voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]Daniel Marsh » 🤖 🌐
@danielmarsh@social.thepixelspulse.com

Red Hat faced a significant supply chain attack where over 30 internal npm packages were backdoored, distributing credential-stealing malware. Attackers compromised a developer's GitHub account, then injected malicious GitHub Actions workflows to abuse trusted publishing and release compromised package versions. This incident, involving the 'Miasma' malware, underscores the urgent need for enhanced CI/CD…

tpp.blog/1bdukym

🤖 This post was AI-generated.

    [?]TechWire ⚡ » 🤖 🌐
    @techwire@social.gamefan.net

    Anthropic files for IPO — Claude maker races OpenAI and SpaceX to Wall Street

    Anthropic, the AI company that makes Claude, confidentially filed to go public with the U.S. Securities and Exchange Commission.

    tomshardware.com/tech-industry

    [Tom's Hardware]

      [?]urlDNA.io :verified: » 🤖 🌐
      @urldna@infosec.exchange

      Possible Phishing 🎣
      on: ⚠️hxxps[:]//hubkucoi[.]zapier[.]app/public
      🧬 Analysis at: urldna.io/scan/6a1e392b3b77500

        [?]TechWire ⚡ » 🤖 🌐
        @techwire@social.gamefan.net

        Windows Server vulnerability can grant system privileges with just a malformed packet — domain controllers are being exploited in the wild

        9.8-rated Windows Server vulnerability can grants system privileges with just a malformed packet — domain controllers being exploited in the wild

        tomshardware.com/tech-industry

        [Tom's Hardware]

          [?]TechWire ⚡ » 🤖 🌐
          @techwire@social.gamefan.net

          Noctua announces new thermal pad for AMD chips in partnership with Carbice — product will work with processors in AM5 and AM4 sockets

          Noctua has entered the thermal pad market in partnership with thermal pad maker Carbice, featuring the new NT-CP1 designed for AM5 and AM4 Ryzen CPUs.

          tomshardware.com/pc-components

          [Tom's Hardware]

            [?]TheHackerWire » 🤖 🌐
            @thehackerwire@mastodon.social

            🔴 CVE-2026-8206 - Critical (9.8)

            The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbitrary email address when a...

            🔗 thehackerwire.com/vulnerabilit

            CVE Alert: CVE-2026-8206

            Alt...CVE Alert: CVE-2026-8206

              [?]EUVD Bot » 🤖 🌐
              @EUVD_Bot@mastodon.social

              🚨 EUVD-2026-33881

              📊 Score: 9.8/10 (CVSS v3.1)
              📦 Product: Kirki – Freeform Page Builder, Website Builder & Customizer
              🏢 Vendor: Themeum
              📅 Updated: 2026-06-02

              📝 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin acce...

              🔗 euvd.enisa.europa.eu/vulnerabi

                [?]EUVD Bot » 🤖 🌐
                @EUVD_Bot@mastodon.social

                🚨 EUVD-2026-33880

                📊 Score: 6.5/10 (CVSS v3.1)
                📦 Product: mlflow/mlflow
                🏢 Vendor: mlflow
                📅 Updated: 2026-06-02

                📝 MLflow 3.9.0 with basic-auth (`--app-name basic-auth`) fails to enforce authorization checks for multiple Gateway API 'list' endpoints. Specifically, the `BEFORE_REQUEST_HANDLERS` dictionary in `mlflow/server/auth/__init__.py` does not include entries f...

                🔗 euvd.enisa.europa.eu/vulnerabi

                  [?]EUVD Bot » 🤖 🌐
                  @EUVD_Bot@mastodon.social

                  🚨 EUVD-2026-33879

                  📊 Score: 5.1/10 (CVSS v3.1)
                  📦 Product: GoClaw, GoClaw, GoClaw (+1 more)
                  🏢 Vendor: nextlevelbuilder
                  📅 Updated: 2026-06-02

                  📝 A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. Affected by this issue is the function Import of the file internal/http/tts_config.go of the component TTS Configuration Endpoint. The manip...

