voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
🎉 SURPRISE! 🎉 #RedHat discovers that their #npm packages have been doing the #malware mambo in broad daylight. 🚨 But don't worry, they promise their next issue will be less "dance and destroy" and more "code and conquer." 👩💻💃
https://github.com/RedHatInsights/javascript-clients/issues/492 #surprise #codeconquer #cybersecurity #open-source #software #HackerNews #ngated
Microsoft could be the next Big Tech antitrust target
Over the past several years, Microsoft has largely managed to withstand populist calls to break up Big Tech while peers faced sweeping lawsuits. But a probe by the Federal Trade Commission suggests that grace period cou…
https://www.theverge.com/policy/940220/microsoft-ftc-antitrust-investigation-cloud-ai
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
A dangerous no-code Android malware known as BTMOB is raising fresh concerns after new research from ESET highlighted its ability to lower the barriers for cybercriminals. The Android remote access trojan (RAT) includes a toolkit that lets attackers generate new payloads and customise phishing lures without coding skills, potentially leading to faster-evolving threats and wider device compromise.
Story here: https://www.techfinitive.com/no-code-android-banking-trojan-btmob-could-cause-devastating-damage-says-eset/
⚠️ Stealer activity surged last week. #Vidar, #Stealc, and #SalatStealer all increased, while #AsyncRAT and #DCRat also continued to grow.
📌 Trend to watch: credential theft is gaining momentum alongside remote access malware, giving attackers more opportunities to move from initial compromise to persistent access. For SOC teams, that means validating credential-related alerts quickly becomes even more important.
Expand threat visibility in your SOC: https://any.run/enterprise/?utm_source=mastodon&utm_medium=post&utm_campaign=top_ten&utm_term=010626&utm_content=linktoenterprise
🚨 EUVD-2026-33570
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Ingredients Stock Management System
🏢 Vendor: CodeAstro
📅 Updated: 2026-06-01
📝 A flaw has been found in CodeAstro Ingredients Stock Management System 1.0. This vulnerability affects unknown code of the file /Ingredients-Stock/stock_manager.php. This manipulation of the argument txt_search_category causes s...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33570
🚨 EUVD-2026-33569
📊 Score: 8.8/10 (CVSS v3.1)
📦 Product: Apache Directory LDAP API
🏢 Vendor: Apache Software Foundation
📅 Updated: 2026-06-01
📝 It was identified that the LDAP client implementation in version 2.1.7 does not verify if the server certificate matches the intended LDAP
hostname. While the underlying code validates the certificate chain
against a tr...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33569
🚨 EUVD-2026-33568
📊 Score: 5.1/10 (CVSS v3.1)
📦 Product: sendportal, sendportal
🏢 Vendor: mettle
📅 Updated: 2026-06-01
📝 A vulnerability was detected in Mettle sendportal up to 3.0.1. This affects an unknown part of the file /webview/ of the component Campaign Handler. The manipulation of the argument content results in cross site scripting. The attack can be lau...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33568
🚨 EUVD-2026-33567
📊 Score: n/a
📦 Product: Apache Airflow
🏢 Vendor: Apache Software Foundation
📅 Updated: 2026-06-01
📝 A bug in the GET `/api/v2/connections/{connection_id}` REST API endpoint in Apache Airflow allowed an authenticated UI/API user with Connection-read permission to retrieve secrets stored in a Connection's `extra` JSON blob under field names not pr...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33567
🚨 EUVD-2026-33566
📊 Score: 4.8/10 (CVSS v3.1)
📦 Product: Assimp, Assimp, Assimp (+2 more)
📅 Updated: 2026-06-01
📝 A security vulnerability has been detected in Assimp up to 6.0.4. Affected by this issue is the function HL1MDLLoader::read_sequence_infos of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. The manipulation of the argument aiString ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33566
🚨 EUVD-2026-33565
📊 Score: 4.8/10 (CVSS v3.1)
📦 Product: Assimp, Assimp, Assimp (+2 more)
📅 Updated: 2026-06-01
📝 A weakness has been identified in Assimp up to 6.0.4. Affected by this vulnerability is the function aiNode::~aiNode of the file scene.cpp of the component ASE File Parser. Executing a manipulation can lead to use after free. The attack needs to be la...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33565
🚨 EUVD-2026-33564
📊 Score: 4.8/10 (CVSS v3.1)
📦 Product: Assimp, Assimp, Assimp (+2 more)
📅 Updated: 2026-06-01
📝 A security flaw has been discovered in Assimp up to 6.0.4. Affected is the function HL1MDLLoader::extract_anim_value of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. Performing a manipulation of the argument num.total results in h...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33564
🚨 EUVD-2026-33563
📊 Score: 4.8/10 (CVSS v3.1)
📦 Product: Assimp, Assimp, Assimp (+2 more)
📅 Updated: 2026-06-01
