voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
Possible Phishing 🎣
on: ⚠️hxxps[:]//main[.]sbm-demo[.]xyz/phishing
🧬 Analysis at: https://urldna.io/scan/6a21bd3b3b7750000881455c
#cybersecurity #phishing #infosec #urldna #scam #infosec
🟠 CVE-2026-41249 - High (8.2)
CoreShop is a Pimcore enhanced eCommerce solution. In versions 5.0.1 through 5.1.0-beta.1,, the GitHub Actions workflow (`.github/workflows/static.yml`) uses the `pull_request_target` trigger but dangerously checks out the unverified code from the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-41249/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
"EFF Testifies to Congress on Protecting Americans’ Rights from Government AI"
"Governments must not adopt emerging and powerful AI technologies without also adopting strong and clear safeguards to protect Constitutional rights, EFF Senior Policy Analyst Dr."
🟠 CVE-2026-41518 - High (7.6)
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In versions 4.9.0 through 5.0.0, an authenticated user with project-editor permissions can store arbitrary HTML/JavaScri...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-41518/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-49941 - High (7.5)
Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses.
The add method called the _encode method to parse addresses. If the addresses did not look like netmasks or network ranges, then they were assumed to single IP addresses...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49941/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Edge Vulnerability CVE-2026-45492: Origin Validation Error Bypasses Windows VBS https://deafnews.it/en/article/edge-vulnerability-cve-2026-45492-origin-validation-error-bypasses-windows-vbs #Cybersecurity
Some clever Fitbit Air owners put a watch on their band and it doesn’t look half bad
This Fitbit Air strap trick solves the two-wrist problem.
https://www.androidauthority.com/fitbit-air-combined-with-analog-watch-3674702/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
#chrome extension Despicable Me Minions Par seems malicious. Its #cybersecurity badness score is 86/100!
```json
{"id": "okhfdikdjelekopikhhihjimihifgagh", "score": 86, "platform": "chrome", "name": "Despicable Me Minions Par"}
```
#chrome extension Editthiscookie Origin seems malicious. Its #cybersecurity badness score is 98/100!
```json
{"id": "edmbemgdldgpaopfpodijnpnaanfdehk", "score": 98, "platform": "chrome", "name": "Editthiscookie Origin"}
```
#chrome extension Lilo & Stitch Elvis Style Live Wallpaper seems malicious. Its #cybersecurity badness score is 92/100!
```json
{"id": "hknohgfkdplfanfeaoeenibilkllofcd", "score": 92, "platform": "chrome", "name": "Lilo & Stitch Elvis Style Live Wallpaper"}
```
Here’s how Google Photos is solving its digital picture frame problem
Aura shares your path forward to restoring Google Photos auto-sync.
https://www.androidauthority.com/google-photos-digital-picture-frame-2-3674708/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Possible Phishing 🎣
on: ⚠️hxxp[:]//netflix-clone-umber-beta[.]vercel[.]app
🧬 Analysis at: https://urldna.io/scan/6a21d2f03b77500008814812
#cybersecurity #phishing #infosec #urldna #scam #infosec
The next time an HR recruiter reaches out to you on LinkedIn, you’d be wise to double check their credentials. A joint advisory issued by the FBI, the U.K.’s security service MI5, and the governments of Australia, Canada, and New Zealand says Chinese spies are posing as online recruiters who represent fake companies with the aim of obtaining non-public information that might benefit the Chinese government. Read more from @Techcrunch:
Meta’s smart glasses face-recognition plans may be further along than you realize
Meta has reportedly placed face-recognition code for smart glasses inside an app downloaded millions of times.
