voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
Preinstall to persistence: Inside the npm Miasma credential-stealing campaign
Microsoft Threat Intelligence discovered a large-scale npm supply chain attack compromising 32 malicious packages across over 90 versions under the @redhat-cloud-services scope. The compromise originated from the RedHatInsights/javascript-clients CI/CD pipeline, enabling attackers to publish trojanized packages through legitimate GitHub Actions OIDC workflows with authentic provenance signatures. The malicious packages executed a heavily obfuscated 4.29 MB dropper via npm preinstall hooks, which downloaded the Bun JavaScript runtime and launched payloads designed to harvest credentials from GitHub, npm, AWS, Azure, GCP, HashiCorp Vault, Kubernetes, and developer systems. The malware scraped GitHub Actions runner memory for secrets, escalated privileges using passwordless sudo, exfiltrated stolen data through GitHub infrastructure, and propagated by compromising additional maintainer packages with forged SLSA provenance. The campaign marker "Miasma: The Spreading Blight" was embedded throughout the malicious
Pulse ID: 6a214311a2c1a61296efbdc5
Pulse Link: https://otx.alienvault.com/pulse/6a214311a2c1a61296efbdc5
Pulse Author: AlienVault
Created: 2026-06-04 09:19:13
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #Azure #Cloud #CyberSecurity #GitHub #InfoSec #Java #JavaScript #Malware #Microsoft #NPM #OTX #OpenThreatExchange #Password #RAT #SupplyChain #Trojan #Word #bot #AlienVault
Browser Spy-Ons: Threat Actor's Extension Hijack Your AI Conversations
Multiple malicious Chrome extensions are exploiting the growing use of AI platforms by disguising themselves as legitimate productivity tools while secretly stealing user conversations and personal data. Extensions including Urban VPN, Smart Sidebar, and AI Assistant/Chat AI collectively reach millions of users but contain hidden scripts that intercept communications with popular AI platforms like ChatGPT, Claude, DeepSeek, Gemini, and others. These extensions inject malicious JavaScript that overrides network requests, monitors DOM elements for chat interactions, and exfiltrates sensitive data including conversation content, session identifiers, and timestamps to remote servers. The threat is particularly concerning as users frequently share confidential personal, medical, and corporate information with AI platforms, making intercepted conversations highly valuable for threat actors.
Pulse ID: 6a20e718f462b45e7fbd0db2
Pulse Link: https://otx.alienvault.com/pulse/6a20e718f462b45e7fbd0db2
Pulse Author: AlienVault
Created: 2026-06-04 02:46:48
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #ChatGPT #Chrome #ChromeExtension #CyberSecurity #InfoSec #Java #JavaScript #LUA #OTX #OpenThreatExchange #RAT #RCE #VPN #bot #AlienVault
Inside the Cross-Platform Propagation of a New Gafgyt Variant C0XMO
A new Gafgyt botnet variant named C0XMO has been discovered that spreads by exploiting a stack buffer overflow vulnerability in DD-WRT router firmware. Unlike earlier versions, this malware separates its lateral movement capabilities into a standalone Python script, enabling more efficient targeting of various system architectures including ARM, MIPS, PowerPC, and x86. The malware establishes persistence through cron jobs and shell profile modifications, eliminates competing botnets, and supports 19 different DDoS attack methods. Its scanner component performs weak-credential brute-force attacks on Telnet and SSH services while also exploiting multiple HTTP-based vulnerabilities and Android Debug Bridge unauthorized access. The malware connects to command-and-control infrastructure and demonstrates significantly more sophisticated architecture compared to traditional IoT botnets.
