voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
🟠 CVE-2026-11136 - High (8.8)
Use after free in Canvas in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-11136/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Critical RCE Vulnerability in Hugging Face Transformers Bypasses Security Settings
Hugging Face patched a high-severity RCE vulnerability (CVE-2026-4372) in the Transformers library that allowed malicious models to execute arbitrary code during routine loading, even when security flags were disabled.
**If you use the Hugging Face Transformers library with the `kernels` package installed, update to version 5.3.0 or later ASAP. After updating, audit your cached model configurations for any suspicious `_attn_implementation_internal` field and avoid loading models from untrusted sources.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/critical-rce-vulnerability-in-hugging-face-transformers-bypasses-security-settings-c-b-d-w-8/gD2P6Ple2L
Matryoshka #3/3: Gamaredon's Gammasteel Infostealer
This analysis examines Gamaredon's (UAC-0010, Armagedon) advanced espionage operations targeting Ukrainian government, military, and critical infrastructure. The FSB-operated group deploys GammaSteel, a sophisticated stealer operating almost entirely from memory using Windows DPAPI encryption and storing 71 distinct payload functions in the HKCU\Printers registry key. The malware employs three concurrent data acquisition mechanisms: timed drive scans, USB monitoring for air-gapped systems, and real-time file surveillance. Exfiltration occurs via legitimate S3-compatible cloud storage (Tebi.io) with fallback to operator-controlled servers. The infection chain extensively uses VBScript for evasion, Dead Drop Resolvers on platforms like Telegram and Mastodon for C2 configuration, and includes bidirectional backdoor capabilities enabling arbitrary remote code execution. Infrastructure demonstrates high automation with servers rotated approximately every 24 hours.
Pulse ID: 6a21844636a81843ce1af3cc
Pulse Link: https://otx.alienvault.com/pulse/6a21844636a81843ce1af3cc
Pulse Author: AlienVault
Created: 2026-06-04 13:57:26
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Cloud #CyberSecurity #Encryption #Espionage #Gamaredon #Government #InfoSec #InfoStealer #Malware #Military #OTX #OpenThreatExchange #RAT #RemoteCodeExecution #SMS #Telegram #Troll #UK #USB #Ukr #Ukrainian #VBS #Windows #bot #AlienVault
Everest Forms Pro: Critical RCE Exploited Months After Patch Release https://deafnews.it/en/article/everest-forms-pro-critical-rce-exploited-months-after-patch-release #Cybersecurity
The following hashtags are trending across South African Mastodon instances:
#Wordle
#wordle1812
#cybersecurity
#a11y
#books
#mastersoftheuniverse
#polls
#food
#womenshealth
#donations
Based on recent posts made by non-automated accounts. Posts with more boosts, favourites, and replies are weighted higher.
Google wants your phone to track your heart rate by simply looking at you
Your smartphone may soon feel your beat.
https://www.androidauthority.com/google-phone-heart-rate-tracking-test-3674854/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
I’ve had the Oura Ring 5 for 72 hours, and it’s already one of my favorite smart rings
A slimmer profile makes a stronger first impression.
https://www.androidauthority.com/oura-ring-5-hands-on-3674208/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Possible Phishing 🎣
on: ⚠️hxxps[:]//is[.]gd/uwOhyk
🧬 Analysis at: https://urldna.io/scan/6a21b6d83b775000099022e5
#cybersecurity #phishing #infosec #urldna #scam #infosec
Samsung can’t stop sending new Play system updates, after making us pine last year
Samsung went from zero Play system updates to seven in the last six months.
https://www.androidauthority.com/samsung-galaxy-play-system-update-may-3674853/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Supply Chain Security: Protecting Software, Services, and Updates - https://www.redpacketsecurity.com/supply-chain-security-protecting-software-services-and-updates-2/
Mythos Preview: Anthropic unterstützt NSA angeblich bei offensivem KI-Einsatz
Mehrere Angestellte von Anthropic arbeiten einem Zeitungsbericht zufolge direkt bei der NSA daran, die mächtige Mythos-KI für offensive Einsätze fit zu machen.
