voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]TheHackerWire » 🤖 🌐
@thehackerwire@mastodon.social

🟠 CVE-2026-11136 - High (8.8)

Use after free in Canvas in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

🔗 thehackerwire.com/vulnerabilit

CVE Alert: CVE-2026-11136

Alt...CVE Alert: CVE-2026-11136

    [?]BeyondMachines :verified: » 🤖 🌐
    @beyondmachines1@infosec.exchange

    Critical RCE Vulnerability in Hugging Face Transformers Bypasses Security Settings

    Hugging Face patched a high-severity RCE vulnerability (CVE-2026-4372) in the Transformers library that allowed malicious models to execute arbitrary code during routine loading, even when security flags were disabled.

    **If you use the Hugging Face Transformers library with the `kernels` package installed, update to version 5.3.0 or later ASAP. After updating, audit your cached model configurations for any suspicious `_attn_implementation_internal` field and avoid loading models from untrusted sources.**

    beyondmachines.net/event_detai

      [?]OTX Bot » 🤖 🌐
      @techbot@social.raytec.co

      Matryoshka #3/3: Gamaredon's Gammasteel Infostealer

      This analysis examines Gamaredon's (UAC-0010, Armagedon) advanced espionage operations targeting Ukrainian government, military, and critical infrastructure. The FSB-operated group deploys GammaSteel, a sophisticated stealer operating almost entirely from memory using Windows DPAPI encryption and storing 71 distinct payload functions in the HKCU\Printers registry key. The malware employs three concurrent data acquisition mechanisms: timed drive scans, USB monitoring for air-gapped systems, and real-time file surveillance. Exfiltration occurs via legitimate S3-compatible cloud storage (Tebi.io) with fallback to operator-controlled servers. The infection chain extensively uses VBScript for evasion, Dead Drop Resolvers on platforms like Telegram and Mastodon for C2 configuration, and includes bidirectional backdoor capabilities enabling arbitrary remote code execution. Infrastructure demonstrates high automation with servers rotated approximately every 24 hours.

      Pulse ID: 6a21844636a81843ce1af3cc
      Pulse Link: otx.alienvault.com/pulse/6a218
      Pulse Author: AlienVault
      Created: 2026-06-04 13:57:26

      Be advised, this data is unverified and should be considered preliminary. Always do further verification.

        [?]deafnews » 🤖 🌐
        @deafnews@infosec.exchange

        [?]Mastodon Trends South Africa » 🤖 🌐
        @trendsZA@mastodon.africa

        The following hashtags are trending across South African Mastodon instances:










        Based on recent posts made by non-automated accounts. Posts with more boosts, favourites, and replies are weighted higher.

          [?]TechWire ⚡ » 🤖 🌐
          @techwire@social.gamefan.net

          Google wants your phone to track your heart rate by simply looking at you

          Your smartphone may soon feel your beat.

          androidauthority.com/google-ph

          [Android Authority]

            [?]TechWire ⚡ » 🤖 🌐
            @techwire@social.gamefan.net

            I’ve had the Oura Ring 5 for 72 hours, and it’s already one of my favorite smart rings

            A slimmer profile makes a stronger first impression.

            androidauthority.com/oura-ring

            [Android Authority]

              [?]urlDNA.io :verified: » 🤖 🌐
              @urldna@infosec.exchange

              Possible Phishing 🎣
              on: ⚠️hxxps[:]//is[.]gd/uwOhyk
              🧬 Analysis at: urldna.io/scan/6a21b6d83b77500

                [?]TechWire ⚡ » 🤖 🌐
                @techwire@social.gamefan.net

                Samsung can’t stop sending new Play system updates, after making us pine last year

                Samsung went from zero Play system updates to seven in the last six months.

                androidauthority.com/samsung-g

                [Android Authority]

                  [?]RedPacket Security » 🌐
                  @RedPacketSecurity@mastodon.social

                  [?]heise online » 🌐
                  @heiseonline@social.heise.de

                  Mythos Preview: Anthropic unterstützt NSA angeblich bei offensivem KI-Einsatz

                  Mehrere Angestellte von Anthropic arbeiten einem Zeitungsbericht zufolge direkt bei der NSA daran, die mächtige Mythos-KI für offensive Einsätze fit zu machen.

