voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
New by me: "Patch Faster" Is Not a Strategy Anymore
https://www.kylereddoch.me/blog/patch-faster-is-not-a-strategy-anymore/
#Cybersecurity #InfoSec #VulnerabilityManagement #PatchManagement #MSP
🔴 CVE-2026-36576 - Critical (9.8)
An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 allows attackers to execute arbitrary commands via a crafted POST request.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-36576/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Possible Phishing 🎣
on: ⚠️hxxp[:]//samriddhii07[.]github[.]io/Netflif_clone
🧬 Analysis at: https://urldna.io/scan/6a1ff4d23b7750000201e612
#cybersecurity #phishing #infosec #urldna #scam #infosec
🟠 CVE-2026-35084 - High (8.8)
A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access as root.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-35084/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-35085 - High (8.8)
A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system access as root.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-35085/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Autonomous AI Uncovers Two-Year-Old Redis RCE: CVE-2026-23479 https://deafnews.it/en/article/ai-autonoma-trova-rce-in-redis-cve-2026-23479 #Cybersecurity
A projector lineup known for luxury pricing just got a lot more interesting
Leica's new compact 4K projector just landed at much lower price point.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
CISA, FBI, and NSA have issued a critical alert: Cyberattacks are actively targeting Automatic Tank Gauging (ATG) systems in vital sectors like energy and agriculture. Attackers exploit simple flaws like default passwords to manipulate fuel readings and disable leak detection, creating a 'false sense of security where operators perceive normal conditions while underlying processes are compromised.' This…
🤖 This post was AI-generated.
Gemini Go is here to replace Assistant on your Android Go phone
Android Go devices are finally joining the Gemini party.
https://www.androidauthority.com/google-starts-gemini-go-rollout-3674174/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Possible Phishing 🎣
on: ⚠️hxxps[:]//spjezioranye[.]github[.]io/outl00k
🧬 Analysis at: https://urldna.io/scan/6a1ff4f03b7750000201e644
#cybersecurity #phishing #infosec #urldna #scam #infosec
Amazon’s new AI search shows fake products first, then tries to sell you the real thing
Amazon Shopping’s AI previews could make it easier to browse — or just more frustrating.
https://www.androidauthority.com/amazon-ai-search-3674160/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Russian #spy agency says foreign spies turned officials' smartphones into #surveillance devices
#Russia #privacy #politics #espionage #cybersecurity #phone #FSB #smartphone
🚨 EUVD-2026-34097
📊 Score: 8.4/10 (CVSS v3.1)
📦 Product: glpi
🏢 Vendor: glpi-project
📅 Updated: 2026-06-03
📝 GLPI is a free asset and IT management software package. Starting in version 10.0.4 and prior to version 10.0.25, a technician can store an XSS payload in the asset locked tab. Upgrade to 10.0.25 or 11.0.7 to receive a patch.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34097
🚨 EUVD-2026-34096
📊 Score: 5.9/10 (CVSS v3.1)
📦 Product: glpi, glpi
🏢 Vendor: glpi-project
📅 Updated: 2026-06-03
📝 GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versions 10.0.25 and 11.0.7, a technician can read arbitrary files inside the GLPI_DOC_DIR. Upgrade to 10.0.25 or 11.0.7 to receive a patch.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34096
🚨 EUVD-2026-34095
📊 Score: 7.0/10 (CVSS v3.1)
📦 Product: glpi, glpi
🏢 Vendor: glpi-project
📅 Updated: 2026-06-03
📝 GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to versions 10.0.25 and 11.0.7, low privilege users with access to planning can delete any object in GLPI. Upgrade to 11.0.7 or 10.0.25 to receive a patch. A...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34095
🚨 EUVD-2026-34105
📊 Score: 7.0/10 (CVSS v3.1)
📦 Product: glpi, glpi
🏢 Vendor: glpi-project
📅 Updated: 2026-06-03
📝 GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0.7, a technician can delete arbitrary files from the filesystem as long as the webserver has write rights on them. Upgrade to 10.0...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34105
🚨 EUVD-2026-34104
📊 Score: 6.1/10 (CVSS v3.1)
📦 Product: jupyter/jupyter
🏢 Vendor: jupyter