#Anthropic #Cybersecurity #Cyberwar #IT #KünstlicheIntelligenz #NSA #news
Noctua shows off improved thermosiphon prototype — passively circulated liquid cooler gets Q3 2027 projec…
Noctua showed off a refined version of its passively circulated thermosiphon liquid cooler at Computex 2026 with an improved evaporator design. The company is confident enough in its progress with this product to set a …
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
🟠 CVE-2026-11262 - High (8.8)
Use after free in TabStrip in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-11262/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-11239 - High (7.5)
Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-11239/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Possible Phishing 🎣
on: ⚠️hxxp[:]//webaccess-email[.]com/s/63BZGFSVBWSFCDX7Y9/584dd8/90eab167-7429-489f-99f6-ce86e8d0d81a
🧬 Analysis at: https://urldna.io/scan/6a21bd303b77500008814547
#cybersecurity #phishing #infosec #urldna #scam #infosec
🚨 EUVD-2026-34784
📊 Score: 7.3/10 (CVSS v3.1)
📦 Product: Graphite
🏢 Vendor: Graphite project
📅 Updated: 2026-06-05
📝 Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34784
🚨 EUVD-2026-34403
📊 Score: 8.8/10 (CVSS v3.1)
📦 Product: Chrome
🏢 Vendor: Google
📅 Published: 2026-06-04 | Updated: 2026-06-05
📝 Use after free in Actor in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34403
🚨 EUVD-2026-34440
📊 Score: 8.8/10 (CVSS v3.1)
📦 Product: Chrome
🏢 Vendor: Google
📅 Published: 2026-06-04 | Updated: 2026-06-05
📝 Use after free in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severit...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34440
🟠 CVE-2026-11241 - High (8)
Insufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-11241/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
AI Agents Exfiltrate 6M Records: The Structural Governance Gap https://deafnews.it/en/article/ai-agents-exfiltrate-6m-records-the-structural-governance-gap #Cybersecurity
The following hashtags are trending across South African Mastodon instances:
#dreamed
#cybersecurity
#a11y
#womenshealth
#donations
#crosswords
Based on recent posts made by non-automated accounts. Posts with more boosts, favourites, and replies are weighted higher.
Corsair launches lightweight budget-friendly HS35 v3 gaming headsets — wired version weighs a cool 230 grams
Corsair launched its HS35 v3 lightweight gaming headsets — wired and wireless — at Computex 2026.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
Computex 2026 Day Two Wrap-Up: Intel atones for Arrow Lake, Wi-Fi 8 comes into focus
Computex 2026 is in full swing in Taipei
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
#chrome extension Stitch Cyberpunk City Live Wallpaper seems malicious. Its #cybersecurity badness score is 92/100!
```json
{"id": "bffpnolcolmhnpobpninklkefbcfnfcb", "score": 92, "platform": "chrome", "name": "Stitch Cyberpunk City Live Wallpaper"}
```
Possible Phishing 🎣
on: ⚠️hxxp[:]//amazonbylio[.]vercel[.]app
🧬 Analysis at: https://urldna.io/scan/6a21e1013b77500008814a15
#cybersecurity #phishing #infosec #urldna #scam #infosec
Google Health’s latest update cleans up nutrition tracking and workout mix-ups
Google is ironing out some of Google Health's biggest tracking headaches.
