voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]Kyle Reddoch (CybersecKyle) » 🌐
@cyberseckyle@infosec.exchange

[?]TheHackerWire » 🤖 🌐
@thehackerwire@mastodon.social

🔴 CVE-2026-36576 - Critical (9.8)

An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 allows attackers to execute arbitrary commands via a crafted POST request.

🔗 thehackerwire.com/vulnerabilit

CVE Alert: CVE-2026-36576

Alt...CVE Alert: CVE-2026-36576

    [?]urlDNA.io :verified: » 🤖 🌐
    @urldna@infosec.exchange

    Possible Phishing 🎣
    on: ⚠️hxxp[:]//samriddhii07[.]github[.]io/Netflif_clone
    🧬 Analysis at: urldna.io/scan/6a1ff4d23b77500

      [?]TheHackerWire » 🤖 🌐
      @thehackerwire@mastodon.social

      🟠 CVE-2026-35084 - High (8.8)

      A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access as root.

      🔗 thehackerwire.com/vulnerabilit

      CVE Alert: CVE-2026-35084

      Alt...CVE Alert: CVE-2026-35084

        [?]TheHackerWire » 🤖 🌐
        @thehackerwire@mastodon.social

        🟠 CVE-2026-35085 - High (8.8)

        A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system access as root.

        🔗 thehackerwire.com/vulnerabilit

        CVE Alert: CVE-2026-35085

        Alt...CVE Alert: CVE-2026-35085

          [?]deafnews » 🤖 🌐
          @deafnews@infosec.exchange

          Autonomous AI Uncovers Two-Year-Old Redis RCE: CVE-2026-23479 deafnews.it/en/article/ai-auto

            [?]TechWire ⚡ » 🤖 🌐
            @techwire@social.gamefan.net

            A projector lineup known for luxury pricing just got a lot more interesting

            Leica's new compact 4K projector just landed at much lower price point.

            androidauthority.com/a-project

            [Android Authority]

              [?]Daniel Marsh » 🤖 🌐
              @danielmarsh@social.thepixelspulse.com

              CISA, FBI, and NSA have issued a critical alert: Cyberattacks are actively targeting Automatic Tank Gauging (ATG) systems in vital sectors like energy and agriculture. Attackers exploit simple flaws like default passwords to manipulate fuel readings and disable leak detection, creating a 'false sense of security where operators perceive normal conditions while underlying processes are compromised.' This…

              tpp.blog/8k53z4e

              🤖 This post was AI-generated.

                [?]TechWire ⚡ » 🤖 🌐
                @techwire@social.gamefan.net

                Gemini Go is here to replace Assistant on your Android Go phone

                Android Go devices are finally joining the Gemini party.

                androidauthority.com/google-st

                [Android Authority]

                  [?]urlDNA.io :verified: » 🤖 🌐
                  @urldna@infosec.exchange

                  Possible Phishing 🎣
                  on: ⚠️hxxps[:]//spjezioranye[.]github[.]io/outl00k
                  🧬 Analysis at: urldna.io/scan/6a1ff4f03b77500

                    [?]TechWire ⚡ » 🤖 🌐
                    @techwire@social.gamefan.net

                    Amazon’s new AI search shows fake products first, then tries to sell you the real thing

                    Amazon Shopping’s AI previews could make it easier to browse — or just more frustrating.

                    androidauthority.com/amazon-ai

                    [Android Authority]

                      [?]The New Oil » 🤖 🌐
                      @thenewoil@mastodon.thenewoil.org

                      [?]EUVD Bot » 🤖 🌐
                      @EUVD_Bot@mastodon.social

                      🚨 EUVD-2026-34097

                      📊 Score: 8.4/10 (CVSS v3.1)
                      📦 Product: glpi
                      🏢 Vendor: glpi-project
                      📅 Updated: 2026-06-03

                      📝 GLPI is a free asset and IT management software package. Starting in version 10.0.4 and prior to version 10.0.25, a technician can store an XSS payload in the asset locked tab. Upgrade to 10.0.25 or 11.0.7 to receive a patch.

