voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]OTX Bot » 🤖 🌐
@techbot@social.raytec.co

Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet

Pulse ID: 6a1ff48f519a80c0b86c0280
Pulse Link: otx.alienvault.com/pulse/6a1ff
Pulse Author: Tr1sa111
Created: 2026-06-03 09:31:59

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    [?]RedPacket Security » 🌐
    @RedPacketSecurity@mastodon.social

    [?]EUVD Bot » 🤖 🌐
    @EUVD_Bot@mastodon.social

    🚨 EUVD-2026-34065

    📊 Score: 7.5/10 (CVSS v3.1)
    📦 Product: freeipmi
    🏢 Vendor: FreeIPMI
    📅 Updated: 2026-06-03

    📝 ipmi-oem in FreeIPMI before 1.16.18 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardwa...

    🔗 euvd.enisa.europa.eu/vulnerabi

      [?]TheHackerWire » 🤖 🌐
      @thehackerwire@mastodon.social

      🟠 CVE-2025-58707 - High (8.1)

      Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Spin allows PHP Local File Inclusion.

      This issue affects Spin: from n/a through 1.8.

      🔗 thehackerwire.com/vulnerabilit

      CVE Alert: CVE-2025-58707

      Alt...CVE Alert: CVE-2025-58707

        [?]TheHackerWire » 🤖 🌐
        @thehackerwire@mastodon.social

        🟠 CVE-2025-58897 - High (8.1)

        Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Fermentio allows PHP Local File Inclusion.

        This issue affects Fermentio: from n/a through 1.5.0.

        🔗 thehackerwire.com/vulnerabilit

        CVE Alert: CVE-2025-58897

        Alt...CVE Alert: CVE-2025-58897

          [?]TheHackerWire » 🤖 🌐
          @thehackerwire@mastodon.social

          🟠 CVE-2026-39550 - High (8.1)

          Deserialization of Untrusted Data vulnerability in Elated-Themes Aperitif allows Object Injection.

          This issue affects Aperitif: from n/a through 1.6.

          🔗 thehackerwire.com/vulnerabilit

          CVE Alert: CVE-2026-39550

          Alt...CVE Alert: CVE-2026-39550

            [?]Hugo | DevOps | Cybersecurity » 🌐
            @hugovalters@mastodon.social

            CVE-2026-0611 - Critical unpatched RCE in Spacelabs Sentinel. CVSS 9.8. Exploit via .NET Remoting on port 8989 enables arbitrary file read/write and webshell deployment. No patch available. Disable port 8989 immediately.

            valtersit.com/cve/CVE-2026-061

              [?]TechWire ⚡ » 🤖 🌐
              @techwire@social.gamefan.net

              Drones to protect undersea cables from Russian sabotage touted in new defense pact — US one of three part…

              The Australian, UK, and U.S. governments just announced a cooperation to develop new technologies to protect underwater cables. The move comes after recent incidents of damages to undersea cables across the world, as we…

              tomshardware.com/tech-industry

              [Tom's Hardware]

                [?]TierraSapiens » 🤖 🌐
                @tierrasapiens@mastodon.social

                🖲️
                ⚫ As Global Powers Explore Humanoid Robots, Cyber-Risk Looms
                🔗 darkreading.com/cyber-risk/glo

                The future of cybersecurity is germinating, as nation-states vie for dominance in the embodied AI market and its supply chain.

                  [?]TechWire ⚡ » 🤖 🌐
                  @techwire@social.gamefan.net

                  Tom's Hardware Unfiltered: Computex 2026, Day 1 — night markets, taking the MRT train, and a slew of demos

                  The Tom's Hardware team in Taipei reports back on what they've been up to as Computex 2026 begins to gather momentum. Take a look at how we're making

                  tomshardware.com/tech-industry

                  [Tom's Hardware]

                    [?]urlDNA.io :verified: » 🤖 🌐
                    @urldna@infosec.exchange

                    Possible Phishing 🎣
                    on: ⚠️hxxps[:]//tryjhytyjctfhdrxtse46ysxfgjxfyjfyjxdthtrterrthfhhhfff[.]weebly[.]com
                    🧬 Analysis at: urldna.io/scan/6a1faeaa3b77500

                      [?]TechWire ⚡ » 🤖 🌐
                      @techwire@social.gamefan.net

                      Google’s wild Gemini tool that creates a talking, moving AI clone of you is now rolling out widely

                      Impressive and creepy at the same time.

                      androidauthority.com/google-ge

                      [Android Authority]

                        [?]TierraSapiens » 🤖 🌐
                        @tierrasapiens@mastodon.social

                        🖲️
                        ⚫ FBI-Flagged Phishing Kit Kali365 Expands Its Reach
                        🔗 darkreading.com/cyber-risk/fbi

                        Once targeting just Microsoft 365, the phishing-as-a-service platform now aims at AWS, Okta, and Russian platforms, while relying on device code phishing.

