voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]TechWire ⚡ » 🤖 🌐
@techwire@social.gamefan.net

The wide Galaxy Z Fold 8 could be lighter than your current phone

Leaker Ice Universe reveals an impressive 201g weight alongside good battery and camera specs for Samsung's wide foldable.

androidauthority.com/samsung-g

[Android Authority]

    [?]ANY.RUN » 🌐
    @anyrun_app@infosec.exchange

    🚨 : The Persistent Backdoor Targeting US Businesses

    A new backdoor is actively targeting enterprises through emails disguised as purchase orders, quotes, and business proposals. Most AV tools miss it entirely.

    ⚠️ Confirmed victims include organizations in the technology, telecom, education, and MSSP sectors. Once inside, attackers can deploy ransomware, steal data, and cause costly business disruption.

    👨‍💻 Investigate the attack chain and persistence mechanisms in a sandbox session: app.any.run/tasks/e39d92e9-a8c

    📌 Learn how to detect JSMonoGlyphRAT before it turns into business impact: any.run/cybersecurity-blog/mon

      [?]urlDNA.io :verified: » 🤖 🌐
      @urldna@infosec.exchange

      Possible Phishing 🎣
      on: ⚠️hxxps[:]//pub-ced20142bdb943418a3d13e869c3b397[.]r2[.]dev/index[.]html
      🧬 Analysis at: urldna.io/scan/6a1e55483b77500

        [?]CTI.FYI » 🤖 🌐
        @CTI_FYI@infosec.exchange

        🚨New ransom group blog post!🚨

        Group name: spacebears
        Post title: Stellar
        Info: cti.fyi/groups/spacebears.html

          [?]TechWire ⚡ » 🤖 🌐
          @techwire@social.gamefan.net

          Gemini Spark is the most impressive and terrifying AI experience I’ve had yet

          Spark is Google’s new agentic answer for everything. According to every product demo from the last four years, planning a trip is a killer use case for AI. Just tell it where you're going, they all promise, and your cha…

          theverge.com/ai-artificial-int

          [The Verge]

            [?]ransomNews » 🌐
            @ransomnews.online@bsky.brid.gy

            🚨 LastPass settlement pays breach victims directly The $24.5M deal reserves $16M for crypto-loss claims tied to stolen vault data from the 2022 LastPass incident. 🔗 read more: lifehacker.com/tech/the-las...

              [?]TechWire ⚡ » 🤖 🌐
              @techwire@social.gamefan.net

              Here’s everything new in June 2026 for the Google Play Store

              Google Play Store v51.7 makes it a lot easier to track app deals and manage pre-registrations.

              androidauthority.com/google-pl

              [Android Authority]

                [?]TechWire ⚡ » 🤖 🌐
                @techwire@social.gamefan.net

                Galaxy Z Fold 8 and Fold 8 Ultra dummies pose for the camera again, this time folded up

                New leak lines up Galaxy Z Fold and Fold 8 Ultra side by side, once again.

                androidauthority.com/galaxy-z-

                [Android Authority]

                  [?]TechFinitive » 🌐
                  @TechFinitive@mastodon.social

                  As organisations race to adopt AI for productivity and growth, CISOs face a growing challenge: balancing innovation with emerging risks. From data exposure and shadow AI to agentic systems, compliance concerns and an expanded attack surface, security leaders must navigate a rapidly evolving landscape while helping teams understand which tools to trust and use effectively.

                  Read our interview with Nicole Carignan of Darktrace here: techfinitive.com/interviews/ni

                    [?]urlDNA.io :verified: » 🤖 🌐
                    @urldna@infosec.exchange

                    Possible Phishing 🎣
                    on: ⚠️hxxps[:]//girl[.]indonesiya[.]com/?m=1/
                    🧬 Analysis at: urldna.io/scan/6a1e32e13b77500

                      [?]BeyondMachines :verified: » 🤖 🌐
                      @beyondmachines1@infosec.exchange

                      Critical Hard-Coded Credentials Vulnerability in FreePBX User Control Panel

                      FreePBX patched a critical vulnerability (CVE-2026-46376) that allows unauthenticated attackers to gain remote access to the User Control Panel via hard-coded credentials.