                  🔗 euvd.enisa.europa.eu/vulnerabi

                    [?]EUVD Bot » 🤖 🌐
                    @EUVD_Bot@mastodon.social

                    🚨 EUVD-2026-33878

                    📊 Score: 5.3/10 (CVSS v3.1)
                    📦 Product: DeDeCMS
                    📅 Updated: 2026-06-02

                    📝 A flaw has been found in DedeCMS 5.7.88. Affected by this vulnerability is the function base64_decode of the file /plus/download.php?open=1. This manipulation of the argument Link causes server-side request forgery. Remote exploitation of the attack is possible. The exploit h...

                    🔗 euvd.enisa.europa.eu/vulnerabi

                      [?]urlDNA.io :verified: » 🤖 🌐
                      @urldna@infosec.exchange

                      Possible Phishing 🎣
                      on: ⚠️hxxps[:]//gneeralverfy[.]weebly[.]com
                      🧬 Analysis at: urldna.io/scan/6a1dfab13b77500

                        [?]TheHackerWire » 🤖 🌐
                        @thehackerwire@mastodon.social

                        🟠 CVE-2026-0096 - High (7.8)

                        In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick the user into forgetting a device due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. U...

                        🔗 thehackerwire.com/vulnerabilit

                        CVE Alert: CVE-2026-0096

                        Alt...CVE Alert: CVE-2026-0096

                          [?]TheHackerWire » 🤖 🌐
                          @thehackerwire@mastodon.social

                          🟠 CVE-2026-0097 - High (8)

                          In multiple locations, there is a possible way to bypass user interaction when pairing an LE device due to a logic error. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User in...

                          🔗 thehackerwire.com/vulnerabilit

                          CVE Alert: CVE-2026-0097

                          Alt...CVE Alert: CVE-2026-0097

                            [?]TechWire ⚡ » 🤖 🌐
                            @techwire@social.gamefan.net

                            Gigabyte debuts fourth-gen Tandem WOLED and multi-mode Mini LED gaming monitors — 27 to 32 inches, up to 480 Hz, and up to 5K resolution

                            Gigabyte Aorus Elite gaming monitors include a multi-mode 5K monitor

                            tomshardware.com/monitors/gami

                            [Tom's Hardware]

                              [?]TechWire ⚡ » 🤖 🌐
                              @techwire@social.gamefan.net

                              AMD Radeon RX 9070 GRE review: thoroughly midrange

                              AMD's $549 Radeon RX 9070 GRE offers strong high-refresh-rate 1080p and 1440p gaming performance as it launches globally at Computex 2026. But a lower price tag could have truly changed the midrange game.

                              tomshardware.com/pc-components

                              [Tom's Hardware]

                                [?]urlDNA.io :verified: » 🤖 🌐
                                @urldna@infosec.exchange

                                Possible Phishing 🎣
                                on: ⚠️hxxps[:]//infoshawmember[.]weebly[.]com
                                🧬 Analysis at: urldna.io/scan/6a1dd6d63b77500

                                  [?]OTX Bot » 🤖 🌐
                                  @techbot@social.raytec.co

                                  FSB’s matryoshka #1/3: Inside Gamaredon Cyber Operations

                                  Pulse ID: 6a1e65e0dbbeb5ee8804848e
                                  Pulse Link: otx.alienvault.com/pulse/6a1e6
                                  Pulse Author: Tr1sa111
                                  Created: 2026-06-02 05:10:56

                                  Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                    [?]TechWire ⚡ » 🤖 🌐
                                    @techwire@social.gamefan.net

                                    Google Photos is finally making backups less painful with a smarter export system

                                    The new feature lets users schedule recurring exports of their Google Photos library.

                                    androidauthority.com/google-ph

                                    [Android Authority]

                                      [?]Miguel Afonso Caetano » 🌐
                                      @remixtures@tldr.nettime.org

                                      "Cybersecurity researchers have disclosed details of a new malicious supply chain campaign that's targeting developers using OpenAI Codex through a legitimate-looking remote web UI.

                                      The tool, named codexui-android, is advertised on GitHub and npm as a remote web UI for OpenAI Codex, attracting over 29,000 weekly downloads. The package is still available for download from the repository.

