voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
Bridle Trails Family Dentistry Email Breach Exposes Data of 20,976 Patients
Bridle Trails Family Dentistry disclosed a data breach affecting 20,976 patients after an unauthorized actor accessed an employee email account in November 2024.
****
#cybersecurity #infosec #incident #databreach
https://beyondmachines.net/event_details/bridle-trails-family-dentistry-email-breach-exposes-data-of-20976-patients-4-t-c-3-t/gD2P6Ple2L
ClickFix Deno Abuse to CastleRAT
Activity began with a ClickFix-style social engineering chain that led to MSI execution, PowerShell staging, and installation/use of Deno to run attacker-controlled JavaScript. Follow-on activity downloaded a portable Python runtime, `install.pyc`, and an encrypted `.MOa` container, which was later decrypted to recover a 64-bit Windows PE payload. Analysis of the recovered payload showed Steam Community being used as a dead-drop resolver for C2, with the profile title resolving to `smokeenew[.]com`, while `ip-api.com` was used for victim network/geolocation profiling. The payload also contained logic for browser/wallet data collection, clipboard/keylogging-related capabilities, Defender exclusions, UAC bypass/relaunch behavior through `ComputerDefaults.exe`, and a C2-tasked mechanism to receive and install an additional `Krutyak.zip` / `usbmmidd_v2` component. Recommendations: Block artifacts where applicable.
Pulse ID: 6a21aa7db4b7cf1351f27cb6
Pulse Link: https://otx.alienvault.com/pulse/6a21aa7db4b7cf1351f27cb6
Pulse Author: AlienVault
Created: 2026-06-04 16:40:29
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Clipboard #CyberSecurity #InfoSec #Java #JavaScript #OTX #OpenThreatExchange #PowerShell #Python #RAT #SocialEngineering #Steam #Troll #USB #Windows #ZIP #bot #AlienVault
Cash App made a magic wand for contactless payments
The Cash App Wand is a novel way to pay for your next coffee. | Image: Cash App The convenience of contactless payments can already feel magical, but Cash App is really leaning into that with its latest accessory. The m…
https://www.theverge.com/tech/942897/cash-app-tags-magic-wand-contactless-payments-price-launch
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
A major data breach at the UN's World Food Programme has exposed sensitive data for 600,000 Gaza households, including names, IDs, and location. This incident, following whistleblower warnings, reveals critical vulnerabilities in aid systems and poses direct safety risks in a conflict zone, echoing past breaches at ICRC and UNHCR.
🤖 This post was AI-generated.
📣🚨 #iFood confirms a data breach affecting 1.2 million customers in Brazil, exposing names, phone numbers, addresses, and CPF numbers. Hackers on #BreachForums claim the actual theft is far larger.
Read: https://hackread.com/ifood-confirms-data-breach-brazil-users/
#chrome extension Databycloud New seems malicious. Its #cybersecurity badness score is 100/100!
```json
{"id": "mgpjmlcdhjpoimnedpjmognfaheemggo", "score": 100, "platform": "chrome", "name": "Databycloud New"}
```
#chrome extension Spongebob Squarepants Wal seems malicious. Its #cybersecurity badness score is 98/100!
```json
{"id": "cikekgdidokdcbkdfakccbofbnlcjllg", "score": 98, "platform": "chrome", "name": "Spongebob Squarepants Wal"}
```
#chrome extension Offline Games To Play seems malicious. Its #cybersecurity badness score is 85/100!
```json
{"id": "gehadamnihncolfbpjdiboaadagpglbf", "score": 85, "platform": "chrome", "name": "Offline Games To Play"}
```
Google gets ready to tighten up its account switcher in Android apps
A more compact account switcher UI could cut down on scrolling.
https://www.androidauthority.com/new-google-account-switcher-3674586/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Possible Phishing 🎣
on: ⚠️hxxps[:]//cobig99[.]github[.]io/microsoft365-en-us-excel/
🧬 Analysis at: https://urldna.io/scan/6a213eb13b775000088133f3
#cybersecurity #phishing #infosec #urldna #scam #infosec
Belkin’s new Joy-Con grips also boost the Switch 2’s battery life
Most of Belkin's Switch 2 accessories are designed to either protect or power up Nintendo's latest handheld, like its Charging Case Pro that actually does both at the same time. Its new multitasking Charging Grip can al…
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Officially day 2 of hackers teaching hackers, got my electronic badge for entry. Looks like it has a LoRa radio, totally going to have to hack this later and see what it’s doing. #Cybersecurity #Spaceballs #hacker #radio #lora
California Attorney General sues 23andMe successor for 2023 data breach
The California Attorney General will sue DNA testing firm Chrome Holding, alleging its predecessor company 23andMe failed to protect sensitive customer data.