                  heise.de/news/Mythos-Preview-A

                  [?]TechWire ⚡ » 🤖 🌐
                  @techwire@social.gamefan.net

                  Noctua shows off improved thermosiphon prototype — passively circulated liquid cooler gets Q3 2027 projec…

                  Noctua showed off a refined version of its passively circulated thermosiphon liquid cooler at Computex 2026 with an improved evaporator design. The company is confident enough in its progress with this product to set a …

                  tomshardware.com/pc-components

                  [Tom's Hardware]

                    [?]TheHackerWire » 🤖 🌐
                    @thehackerwire@mastodon.social

                    🟠 CVE-2026-11262 - High (8.8)

                    Use after free in TabStrip in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)

                    🔗 thehackerwire.com/vulnerabilit

                    CVE Alert: CVE-2026-11262

                    Alt...CVE Alert: CVE-2026-11262

                      [?]TheHackerWire » 🤖 🌐
                      @thehackerwire@mastodon.social

                      🟠 CVE-2026-11239 - High (7.5)

                      Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)

                      🔗 thehackerwire.com/vulnerabilit

                      CVE Alert: CVE-2026-11239

                      Alt...CVE Alert: CVE-2026-11239

                        [?]urlDNA.io :verified: » 🤖 🌐
                        @urldna@infosec.exchange

                        Possible Phishing 🎣
                        on: ⚠️hxxp[:]//webaccess-email[.]com/s/63BZGFSVBWSFCDX7Y9/584dd8/90eab167-7429-489f-99f6-ce86e8d0d81a
                        🧬 Analysis at: urldna.io/scan/6a21bd303b77500

                          [?]EUVD Bot » 🤖 🌐
                          @EUVD_Bot@mastodon.social

                          🚨 EUVD-2026-34784

                          📊 Score: 7.3/10 (CVSS v3.1)
                          📦 Product: Graphite
                          🏢 Vendor: Graphite project
                          📅 Updated: 2026-06-05

                          📝 Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range.

                          🔗 euvd.enisa.europa.eu/vulnerabi

                            [?]EUVD Bot » 🤖 🌐
                            @EUVD_Bot@mastodon.social

                            🚨 EUVD-2026-34403

                            📊 Score: 8.8/10 (CVSS v3.1)
                            📦 Product: Chrome
                            🏢 Vendor: Google
                            📅 Published: 2026-06-04 | Updated: 2026-06-05

                            📝 Use after free in Actor in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

                            🔗 euvd.enisa.europa.eu/vulnerabi

                              [?]EUVD Bot » 🤖 🌐
                              @EUVD_Bot@mastodon.social

                              🚨 EUVD-2026-34440

                              📊 Score: 8.8/10 (CVSS v3.1)
                              📦 Product: Chrome
                              🏢 Vendor: Google
                              📅 Published: 2026-06-04 | Updated: 2026-06-05

                              📝 Use after free in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severit...

                              🔗 euvd.enisa.europa.eu/vulnerabi

                                [?]TheHackerWire » 🤖 🌐
                                @thehackerwire@mastodon.social

                                🟠 CVE-2026-11241 - High (8)

                                Insufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)

                                🔗 thehackerwire.com/vulnerabilit

                                CVE Alert: CVE-2026-11241

                                Alt...CVE Alert: CVE-2026-11241

                                  [?]deafnews » 🤖 🌐
                                  @deafnews@infosec.exchange

                                  [?]Mastodon Trends South Africa » 🤖 🌐
                                  @trendsZA@mastodon.africa

                                  The following hashtags are trending across South African Mastodon instances:






                                  Based on recent posts made by non-automated accounts. Posts with more boosts, favourites, and replies are weighted higher.

                                    [?]TechWire ⚡ » 🤖 🌐
                                    @techwire@social.gamefan.net

                                    Corsair launches lightweight budget-friendly HS35 v3 gaming headsets — wired version weighs a cool 230 grams

                                    Corsair launched its HS35 v3 lightweight gaming headsets — wired and wireless — at Computex 2026.

                                    tomshardware.com/peripherals/g

                                    [Tom's Hardware]

                                      [?]TechWire ⚡ » 🤖 🌐
                                      @techwire@social.gamefan.net

                                      [?]Malicious Extension Bot » 🤖 🌐
                                      @malicious_browser_bot@infosec.exchange

                                      extension Stitch Cyberpunk City Live Wallpaper seems malicious. Its badness score is 92/100!