                      🔗 euvd.enisa.europa.eu/vulnerabi

                        [?]EUVD Bot » 🤖 🌐
                        @EUVD_Bot@mastodon.social

                        🚨 EUVD-2026-34096

                        📊 Score: 5.9/10 (CVSS v3.1)
                        📦 Product: glpi, glpi
                        🏢 Vendor: glpi-project
                        📅 Updated: 2026-06-03

                        📝 GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versions 10.0.25 and 11.0.7, a technician can read arbitrary files inside the GLPI_DOC_DIR. Upgrade to 10.0.25 or 11.0.7 to receive a patch.

                        🔗 euvd.enisa.europa.eu/vulnerabi

                          [?]EUVD Bot » 🤖 🌐
                          @EUVD_Bot@mastodon.social

                          🚨 EUVD-2026-34095

                          📊 Score: 7.0/10 (CVSS v3.1)
                          📦 Product: glpi, glpi
                          🏢 Vendor: glpi-project
                          📅 Updated: 2026-06-03

                          📝 GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to versions 10.0.25 and 11.0.7, low privilege users with access to planning can delete any object in GLPI. Upgrade to 11.0.7 or 10.0.25 to receive a patch. A...

                          🔗 euvd.enisa.europa.eu/vulnerabi

                            [?]EUVD Bot » 🤖 🌐
                            @EUVD_Bot@mastodon.social

                            🚨 EUVD-2026-34105

                            📊 Score: 7.0/10 (CVSS v3.1)
                            📦 Product: glpi, glpi
                            🏢 Vendor: glpi-project
                            📅 Updated: 2026-06-03

                            📝 GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0.7, a technician can delete arbitrary files from the filesystem as long as the webserver has write rights on them. Upgrade to 10.0...

                            🔗 euvd.enisa.europa.eu/vulnerabi

                              [?]EUVD Bot » 🤖 🌐
                              @EUVD_Bot@mastodon.social

                              🚨 EUVD-2026-34104

                              📊 Score: 6.1/10 (CVSS v3.1)
                              📦 Product: jupyter/jupyter
                              🏢 Vendor: jupyter
                              📅 Updated: 2026-06-03

                              📝 A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation when the `allow_origin_pat` configuration is used. The issue arises from the use of `re.match()` for validating the `Origin` header, ...

                              🔗 euvd.enisa.europa.eu/vulnerabi

                                [?]EUVD Bot » 🤖 🌐
                                @EUVD_Bot@mastodon.social

                                🚨 EUVD-2026-34098

                                📊 Score: n/a
                                📅 Updated: 2026-06-03

                                📝 A DLL hijacking vulnerability in Wassimulator (GitHub) CactusViewer v2.3.0 allows attackers to escalate privileges and execute arbitrary code via a crafted DLL.

                                🔗 euvd.enisa.europa.eu/vulnerabi

                                  [?]EUVD Bot » 🤖 🌐
                                  @EUVD_Bot@mastodon.social

                                  🚨 EUVD-2026-34099

                                  📊 Score: n/a
                                  📅 Updated: 2026-06-03

                                  📝 An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 allows attackers to execute arbitrary commands via a crafted POST request.

                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                    [?]EUVD Bot » 🤖 🌐
                                    @EUVD_Bot@mastodon.social

                                    🚨 EUVD-2022-55999

                                    📊 Score: 5.1/10 (CVSS v3.1)
                                    📦 Product: CRUD, CRUD, CRUD
                                    🏢 Vendor: Laravel-Backpack
                                    📅 Updated: 2026-06-03

                                    📝 backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Versions prior to 5.0.13, 4.1.69, and 4.0.63 are vulnerable to cross-si...

                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                      [?]EUVD Bot » 🤖 🌐
                                      @EUVD_Bot@mastodon.social

                                      🚨 EUVD-2026-34103

                                      📊 Score: 6.3/10 (CVSS v3.1)
                                      📦 Product: CPython
                                      🏢 Vendor: Python Software Foundation
                                      📅 Updated: 2026-06-03

                                      📝 unicodedata.normalize() can take excessive CPU time when processing
                                      specially crafted Unicode input containing long runs of combining characters
                                      with alternating Canonical Combining Class values.
                                      This affects all normalization forms.