                          [?]EUVD Bot » 🤖 🌐
                          @EUVD_Bot@mastodon.social

                          🚨 EUVD-2026-34057

                          📊 Score: 5.3/10 (CVSS v3.1)
                          📦 Product: code-index-mcp, code-index-mcp, code-index-mcp (+12 more)
                          🏢 Vendor: johnhuang316
                          📅 Updated: 2026-06-02

                          📝 A weakness has been identified in johnhuang316 code-index-mcp up to 2.14.0. Affected is the function is_safe_regex_pattern of the component search_code_advanced. Executing a manipulation of the argument ...

                          🔗 euvd.enisa.europa.eu/vulnerabi

                            [?]EUVD Bot » 🤖 🌐
                            @EUVD_Bot@mastodon.social

                            🚨 EUVD-2026-34056

                            📊 Score: 5.3/10 (CVSS v3.1)
                            📦 Product: DesktopCommanderMCP, DesktopCommanderMCP, DesktopCommanderMCP (+36 more)
                            🏢 Vendor: wonderwhy-er
                            📅 Updated: 2026-06-02

                            📝 A security flaw has been discovered in wonderwhy-er DesktopCommanderMCP up to 0.2.38. This impacts an unknown function of the file src/search-manager.ts of the component start_search. Perf...

                            🔗 euvd.enisa.europa.eu/vulnerabi

                              [?]EUVD Bot » 🤖 🌐
                              @EUVD_Bot@mastodon.social

                              🚨 EUVD-2026-34055

                              📊 Score: 4.3/10 (CVSS v3.1)
                              📦 Product: EmergencyWP – Dead Man's switch & legacy deliverance
                              🏢 Vendor: planetshaker
                              📅 Updated: 2026-06-02

                              📝 The EmergencyWP – Dead Man's switch & legacy deliverance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This is due to missing or incorrect nonce...

                              🔗 euvd.enisa.europa.eu/vulnerabi

                                [?]EUVD Bot » 🤖 🌐
                                @EUVD_Bot@mastodon.social

                                🚨 EUVD-2026-34054

                                📊 Score: 4.4/10 (CVSS v3.1)
                                📦 Product: Passeum Ticketing
                                🏢 Vendor: passeum
                                📅 Updated: 2026-06-02

                                📝 The Passeum Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.0. This is due to the `get_shop_url()` method returning the `shop_name` setting value without sanitization when it begin...

                                🔗 euvd.enisa.europa.eu/vulnerabi

                                  [?]EUVD Bot » 🤖 🌐
                                  @EUVD_Bot@mastodon.social

                                  🚨 EUVD-2026-34053

                                  📊 Score: 5.3/10 (CVSS v3.1)
                                  📦 Product: DesktopCommanderMCP
                                  🏢 Vendor: wonderwhy-er
                                  📅 Updated: 2026-06-02

                                  📝 A vulnerability was identified in wonderwhy-er DesktopCommanderMCP 0.2.37. This affects the function readFileFromUrl of the file src/tools/filesystem.ts of the component read_file. Such manipulation of the argument url leads to server-side r...

                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                    [?]EUVD Bot » 🤖 🌐
                                    @EUVD_Bot@mastodon.social

                                    🚨 EUVD-2026-34052

                                    📊 Score: 7.1/10 (CVSS v3.1)
                                    📦 Product: glpi
                                    🏢 Vendor: glpi-project
                                    📅 Updated: 2026-06-02

                                    📝 GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, a technician can store an XSS payload in a ITIL costs. This issue has been fixed in version 11.0.7.

                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                      [?]urlDNA.io :verified: » 🤖 🌐
                                      @urldna@infosec.exchange

                                      Possible Phishing 🎣
                                      on: ⚠️hxxp[:]//sahana-saini[.]github[.]io/view-vibes
                                      🧬 Analysis at: urldna.io/scan/6a1f68323b77500

                                        [?]EUVD Bot » 🤖 🌐
                                        @EUVD_Bot@mastodon.social

                                        🚨 EUVD-2026-34051

                                        📊 Score: 4.9/10 (CVSS v3.1)
                                        📦 Product: alf.io
                                        🏢 Vendor: alfio-event
                                        📅 Updated: 2026-06-02

                                        📝 alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5-2606, the alf.io extension sandbox injects a fully-functional HTTP client (`simpleHttpClient`) into every extension script's s...

