verified: » 🤖 🌐
                      @urldna@infosec.exchange

                      Possible Phishing 🎣
                      on: ⚠️hxxp[:]//www[.]365wtvip[.]cc/
                      🧬 Analysis at: urldna.io/scan/6a5bb13d3b77500

                        [?]TechWire ⚡ » 🤖 🌐
                        @techwire@social.gamefan.net

                        Limited series ‘Lucky’, starring Anya Taylor-Joy, premieres on Apple TV

                        The first episodes of Lucky, Apple TV’s new limited series starring Anya Taylor-Joy (The Menu), are now streaming. Watch the trailer below.

                        9to5mac.com/2026/07/14/limited

                        [9to5Mac]

                          [?]TheHackerWire » 🤖 🌐
                          @thehackerwire@mastodon.social

                          🟠 CVE-2026-14499 - High (8.8)

                          IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input in the Python Interpreter component.

                          🔗 thehackerwire.com/vulnerabilit

                          CVE Alert: CVE-2026-14499

                          Alt...CVE Alert: CVE-2026-14499

                            [?]TheHackerWire » 🤖 🌐
                            @thehackerwire@mastodon.social

                            🟠 CVE-2026-58195 - High (8.8)

                            Agentic-Flow is an AI agent orchestration platform. Prior to 2.0.14, agentic-flow MCP server tools in src/mcp/standalone-stdio.ts, src/mcp/fastmcp/servers/claude-flow-sdk.ts, src/mcp/fastmcp/servers/stdio-full.ts, src/mcp/fastmcp/servers/http-stre...

                            🔗 thehackerwire.com/vulnerabilit

                            CVE Alert: CVE-2026-58195

                            Alt...CVE Alert: CVE-2026-58195

                              [?]TheHackerWire » 🤖 🌐
                              @thehackerwire@mastodon.social

                              🟠 CVE-2026-52746 - High (7.5)

                              JSONata is a JSON query and transformation language. Prior to 2.2.0, malicious non-matching inputs to the $toMillis function can cause superlinear backtracking in the ISO-8601 validation regex, leading to denial of service in applications that eva...

                              🔗 thehackerwire.com/vulnerabilit

                              CVE Alert: CVE-2026-52746

                              Alt...CVE Alert: CVE-2026-52746

                                [?]TheHackerWire » 🤖 🌐
                                @thehackerwire@mastodon.social

                                🟠 CVE-2026-45162 - High (8)

                                Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, multiple Pimcore locations call PHP's unserialize() on data from database columns and filesystem files without the allowed_classes restriction, inc...

                                🔗 thehackerwire.com/vulnerabilit

                                CVE Alert: CVE-2026-45162

                                Alt...CVE Alert: CVE-2026-45162

                                  [?]TheHackerWire » 🤖 🌐
                                  @thehackerwire@mastodon.social

                                  🔴 CVE-2026-9198 - Critical (9.8)

                                  IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow de...

                                  🔗 thehackerwire.com/vulnerabilit

                                  CVE Alert: CVE-2026-9198

                                  Alt...CVE Alert: CVE-2026-9198

                                    [?]TechWire ⚡ » 🤖 🌐
                                    @techwire@social.gamefan.net

                                    Apple Arcade adding the ultimate NFL game just in time for football season

                                    Apple Arcade is scoring a major hit game in August. Apple announced today that the subscription game service will add Madden NFL 27 Arcade Edition on August 6. The new game will arrive just before the new NFL pre-season…

                                    9to5mac.com/2026/07/14/apple-a

                                    [9to5Mac]

                                      [?]TechWire ⚡ » 🤖 🌐
                                      @techwire@social.gamefan.net

                                      IDC: Apple shipped nearly 1 in 5 smartphones in China in Q2 2026

                                      In a report published today, IDC said Huawei and Apple were the only smartphone makers to record shipment growth in China during the second quarter of 2026. Here are the details.

                                      9to5mac.com/2026/07/14/idc-app

                                      [9to5Mac]

                                        [?]The New Oil » 🤖 🌐
                                        @thenewoil@mastodon.thenewoil.org

                                        [?]CyberIntel News » 🌐
                                        @cyberintelnews@mastodon.social

                                        New CyberIntel brief: Survey Finds Organizations Pressure Employees to Keep Security Breaches Confidential

                                        cyberintelnews.com/

                                          [?]Avoca » 🌐
                                          @avoca@gladtech.social

                                          [?]TechWire ⚡ » 🤖 🌐
                                          @techwire@social.gamefan.net

                                          Anthropic is giving teachers free access to premium Claude features, details here

                                          Anthropic is providing free access to premium Claude AI features to K-12 teachers in the United States. The effort is part of a new Claude for Teachers initiative.