                      **If you run FreePBX, first make sure your VoIP server management interfaces User and Admin Control Panels are isolated from the internet and reachable only from trusted networks or via VPN . Then update the userman module to version 16.0.45 or 17.0.7 to replace the hard-coded credentials, and enable MFA or SAML for an added layer of login protection.**

                      beyondmachines.net/event_detai

                        [?]deafnews » 🤖 🌐
                        @deafnews@infosec.exchange

                        [?]TechWire ⚡ » 🤖 🌐
                        @techwire@social.gamefan.net

                        Google’s June update finally fixes Android’s biggest password headache

                        Google adds a simpler way to export and import passkeys on Android.

                        androidauthority.com/google-pa

                        [Android Authority]

                          [?]TechWire ⚡ » 🤖 🌐
                          @techwire@social.gamefan.net

                          5 Android phones you should buy instead of the Moto G Stylus (2026)

                          The new Stylus is fine, but you can do better.

                          androidauthority.com/motorola-

                          [Android Authority]

                            [?]urlDNA.io :verified: » 🤖 🌐
                            @urldna@infosec.exchange

                            Possible Phishing 🎣
                            on: ⚠️hxxps[:]//profilcledigitale[.]firebaseapp[.]com/
                            🧬 Analysis at: urldna.io/scan/6a1e7f773b77500

                              [?]OTX Bot » 🤖 🌐
                              @techbot@social.raytec.co

                              A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites

                              A sophisticated threat actor named DriveSurge operates as an Initial Access Broker using a Pay-Per-Install model to deliver malware at scale. The actor compromises thousands of legitimate websites and uses zTDS (Traffic Distribution System) to silently redirect visitors to malicious content. Victims encounter either FakeUpdates campaigns that impersonate browser update prompts for 11 different browsers, or ClickFix attacks that trick users into executing malicious commands through fake error messages. DriveSurge's infrastructure utilizes bulletproof hosting services, primarily NiceNIC registrar, and has been operating since at least 2015. The campaigns target both Windows and macOS systems, employing sophisticated obfuscation techniques and clipboard hijacking to achieve infection. Eight technical fingerprints have been identified to track this actor's infrastructure and activities.

                              Pulse ID: 6a1dde5fb26dd1b1cbbdb913
                              Pulse Link: otx.alienvault.com/pulse/6a1dd
                              Pulse Author: AlienVault
                              Created: 2026-06-01 19:32:47

                              Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                [?]OTX Bot » 🤖 🌐
                                @techbot@social.raytec.co

                                Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages

                                A supply chain attack compromised multiple @redhat-cloud-services npm packages, executing malicious payloads automatically during installation via preinstall hooks. The attack uses AES-GCM encrypted payloads and obfuscated JavaScript loaders to harvest GitHub Actions secrets, npm tokens, cloud credentials (AWS, Azure, GCP), Kubernetes and Vault material, SSH keys, Git credentials, and cryptocurrency wallet files. The payload can daemonize on developer workstations, includes Russian-locale avoidance mechanisms, and exfiltrates stolen data through encrypted HTTPS channels with GitHub API fallback mechanisms. The campaign employs tactics similar to the publicly released Shai-Hulud toolkit, though attribution remains unclear due to the availability of open-source attack tooling.

                                Pulse ID: 6a1dde0e4e662ca1f8b4b0b2
                                Pulse Link: otx.alienvault.com/pulse/6a1dd
                                Pulse Author: AlienVault
                                Created: 2026-06-01 19:31:26

                                Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                  [?]OTX Bot » 🤖 🌐
                                  @techbot@social.raytec.co

                                  FSB’s matryoshka #1/3 – Gamaredon’s gifts that keeps unpacking – GammaPhish and GammaWorm

                                  Gamaredon, a cyberespionage group operated by Russia's FSB, conducts long-term intrusion operations targeting Ukrainian government, military, and critical infrastructure. This analysis documents their 2026 infection chain, which uses HTML smuggling with weaponized xHTML files delivering RAR archives that exploit CVE-2025-8088 to extract HTA files into Windows Startup directories. The chain deploys GammaPhish for initial access, GammaLoad for staging, GammaWorm for propagation via USB and network drives, and GammaSteal for exfiltration. The architecture is nearly fileless, leveraging NTFS Alternate Data Streams to conceal modules and using Dead Drop Resolvers on legitimate platforms like Telegram and Cloudflare for C2 infrastructure. Every stage functions as an independent backdoor capable of executing arbitrary VBScript, representing a shift from their historical Pteranodon framework to a modular ecosystem designed for persistent espionage.