                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                          [?]EUVD Bot » 🤖 🌐
                                          @EUVD_Bot@mastodon.social

                                          🚨 EUVD-2026-34050

                                          📊 Score: 8.0/10 (CVSS v3.1)
                                          📦 Product: alf.io
                                          🏢 Vendor: alfio-event
                                          📅 Updated: 2026-06-02

                                          📝 alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5-2606, a sandbox escape vulnerability in the alf.io extension script engine allows an authenticated administrator to execute ar...

                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                            [?]TheHackerWire » 🤖 🌐
                                            @thehackerwire@mastodon.social

                                            🔴 CVE-2026-7198 - Critical (9.8)

                                            CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unauthenticated attacker to access content that should be restricted, resulting in full compromise of confidentiality, integrity, an...

                                            🔗 thehackerwire.com/vulnerabilit

                                            CVE Alert: CVE-2026-7198

                                            Alt...CVE Alert: CVE-2026-7198

                                              [?]EUVD Bot » 🤖 🌐
                                              @EUVD_Bot@mastodon.social

                                              🚨 EUVD-2026-34049

                                              📊 Score: 5.7/10 (CVSS v3.1)
                                              📦 Product: LibreChat
                                              🏢 Vendor: danny-avila
                                              📅 Updated: 2026-06-02

                                              📝 LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, a shared-agent editor can delete file records through `DELETE /api/files` that the owner has reused across multiple agents. The deletion ...

                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                [?]EUVD Bot » 🤖 🌐
                                                @EUVD_Bot@mastodon.social

                                                🚨 EUVD-2026-34048

                                                📊 Score: 5.1/10 (CVSS v3.1)
                                                📦 Product: blender-mcp
                                                🏢 Vendor: ahujasid
                                                📅 Updated: 2026-06-02

                                                📝 A vulnerability was determined in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. The impacted element is the function execute_blender_code of the file /src/blender_mcp/server.py. This manipulation of the argument code causes code i...

                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                  [?]EUVD Bot » 🤖 🌐
                                                  @EUVD_Bot@mastodon.social

                                                  🚨 EUVD-2026-34047

                                                  📊 Score: 6.5/10 (CVSS v3.1)
                                                  📦 Product: LibreChat
                                                  🏢 Vendor: danny-avila
                                                  📅 Updated: 2026-06-02

                                                  📝 LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, users with only `VIEW` access to an MCP server can retrieve the server's decrypted admin-managed secrets through `GET /api/mcp/servers` a...

                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                    [?]EUVD Bot » 🤖 🌐
                                                    @EUVD_Bot@mastodon.social

                                                    🚨 EUVD-2026-34046

                                                    📊 Score: 9.6/10 (CVSS v3.1)
                                                    📦 Product: LibreChat
                                                    🏢 Vendor: danny-avila
                                                    📅 Updated: 2026-06-02

                                                    📝 LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, the Model Context Protocol (MCP) server integration resolves ${VAR} placeholders against the server's process.env during Zod schema valid...

                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                      [?]EUVD Bot » 🤖 🌐
                                                      @EUVD_Bot@mastodon.social

                                                      🚨 EUVD-2026-34045

                                                      📊 Score: 1.8/10 (CVSS v3.1)
                                                      📅 Updated: 2026-06-02

                                                      📝 Out of bounds write in openSeaChest’s --showSupportedFormats in Seagate’s openSeaChest v25.05.3 on all supported platforms allows for writing 1 extra byte outside of allocated memory which sets a value to 1 via a maliciously crafted NVMe device with a bogus value in the namespace FLBAS byte.

                                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                                        [?]TheHackerWire » 🤖 🌐
                                                        @thehackerwire@mastodon.social

                                                        🟠 CVE-2026-7201 - High (8.8)

                                                        CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, and 15.4.x before 15.4.8630 allows a remote authenticated attacker to modify account properties of o...

                                                        🔗 thehackerwire.com/vulnerabilit

                                                        CVE Alert: CVE-2026-7201

                                                        Alt...CVE Alert: CVE-2026-7201

                                                          [?]TechWire ⚡ » 🤖 🌐
                                                          @techwire@social.gamefan.net

                                                          Ubuntu 26.04 is the OS for the AI agentic era, says Canonical's Mark Shuttleworth - here's why

                                                          Canonical's pitch starts with snaps and security.

                                                          zdnet.com/article/ubuntu-26-04

                                                          [ZDNet]

                                                            [?]TechWire ⚡ » 🤖 🌐
                                                            @techwire@social.gamefan.net

                                                            Amazon Prime Day is June 23-26: Everything to know about start times, deals, and more

                                                            Here's everything we know about Amazon's June Prime event - including confirmed dates, how to prep for early deals, and how it compares to previous July sales.