#ChromeHolding #23andme #databreach #California #security #cybersecurity
Google Gemini Hijacked via Messaging Notifications: The 'Dual Illusion' Attack https://deafnews.it/en/article/google-gemini-hijacked-via-messaging-notifications-the-dual-illusion-attack #Cybersecurity
⚠️ CRITICAL: New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare
HTTP/2 Bomb is a remote DoS vulnerability affecting NGINX, Apache HTTPD, IIS, Envoy, and Cloudflare Pingora. Attackers can exhaust server memory (32GB in seconds) by sending crafted HTTP/2 requests that exploit HPACK compression and flow-control mechanisms. Unpatched servers are at immediate risk o…
⚠️ CRITICAL: Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited
Google patched 124 Android vulnerabilities in June 2026, including CVE-2025-48595, a high-severity privilege escalation flaw (CVSS 8.4) in the Framework component that is actively exploited in the wild. The vulnerability affects Android 14, 15, 16, and 16 QPR2, allowing code execution through integ…
⚠️ CRITICAL: Critical Kirki flaw exploited to hijack WordPress admin accounts
Critical privilege escalation flaw in Kirki WordPress plugin (CVE-2026-8206) allows unauthenticated attackers to reset any user account including admins via an unvalidated REST API endpoint. Wordfence has already blocked 222+ exploitation attempts in 24 hours. Any WordPress site running Kirki versi…
🔥 Q1 2026 Cyber Risk report by #ANYRUN is out!
Explore the cyber risks and threat shifts for CISOs, including:
❗️ +14.7% credential theft
❗️ +98.3% loader attacks
❗️ +58.4% LOLBAS attacks
Turn Q1 intel into Q2 security priorities. Get the report: https://any.run/cybersecurity-blog/cyber-risk-report-q1-2026/?utm_source=mastodon&utm_medium=post&utm_campaign=cyber_risk_report_q1_2026&utm_content=linktoreport&utm_term=040626
The slimmest Galaxy Z Fold 8 competitor is going global with a huge battery in tow
HONOR’s Magic V6 packs a record battery into an impossibly thin foldable.
https://www.androidauthority.com/honor-magic-v6-global-launch-3674524/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
The Galaxy Z Fold 8 Ultra could get a useful accessory from the Galaxy Z Trifold
The upcoming "Carbon Standing Case" could make it easier to use the Galaxy Z Fold 8 and Z Fold 8 Ultra.
https://www.androidauthority.com/galaxy-z-fold-8-trifold-standing-case-filing-3674518/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Possible Phishing 🎣
on: ⚠️hxxp[:]//f[.]digitalmaillane[.]com/igit/4/9umr931Ygzdtucv6mgY2ixYqpl4tmgY6glYiiaYt6YmYf
🧬 Analysis at: https://urldna.io/scan/6a211c353b7750000881301b
#cybersecurity #phishing #infosec #urldna #scam #infosec
🚨 Chrome extension developers face tailored credential theft The phishing kit pulls real extension metadata, creates fake takedown timelines and captures #Google logins via a fake accounts[.]google[.]com window. 🔗 read more: gbhackers.com/fake-chrome-... #ransomNews #cybersecurity #Chrome
🚨New ransom group blog post!🚨
Group name: akira
Post title: Northern Ohio Regional Multiple Listing Service
Info: https://cti.fyi/groups/akira.html
#ransomware #cti #threatintelligence #cybersecurity #infosec
This Google Photos update has saved your digital photo frame
Now you don’t have to manually add new photos of loved ones to your grandma’s Aura frame. | Image: Aura Aura's digital photo frames will continue to automatically sync with your Google Photos albums, after API changes t…
https://www.theverge.com/tech/942860/aura-frame-google-photos-api-update-auto-sync
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
FSB’s matryoshka #2/3 – Gamaredon’s gifts that keeps unpacking – GammaLoad
Gamaredon, an FSB-operated cyberespionage group, continues targeting Ukrainian government, military, and critical infrastructure through sophisticated multi-stage infection chains. This analysis examines GammaLoad, a collection of VBScript loaders that establish continuous access through three distinct stages. The malware leverages Dead Drop Resolvers on legitimate platforms including Telegram, Telegraph, and Check-Host to maintain persistent C2 communications while storing configurations in Windows registry keys. Each stage employs different techniques: the first fingerprints hosts and uses failover mechanisms, the second writes payloads to Alternate Data Streams and establishes persistence via scheduled tasks, and the third executes obfuscated PowerShell to deliver the final GammaSteel payload. This matryoshka architecture enables operators to deploy arbitrary payloads while remaining largely invisible by abusing trusted Windows features and cloud platforms.