                                      What makes this activity noteworthy is that it's not a traditional attack that uses a typosquat or throwaway package to trick developers. Rather, the malicious code is embedded into a functional npm package that has undergone active development. The associated GitHub repository remains clean.

                                      "And for the past month, every single invocation has been quietly exfiltrating your Codex authentication tokens to an attacker-controlled server," Aikido Security researcher Charlie Eriksen said.

                                      The nefarious changes are said to have been introduced about a month after the package was published to the registry, likely in an effort to build user trust and expand its reach. The npm account associated with the package is "friuns" (aka Igor Levochkin)."

                                      thehackernews.com/2026/06/open

                                        [?]Miguel Afonso Caetano » 🌐
                                        @remixtures@tldr.nettime.org

                                        "Meanwhile, the AI strategy itself threatens to create more barriers to AI adoption. The strategy is expected to include mandated age verification for using both social media and AI chatbots, with a plan to establish new restrictions on the use of these services for those under the age of 16. But limiting AI access to adults will require everyone to certify their age, typically through foreign third-party services that introduce new privacy risks to sensitive personal information.

                                        You can’t proclaim AI leadership while eschewing rules that address safety issues for all users by instead relying on age-gating services with requirements that will affect tens of millions of Canadians. Yet that is what the federal government is proposing to do with promises of “AI for all” that may actually become “ID for all”.

                                        None of this is hypothetical, either, because Ottawa has been here before. When it passed the Online News Act, it brushed aside warnings that Meta would block news rather than pay for news links. And when Meta followed through on its threats – a blockade that is in place to this day – Canadians simply lost access to the links (and credible information) that the law was trying to protect. The lesson the government keeps ignoring is that when the rules become impossible or unpalatable to follow, companies are prepared to leave."

                                        theglobeandmail.com/opinion/ar

                                          [?]TechWire ⚡ » 🤖 🌐
                                          @techwire@social.gamefan.net

                                          Save 78% on Nord's latest Complete VPN package — 27 months of online protection for $107

                                          Pick up 27 months of NordVPN coverage for just $107. Fast VPN connections, anti-virus protection, and a password manager for only $3.99 per month.

                                          tomshardware.com/software/vpn/

                                          [Tom's Hardware]

                                            [?]TechWire ⚡ » 🤖 🌐
                                            @techwire@social.gamefan.net

                                            Supermicro shows off Vera Rubin NVL72 rack with all-new type of coolant — company claims coolant offers 1,000 times higher electrical impedance over standard cooling

                                            Supermicro demonstrates upcoming servers based on AMD’s EPYC ‘Venice’ CPUs, MI450 accelerators, and Nvidia’s Vera Rubin-based solutions.

                                            tomshardware.com/desktops/serv

                                            [Tom's Hardware]

                                              [?]EUVD Bot » 🤖 🌐
                                              @EUVD_Bot@mastodon.social

                                              🚨 EUVD-2026-33852

                                              📊 Score: 5.3/10 (CVSS v3.1)
                                              📦 Product: Fees Management System
                                              🏢 Vendor: itsourcecode
                                              📅 Updated: 2026-06-01

                                              📝 A flaw has been found in itsourcecode Fees Management System 1.0. The impacted element is an unknown function of the file /manage_fee.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched r...

                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                [?]EUVD Bot » 🤖 🌐
                                                @EUVD_Bot@mastodon.social

                                                🚨 EUVD-2026-33851

                                                📊 Score: 4.3/10 (CVSS v3.1)
                                                📦 Product: Slider Revolution
                                                🏢 Vendor: Revolution Slider
                                                📅 Updated: 2026-06-01

                                                📝 The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 7.0.0 - 7.0.14, via the 'slider.get.full' AJAX Action. This makes it possible for authenticated attackers, with Contributor-level acces...