                                                            zdnet.com/article/amazon-prime

                                                            [ZDNet]

                                                              [?]urlDNA.io :verified: » 🤖 🌐
                                                              @urldna@infosec.exchange

                                                              Possible Phishing 🎣
                                                              on: ⚠️hxxps[:]//f4krw6wfqi327wcozwyvnwxtl46mnt7kcicpd6tuuqp5cwzb5ekq[.]mrciga[.]com
                                                              🧬 Analysis at: urldna.io/scan/6a1f0c213b77500

                                                                [?]TechWire ⚡ » 🤖 🌐
                                                                @techwire@social.gamefan.net

                                                                I found 15 Amazon deals on editor-approved tech already live for Prime Day

                                                                Amazon's Prime Day sale returns this month. These are our favorite early deals you can shop now.

                                                                zdnet.com/article/best-early-a

                                                                [ZDNet]

                                                                  [?]EUVD Bot » 🤖 🌐
                                                                  @EUVD_Bot@mastodon.social

                                                                  🚨 EUVD-2026-33994

                                                                  📊 Score: 7.5/10 (CVSS v3.1)
                                                                  📦 Product: turbo-stream, react-router
                                                                  🏢 Vendor: remix-run
                                                                  📅 Updated: 2026-06-02

                                                                  📝 React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect ha...

                                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                                    [?]EUVD Bot » 🤖 🌐
                                                                    @EUVD_Bot@mastodon.social

                                                                    🚨 EUVD-2026-33988

                                                                    📊 Score: 8.0/10 (CVSS v3.1)
                                                                    📦 Product: react-router
                                                                    🏢 Vendor: remix-run
                                                                    📅 Updated: 2026-06-02

                                                                    📝 React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redi...

                                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                                      [?]EUVD Bot » 🤖 🌐
                                                                      @EUVD_Bot@mastodon.social

                                                                      🚨 EUVD-2019-20157

                                                                      📊 Score: 7.1/10 (CVSS v3.1)
                                                                      📦 Product: Infinity M300
                                                                      🏢 Vendor: Dräger
                                                                      📅 Updated: 2026-06-02

                                                                      📝 Dräger Infinity M300 patient worn monitors with software version VG2.3.1 and earlier contain a network-based denial of service vulnerability that allows network-adjacent attackers to repeatedly trigger device reboots by sending malicious requests over t...

                                                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                                                        [?]EUVD Bot » 🤖 🌐
                                                                        @EUVD_Bot@mastodon.social

                                                                        🚨 EUVD-2026-33993

                                                                        📊 Score: 8.8/10 (CVSS v3.1)
                                                                        📦 Product: Content Visibility for Divi Builder
                                                                        🏢 Vendor: jhorowitz
                                                                        📅 Updated: 2026-06-02

                                                                        📝 The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.02 via the 'et_pb_text' shortcode 'cvdb_content_visibility_check' parameter. This makes ...

                                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                                          [?]EUVD Bot » 🤖 🌐
                                                                          @EUVD_Bot@mastodon.social

                                                                          🚨 EUVD-2026-33992

                                                                          📊 Score: 8.4/10 (CVSS v3.1)
                                                                          📦 Product: NI-PAL
                                                                          🏢 Vendor: NI
                                                                          📅 Updated: 2026-06-02

                                                                          📝 Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary system memory, potentially leading to privilege escalation. This vulnerability affects NI-PAL 26.3.0 and prior versions on Windows and Linux.

                                                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                                                            [?]EUVD Bot » 🤖 🌐
                                                                            @EUVD_Bot@mastodon.social

                                                                            🚨 EUVD-2026-33991

                                                                            📊 Score: 6.9/10 (CVSS v3.1)
                                                                            📦 Product: NI-PAL
                                                                            🏢 Vendor: NI
                                                                            📅 Updated: 2026-06-02

                                                                            📝 Improper input validation in the NI-PAL kernel driver may allow a local authenticated user to cause a denial of service by triggering a crash due to a NULL pointer dereference. This vulnerability affects NI-PAL 26.3.0 and prior versions on Windows and Linux.

                                                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                                                              [?]EUVD Bot » 🤖 🌐
                                                                              @EUVD_Bot@mastodon.social

                                                                              🚨 EUVD-2026-33990

                                                                              📊 Score: n/a
                                                                              📅 Updated: 2026-06-02

                                                                              📝 JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3.

                                                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                Back to top - More...