Pulse ID: 6a20a73f2ecb12c1ffd10df5
Pulse Link: https://otx.alienvault.com/pulse/6a20a73f2ecb12c1ffd10df5
Pulse Author: AlienVault
Created: 2026-06-03 22:14:23
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #CyberSecurity #DDoS #DoS #Gafgyt #HTTP #InfoSec #IoT #Malware #OTX #OpenThreatExchange #Python #RAT #RCE #RPC #SSH #Telnet #Vulnerability #bot #botnet #AlienVault
The Demon Arrives Later: A Havoc Stager Hides Behind Microsoft Defender DLP
Cybercriminals in Brazil are exploiting the country's electronic invoice system (Nota Fiscal eletrônica) to deliver Havoc framework implants. The campaign surfaced during May 2026, coinciding with tax season when accountants routinely process invoice-related emails. Attackers distribute malicious ZIP files disguised as legitimate invoices, containing VBScript droppers that download MSI installers from Google Cloud Storage. These installers deploy a fake Microsoft Defender DLP module (endpointdlp.dll) alongside a legitimate signed executable. The stager DLL downloads Havoc demon shellcode from command-and-control infrastructure at runtime, never writing the final payload to disk. Analysis reveals nine stager variants originating from a single builder, distributed through multiple channels including Brazilian NF-e-themed lures and Malaysia-registered domains. The implant establishes persistence through the rarely-monitored UserInitMprLogonScript registry key and employs advanced anti-forensic techniques incl...
Pulse ID: 6a20a73fc005e1fc15255876
Pulse Link: https://otx.alienvault.com/pulse/6a20a73fc005e1fc15255876
Pulse Author: AlienVault
Created: 2026-06-03 22:14:23
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Brazil #Cloud #CyberSecurity #Email #Endpoint #Google #InfoSec #Microsoft #MicrosoftDefender #OTX #OpenThreatExchange #ShellCode #VBS #ZIP #bot #AlienVault
Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem
A large-scale operation impersonates open-source and freeware projects to capture search traffic, targeting tools such as Ghidra, dnSpy, and SpiderFoot. The professionally designed sites load CloudFront-hosted JavaScript that converts download button clicks into handoffs to a Traffic Distribution System (TDS), which enforces strict gating including first-visit state, click confirmation, anti-bot logic, VPN filtering, and frequency capping. The ecosystem appears primarily built for traffic acquisition and monetization using legitimate ad-tech, but downstream redirect chains repeatedly led selected users to malware delivery infrastructure. The observed payloads include SessionGate (a multi-stage loader with heavy obfuscation delivering potentially unwanted applications), RemusStealer (an infostealer targeting over 20 browsers and hundreds of extensions), and AnimateClipper (a cryptocurrency clipper supporting 20+ blockchain ecosystems). Over 5,000 VirusTotal submissions indicate substantial reach across the ...
Pulse ID: 6a20679f5ade869dcb4bf6b5
Pulse Link: https://otx.alienvault.com/pulse/6a20679f5ade869dcb4bf6b5
Pulse Author: AlienVault
Created: 2026-06-03 17:42:55
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Browser #Cloud #CyberSecurity #DNS #InfoSec #InfoStealer #Java #JavaScript #Malware #Nim #OTX #OpenThreatExchange #RAT #RCE #Rust #VPN #VirusTotal #bot #cryptocurrency #AlienVault
Quick Share might soon give your family an easier way to share files with you
Get ready for your annoying sibling to spam you endlessly.
https://www.androidauthority.com/quick-share-receive-family-visibility-3674392/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
PCPJack Hijacked 230 AWS, GCP, and Azure Servers to Run a Hidden SMTP Relay Network
PCPJack operators compromised 230 cloud Linux servers across AWS, GCP, and Azure to build a covert SMTP relay network for email-based attacks. Researchers discovered exposed directories on infrastructure at 213.136.80[.]73 containing complete deployment toolkits including Chisel binaries, Python deployers, and operational state files. The campaign deployed Sliver C2 beacons and established reverse SOCKS5 tunnels on compromised hosts, testing each for SMTP relay capability. Three deployment versions showed operational evolution from 50 to 230 nodes, with verified proxies synchronized every five minutes to a downstream aggregation server. The operation targeted cloud-hosted web applications, exploiting them to gain initial access, then establishing persistence through systemd services and cron jobs disguised as system utilities. Victims included small to medium businesses across multiple regions running containerized and traditional workloads.