                                  Pulse ID: 6a1dde0927ce7587f79534ee
                                  Pulse Link: otx.alienvault.com/pulse/6a1dd
                                  Pulse Author: AlienVault
                                  Created: 2026-06-01 19:31:21

                                  Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                    [?]CTI.FYI » 🤖 🌐
                                    @CTI_FYI@infosec.exchange

                                    🚨New ransom group blog post!🚨

                                    Group name: qilin
                                    Post title: Clinica Maitenes
                                    Info: cti.fyi/groups/qilin.html

                                      [?]ransomNews » 🌐
                                      @ransomnews.online@bsky.brid.gy

                                      ⚠️ Chrome binds sessions to the device Chrome 146 on Windows uses DBSC and TPM-backed keys so stolen cookies expire quickly and cannot be replayed elsewhere. 🔗 read more: lifehacker.com/tech/google-...

                                        [?]TechWire ⚡ » 🤖 🌐
                                        @techwire@social.gamefan.net

                                        Hackers stole high-profile Instagram accounts by simply asking Meta AI nicely

                                        A staggering security oversight in Meta's AI support chatbot allowed attackers to bypass verification entirely.

                                        androidauthority.com/meta-ai-s

                                        [Android Authority]

                                          [?]TechWire ⚡ » 🤖 🌐
                                          @techwire@social.gamefan.net

                                          Computex 2026 Day Zero Wrap-Up: Nvidia launches RTX Spark Superchip assault on laptop and desktop markets, Intel readies Xeon 6+

                                          Here's the best of what was announced during the opening hours of Computex 2026

                                          tomshardware.com/tech-industry

                                          [Tom's Hardware]

                                            [?]Daniel Marsh » 🤖 🌐
                                            @danielmarsh@social.thepixelspulse.com

                                            Red Hat faced a significant supply chain attack where over 30 internal npm packages were backdoored, distributing credential-stealing malware. Attackers compromised a developer's GitHub account, then injected malicious GitHub Actions workflows to abuse trusted publishing and release compromised package versions. This incident, involving the 'Miasma' malware, underscores the urgent need for enhanced CI/CD…

                                            tpp.blog/1bdukym

                                            🤖 This post was AI-generated.

                                              [?]TechWire ⚡ » 🤖 🌐
                                              @techwire@social.gamefan.net

                                              Anthropic files for IPO — Claude maker races OpenAI and SpaceX to Wall Street

                                              Anthropic, the AI company that makes Claude, confidentially filed to go public with the U.S. Securities and Exchange Commission.

                                              tomshardware.com/tech-industry

                                              [Tom's Hardware]

                                                [?]urlDNA.io :verified: » 🤖 🌐
                                                @urldna@infosec.exchange

                                                Possible Phishing 🎣
                                                on: ⚠️hxxps[:]//hubkucoi[.]zapier[.]app/public
                                                🧬 Analysis at: urldna.io/scan/6a1e392b3b77500

                                                  [?]TechWire ⚡ » 🤖 🌐
                                                  @techwire@social.gamefan.net

                                                  Windows Server vulnerability can grant system privileges with just a malformed packet — domain controllers are being exploited in the wild

                                                  9.8-rated Windows Server vulnerability can grants system privileges with just a malformed packet — domain controllers being exploited in the wild

                                                  tomshardware.com/tech-industry

                                                  [Tom's Hardware]

                                                    [?]TechWire ⚡ » 🤖 🌐
                                                    @techwire@social.gamefan.net

                                                    Noctua announces new thermal pad for AMD chips in partnership with Carbice — product will work with processors in AM5 and AM4 sockets

                                                    Noctua has entered the thermal pad market in partnership with thermal pad maker Carbice, featuring the new NT-CP1 designed for AM5 and AM4 Ryzen CPUs.

                                                    tomshardware.com/pc-components

                                                    [Tom's Hardware]

                                                      [?]TheHackerWire » 🤖 🌐
                                                      @thehackerwire@mastodon.social

                                                      🔴 CVE-2026-8206 - Critical (9.8)

                                                      The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbitrary email address when a...