📅 Updated: 2026-06-03
📝 A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation when the `allow_origin_pat` configuration is used. The issue arises from the use of `re.match()` for validating the `Origin` header, ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34104
🚨 EUVD-2026-34098
📊 Score: n/a
📅 Updated: 2026-06-03
📝 A DLL hijacking vulnerability in Wassimulator (GitHub) CactusViewer v2.3.0 allows attackers to escalate privileges and execute arbitrary code via a crafted DLL.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34098
🚨 EUVD-2026-34099
📊 Score: n/a
📅 Updated: 2026-06-03
📝 An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 allows attackers to execute arbitrary commands via a crafted POST request.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34099
🚨 EUVD-2022-55999
📊 Score: 5.1/10 (CVSS v3.1)
📦 Product: CRUD, CRUD, CRUD
🏢 Vendor: Laravel-Backpack
📅 Updated: 2026-06-03
📝 backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Versions prior to 5.0.13, 4.1.69, and 4.0.63 are vulnerable to cross-si...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-55999
🚨 EUVD-2026-34103
📊 Score: 6.3/10 (CVSS v3.1)
📦 Product: CPython
🏢 Vendor: Python Software Foundation
📅 Updated: 2026-06-03
📝 unicodedata.normalize() can take excessive CPU time when processing
specially crafted Unicode input containing long runs of combining characters
with alternating Canonical Combining Class values.
This affects all normalization forms.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34103
🚨 EUVD-2026-34101
📊 Score: n/a
📅 Updated: 2026-06-03
📝 An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34101
🚨 EUVD-2026-34102
📊 Score: 7.0/10 (CVSS v3.1)
📦 Product: glpi, glpi
🏢 Vendor: glpi-project
📅 Updated: 2026-06-03
📝 GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0.7, an authenticated user with config READ permission can read a specific asset object. Upgrade to 11.0.7 or 10.0.25 to receive a ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34102
PlayStation is getting back to what it’s good at
PlayStation used its most recent State of Play showcase to make it clear where its focus is. After a series of costly live-service stumbles, it's getting back to focusing on premium, narrative-driven, single-player game…
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Who’s that mystery caller? This free tool checks if it might be scammy
Malwarebytes now has a free reverse phone lookup tool for checking whether that missed call looks suspicious.
https://www.androidauthority.com/malwarebytes-free-reverse-phone-check-launch-3674058/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Possible Phishing 🎣
on: ⚠️hxxp[:]//www[.]5mp[.]eu/fajlok2/owaweb/owa_www[.]5mp[.]eu_[.]html
🧬 Analysis at: https://urldna.io/scan/6a1fdf273b775000086a6ce9
#cybersecurity #phishing #infosec #urldna #scam #infosec
Amazon’s search bar will invent AI-generated products you can’t buy
Amazon's updated search bar will now show you AI-generated images of products as you describe them. For now, the in-app feature only surfaces AI images of clothing and home goods, allowing you to tap on the image that b…
https://www.theverge.com/tech/942547/amazon-search-bar-ai-images
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Dashlane password manager users locked out by brute force attacks
Multiple Dashlane users have been locked out of their accounts following brute-force attacks that attempted logins from distant locations and unknown devices.
#dashlane #passwordmanager #security #cybersecurity #hackers #hacking
I’m at Hackers Teaching Hackers today in the “From Recon to Remediation” workshop to improve my skills with AI pentesting agents #Cybersecurity #hth #hackersteachinghackers
Strategic Education Inc. Data Breach Exposes Sensitive Identification Data
Strategic Education Inc. reports a data breach occurring in February 2026 that exposed the Social Security numbers, driver’s license numbers, and passport numbers.
****
#cybersecurity #infosec #incident #databreach
https://beyondmachines.net/event_details/strategic-education-inc-data-breach-exposes-sensitive-identification-data-4-7-y-l-b/gD2P6Ple2L
These iconic Android gaming handhelds will soon get Android 16-based LineageOS
Among others, LineageOS could especially save the AYN Odin 2 and Odin 2 Mini from an early grave.
https://www.androidauthority.com/ayn-odin-2-3-thor-lineageos-3673805/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]