Pulse ID: 6a2067cbef8cf15f958711ce
Pulse Link: https://otx.alienvault.com/pulse/6a2067cbef8cf15f958711ce
Pulse Author: AlienVault
Created: 2026-06-03 17:43:39
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #Azure #Cloud #CyberSecurity #Email #InfoSec #Linux #OTX #OpenThreatExchange #Python #RAT #Sliver #bot #socks5 #AlienVault
🔴 CVE-2026-41283 - Critical (9.9)
OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-41283/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-41010 - High (8.2)
ReleaseJob#unpack builds job_dir = File.join(@release_dir, 'jobs', name) and job_tgz = File.join(@release_dir, 'jobs', "#{name}.tgz") where name returns @job_meta['name'], a value taken verbatim from the jobs: array of the attacker-supplied releas...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-41010/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-41859 - High (7.8)
A network man-in-the-middle between nats-sync and the BOSH director can steal the director credentials (Basic auth header or UAA client secret) and can tamper with the VM list that is written into the NATS authorization file. Stolen credentials gr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-41859/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🚨 EUVD-2026-34201
📊 Score: 9.9/10 (CVSS v3.1)
📦 Product: Mistral, Mistral, Mistral
🏢 Vendor: OpenStack
📅 Updated: 2026-06-04
📝 OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34201
🚨 EUVD-2026-34200
📊 Score: 8.6/10 (CVSS v3.1)
📦 Product: Connect M6E 5G Portable WiFi Router
🏢 Vendor: Acer
📅 Updated: 2026-06-04
📝 The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +) to enumerate hidden network devices or publish rogue control commands.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34200
🚨 EUVD-2026-34202
📊 Score: 4.9/10 (CVSS v3.1)
📦 Product: Ironic, Ironic, Ironic (+1 more)
🏢 Vendor: OpenStack
📅 Updated: 2026-06-04
📝 OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34202
🚨 EUVD-2026-34203
📊 Score: 5.9/10 (CVSS v3.1)
📦 Product: Ironic, Ironic, Ironic (+1 more)
🏢 Vendor: OpenStack
📅 Updated: 2026-06-04
📝 OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34203
🚨 EUVD-2026-34199
📊 Score: 10.0/10 (CVSS v3.1)
📦 Product: Connect M6E 5G Portable WiFi Router
🏢 Vendor: Acer
📅 Updated: 2026-06-04
📝 The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34199
🚨 EUVD-2026-34198
📊 Score: 8.7/10 (CVSS v3.1)
📦 Product: BOSH Director
🏢 Vendor: Cloud Foundry Foundation
📅 Updated: 2026-06-04
📝 ReleaseJob#unpack builds job_dir = File.join(@release_dir, 'jobs', name) and job_tgz = File.join(@release_dir, 'jobs', "#{name}.tgz") where name returns @job_meta['name'], a value taken verbatim from the jobs: array of the attacker-sup...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34198
🔴 CVE-2026-47065 - Critical (9.8)
ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy
Assessment: Fully addressed.
When the serialised stream contains a TC_PROXYCLASSDESC (the marker
for a java.lang.reflect.Proxy ), JDK’s O...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47065/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2025-14772 - High (8.8)
Authorization bypass through User-Controlled key vulnerability in ABB T-MAC Plus.
This issue affects T-MAC Plus: 4.0-24.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-14772/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2025-14773 - High (8)
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in ABB T-MAC Plus.