                                          9to5mac.com/2026/07/14/anthrop

                                          [9to5Mac]

                                            [?]TechWire ⚡ » 🤖 🌐
                                            @techwire@social.gamefan.net

                                            Dave Eggers told OpenAI staff that ChatGPT was ‘silencing an entire generation’

                                            Dave Eggers attends the "The Turning Point: To Be Destroyed" premiere. | Image: John Lamparski/Getty Images for Tribeca Festival Last year, Sam Altman invited author Dave Eggers to give a talk to around 200 OpenAI staff…

                                            theverge.com/ai-artificial-int

                                            [The Verge]

                                              [?]EUVD Bot » 🤖 🌐
                                              @EUVD_Bot@mastodon.social

                                              🚨 EUVD-2026-45397

                                              📊 Score: 5.3/10 (CVSS v3.1)
                                              📦 Product: carto-api-client
                                              🏢 Vendor: CartoDB
                                              📅 Updated: 2026-07-18

                                              📝 A vulnerability has been found in CartoDB carto-api-client 0.5.29. This impacts the function addFilter of the file src/filters.ts. Such manipulation of the argument column leads to improperly controlled modification of object prototype attributes. T...

                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                [?]EUVD Bot » 🤖 🌐
                                                @EUVD_Bot@mastodon.social

                                                🚨 EUVD-2026-45396

                                                📊 Score: 7.7/10 (CVSS v3.1)
                                                📦 Product: ProFTPD
                                                🏢 Vendor: ProFTPD Project
                                                📅 Updated: 2026-07-18

                                                📝 ProFTPD mod_sftp contains a heap-based buffer overflow reachable by an authenticated SFTP user. The fxp_packet_read() function accepts the attacker-supplied 32-bit big-endian SFTP packet length without a minimum sanity check. A value of 0 causes an u...

                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                  [?]EUVD Bot » 🤖 🌐
                                                  @EUVD_Bot@mastodon.social

                                                  🚨 EUVD-2026-45395

                                                  📊 Score: 6.8/10 (CVSS v3.1)
                                                  📦 Product: Stoat for Android
                                                  🏢 Vendor: stoatchat
                                                  📅 Updated: 2026-07-18

                                                  📝 Stoat for Android exports the chat.stoat.activities.ShareTargetActivity component (reachable to any process on the device via the android.intent.action.SEND intent) and accepts the file to share as a URI supplied through the android.intent.extra....

                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                    [?]EUVD Bot » 🤖 🌐
                                                    @EUVD_Bot@mastodon.social

                                                    🚨 EUVD-2026-45394

                                                    📊 Score: 5.3/10 (CVSS v3.1)
                                                    📦 Product: Inputmask, Inputmask, Inputmask (+7 more)
                                                    🏢 Vendor: RobinHerbots
                                                    📅 Updated: 2026-07-18

                                                    📝 A vulnerability was found in RobinHerbots Inputmask up to 5.0.9. Affected by this issue is the function extendDefaults/extendDefinitions/extendAliases in the library lib/dependencyLibs/extend.js of the component Interna...

                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                      [?]urlDNA.io :verified: » 🤖 🌐
                                                      @urldna@infosec.exchange

                                                      Possible Phishing 🎣
                                                      on: ⚠️hxxps[:]//wadeswarehouse[.]com/ads-docusig[.]html
                                                      🧬 Analysis at: urldna.io/scan/6a5ba32c3b77500

                                                        [?]TierraSapiens » 🤖 🌐
                                                        @tierrasapiens@mastodon.social

                                                        🖲️
                                                        ⚫ Forgotten Bootloaders Expose Secure Boot Blind Spot
                                                        🔗 darkreading.com/cyber-risk/for

                                                        Nearly a dozen vulnerable and now revoked UEFI shim bootloaders remained trusted for years, giving attackers a path to bypass Secure Boot.

                                                          [?]TechWire ⚡ » 🤖 🌐
                                                          @techwire@social.gamefan.net

                                                          Leaker says next iPad mini will stick with a 60Hz display despite OLED upgrade

                                                          Apple’s next iPad mini might miss out on ProMotion despite switching to OLED, per leaker yeux1122. Here are the details.

                                                          9to5mac.com/2026/07/14/leaker-

                                                          [9to5Mac]

                                                            [?]Malicious Extension Bot » 🤖 🌐
                                                            @malicious_browser_bot@infosec.exchange

                                                            extension Happy easter seems malicious. Its badness score is 94/100!

                                                            ```json
                                                            {"id": "kipeiplohldbbalmchafbfnnpnenonlg", "score": 94, "platform": "chrome", "name": "Happy easter"}
                                                            ```

                                                              [?]Malicious Extension Bot » 🤖 🌐
                                                              @malicious_browser_bot@infosec.exchange

                                                              extension Light Yagami Death Note Live Wallpaper seems malicious. Its badness score is 99/100!

                                                              ```json
                                                              {"id": "icjkaoepdngbaakafgjoiicgjloncjhd", "score": 99, "platform": "chrome", "name": "Light Yagami Death Note Live Wallpaper"}
                                                              ```

                                                                [?]Malicious Extension Bot » 🤖 🌐
                                                                @malicious_browser_bot@infosec.exchange

                                                                extension Yuji Itadori from Jujutsu Kaisen Live Wallpaper seems malicious. Its badness score is 85/100!

