voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
⚠️ #JOMANGY malware hijacks your FreePBX system and runs fraudulent calls on SIP trunks — billed to you.
❗️ 6 self-healing persistence layers. 700+ businesses still infected 5 months later. Is your PBX off the internet?
See the impact of this threat: https://any.run/malware-trends/jomangy/?utm_source=mastodon&utm_medium=post&utm_campaign=jomangy_mtt&utm_term=080626&utm_content=linktomtt
🚨 CRITICAL: CVE-2026-11499 in Tenda HG7HG9/HG10 (firmware 300001138_en_xpon) allows remote stack-based buffer overflow via blkDomain in formDOMAINBLK. No patch yet — restrict access and monitor traffic. https://radar.offseq.com/threat/cve-2026-11499-stack-based-buffer-overflow-in-tend-ca49c238 #OffSeq #Vuln #IoT #CyberSecurity
Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms
From January through May 2026, a financially motivated data theft extortion campaign executed by threat cluster UNC3753 targeted dozens of organizations across professional, legal, and financial services in the United States. The threat actors leverage voice phishing and social engineering techniques, posing as IT support to convince targets to host screen-sharing sessions and download remote monitoring and management utilities. Once inside environments, they conduct searches to locate and exfiltrate highly sensitive data including proprietary legal agreements, personally identifiable information, and financial records for subsequent extortion demands. The entire attack sequence often occurs within a single business day, with recent incidents showing data theft initiated in under an hour. Notably, threat actors have also accessed victims' systems in person, with individuals posing as IT technicians entering corporate offices to attempt direct exfiltration using USB storage media.
Pulse ID: 6a231076a2659c774fa84285
Pulse Link: https://otx.alienvault.com/pulse/6a231076a2659c774fa84285
Pulse Author: AlienVault
Created: 2026-06-05 18:07:50
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DataTheft #Extortion #InfoSec #OTX #Office #OpenThreatExchange #Phishing #RAT #SocialEngineering #USB #UnitedStates #bot #AlienVault
VerdantBamboo: Just Another BRICKSTORM in the Firewall
Chinese threat actor VerdantBamboo compromised a victim organization and its Managed Services Provider over an 18-month period, deploying malware on network edge devices lacking EDR coverage. The initial breach involved an Egnyte Storage Sync system, where attackers exploited a sudo misconfiguration for privilege escalation and installed BRICKSTORM backdoor and AGENTPSD fallback implant. Investigation revealed the MSP's pfSense firewall was also compromised with a FreeBSD variant of BRICKSTORM. After remediation, VerdantBamboo regained access through stolen firewall credentials, enabling custom VPN access and deploying PLENET backdoor on a Synology NAS. The threat actor leveraged compromised systems as proxies to access Microsoft 365 environments while evading security controls. VerdantBamboo demonstrated operational discipline by targeting appliances without EDR capabilities and using sophisticated malware including PLENET, compiled with .NET Native AOT to hinder analysis.
Pulse ID: 6a2310765ec1df9836ee072f
Pulse Link: https://otx.alienvault.com/pulse/6a2310765ec1df9836ee072f
Pulse Author: AlienVault
Created: 2026-06-05 18:07:50
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Chinese #CyberSecurity #EDR #Edge #InfoSec #Malware #Microsoft #NET #OTX #OpenThreatExchange #RAT #VPN #bot #AlienVault
Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257
An unidentified threat actor is actively exploiting CVE-2026-0257, an authentication bypass vulnerability in PAN-OS GlobalProtect portal and gateway components. The flaw allows unauthorized attackers to circumvent security controls and initiate VPN connections. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on May 29, 2026. Exploitation activity has been detected targeting GlobalProtect, with a small portion of probed devices successfully establishing VPN sessions. No post-access behavior or lateral movement has been identified. Organizations are advised to hunt for indicators including specific IP addresses, suspicious host IDs, and MAC addresses. Palo Alto Networks recommends following security advisory guidance, implementing available workarounds, and upgrading to patched versions.