                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                  [?]EUVD Bot » 🤖 🌐
                                                  @EUVD_Bot@mastodon.social

                                                  🚨 EUVD-2026-33850

                                                  📊 Score: 4.3/10 (CVSS v3.1)
                                                  📦 Product: Slider Revolution, Slider Revolution
                                                  🏢 Vendor: Revolution Slider
                                                  📅 Updated: 2026-06-01

                                                  📝 The Slider Revolution plugin for WordPress in versions 6.0.0-6.7.55 and 7.0.0-7.0.14 is vulnerable to unauthorized modification of data. This is due to the plugin not properly verifying that a user is authorized to perf...

                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                    [?]EUVD Bot » 🤖 🌐
                                                    @EUVD_Bot@mastodon.social

                                                    🚨 EUVD-2026-33849

                                                    📊 Score: 5.3/10 (CVSS v3.1)
                                                    📦 Product: Fees Management System
                                                    🏢 Vendor: itsourcecode
                                                    📅 Updated: 2026-06-01

                                                    📝 A vulnerability was detected in itsourcecode Fees Management System 1.0. The affected element is an unknown function of the file index.php. Performing a manipulation of the argument page results in cross site scripting. The attack may be ...

                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                      [?]urlDNA.io :verified: » 🤖 🌐
                                                      @urldna@infosec.exchange

                                                      Possible Phishing 🎣
                                                      on: ⚠️hxxps[:]//gemiximlogen[.]gitbook[.]io
                                                      🧬 Analysis at: urldna.io/scan/6a1dd06a3b77500

                                                        [?]TheHackerWire » 🤖 🌐
                                                        @thehackerwire@mastodon.social

                                                        🟠 CVE-2026-25260 - High (7.8)

                                                        Memory Corruption when accessing shared buffers without validation of concurrent user-mode input modifications.

                                                        🔗 thehackerwire.com/vulnerabilit

                                                        CVE Alert: CVE-2026-25260

                                                        Alt...CVE Alert: CVE-2026-25260

                                                          [?]TheHackerWire » 🤖 🌐
                                                          @thehackerwire@mastodon.social

                                                          🟠 CVE-2026-25276 - High (8.8)

                                                          Memory corruption while using Strongbox due to missing bounds check.

                                                          🔗 thehackerwire.com/vulnerabilit

                                                          CVE Alert: CVE-2026-25276

                                                          Alt...CVE Alert: CVE-2026-25276

                                                            [?]TheHackerWire » 🤖 🌐
                                                            @thehackerwire@mastodon.social

                                                            🟠 CVE-2026-25277 - High (8.8)

                                                            Memory corruption while using Strongbox due to buffer overflow.

                                                            🔗 thehackerwire.com/vulnerabilit

                                                            CVE Alert: CVE-2026-25277

                                                            Alt...CVE Alert: CVE-2026-25277

                                                              [?]TheHackerWire » 🤖 🌐
                                                              @thehackerwire@mastodon.social

                                                              🔴 CVE-2026-25879 - Critical (9.8)

                                                              Langroid is a framework for building large-language-model-powered applications. Prior to version 0.63.0, SQLChatAgent executes SQL produced by an LLM, which is influenceable by prompt injection. When configured with a database role that has privil...

                                                              🔗 thehackerwire.com/vulnerabilit

                                                              CVE Alert: CVE-2026-25879

                                                              Alt...CVE Alert: CVE-2026-25879

                                                                [?]TheHackerWire » 🤖 🌐
                                                                @thehackerwire@mastodon.social

                                                                🟠 CVE-2026-24752 - High (8.2)

                                                                Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could allow an external attacker to trick a user into executing arbitrary JavaScript code. Upgrade Kiteworks to version...

                                                                🔗 thehackerwire.com/vulnerabilit

                                                                CVE Alert: CVE-2026-24752

                                                                Alt...CVE Alert: CVE-2026-24752

                                                                  [?]TheHackerWire » 🤖 🌐
                                                                  @thehackerwire@mastodon.social

                                                                  🟠 CVE-2026-24088 - High (8.2)

                                                                  Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.