📝 A vulnerability was identified in Assimp up to 6.0.4. This impacts the function Assimp::MDL::HalfLife::HL1MDLLoader::read_animations of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. Such manipulation leads to heap-based buffer ove...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33563
🚨 EUVD-2026-33562
📊 Score: 4.8/10 (CVSS v3.1)
📦 Product: Assimp, Assimp, Assimp (+2 more)
📅 Updated: 2026-06-01
📝 A vulnerability was determined in Assimp up to 6.0.4. This affects the function HL1MDLLoader::read_meshes of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. This manipulation causes heap-based buffer overflow. The attack is restrict...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33562
🚨 EUVD-2026-33561
📊 Score: 5.1/10 (CVSS v3.1)
📦 Product: student_management_system_by_php
🏢 Vendor: raisulislamg4
📅 Updated: 2026-06-01
📝 A vulnerability was found in raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff9444382d16d1. The impacted element is an unknown function of the file admission_form_check.php. The manipulation of t...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33561
Possible Phishing 🎣
on: ⚠️hxxps[:]//form[.]jotform[.]com/252075695944065
🧬 Analysis at: https://urldna.io/scan/6a1d0b963b7750000294ea9f
#cybersecurity #phishing #infosec #urldna #scam #infosec
A stealthy RAT burrowing deep into Android devices
BTMOB is an Android remote access trojan that evolved from SpySolr malware and poses significant threats beyond traditional banking trojans. The malware combines phishing-led delivery with an APK builder interface that enables rapid payload generation without coding skills. Distributed through fake app stores impersonating streaming services, cryptocurrency platforms, and government agencies, BTMOB abuses Android Accessibility Services to gain elevated permissions. Marketed as malware-as-a-service with a reported $5,000 lifetime license, it provides adversaries with capabilities to exfiltrate sensitive data, capture screenshots, record device activity, and establish remote control. The tool's customizable phishing lures have been adapted for specific regions, including campaigns impersonating Argentine tax authorities, making it a rapidly evolving threat with global reach.
Pulse ID: 6a1cc51d7c8f832f819a0a43
Pulse Link: https://otx.alienvault.com/pulse/6a1cc51d7c8f832f819a0a43
Pulse Author: AlienVault
Created: 2026-05-31 23:32:45
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APK #Android #Bank #BankingTrojan #CyberSecurity #Government #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #Phishing #RAT #RemoteAccessTrojan #Trojan #bot #cryptocurrency #AlienVault
I’m glad Samsung is finally killing the Galaxy Note design, even if fans hate it
There's nothing wrong with the older design, but I prefer design consistency.
https://www.androidauthority.com/samsung-galaxy-note-design-death-good-3669801/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Microsoft Surface Laptop Ultra weilds Nvidia's RTX Spark superchip with 128GB of RAM, 20 Arm CPU cores, and a Blackwell GPU — 15-inch mini-LED PixelSense Ultra display rounds out th…
Powered by Nvidia's RTX Spark Superchip, the Surface Laptop Ultra features 20 Arm CPU cores, 6,144 CUDA cores, and up to 128GB of unified memory
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
Possible Phishing 🎣
on: ⚠️hxxps[:]//nwm-iitk-ac-in-log[.]weebly[.]com/
🧬 Analysis at: https://urldna.io/scan/6a1cbd7c3b7750000294e3c2
#cybersecurity #phishing #infosec #urldna #scam #infosec
YouTube for TVs is getting another dose of Gemini, but it could make sense for once
You can now get YouTube video results, AI Mode-style.
https://www.androidauthority.com/ask-youtube-smart-tv-3673019/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
🚨 EUVD-2026-33547
📊 Score: 7.1/10 (CVSS v3.1)
📦 Product: OTRS, ((OTRS)) Community Edition
🏢 Vendor: OTRS AG
📅 Updated: 2026-06-01
📝 An improper neutralization of user-controllable input in OTRS or ((OTRS)) Community Edition ticket handling allows authenticated attackers to perform reflected cross-site scripting (XSS) attacks via crafted request parameters associa...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33547
Possible Phishing 🎣
on: ⚠️hxxp[:]//company[.]it-admincenter[.]com/s/63BZGFSVBWSFCDX7Y9/584dd8/90eab167-7429-489f-99f6-ce86e8d0d81a
🧬 Analysis at: https://urldna.io/scan/6a1c7f003b7750000294ddf3
#cybersecurity #phishing #infosec #urldna #scam #infosec
🚨 EUVD-2026-33546
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: hermes-agent, hermes-agent, hermes-agent (+28 more)
🏢 Vendor: NousResearch
📅 Updated: 2026-06-01
📝 A vulnerability was determined in NousResearch hermes-agent up to 2026.4.30. Affected is the function _serve_plugin_skill/skill_view of the file tools/skills_tool.py. Executing a manipulation can lead to injec...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33546
🚨 EUVD-2026-33545
📊 Score: n/a
📦 Product: MediaTek chipset, MediaTek chipset, MediaTek chipset (+3 more)
🏢 Vendor: MediaTek, Inc.