https://www.androidauthority.com/meta-smart-glasses-face-recognition-code-in-app-3674720/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
🚨 EUVD-2026-34288
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: go.opentelemetry.io/otel/baggage, go.opentelemetry.io/otel/baggage, go.opentelemetry.io/otel/propagation (+1 more)
🏢 Vendor: open-telemetry
📅 Updated: 2026-06-04
📝 OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and it causes `Parse` to pro...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34288
🚨 EUVD-2026-34282
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: CPython
🏢 Vendor: Python Software Foundation
📅 Updated: 2026-06-04
📝 tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to c...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34282
🚨 EUVD-2026-34286
📊 Score: 9.9/10 (CVSS v3.1)
📦 Product: Tautulli
🏢 Vendor: Tautulli
📅 Updated: 2026-06-04
📝 Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose a public `/image/<hash>` route that resolves attacker-controlled entries from `image_hash_lookup` and replays them through the same server-side i...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34286
🚨 EUVD-2026-34285
📊 Score: 8.8/10 (CVSS v3.1)
📦 Product: Tautulli
🏢 Vendor: Tautulli
📅 Updated: 2026-06-04
📝 Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `configUpdate` as a state-changing administrator endpoint, but the route does not enforce `POST` and does not use any anti-CSRF token. In the def...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34285
🚨 EUVD-2026-34284
📊 Score: 8.9/10 (CVSS v3.1)
📦 Product: Tautulli
🏢 Vendor: Tautulli
📅 Updated: 2026-06-04
📝 Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `log_js_errors` to any authenticated user, including guest users when guest access is enabled. The endpoint writes attacker-controlled strings di...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34284
🚨 EUVD-2026-34283
📊 Score: 8.8/10 (CVSS v3.1)
📦 Product: WriteUp Mobile App
🏢 Vendor: Kurt Software Studio
📅 Updated: 2026-06-04
📝 Improper Access Control, Missing Authorization vulnerability in Kurt Software Studio WriteUp Mobile App allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects WriteUp Mobile App: from 1.3.0 through 04062026.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34283
Bridle Trails Family Dentistry Email Breach Exposes Data of 20,976 Patients
Bridle Trails Family Dentistry disclosed a data breach affecting 20,976 patients after an unauthorized actor accessed an employee email account in November 2024.
****
#cybersecurity #infosec #incident #databreach
https://beyondmachines.net/event_details/bridle-trails-family-dentistry-email-breach-exposes-data-of-20976-patients-4-t-c-3-t/gD2P6Ple2L
ClickFix Deno Abuse to CastleRAT
Activity began with a ClickFix-style social engineering chain that led to MSI execution, PowerShell staging, and installation/use of Deno to run attacker-controlled JavaScript. Follow-on activity downloaded a portable Python runtime, `install.pyc`, and an encrypted `.MOa` container, which was later decrypted to recover a 64-bit Windows PE payload. Analysis of the recovered payload showed Steam Community being used as a dead-drop resolver for C2, with the profile title resolving to `smokeenew[.]com`, while `ip-api.com` was used for victim network/geolocation profiling. The payload also contained logic for browser/wallet data collection, clipboard/keylogging-related capabilities, Defender exclusions, UAC bypass/relaunch behavior through `ComputerDefaults.exe`, and a C2-tasked mechanism to receive and install an additional `Krutyak.zip` / `usbmmidd_v2` component. Recommendations: Block artifacts where applicable.
Pulse ID: 6a21aa7db4b7cf1351f27cb6
Pulse Link: https://otx.alienvault.com/pulse/6a21aa7db4b7cf1351f27cb6
Pulse Author: AlienVault
Created: 2026-06-04 16:40:29
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Clipboard #CyberSecurity #InfoSec #Java #JavaScript #OTX #OpenThreatExchange #PowerShell #Python #RAT #SocialEngineering #Steam #Troll #USB #Windows #ZIP #bot #AlienVault
Cash App made a magic wand for contactless payments
The Cash App Wand is a novel way to pay for your next coffee. | Image: Cash App The convenience of contactless payments can already feel magical, but Cash App is really leaning into that with its latest accessory. The m…
https://www.theverge.com/tech/942897/cash-app-tags-magic-wand-contactless-payments-price-launch
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
A major data breach at the UN's World Food Programme has exposed sensitive data for 600,000 Gaza households, including names, IDs, and location. This incident, following whistleblower warnings, reveals critical vulnerabilities in aid systems and poses direct safety risks in a conflict zone, echoing past breaches at ICRC and UNHCR.
🤖 This post was AI-generated.