                                      ```json
                                      {"id": "bffpnolcolmhnpobpninklkefbcfnfcb", "score": 92, "platform": "chrome", "name": "Stitch Cyberpunk City Live Wallpaper"}
                                      ```

                                        [?]urlDNA.io :verified: » 🤖 🌐
                                        @urldna@infosec.exchange

                                        Possible Phishing 🎣
                                        on: ⚠️hxxp[:]//amazonbylio[.]vercel[.]app
                                        🧬 Analysis at: urldna.io/scan/6a21e1013b77500

                                          [?]TechWire ⚡ » 🤖 🌐
                                          @techwire@social.gamefan.net

                                          Google Health’s latest update cleans up nutrition tracking and workout mix-ups

                                          Google is ironing out some of Google Health's biggest tracking headaches.

                                          androidauthority.com/google-he

                                          [Android Authority]

                                            [?]EUVD Bot » 🤖 🌐
                                            @EUVD_Bot@mastodon.social

                                            🚨 EUVD-2026-34682

                                            📊 Score: n/a
                                            📦 Product: Chrome
                                            🏢 Vendor: Google
                                            📅 Updated: 2026-06-04

                                            📝 Insufficient validation of untrusted input in PointerLock in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                              [?]EUVD Bot » 🤖 🌐
                                              @EUVD_Bot@mastodon.social

                                              🚨 EUVD-2026-34772

                                              📊 Score: 5.3/10 (CVSS v3.1)
                                              📦 Product: Ship Ferry Ticket Reservation System
                                              🏢 Vendor: SourceCodester
                                              📅 Updated: 2026-06-05

                                              📝 A weakness has been identified in SourceCodester Ship Ferry Ticket Reservation System 1.0. This affects an unknown function of the file /admin/. This manipulation of the argument page causes improper authorization. Remote ...

                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                [?]EUVD Bot » 🤖 🌐
                                                @EUVD_Bot@mastodon.social

                                                🚨 EUVD-2026-34671

                                                📊 Score: n/a
                                                📦 Product: Chrome
                                                🏢 Vendor: Google
                                                📅 Updated: 2026-06-04

                                                📝 Inappropriate implementation in Safe Browsing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access control via a crafted RAR file. (Chromium security severity: Medium)

                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                  [?]EUVD Bot » 🤖 🌐
                                                  @EUVD_Bot@mastodon.social

                                                  🚨 EUVD-2026-34757

                                                  📊 Score: n/a
                                                  📦 Product: Chrome
                                                  🏢 Vendor: Google
                                                  📅 Updated: 2026-06-05

                                                  📝 Inappropriate implementation in ImageCapture in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)

                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                    [?]EUVD Bot » 🤖 🌐
                                                    @EUVD_Bot@mastodon.social

                                                    🚨 EUVD-2026-34682

                                                    📊 Score: n/a
                                                    📦 Product: Chrome
                                                    🏢 Vendor: Google
                                                    📅 Updated: 2026-06-04

                                                    📝 Insufficient validation of untrusted input in PointerLock in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                      [?]EUVD Bot » 🤖 🌐
                                                      @EUVD_Bot@mastodon.social

                                                      🚨 EUVD-2026-34697

                                                      📊 Score: n/a
                                                      📦 Product: Chrome
                                                      🏢 Vendor: Google
                                                      📅 Updated: 2026-06-04

                                                      📝 Insufficient policy enforcement in Web Bluetooth in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

                                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                                        [?]EUVD Bot » 🤖 🌐
                                                        @EUVD_Bot@mastodon.social

                                                        🚨 EUVD-2026-34681

                                                        📊 Score: n/a
                                                        📦 Product: Chrome
                                                        🏢 Vendor: Google
                                                        📅 Updated: 2026-06-04

                                                        📝 Insufficient validation of untrusted input in Navigation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)

                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                          [?]EUVD Bot » 🤖 🌐
                                                          @EUVD_Bot@mastodon.social

                                                          🚨 EUVD-2026-34705

                                                          📊 Score: n/a
                                                          📦 Product: Chrome
                                                          🏢 Vendor: Google
                                                          📅 Updated: 2026-06-04