Pulse ID: 6a2029a0dfb4183bb573e8b2
Pulse Link: https://otx.alienvault.com/pulse/6a2029a0dfb4183bb573e8b2
Pulse Author: AlienVault
Created: 2026-06-03 13:18:24
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #Cyberespionage #Espionage #Gamaredon #Government #InfoSec #Malware #Military #OTX #OpenThreatExchange #PowerShell #RAT #Rust #SMS #Telegram #UK #Ukr #Ukrainian #VBS #Windows #bot #AlienVault
Error 524 Decoy: Unmasking a Global Smishing Operation Hiding Behind Error Pages
A sophisticated smishing and phishing operation active since the second half of 2025 has impersonated over 267 brands across 72 countries, with particular concentration in Latin America. The campaign generated 4,389 phishing domain instances, with Mexico accounting for 1,851 cases. Telecommunications is the most targeted sector with 1,754 instances, followed by financial services and consumer rewards programs. The operation employs fake Cloudflare error pages as decoys, revealing malicious content only to victims matching specific geofencing and mobile device criteria. Data exfiltration occurs through encrypted WebSocket channels using binary encoded payloads. Approximately 30% of infrastructure is hosted on Tencent Cloud and Alibaba US servers, fronted by Cloudflare to mask hosting IPs. The attack chain progresses from SMS lures through progressive credential harvesting, ultimately capturing complete credit card details including CVV codes.
Pulse ID: 6a20299f34e4961fdaff1615
Pulse Link: https://otx.alienvault.com/pulse/6a20299f34e4961fdaff1615
Pulse Author: AlienVault
Created: 2026-06-03 13:18:23
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CredentialHarvesting #CreditCard #CyberSecurity #InfoSec #LatinAmerica #Mexico #OTX #OpenThreatExchange #Phishing #RAT #SMS #Smishing #Telecom #Telecommunication #bot #AlienVault
Espionage Campaign Targeted Stock Exchange Executive for Five Months
Unknown attackers conducted a five-month espionage campaign against a senior executive at a major global stock exchange, systematically stealing the victim's Outlook mailbox in incremental batches. The attackers demonstrated sophisticated operational discipline by using legitimate cloud services like Dropbox and OneDrive Personal for exfiltration and command-and-control infrastructure. They employed an Aspose-based mailbox stealer to extract OST files in date-range windows, beginning with historical emails from August 2025 and continuing with regular two-to-four-week intervals through February 2026. The intrusion maintained persistence through masquerading binaries and scheduled tasks themed around legitimate Adobe and Lenovo services. By extracting mailbox data incrementally and routing traffic through trusted cloud platforms, the attackers avoided detection while building a comprehensive intelligence picture of the executive's communications and organizational activities.