Pulse ID: 6a230a1d075271a064d3f708
Pulse Link: https://otx.alienvault.com/pulse/6a230a1d075271a064d3f708
Pulse Author: AlienVault
Created: 2026-06-05 17:40:45
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CISA #CyberSecurity #InfoSec #Mac #OTX #OpenThreatExchange #PaloAlto #VPN #Vulnerability #bot #AlienVault
Child Identity Theft: When the First Debt Arrives at 18 https://deafnews.it/en/article/child-identity-theft-when-the-first-debt-arrives-at-18 #Cybersecurity
Here’s how Google is quietly reimagining how you use your Android phone
AppFunctions is the genie that will make it all work together.
https://www.androidauthority.com/google-android-appfunctions-explained-3673380/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Vertiv prezentuje pierwszego cyfrowego bliźniaka konwergentnej infrastruktury fizycznej dla NVIDIA Omniverse DSX. Oparta na modelach funkcja cyfrowego bliźniaka Vertiv SmartRun pomaga przyspieszyć procesy projektowania, symulacji i wdrażania fabryk AI. https://linuxiarze.pl/vertiv-prezentuje-pierwszego-cyfrowego-blizniaka-konwergentnej-infrastruktury-fizycznej-dla-nvidia-omniverse-dsx/ #sztucznainteligencja #cybersecurity
Vertiv prezentuje pierwszego cyfrowego bliźniaka konwergentnej infrastruktury fizycznej dla NVIDIA Omniverse DSX. Oparta na modelach funkcja cyfrowego bliźniaka Vertiv SmartRun pomaga przyspieszyć procesy projektowania, symulacji i wdrażania fabryk AI. https://linuxiarze.pl/vertiv-prezentuje-pierwszego-cyfrowego-blizniaka-konwergentnej-infrastruktury-fizycznej-dla-nvidia-omniverse-dsx/ #sztucznainteligencja #cybersecurity
HomeKit Weekly: SwitchBot launches a battery-powered standing fan with Apple Home integration
Fans are one of those categories where true innovation is kind of hard to find. Ultimately, it’s just there to cool things and circulate air. SwitchBot recently launched its new SwitchBot Standing Circulator Fan, which …
https://9to5mac.com/2026/06/05/switchbot-standing-circulator-fan/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
Possible Phishing 🎣
on: ⚠️hxxps[:]//rohit-kumar-0407[.]github[.]io/Amazon-Clone/
🧬 Analysis at: https://urldna.io/scan/6a25e3ab3b77500006e830b8
#cybersecurity #phishing #infosec #urldna #scam #infosec
Miasma Worm Campaign Spreads with New PyPI Wave
A coordinated PyPI compromise campaign involving 37 malicious wheel artifacts across 19 packages was detected, utilizing Python startup hooks to execute credential-stealing payloads. The attack leverages .pth files for automatic execution during Python interpreter startup, downloads the Bun JavaScript runtime, and runs obfuscated JavaScript payloads. The malware targets high-value developer and CI/CD credentials including GitHub, npm, PyPI, cloud providers (AWS, GCP, Azure), Kubernetes, Vault, SSH keys, and AI tool tokens. This represents a PyPI branch of the Shai-Hulud/Miasma campaign family, using a Hades-themed variant for GitHub exfiltration. Compromised packages included established bioinformatics tools with significant download counts, stemming from apparent maintainer account takeover. The payload employs multi-layer obfuscation, AES-GCM encryption, and exfiltrates data through GitHub repositories with distinctive markers. The campaign demonstrates cross-runtime attack capabilities and ecosystem-spe...
Pulse ID: 6a255457476fc6d2bbe99c64
Pulse Link: https://otx.alienvault.com/pulse/6a255457476fc6d2bbe99c64
Pulse Author: AlienVault
Created: 2026-06-07 11:21:59
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #Azure #Cloud #CyberSecurity #Encryption #GitHub #ICS #InfoSec #Java #JavaScript #Malware #NPM #OTX #OpenThreatExchange #PyPI #Python #RAT #SSH #Worm #bot #AlienVault
After 17 years in cybersecurity and leadership roles at Sourcefire, Palo Alto Networks, Baffin Bay Networks and Zscaler, James Tucker has earned a hearing. In this interview, he discusses AI-era threats, ethical hacking, legacy systems, and why blaming users for security mistakes gets organisations nowhere.
Read the interview: https://www.techfinitive.com/interviews/james-tucker-head-of-ciso-international-at-zscaler/
#chrome extension Muted Peak – Privacy Mini seems malicious. Its #cybersecurity badness score is 95/100!
```json
{"id": "cjkcloaoljficalpjnfcfhlobidchoee", "score": 95, "platform": "chrome", "name": "Muted Peak \u2013 Privacy Mini"}
```
#chrome extension Gemini Studio App seems malicious. Its #cybersecurity badness score is 85/100!