                                                                  🔗 thehackerwire.com/vulnerabilit

                                                                  CVE Alert: CVE-2026-24088

                                                                  Alt...CVE Alert: CVE-2026-24088

                                                                    [?]deafnews » 🤖 🌐
                                                                    @deafnews@infosec.exchange

                                                                    [?]TechWire ⚡ » 🤖 🌐
                                                                    @techwire@social.gamefan.net

                                                                    Asus' monstrous ROG Astral GeForce RTX 5090 Edition 20 includes expansive curved AMOLED display — also debuts 3,000W power supply and striking PC…

                                                                    Asus has used its Computex press event to showcase a huge celebration of its ROG gaming sub-brand with commemorative gear including the Asus ROG Astral GeForce RTX 5090 Edition 20.

                                                                    tomshardware.com/pc-components

                                                                    [Tom's Hardware]

                                                                      [?]TechWire ⚡ » 🤖 🌐
                                                                      @techwire@social.gamefan.net

                                                                      Nvidia says RTX Spark chip will support all major anti-cheat and DRM technologies — Fortnite, Valorant, D…

                                                                      Microsoft and Nvidia are working together to bring popular anti-cheat software to the new RTX Spark chip, allowing support for all major multiplayer games. So far, Fortnite is the only game that runs on Windows-on-Arm d…

                                                                      tomshardware.com/pc-components

                                                                      [Tom's Hardware]

                                                                        [?]CTI.FYI » 🤖 🌐
                                                                        @CTI_FYI@infosec.exchange

                                                                        🚨New ransom group blog post!🚨

                                                                        Group name: anubis
                                                                        Post title: Power & Tel
                                                                        Info: cti.fyi/groups/anubis.html

                                                                          [?]urlDNA.io :verified: » 🤖 🌐
                                                                          @urldna@infosec.exchange

                                                                          Possible Phishing 🎣
                                                                          on: ⚠️hxxp[:]//priyanshisingh19[.]github[.]io/Netflix-clon
                                                                          🧬 Analysis at: urldna.io/scan/6a1e24e33b77500

                                                                            [?]BastilleBSD :freebsd: » 🌐
                                                                            @BastilleBSD@fosstodon.org

                                                                            More IDN homograph detection research today. This screenshot is a bit horrifying considering how nearly identical many of the invalid entries visually match the valid entry (top).

                                                                            TIME CLIENT DOMAIN TYPE STATUS SOURCE SEC LATENCY
2026-06-02 01:29 UTC 10.17.89.197 paypal.com. MX CACHE 0.1ms
2026-06-02 01:29 UTC 10.17.89.197 paypal.com. AAAA FORWARD v SEC 43.1ms
2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A CACHE 0.1ms
2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms
2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms
2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms
2026-06-02 01:29 UTC 10.17.89.197 paypat.com. A BLOCKED HOMOGRAPH 0.0ms
2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms
2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms
2026-06-02 01:29 UTC 10.17.89.197 paypat.com. A BLOCKED HOMOGRAPH 0.0ms
2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms
2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms
2026-06-02 01:29 UTC 10.17.89.197 paypat.com. A BLOCKED HOMOGRAPH 0.0ms
2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms
2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms
2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms

                                                                            Alt...TIME CLIENT DOMAIN TYPE STATUS SOURCE SEC LATENCY 2026-06-02 01:29 UTC 10.17.89.197 paypal.com. MX CACHE 0.1ms 2026-06-02 01:29 UTC 10.17.89.197 paypal.com. AAAA FORWARD v SEC 43.1ms 2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A CACHE 0.1ms 2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms 2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms 2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms 2026-06-02 01:29 UTC 10.17.89.197 paypat.com. A BLOCKED HOMOGRAPH 0.0ms 2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms 2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms 2026-06-02 01:29 UTC 10.17.89.197 paypat.com. A BLOCKED HOMOGRAPH 0.0ms 2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms 2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms 2026-06-02 01:29 UTC 10.17.89.197 paypat.com. A BLOCKED HOMOGRAPH 0.0ms 2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms 2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms 2026-06-02 01:29 UTC 10.17.89.197 paypal.com. A BLOCKED HOMOGRAPH 0.0ms

                                                                              [?]TechWire ⚡ » 🤖 🌐
                                                                              @techwire@social.gamefan.net

                                                                              Tom's Hardware Unfiltered: Computex 2026, Day 0 — peek behind the curtain to see how we're covering the biggest…

                                                                              Our team is on the ground in Taipei for Computex 2026. For the first time, we're peeling back the curtain to show you exactly how we're covering it, documenting our trials and tribulations during the massive event.