                                                          📝 Insufficient validation of untrusted input in WebAuthentication in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)

                                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                                            [?]EUVD Bot » 🤖 🌐
                                                            @EUVD_Bot@mastodon.social

                                                            🚨 EUVD-2026-34756

                                                            📊 Score: n/a
                                                            📦 Product: Chrome
                                                            🏢 Vendor: Google
                                                            📅 Updated: 2026-06-05

                                                            📝 Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)

                                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                                              [?]EUVD Bot » 🤖 🌐
                                                              @EUVD_Bot@mastodon.social

                                                              🚨 EUVD-2026-34681

                                                              📊 Score: n/a
                                                              📦 Product: Chrome
                                                              🏢 Vendor: Google
                                                              📅 Updated: 2026-06-04

                                                              📝 Insufficient validation of untrusted input in Navigation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)

                                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                                [?]EUVD Bot » 🤖 🌐
                                                                @EUVD_Bot@mastodon.social

                                                                🚨 EUVD-2026-34670

                                                                📊 Score: n/a
                                                                📦 Product: Chrome
                                                                🏢 Vendor: Google
                                                                📅 Updated: 2026-06-04

                                                                📝 Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

                                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                                  [?]EUVD Bot » 🤖 🌐
                                                                  @EUVD_Bot@mastodon.social

                                                                  🚨 EUVD-2026-34696

                                                                  📊 Score: n/a
                                                                  📦 Product: Chrome
                                                                  🏢 Vendor: Google
                                                                  📅 Updated: 2026-06-04

                                                                  📝 Insufficient policy enforcement in Compositing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

                                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                                    [?]EUVD Bot » 🤖 🌐
                                                                    @EUVD_Bot@mastodon.social

                                                                    🚨 EUVD-2026-34771

                                                                    📊 Score: 7.2/10 (CVSS v3.1)
                                                                    📦 Product: Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns
                                                                    🏢 Vendor: wpdevteam
                                                                    📅 Updated: 2026-06-05

                                                                    📝 The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.3 vi...

                                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                                      [?]TechWire ⚡ » 🤖 🌐
                                                                      @techwire@social.gamefan.net

                                                                      GoPro warns 'substantial doubt about the company’s ability to continue' in regulatory filings — AI memory shortage hits action camera maker

                                                                      Higher memory costs and lower sales is hitting GoPro hard. The company isn't filing for bankruptcy yet, but it might end up doing that if it does not resolve the issue sooner.

                                                                      tomshardware.com/pc-components

                                                                      [Tom's Hardware]

                                                                        [?]EUVD Bot » 🤖 🌐
                                                                        @EUVD_Bot@mastodon.social

                                                                        🚨 EUVD-2026-34668

                                                                        📊 Score: n/a
                                                                        📦 Product: Chrome
                                                                        🏢 Vendor: Google
                                                                        📅 Updated: 2026-06-05

                                                                        📝 Insufficient validation of untrusted input in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: Medium)

                                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                                          [?]TechWire ⚡ » 🤖 🌐
                                                                          @techwire@social.gamefan.net

                                                                          Corsair shows off gaming mouse with dedicated Stream Deck launch button — wireless mouse also gets almost 50 hours of 8K battery life

                                                                          Corsair showed off its Stream Deck-integrated gaming mouse, the Nightsword v2 Wireless SD, which has a dedicated Stream Deck launch button.

                                                                          tomshardware.com/peripherals/g

                                                                          [Tom's Hardware]

                                                                            [?]urlDNA.io :verified: » 🤖 🌐
                                                                            @urldna@infosec.exchange

                                                                            Possible Phishing 🎣
                                                                            on: ⚠️hxxps[:]//serwer2445982[.]home[.]pl
                                                                            🧬 Analysis at: urldna.io/scan/6a221f9d3b77500

                                                                              [?]TechWire ⚡ » 🤖 🌐
                                                                              @techwire@social.gamefan.net

                                                                              32GB of DDR5 now costs $375 minimum — AI shortage continues to squeeze PC building

                                                                              32GB of DDR5 RAM can now no longer be found for less than $374.97.

                                                                              tomshardware.com/pc-components

                                                                              [Tom's Hardware]

                                                                                Back to top - More...