```json
{"id": "oondabmhecdagnndhjhgnhhhnninpagc", "score": 85, "platform": "chrome", "name": "Gemini Studio App"}
```
#chrome extension Backlink Generator seems malicious. Its #cybersecurity badness score is 95/100!
```json
{"id": "olhagmdfojhfdbfgmiofiofnifcmehdb", "score": 95, "platform": "chrome", "name": "Backlink Generator"}
```
#chrome extension HideMyName VPN seems malicious. Its #cybersecurity badness score is 93/100!
```json
{"id": "jageecdigmlcciccgcbifiidgfoafjke", "score": 93, "platform": "chrome", "name": "HideMyName VPN"}
```
Samsung Galaxy S27 Pro battery size may have just leaked, and now we’re excited
The battery upgrade everyone can appreciate.
https://www.androidauthority.com/samsung-galaxy-s27-pro-battery-leak-3675317/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
1k Data Breaches Later, the Disclosure Lag Is Worse
https://www.troyhunt.com/1000-data-breaches-later-the-disclosure-lag-is-worse-than-ever/
#HackerNews #data #breaches #cybersecurity #disclosure #lag #privacy #issues #information #security
Edge Tab-Splitting and Invisible Phishing: The Pwn2Own Flaw https://deafnews.it/en/article/edge-tab-splitting-and-invisible-phishing-the-pwn2own-flaw #Cybersecurity
Heading to Apple Park for WWDC? There is new merch waiting for you at the Visitor Center store
The Apple Park Visitor Center store got a fresh batch of merch today ahead of next week’s WWDC, when Apple is expected to welcome more than 1,000 developers, students, journalists, and other guests to its campus. more…
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
iOS 27 bill splitting, new hardware waiting on new Siri, final WWDC expectations
Benjamin and Chance talk about the late-breaking iOS 27 rumors, including a new bill splitting feature for the Wallet app, as well as give their final expectations for next week’s WWDC announcements. Apple fixes Mayo’s …
https://9to5mac.com/2026/06/04/happy-hour-593/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
Possible Phishing 🎣
on: ⚠️hxxp[:]//fullaski[.]com/longman/ourtimepge/v3/index[.]html
🧬 Analysis at: https://urldna.io/scan/6a25570c3b77500003c14143
#cybersecurity #phishing #infosec #urldna #scam #infosec
Room Keys in Apple Wallet are coming to more hotels through Salto
Smart access company Salto has announced that its hospitality platform now supports Room Keys in Apple Wallet. Here are the details. more…
https://9to5mac.com/2026/06/04/room-keys-in-apple-wallet-are-coming-to-more-hotels-through-salto/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
Lamine Yamal teases second color of upcoming Beats headphones
Soccer sensation Lamine Yamal has published a second photo featuring a pair of unreleased Beats headphones. Here are the details. more…
https://9to5mac.com/2026/06/04/lamine-yamal-teases-second-color-of-upcoming-beats-headphones/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
Possible Phishing 🎣
on: ⚠️hxxp[:]//clubeamigosdopedrosegundo[.]com[.]br/list/index[.]php?email=abuse@brain[.]net[.]pk
🧬 Analysis at: https://urldna.io/scan/6a25f8173b77500006e83301
#cybersecurity #phishing #infosec #urldna #scam #infosec
🚨 EUVD-2026-35013
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: Class and Exam Timetabling System
🏢 Vendor: SourceCodester
📅 Updated: 2026-06-08
📝 A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is an unknown function of the file /archive5.php. The manipulation of the argument sy leads to sql injection. The at...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-35013
🚨 EUVD-2026-35012
📊 Score: 2.0/10 (CVSS v3.1)
📦 Product: grepai, grepai, grepai (+32 more)
🏢 Vendor: yoanbernabeu
📅 Updated: 2026-06-08
📝 A vulnerability was determined in yoanbernabeu grepai up to 0.35.0. The affected element is the function PostgresStore.LookupByContentHash of the file indexer/chunker.go of the component Postgres Embedding Cache. Executing a ma...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-35012
🚨 EUVD-2026-35011
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: BeikeShop, BeikeShop, BeikeShop (+20 more)
🏢 Vendor: Chengdu Everbrite Network Technology
📅 Updated: 2026-06-08
📝 A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. Impacted is an unknown function of the file beike/Admin/Routes/admin.php of the component Admin Design...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-35011
🚨 EUVD-2026-35010
📊 Score: 2.3/10 (CVSS v3.1)
📦 Product: grepai
🏢 Vendor: yoanbernabeu
📅 Updated: 2026-06-08
📝 A vulnerability has been found in yoanbernabeu grepai 0.35.0. This issue affects some unknown processing of the file indexer/chunker.go of the component Qdrant Backend. Such manipulation leads to use of weak hash. The attack may be performed from remote....