📣🚨 #iFood confirms a data breach affecting 1.2 million customers in Brazil, exposing names, phone numbers, addresses, and CPF numbers. Hackers on #BreachForums claim the actual theft is far larger.
Read: https://hackread.com/ifood-confirms-data-breach-brazil-users/
#chrome extension Databycloud New seems malicious. Its #cybersecurity badness score is 100/100!
```json
{"id": "mgpjmlcdhjpoimnedpjmognfaheemggo", "score": 100, "platform": "chrome", "name": "Databycloud New"}
```
#chrome extension Spongebob Squarepants Wal seems malicious. Its #cybersecurity badness score is 98/100!
```json
{"id": "cikekgdidokdcbkdfakccbofbnlcjllg", "score": 98, "platform": "chrome", "name": "Spongebob Squarepants Wal"}
```
#chrome extension Offline Games To Play seems malicious. Its #cybersecurity badness score is 85/100!
```json
{"id": "gehadamnihncolfbpjdiboaadagpglbf", "score": 85, "platform": "chrome", "name": "Offline Games To Play"}
```
Google gets ready to tighten up its account switcher in Android apps
A more compact account switcher UI could cut down on scrolling.
https://www.androidauthority.com/new-google-account-switcher-3674586/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Possible Phishing 🎣
on: ⚠️hxxps[:]//cobig99[.]github[.]io/microsoft365-en-us-excel/
🧬 Analysis at: https://urldna.io/scan/6a213eb13b775000088133f3
#cybersecurity #phishing #infosec #urldna #scam #infosec
Belkin’s new Joy-Con grips also boost the Switch 2’s battery life
Most of Belkin's Switch 2 accessories are designed to either protect or power up Nintendo's latest handheld, like its Charging Case Pro that actually does both at the same time. Its new multitasking Charging Grip can al…
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Officially day 2 of hackers teaching hackers, got my electronic badge for entry. Looks like it has a LoRa radio, totally going to have to hack this later and see what it’s doing. #Cybersecurity #Spaceballs #hacker #radio #lora
California Attorney General sues 23andMe successor for 2023 data breach
The California Attorney General will sue DNA testing firm Chrome Holding, alleging its predecessor company 23andMe failed to protect sensitive customer data.
#ChromeHolding #23andme #databreach #California #security #cybersecurity
Google Gemini Hijacked via Messaging Notifications: The 'Dual Illusion' Attack https://deafnews.it/en/article/google-gemini-hijacked-via-messaging-notifications-the-dual-illusion-attack #Cybersecurity
⚠️ CRITICAL: New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare
HTTP/2 Bomb is a remote DoS vulnerability affecting NGINX, Apache HTTPD, IIS, Envoy, and Cloudflare Pingora. Attackers can exhaust server memory (32GB in seconds) by sending crafted HTTP/2 requests that exploit HPACK compression and flow-control mechanisms. Unpatched servers are at immediate risk o…
⚠️ CRITICAL: Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited
Google patched 124 Android vulnerabilities in June 2026, including CVE-2025-48595, a high-severity privilege escalation flaw (CVSS 8.4) in the Framework component that is actively exploited in the wild. The vulnerability affects Android 14, 15, 16, and 16 QPR2, allowing code execution through integ…
⚠️ CRITICAL: Critical Kirki flaw exploited to hijack WordPress admin accounts
Critical privilege escalation flaw in Kirki WordPress plugin (CVE-2026-8206) allows unauthenticated attackers to reset any user account including admins via an unvalidated REST API endpoint. Wordfence has already blocked 222+ exploitation attempts in 24 hours. Any WordPress site running Kirki versi…
🔥 Q1 2026 Cyber Risk report by #ANYRUN is out!
Explore the cyber risks and threat shifts for CISOs, including:
❗️ +14.7% credential theft
❗️ +98.3% loader attacks
❗️ +58.4% LOLBAS attacks
Turn Q1 intel into Q2 security priorities. Get the report: https://any.run/cybersecurity-blog/cyber-risk-report-q1-2026/?utm_source=mastodon&utm_medium=post&utm_campaign=cyber_risk_report_q1_2026&utm_content=linktoreport&utm_term=040626