                                                                              tomshardware.com/tech-industry

                                                                              [Tom's Hardware]

                                                                                [?]TheHackerWire » 🤖 🌐
                                                                                @thehackerwire@mastodon.social

                                                                                🟠 CVE-2026-7770 - High (8.8)

                                                                                IBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solutions (ACS) is vulnerable to remote code execution when configured to listen for requests from IBM i Navigator.

                                                                                🔗 thehackerwire.com/vulnerabilit

                                                                                CVE Alert: CVE-2026-7770

                                                                                Alt...CVE Alert: CVE-2026-7770

                                                                                  [?]urlDNA.io :verified: » 🤖 🌐
                                                                                  @urldna@infosec.exchange

                                                                                  Possible Phishing 🎣
                                                                                  on: ⚠️hxxps[:]//ex-cmetamask-wallet-cdn[.]groovehq[.]com
                                                                                  🧬 Analysis at: urldna.io/scan/6a1dde873b77500

                                                                                    [?]TheHackerWire » 🤖 🌐
                                                                                    @thehackerwire@mastodon.social

                                                                                    🟠 CVE-2026-47294 - High (8)

                                                                                    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

                                                                                    🔗 thehackerwire.com/vulnerabilit

                                                                                    CVE Alert: CVE-2026-47294

                                                                                    Alt...CVE Alert: CVE-2026-47294

                                                                                      [?]TheHackerWire » 🤖 🌐
                                                                                      @thehackerwire@mastodon.social

                                                                                      🟠 CVE-2026-45545 - High (8.2)

                                                                                      Nextcloud is an open source content collaboration platform. From versions 0.7.0 to before 0.7.7, 0.8.0 to before 0.8.10, 0.9.0 to before 0.9.8, and 1.0.0 to before 1.0.4, an authenticated attacker with access to the Tables app may be able to execu...

                                                                                      🔗 thehackerwire.com/vulnerabilit

                                                                                      CVE Alert: CVE-2026-45545

                                                                                      Alt...CVE Alert: CVE-2026-45545

                                                                                        [?]TheHackerWire » 🤖 🌐
                                                                                        @thehackerwire@mastodon.social

                                                                                        🟠 CVE-2026-45302 - High (8.2)

                                                                                        parse-nested-form-data is a tiny node module for parsing FormData by name into objects and arrays. Prior to version 1.0.1, parseFormData() walks bracket and dot-notation FormData field names into nested objects without filtering reserved property ...

                                                                                        🔗 thehackerwire.com/vulnerabilit

                                                                                        CVE Alert: CVE-2026-45302

                                                                                        Alt...CVE Alert: CVE-2026-45302

                                                                                          [?]TheHackerWire » 🤖 🌐
                                                                                          @thehackerwire@mastodon.social

                                                                                          🟠 CVE-2026-45281 - High (8.1)

                                                                                          Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, with the knowledge of other users’ principal URL an attacker could possibly send a request to gai...

                                                                                          🔗 thehackerwire.com/vulnerabilit

                                                                                          CVE Alert: CVE-2026-45281

                                                                                          Alt...CVE Alert: CVE-2026-45281

                                                                                            [?]TheHackerWire » 🤖 🌐
                                                                                            @thehackerwire@mastodon.social

                                                                                            🟠 CVE-2026-43958 - High (7.8)

                                                                                            A flaw was found in rrdcached, a component of rrdtool. A local attacker with access to a rrdcached socket can exploit a stack-based buffer overflow by sending an oversized CREATE request. This vulnerability can lead to a denial of service by crash...

                                                                                            🔗 thehackerwire.com/vulnerabilit

                                                                                            CVE Alert: CVE-2026-43958

                                                                                            Alt...CVE Alert: CVE-2026-43958

                                                                                              Back to top - More...