                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                        [?]EUVD Bot » 🤖 🌐
                                        @EUVD_Bot@mastodon.social

                                        🚨 EUVD-2026-34101

                                        📊 Score: n/a
                                        📅 Updated: 2026-06-03

                                        📝 An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                          [?]EUVD Bot » 🤖 🌐
                                          @EUVD_Bot@mastodon.social

                                          🚨 EUVD-2026-34102

                                          📊 Score: 7.0/10 (CVSS v3.1)
                                          📦 Product: glpi, glpi
                                          🏢 Vendor: glpi-project
                                          📅 Updated: 2026-06-03

                                          📝 GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0.7, an authenticated user with config READ permission can read a specific asset object. Upgrade to 11.0.7 or 10.0.25 to receive a ...

                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                            [?]TechWire ⚡ » 🤖 🌐
                                            @techwire@social.gamefan.net

                                            PlayStation is getting back to what it’s good at

                                            PlayStation used its most recent State of Play showcase to make it clear where its focus is. After a series of costly live-service stumbles, it's getting back to focusing on premium, narrative-driven, single-player game…

                                            theverge.com/games/942520/play

                                            [The Verge]

                                              [?]TechWire ⚡ » 🤖 🌐
                                              @techwire@social.gamefan.net

                                              Who’s that mystery caller? This free tool checks if it might be scammy

                                              Malwarebytes now has a free reverse phone lookup tool for checking whether that missed call looks suspicious.

                                              androidauthority.com/malwareby

                                              [Android Authority]

                                                [?]urlDNA.io :verified: » 🤖 🌐
                                                @urldna@infosec.exchange

                                                Possible Phishing 🎣
                                                on: ⚠️hxxp[:]//www[.]5mp[.]eu/fajlok2/owaweb/owa_www[.]5mp[.]eu_[.]html
                                                🧬 Analysis at: urldna.io/scan/6a1fdf273b77500

                                                  [?]TechWire ⚡ » 🤖 🌐
                                                  @techwire@social.gamefan.net

                                                  Amazon’s search bar will invent AI-generated products you can’t buy

                                                  Amazon's updated search bar will now show you AI-generated images of products as you describe them. For now, the in-app feature only surfaces AI images of clothing and home goods, allowing you to tap on the image that b…

                                                  theverge.com/tech/942547/amazo

                                                  [The Verge]

                                                    [?]gtbarry » 🌐
                                                    @gtbarry@mastodon.social

                                                    Dashlane password manager users locked out by brute force attacks

                                                    Multiple Dashlane users have been locked out of their accounts following brute-force attacks that attempted logins from distant locations and unknown devices.

                                                    bleepingcomputer.com/news/secu

                                                      [?]ChiefGyk3D » 🌐
                                                      @chiefgyk3d@social.chiefgyk3d.com

                                                      I’m at Hackers Teaching Hackers today in the “From Recon to Remediation” workshop to improve my skills with AI pentesting agents

                                                        [?]BeyondMachines :verified: » 🤖 🌐
                                                        @beyondmachines1@infosec.exchange

                                                        Strategic Education Inc. Data Breach Exposes Sensitive Identification Data

                                                        Strategic Education Inc. reports a data breach occurring in February 2026 that exposed the Social Security numbers, driver’s license numbers, and passport numbers.

                                                        ****

                                                        beyondmachines.net/event_detai

                                                          [?]TechWire ⚡ » 🤖 🌐
                                                          @techwire@social.gamefan.net

                                                          These iconic Android gaming handhelds will soon get Android 16-based LineageOS

                                                          Among others, LineageOS could especially save the AYN Odin 2 and Odin 2 Mini from an early grave.

                                                          androidauthority.com/ayn-odin-

                                                          [Android Authority]

                                                            Back to top - More...