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-35010
🚨 EUVD-2026-35009
📊 Score: 4.8/10 (CVSS v3.1)
📦 Product: tiny-regex-c
🏢 Vendor: kokke
📅 Updated: 2026-06-08
📝 A flaw has been found in kokke tiny-regex-c up to f2632c6d9ed25272987471cdb8b70395c2460bdb. This vulnerability affects the function matchstar of the file re.c of the component Pattern Handler. This manipulation causes inefficient regular expression comple...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-35009
Microsoft Backtracks on Legal Threats Against Zero-Day Researcher Following Industry Backlash https://deafnews.it/en/article/microsoft-backtracks-on-legal-threats-against-zero-day-researcher-following-industry-backlash #Cybersecurity
Epic Games asks U.S. Supreme Court to deny Apple’s petition in App Store case
Epic Games is asking the U.S. Supreme Court to reject Apple’s latest attempt to challenge two rulings in its long-running legal fight over off-App-Store purchases. Here are the details. more…
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
Apple TV debuts a new series remake of thriller Cape Fear, stream now
Apple TV debuts a new remake of thriller Cape Fear. This latest limited series adaptation is star-studded, with Amy Adams, Javier Bardem and Patrick Wilson headlining the cast. Inspired by the 1991 movie, in Cape Fear, …
https://9to5mac.com/2026/06/04/apple-tv-new-thriller-cape-fear/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
Possible Phishing 🎣
on: ⚠️hxxps[:]//zmail-tnebnet-org-zimbra-login[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a258f523b77500002dca933
#cybersecurity #phishing #infosec #urldna #scam #infosec
iOS 27: You might have to join a waitlist to try new Siri features
Apple is set to announce iOS 27 and an all-new version of Siri at WWDC in just a few days. Ahead of that, Bloomberg has published a monster recap of everything to expect at the event. There’s one specifically interestin…
https://9to5mac.com/2026/06/05/ios-27-you-might-have-to-join-a-waitlist-to-try-new-siri-features/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
🚨 EUVD-2026-34993
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: BeikeShop, BeikeShop, BeikeShop (+20 more)
🏢 Vendor: Chengdu Everbrite Network Technology
📅 Updated: 2026-06-07
📝 A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. This impacts the function callback of the file plugins/Stripe/Controllers/StripeController.php of the ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34993
Deals: AirPods Max 2 hit Amazon all-time low, AirPods Pro 3, iPhone Air $149 off, Watch bands from $15, more
Joining AirPods Pro 3 at one of the lowest prices to date and AirPods 4 at nearly 25% off, today’s 9to5Toys Lunch Break is headlined by Apple’s new AirPods Max 2 hitting the best price ever. Best Buy has indeed launched…
https://9to5mac.com/2026/06/04/deals-airpods-max-2-airpods-pro-3-iphone-air/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
Law firms, beware: The Silent Ransom Group (SRG), tracked as UNC3753, Luna Moth, and Chatty Spider, has evolved its tactics beyond traditional ransomware. They're now using sophisticated social engineering, including fake IT support calls and in-person visits, to exploit human trust, gain remote access, and exfiltrate high-value data for aggressive extortion. This shift bypasses technical…
#cybersecurity #silentransomgroup #srg
🤖 This post was AI-generated.
I built the ultimate Cosmic Orange iPhone everyday carry [Video]
When Apple unveiled the Cosmic Orange iPhone 17 Pro and Pro Max, I was a bit skeptical. Apple usually reserves more “professional” and dull colors for the Pro models and the more vibrant colors for the regular iPhone li…
https://9to5mac.com/2026/06/04/i-built-the-ultimate-cosmic-orange-iphone-everyday-carry-video/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
Possible Phishing 🎣
on: ⚠️hxxp[:]//amazon-clone-jade-three[.]vercel[.]app
🧬 Analysis at: https://urldna.io/scan/6a23a9563b775000044d2738
#cybersecurity #phishing #infosec #urldna #scam #infosec