                                                                ```json
                                                                {"id": "icjlgklmnnljflhhcmhoklpgedppamap", "score": 85, "platform": "chrome", "name": "Yuji Itadori from Jujutsu Kaisen Live Wallpaper"}
                                                                ```

                                                                  [?]Malicious Extension Bot » 🤖 🌐
                                                                  @malicious_browser_bot@infosec.exchange

                                                                  extension Keroppi Wallpapers New Tab seems malicious. Its badness score is 91/100!

                                                                  ```json
                                                                  {"id": "dldbdcpgbgbefbjeljfofbijamjdbkpb", "score": 91, "platform": "chrome", "name": "Keroppi Wallpapers New Tab"}
                                                                  ```

                                                                    [?]Malicious Extension Bot » 🤖 🌐
                                                                    @malicious_browser_bot@infosec.exchange

                                                                    extension Hiyuki Dance of the Frostblade (WuWa) Live Wallpaper seems malicious. Its badness score is 97/100!

                                                                    ```json
                                                                    {"id": "cmbbakgpfghgekiehoadnhgcogpbfgip", "score": 97, "platform": "chrome", "name": "Hiyuki Dance of the Frostblade (WuWa) Live Wallpaper"}
                                                                    ```

                                                                      [?]SagaLinked » 🤖 🌐
                                                                      @sagalinked@mastodon.social

                                                                      📰 Coca-Cola suspended production at its Fairlife dairy unit in the United States due to a ransomware attack.

                                                                      🔗 techcrunch.com/2026/07/16/coca

                                                                        [?]SagaLinked | CYBER NEWS » 🤖 🌐
                                                                        @sagalinked@infosec.exchange

                                                                        📰 Coca-Cola suspended production at its Fairlife dairy unit in the United States due to a ransomware attack.

                                                                        🔗 techcrunch.com/2026/07/16/coca

                                                                          [?]TheHackerWire » 🤖 🌐
                                                                          @thehackerwire@mastodon.social

                                                                          🟠 CVE-2026-9323 - High (8.1)

                                                                          The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.start() by concatenating two random.randrange(10**9) calls that use Python's Mersenne Twister PRNG, which is not cryptographically secure. ...

                                                                          🔗 thehackerwire.com/vulnerabilit

                                                                          CVE Alert: CVE-2026-9323

                                                                          Alt...CVE Alert: CVE-2026-9323

                                                                            [?]TheHackerWire » 🤖 🌐
                                                                            @thehackerwire@mastodon.social

                                                                            🟠 CVE-2026-11826 - High (8.8)

                                                                            OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core/modbus_master.cpp. getData() reads characters between two delimiters into a caller-supplied buffer with no size parameter and no bounds check. In parseCon...

                                                                            🔗 thehackerwire.com/vulnerabilit

                                                                            CVE Alert: CVE-2026-11826

                                                                            Alt...CVE Alert: CVE-2026-11826

                                                                              [?]TheHackerWire » 🤖 🌐
                                                                              @thehackerwire@mastodon.social

                                                                              🔴 CVE-2026-16117 - Critical (10)

                                                                              Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's router URL-decodes paths for route matching, but request.url retains the original encoded form, an...

                                                                              🔗 thehackerwire.com/vulnerabilit

                                                                              CVE Alert: CVE-2026-16117

                                                                              Alt...CVE Alert: CVE-2026-16117

                                                                                [?]TheHackerWire » 🤖 🌐
                                                                                @thehackerwire@mastodon.social

                                                                                🟠 CVE-2026-7667 - High (8.8)

                                                                                IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an attacker-controlled URL that returns a specially crafted Content-Disposition header (e.g., filename="../../../target/path" ), enabling...

                                                                                🔗 thehackerwire.com/vulnerabilit

                                                                                CVE Alert: CVE-2026-7667

                                                                                Alt...CVE Alert: CVE-2026-7667

                                                                                  [?]TheHackerWire » 🤖 🌐
                                                                                  @thehackerwire@mastodon.social

                                                                                  🟠 CVE-2026-7754 - High (7.7)

                                                                                  IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure default configuration and incomplete enforcement of the SSRF protection mechanism.

                                                                                  🔗 thehackerwire.com/vulnerabilit

                                                                                  CVE Alert: CVE-2026-7754

                                                                                  Alt...CVE Alert: CVE-2026-7754

                                                                                    [?]TheHackerWire » 🤖 🌐
                                                                                    @thehackerwire@mastodon.social

                                                                                    🔴 CVE-2026-63030 - Critical (9.8)

                                                                                    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection an...

                                                                                    🔗 thehackerwire.com/vulnerabilit

                                                                                    CVE Alert: CVE-2026-63030

                                                                                    Alt...CVE Alert: CVE-2026-63030

                                                                                      [?]TheHackerWire » 🤖 🌐
                                                                                      @thehackerwire@mastodon.social

                                                                                      🟠 CVE-2026-50151 - High (7.5)

                                                                                      oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completePushAfterInitialPost follows a registry-controlled Location header during monolithic blob upload and reuses the Authorization he...

                                                                                      🔗 thehackerwire.com/vulnerabilit

                                                                                      CVE Alert: CVE-2026-50151

                                                                                      Alt...CVE Alert: CVE-2026-50151

                                                                                        Back to top - More...