Pulse ID: 6a20244c903528f34d6a04f4
Pulse Link: https://otx.alienvault.com/pulse/6a20244c903528f34d6a04f4
Pulse Author: AlienVault
Created: 2026-06-03 12:55:40
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Adobe #Cloud #CyberSecurity #Dropbox #EDR #Email #Espionage #InfoSec #OTX #OpenThreatExchange #Outlook #RAT #Rust #Windows #bot #AlienVault
Inside DesckVB Rat Analysis: From Malspam to In-Memory RAT
DesckVB RAT emerged in February 2026 through a sophisticated malspam campaign utilizing a dynamic delivery kit that personalizes lures on-the-fly by extracting victim email addresses and pulling company logos in real-time. The attack chain routes through Google's DoubleClick domain to evade email gateways before delivering a five-stage infection: HTML redirect, JScript loader, PowerShell dropper, .NET loader, and finally the RAT itself. The malware employs extensive anti-analysis techniques including sandbox detection, forced reboots upon detection, and in-memory execution via .NET reflection. Once established, it patches AMSI and ETW at the native API level, injects into legitimate Microsoft-signed binaries like InstallUtil.exe and MSBuild.exe, and establishes persistence through registry keys and scheduled tasks. The RAT communicates with DDNS-based C2 infrastructure on non-standard ports, performs system reconnaissance including GPU enumeration possibly for crypto mining, and can deliver additional payl...
Pulse ID: 6a20299eb75a686b68713273
Pulse Link: https://otx.alienvault.com/pulse/6a20299eb75a686b68713273
Pulse Author: AlienVault
Created: 2026-06-03 13:18:22
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CryptoMining #CyberSecurity #DNS #DoubleClick #ELF #Email #Google #HTML #InfoSec #MSBuild #MalSpam #Malware #Microsoft #NET #OTX #OpenThreatExchange #PowerShell #RAT #RCE #Spam #bot #AlienVault
Google’s latest on-device AI model is custom-made for your laptop
It bridges the gap between the E4B and 26B MoE models.
https://www.androidauthority.com/google-gemma-4-12b-multimodal-ai-model-3674379/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
CVE-2026-8206 (CVSS 9.8): Kirki WordPress Plugin Flaw Lets Attackers Steal Admin Accounts on 500,000+ Sites
#CyberSecurity
https://securebulletin.com/cve-2026-8206-cvss-9-8-kirki-wordpress-plugin-flaw-lets-attackers-steal-admin-accounts-on-500000-sites/
Five OpenClaw Zero-Days Let Attackers Silently Hijack AI Agent Access on Slack, Teams, and Discord
#CyberSecurity
https://securebulletin.com/five-openclaw-zero-days-let-attackers-silently-hijack-ai-agent-access-on-slack-teams-and-discord/
Threat Actors Use AI Agents and Cursor IDE to Automate Active Directory Attacks and Beat EDR
#CyberSecurity
https://securebulletin.com/threat-actors-use-ai-agents-and-cursor-ide-to-automate-active-directory-attacks-and-beat-edr/
I’ve finally figured out exactly who this Google Pixel is meant for
Approachable enough to charm three generations.
https://www.androidauthority.com/google-pixel-10a-experience-3672890/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
CVE-2025-48595: Android 0-Day Actively Exploited — Patch Your Devices Now
#CyberSecurity
https://securebulletin.com/cve-2025-48595-android-0-day-actively-exploited-patch-your-devices-now/
Possible Phishing 🎣
on: ⚠️hxxps[:]//consejo-superior-esic[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a20f1ff3b77500008812c10
#cybersecurity #phishing #infosec #urldna #scam #infosec
Argamal: Malware hidden in hentai games
In April 2026, researchers discovered a malware campaign targeting players of adult-themed games. The infected games install a previously unknown implant called Argamal that downloads and executes a RAT after several days, resulting in full system compromise. The malware uses COM hijacking to persist, replacing the InprocServer32 entry for Windows Color System Calibration Loader DLL. Delivery occurs through trojanized games distributed via dedicated websites and torrent trackers, containing modified FFmpeg DLLs that load malicious components. The RAT provides broad functionality including system control, surveillance, file operations, and reconnaissance capabilities. Hundreds of victims have been identified primarily in Russia, Brazil, Germany, and Vietnam. Attribution suggests a Spanish-speaking developer, with infrastructure pointing to ASN 11664 and multiple C2 domains.
Pulse ID: 6a214338125edff8d16ab273
Pulse Link: https://otx.alienvault.com/pulse/6a214338125edff8d16ab273
Pulse Author: AlienVault
Created: 2026-06-04 09:19:52
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Brazil #CyberSecurity #Germany #InfoSec #Malware #OTX #OpenThreatExchange #RAT #Russia #Trojan #Vietnam #Windows #bot #AlienVault