This issue affects T-MAC Plus: 4.0-24.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-14773/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor
Pulse ID: 6a2105954034647e83ac7c6c
Pulse Link: https://otx.alienvault.com/pulse/6a2105954034647e83ac7c6c
Pulse Author: Tr1sa111
Created: 2026-06-04 04:56:53
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #InfoSec #Mac #MacOS #Malvertising #OTX #OpenThreatExchange #RAT #bot #Tr1sa111
Asus unveils its first Wi-Fi 8 router — ROG Rapture GT-BN98 Pro offers up to 2x real-world throughput uplift over Wi-Fi 7
Wi-Fi 8 is aimed at improving real-world performance over Wi-Fi 7
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
NIS2: decalogo per la conformita' del controllo accessi: di ISEO Ultimate Access Technologies Nell'ambito dell'entrata in vigore della Direttiva europea "Network and Information Security 2", ISEO Ultimate Access Technologies pubblica un decalogo operativo dedicato ai responsabili della sicurezza di infrastrutture critiche: dieci best practice imprescindibili...
#ISEO #NIS2 #cybersecurity #controlloaccessi #UltimateAccessTechnologies http://dlvr.it/TSsZv7
Samsung Health is getting a major update ahead of Galaxy Watch 9 launch
Samsung is giving Galaxy Watch users a smarter health companion just in time for its new smartwatches.
https://www.androidauthority.com/samsung-health-update-new-features-3674292/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Possible Phishing 🎣
on: ⚠️hxxps[:]//hbtnew[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a2100003b77500008812d62
#cybersecurity #phishing #infosec #urldna #scam #infosec
Microsoft announces Majorana 2 quantum computing chip — claims a practical machine will come in 2029
Microsoft's Majorana 2 quantum computing chip switches to lead-based materials. Microsoft is accelerating its roadmap and expects a practical machine in 2029.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
Nintendo confirms it will sell a new Switch 2 with replaceable battery in the EU
Nintendo is planning to launch versions of Switch 2 hardware in the EU that will let users easily replace the battery. To meet its obligations from a new EU regulation that's set to go into effect on February 18th, 2027…
https://www.theverge.com/games/942808/nintendo-switch-2-replaceable-battery-eu
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Red Hat hit by npm supply‑chain attack - here's how to stay safe
Days after IBM and Red Hat announced a master security plan for open-source software, Red Hat suffers a major breach of its own. Here's what you can do about it.
https://www.zdnet.com/article/red-hat-hit-by-npm-supply-chain-attack-how-to-stay-safe/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
Possible Phishing 🎣
on: ⚠️hxxp[:]//roblox[.]com[.]ge/games/96645548064314/Catch-And-Tame?privateServerLinkCode=21971597654613483557457763516693
🧬 Analysis at: https://urldna.io/scan/6a1fed353b7750000201e4e3
#cybersecurity #phishing #infosec #urldna #scam #infosec
I tested Microsoft Copilot Health with my real medical records - here's my verdict
By sharing your health history and records with Copilot, the AI aims to better address your own medical questions. But what are the downsides?
https://www.zdnet.com/article/microsoft-copilot-health-medical-issues/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
🚨New ransom group blog posts!🚨
Group name: incransom
Post title: CUSTOMSIGN
Info: https://cti.fyi/groups/incransom.html
Group name: medusalocker
Post title: BAIAPAI
Info: https://cti.fyi/groups/medusalocker.html
#ransomware #cti #threatintelligence #cybersecurity #infosec
How to try out over 85 Linux distros, no installation required - with DistroSea
This web-based Linux platform makes it easy to explore dozens of distributions, from the familiar to the obscure. It's free and works in any browser.
https://www.zdnet.com/article/try-dozens-of-linux-distros-no-installation-distrosea/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
Possible Phishing 🎣
on: ⚠️hxxps[:]//microsoft-clone-neon[.]vercel[.]app
🧬 Analysis at: https://urldna.io/scan/6a2002fe3b7750000201e841
#cybersecurity #phishing #infosec #urldna #scam #infosec
🚨 EUVD-2026-34187
📊 Score: 2.0/10 (CVSS v3.1)
📦 Product: gradio
🏢 Vendor: gradio-app
📅 Updated: 2026-06-03
📝 A security flaw has been discovered in gradio-app gradio 6.14.0. This affects the function save_audio_to_cache of the component Audio Cache Key Handler. Performing a manipulation results in use of weak hash. The attack must be initiated from a local positi...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34187
AI is causing cognitive fatigue. Here's how to work with more haste and less speed
Research suggests people are working harder and not smarter with AI, but there are ways to turn emerging tech into a valuable tool.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
#chrome extension Happy Easter Wallpapers seems malicious. Its #cybersecurity badness score is 93/100!