                                                      🔗 thehackerwire.com/vulnerabilit

                                                      CVE Alert: CVE-2026-8206

                                                      Alt...CVE Alert: CVE-2026-8206

                                                        [?]EUVD Bot » 🤖 🌐
                                                        @EUVD_Bot@mastodon.social

                                                        🚨 EUVD-2026-33881

                                                        📊 Score: 9.8/10 (CVSS v3.1)
                                                        📦 Product: Kirki – Freeform Page Builder, Website Builder & Customizer
                                                        🏢 Vendor: Themeum
                                                        📅 Updated: 2026-06-02

                                                        📝 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin acce...

                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                          [?]EUVD Bot » 🤖 🌐
                                                          @EUVD_Bot@mastodon.social

                                                          🚨 EUVD-2026-33880

                                                          📊 Score: 6.5/10 (CVSS v3.1)
                                                          📦 Product: mlflow/mlflow
                                                          🏢 Vendor: mlflow
                                                          📅 Updated: 2026-06-02

                                                          📝 MLflow 3.9.0 with basic-auth (`--app-name basic-auth`) fails to enforce authorization checks for multiple Gateway API 'list' endpoints. Specifically, the `BEFORE_REQUEST_HANDLERS` dictionary in `mlflow/server/auth/__init__.py` does not include entries f...

                                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                                            [?]EUVD Bot » 🤖 🌐
                                                            @EUVD_Bot@mastodon.social

                                                            🚨 EUVD-2026-33879

                                                            📊 Score: 5.1/10 (CVSS v3.1)
                                                            📦 Product: GoClaw, GoClaw, GoClaw (+1 more)
                                                            🏢 Vendor: nextlevelbuilder
                                                            📅 Updated: 2026-06-02

                                                            📝 A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. Affected by this issue is the function Import of the file internal/http/tts_config.go of the component TTS Configuration Endpoint. The manip...

                                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                                              [?]EUVD Bot » 🤖 🌐
                                                              @EUVD_Bot@mastodon.social

                                                              🚨 EUVD-2026-33878

                                                              📊 Score: 5.3/10 (CVSS v3.1)
                                                              📦 Product: DeDeCMS
                                                              📅 Updated: 2026-06-02

                                                              📝 A flaw has been found in DedeCMS 5.7.88. Affected by this vulnerability is the function base64_decode of the file /plus/download.php?open=1. This manipulation of the argument Link causes server-side request forgery. Remote exploitation of the attack is possible. The exploit h...

                                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                                [?]urlDNA.io :verified: » 🤖 🌐
                                                                @urldna@infosec.exchange

                                                                Possible Phishing 🎣
                                                                on: ⚠️hxxps[:]//gneeralverfy[.]weebly[.]com
                                                                🧬 Analysis at: urldna.io/scan/6a1dfab13b77500

                                                                  [?]TheHackerWire » 🤖 🌐
                                                                  @thehackerwire@mastodon.social

                                                                  🟠 CVE-2026-0096 - High (7.8)

                                                                  In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick the user into forgetting a device due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. U...

                                                                  🔗 thehackerwire.com/vulnerabilit

                                                                  CVE Alert: CVE-2026-0096

                                                                  Alt...CVE Alert: CVE-2026-0096

                                                                    [?]TheHackerWire » 🤖 🌐
                                                                    @thehackerwire@mastodon.social

                                                                    🟠 CVE-2026-0097 - High (8)

                                                                    In multiple locations, there is a possible way to bypass user interaction when pairing an LE device due to a logic error. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User in...

                                                                    🔗 thehackerwire.com/vulnerabilit

                                                                    CVE Alert: CVE-2026-0097

                                                                    Alt...CVE Alert: CVE-2026-0097

                                                                      [?]TechWire ⚡ » 🤖 🌐
                                                                      @techwire@social.gamefan.net

                                                                      Gigabyte debuts fourth-gen Tandem WOLED and multi-mode Mini LED gaming monitors — 27 to 32 inches, up to 480 Hz, and up to 5K resolution

                                                                      Gigabyte Aorus Elite gaming monitors include a multi-mode 5K monitor

                                                                      tomshardware.com/monitors/gami

                                                                      [Tom's Hardware]

                                                                        [?]TechWire ⚡ » 🤖 🌐
                                                                        @techwire@social.gamefan.net

                                                                        AMD Radeon RX 9070 GRE review: thoroughly midrange

                                                                        AMD's $549 Radeon RX 9070 GRE offers strong high-refresh-rate 1080p and 1440p gaming performance as it launches globally at Computex 2026. But a lower price tag could have truly changed the midrange game.