https://www.androidauthority.com/google-health-app-update-june-2026-3674767/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
🚨 EUVD-2026-34682
📊 Score: n/a
📦 Product: Chrome
🏢 Vendor: Google
📅 Updated: 2026-06-04
📝 Insufficient validation of untrusted input in PointerLock in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34682
🚨 EUVD-2026-34772
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Ship Ferry Ticket Reservation System
🏢 Vendor: SourceCodester
📅 Updated: 2026-06-05
📝 A weakness has been identified in SourceCodester Ship Ferry Ticket Reservation System 1.0. This affects an unknown function of the file /admin/. This manipulation of the argument page causes improper authorization. Remote ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34772
🚨 EUVD-2026-34671
📊 Score: n/a
📦 Product: Chrome
🏢 Vendor: Google
📅 Updated: 2026-06-04
📝 Inappropriate implementation in Safe Browsing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access control via a crafted RAR file. (Chromium security severity: Medium)
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34671
🚨 EUVD-2026-34757
📊 Score: n/a
📦 Product: Chrome
🏢 Vendor: Google
📅 Updated: 2026-06-05
📝 Inappropriate implementation in ImageCapture in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34757
🚨 EUVD-2026-34682
📊 Score: n/a
📦 Product: Chrome
🏢 Vendor: Google
📅 Updated: 2026-06-04
📝 Insufficient validation of untrusted input in PointerLock in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34682
🚨 EUVD-2026-34697
📊 Score: n/a
📦 Product: Chrome
🏢 Vendor: Google
📅 Updated: 2026-06-04
📝 Insufficient policy enforcement in Web Bluetooth in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34697
🚨 EUVD-2026-34681
📊 Score: n/a
📦 Product: Chrome
🏢 Vendor: Google
📅 Updated: 2026-06-04
📝 Insufficient validation of untrusted input in Navigation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34681
🚨 EUVD-2026-34705
📊 Score: n/a
📦 Product: Chrome
🏢 Vendor: Google
📅 Updated: 2026-06-04
📝 Insufficient validation of untrusted input in WebAuthentication in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34705
🚨 EUVD-2026-34756
📊 Score: n/a
📦 Product: Chrome
🏢 Vendor: Google
📅 Updated: 2026-06-05
📝 Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34756
🚨 EUVD-2026-34681
📊 Score: n/a
📦 Product: Chrome
🏢 Vendor: Google
📅 Updated: 2026-06-04
📝 Insufficient validation of untrusted input in Navigation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34681
🚨 EUVD-2026-34670
📊 Score: n/a
📦 Product: Chrome
🏢 Vendor: Google
📅 Updated: 2026-06-04
📝 Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34670
🚨 EUVD-2026-34696
📊 Score: n/a
📦 Product: Chrome
🏢 Vendor: Google
📅 Updated: 2026-06-04
📝 Insufficient policy enforcement in Compositing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34696
🚨 EUVD-2026-34771
📊 Score: 7.2/10 (CVSS v3.1)
📦 Product: Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns
🏢 Vendor: wpdevteam
📅 Updated: 2026-06-05
📝 The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.3 vi...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34771
GoPro warns 'substantial doubt about the company’s ability to continue' in regulatory filings — AI memory shortage hits action camera maker
Higher memory costs and lower sales is hitting GoPro hard. The company isn't filing for bankruptcy yet, but it might end up doing that if it does not resolve the issue sooner.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
🚨 EUVD-2026-34668
📊 Score: n/a
📦 Product: Chrome
🏢 Vendor: Google
📅 Updated: 2026-06-05
📝 Insufficient validation of untrusted input in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: Medium)
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34668
Corsair shows off gaming mouse with dedicated Stream Deck launch button — wireless mouse also gets almost 50 hours of 8K battery life
Corsair showed off its Stream Deck-integrated gaming mouse, the Nightsword v2 Wireless SD, which has a dedicated Stream Deck launch button.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
Possible Phishing 🎣
on: ⚠️hxxps[:]//serwer2445982[.]home[.]pl
🧬 Analysis at: https://urldna.io/scan/6a221f9d3b775000052e72b3
#cybersecurity #phishing #infosec #urldna #scam #infosec
32GB of DDR5 now costs $375 minimum — AI shortage continues to squeeze PC building
32GB of DDR5 RAM can now no longer be found for less than $374.97.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]