```json
{"id": "opdcfknedcfgiophhnojmnljpndojbom", "score": 93, "platform": "chrome", "name": "Happy Easter Wallpapers"}
```
#chrome extension Pikachu Wallpaper seems malicious. Its #cybersecurity badness score is 93/100!
```json
{"id": "jeoonjgjpiepmdcmgcdnadamojoefbad", "score": 93, "platform": "chrome", "name": "Pikachu Wallpaper"}
```
#chrome extension Keroppi Live Wallpaper seems malicious. Its #cybersecurity badness score is 98/100!
```json
{"id": "djlolemkfmghdipoalonefccpgjbfanc", "score": 98, "platform": "chrome", "name": "Keroppi Live Wallpaper"}
```
#chrome extension Obito Uchiha Live Wallpaper seems malicious. Its #cybersecurity badness score is 90/100!
```json
{"id": "cnlabipcnjebmibdelcindmhkkchndpd", "score": 90, "platform": "chrome", "name": "Obito Uchiha Live Wallpaper"}
```
I built a vulnerable app and spent $1,500 seeing if LLMs could hack it
https://kasra.blog/blog/i-spent-1500-seeing-if-llms-could-hack-my-app/
#HackerNews #vulnerableapp #LLM #hacking #cybersecurity #techexperiment #AIsecurity
On a budget? These are the best deals under $25 ahead of Amazon Prime Day
Amazon Prime Day is coming soon, and we've rounded up all the best cheap deals on gadgets and devices.
https://www.zdnet.com/article/best-early-amazon-prime-day-deals-under-25-2026/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
Possible Phishing 🎣
on: ⚠️hxxps[:]//bit[.]ly/4bSM5DP
🧬 Analysis at: https://urldna.io/scan/6a209da83b7750000201fca6
#cybersecurity #phishing #infosec #urldna #scam #infosec
🚨New ransom group blog post!🚨
Group name: shinyhunters
Post title: Baker Distributing Company
Info: https://cti.fyi/groups/shinyhunters.html
#ransomware #cti #threatintelligence #cybersecurity #infosec
Frustrated with your Bluetooth? How multipoint works - and why it sometimes won't
Why is dual-device wireless connectivity for your headphones and earbuds so unreliable? It's the gaping chasm between actual product specs and marketing speak.
https://www.zdnet.com/article/bluetooth-mulitpoint-explained/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
#chrome extension My Melody Cafe Live Wallpaper seems malicious. Its #cybersecurity badness score is 92/100!
```json
{"id": "kjhnajdlflnfmfdghcckbngdchajaime", "score": 92, "platform": "chrome", "name": "My Melody Cafe Live Wallpaper"}
```
#chrome extension Battlefield 6 Enshrouded Soldier Live Wallpaper seems malicious. Its #cybersecurity badness score is 98/100!
```json
{"id": "jnnkcihkpoljaejgnmaohgbodpdmfmdg", "score": 98, "platform": "chrome", "name": "Battlefield 6 Enshrouded Soldier Live Wallpaper"}
```
#chrome extension One Punch Man Saitama Space Exploration Live Wallpaper seems malicious. Its #cybersecurity badness score is 95/100!
```json
{"id": "eeicldodfhmgcjedepfmmpdpibebgkbl", "score": 95, "platform": "chrome", "name": "One Punch Man Saitama Space Exploration Live Wallpaper"}
```
How I used a $170 sports watch as my training coach to help me avoid injuries
The Amazfit Active 3 Premium offers everything you need to create a custom training plan, track metrics during your runs, and improve your fitness in just weeks.
https://www.zdnet.com/article/amazfit-active-3-premium-review/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]