                                                                        tomshardware.com/pc-components

                                                                        [Tom's Hardware]

                                                                          [?]urlDNA.io :verified: » 🤖 🌐
                                                                          @urldna@infosec.exchange

                                                                          Possible Phishing 🎣
                                                                          on: ⚠️hxxps[:]//infoshawmember[.]weebly[.]com
                                                                          🧬 Analysis at: urldna.io/scan/6a1dd6d63b77500

                                                                            [?]OTX Bot » 🤖 🌐
                                                                            @techbot@social.raytec.co

                                                                            FSB’s matryoshka #1/3: Inside Gamaredon Cyber Operations

                                                                            Pulse ID: 6a1e65e0dbbeb5ee8804848e
                                                                            Pulse Link: otx.alienvault.com/pulse/6a1e6
                                                                            Pulse Author: Tr1sa111
                                                                            Created: 2026-06-02 05:10:56

                                                                            Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                                                              [?]TechWire ⚡ » 🤖 🌐
                                                                              @techwire@social.gamefan.net

                                                                              Google Photos is finally making backups less painful with a smarter export system

                                                                              The new feature lets users schedule recurring exports of their Google Photos library.

                                                                              androidauthority.com/google-ph

                                                                              [Android Authority]

                                                                                [?]Miguel Afonso Caetano » 🌐
                                                                                @remixtures@tldr.nettime.org

                                                                                "Cybersecurity researchers have disclosed details of a new malicious supply chain campaign that's targeting developers using OpenAI Codex through a legitimate-looking remote web UI.

                                                                                The tool, named codexui-android, is advertised on GitHub and npm as a remote web UI for OpenAI Codex, attracting over 29,000 weekly downloads. The package is still available for download from the repository.

                                                                                What makes this activity noteworthy is that it's not a traditional attack that uses a typosquat or throwaway package to trick developers. Rather, the malicious code is embedded into a functional npm package that has undergone active development. The associated GitHub repository remains clean.

                                                                                "And for the past month, every single invocation has been quietly exfiltrating your Codex authentication tokens to an attacker-controlled server," Aikido Security researcher Charlie Eriksen said.

                                                                                The nefarious changes are said to have been introduced about a month after the package was published to the registry, likely in an effort to build user trust and expand its reach. The npm account associated with the package is "friuns" (aka Igor Levochkin)."

                                                                                thehackernews.com/2026/06/open

                                                                                  [?]Miguel Afonso Caetano » 🌐
                                                                                  @remixtures@tldr.nettime.org

                                                                                  "Meanwhile, the AI strategy itself threatens to create more barriers to AI adoption. The strategy is expected to include mandated age verification for using both social media and AI chatbots, with a plan to establish new restrictions on the use of these services for those under the age of 16. But limiting AI access to adults will require everyone to certify their age, typically through foreign third-party services that introduce new privacy risks to sensitive personal information.

                                                                                  You can’t proclaim AI leadership while eschewing rules that address safety issues for all users by instead relying on age-gating services with requirements that will affect tens of millions of Canadians. Yet that is what the federal government is proposing to do with promises of “AI for all” that may actually become “ID for all”.

                                                                                  None of this is hypothetical, either, because Ottawa has been here before. When it passed the Online News Act, it brushed aside warnings that Meta would block news rather than pay for news links. And when Meta followed through on its threats – a blockade that is in place to this day – Canadians simply lost access to the links (and credible information) that the law was trying to protect. The lesson the government keeps ignoring is that when the rules become impossible or unpalatable to follow, companies are prepared to leave."

                                                                                  theglobeandmail.com/opinion/ar

                                                                                    [?]TechWire ⚡ » 🤖 🌐
                                                                                    @techwire@social.gamefan.net

                                                                                    Save 78% on Nord's latest Complete VPN package — 27 months of online protection for $107

                                                                                    Pick up 27 months of NordVPN coverage for just $107. Fast VPN connections, anti-virus protection, and a password manager for only $3.99 per month.

                                                                                    tomshardware.com/software/vpn/

                                                                                    [Tom's Hardware]

                                                                                      Back to top - More...