📅 Updated: 2026-06-01
📝 In wlan STA driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitati...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33545
🚨 EUVD-2026-33544
📊 Score: n/a
📦 Product: MediaTek chipset, MediaTek chipset, MediaTek chipset (+33 more)
🏢 Vendor: MediaTek, Inc.
📅 Updated: 2026-06-01
📝 In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interac...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33544
🚨 EUVD-2026-33543
📊 Score: n/a
📦 Product: MediaTek chipset, MediaTek chipset, MediaTek chipset (+33 more)
🏢 Vendor: MediaTek, Inc.
📅 Updated: 2026-06-01
📝 In geniezone, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction i...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33543
🚨 EUVD-2026-33542
📊 Score: n/a
📦 Product: MediaTek chipset, MediaTek chipset, MediaTek chipset (+33 more)
🏢 Vendor: MediaTek, Inc.
📅 Updated: 2026-06-01
📝 In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interac...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33542
🚨 EUVD-2026-33541
📊 Score: n/a
📦 Product: MediaTek chipset, MediaTek chipset, MediaTek chipset (+6 more)
🏢 Vendor: MediaTek, Inc.
📅 Updated: 2026-06-01
📝 In wlan AP driver, there is a possible memory corruption due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with User execution privileges needed. User interaction is not...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33541
🚨 EUVD-2026-33540
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: GoClaw, GoClaw, GoClaw (+1 more)
🏢 Vendor: nextlevelbuilder
📅 Updated: 2026-06-01
📝 A vulnerability was found in nextlevelbuilder GoClaw up to 3.11.3. This impacts the function FsBridge.WriteFile of the file internal/sandbox/fsbridge.go of the component write_file Tool. Performing a manipulation results in ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33540
🚨 EUVD-2026-33539
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: GoClaw, GoClaw, GoClaw (+1 more)
🏢 Vendor: nextlevelbuilder
📅 Updated: 2026-06-01
📝 A vulnerability has been found in nextlevelbuilder GoClaw up to 3.11.3. This affects the function auth of the file internal/http/evolution_handlers.go. Such manipulation leads to improper authorization. The attack can be exe...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33539
🚨 EUVD-2026-33538
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: GoClaw, GoClaw, GoClaw (+1 more)
🏢 Vendor: nextlevelbuilder
📅 Updated: 2026-06-01
📝 A flaw has been found in nextlevelbuilder GoClaw up to 3.11.3. The impacted element is the function handleSave of the file internal/http/tts_config.go of the component RoleAdmin Gateway. This manipulation causes improper pri...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33538
🚨 EUVD-2026-33537
📊 Score: 6.3/10 (CVSS v3.1)
📦 Product: droidclaw, droidclaw, droidclaw (+1 more)
🏢 Vendor: unitedbyai
📅 Updated: 2026-06-01
📝 A vulnerability was detected in unitedbyai droidclaw up to 0.5.3. The affected element is an unknown function of the file server/src/routes/pairing.ts of the component claim Endpoint. The manipulation results in improper ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33537
🟠 CVE-2026-9949 - High (8.3)
Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9949/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-9951 - High (8.3)
Use after free in UI in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9951/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-9952 - High (8.8)
Use after free in WebAudio in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9952/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Nvidia unveils RTX Spark Superchip for laptops and desktop PCs at Computex 2026 – new platform promises t…
At Computex 2026, Nvidia CEO Jensen Huang unveiled the RTX Spark Superchip, a new Arm laptop and desktop platform that powers agentic AI on Windows with a 20-core Arm CPU, powerful 6144-CUDA-core Blackwell GPU, and up t…
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
The new Google Home Speaker might finally arrive this month after a long wait
We may be just days away from being able to buy Google's first smart speaker built with Gemini from the ground up.
https://www.androidauthority.com/google-home-speaker-release-date-best-buy-3672960/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Salt Typhoon: Was Chinas Datenstrategie über den neuen Geheimdienstwettbewerb verrät
Die Nation, die am schnellsten aus den Informationen lernt, über die sie bereits verfügt, wird die nächste Ära des Geheimdienstwettbewerbs bestimmen.
Possible Phishing 🎣
on: ⚠️hxxp[:]//netflix-clone-eight-teal[.]vercel[.]app
🧬 Analysis at: https://urldna.io/scan/6a1c85463b7750000294de79
#cybersecurity #phishing #infosec #urldna #scam #infosec
Union workers protest Apple’s planned Towson store closure
The IAM Union held a protest against Apple’s decision to close its Towson store, the first unionized Apple retail location in the United States. Here are the details. more…
https://9to5mac.com/2026/05/28/union-workers-protest-apples-planned-towson-store-closure/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
🚨 EUVD-2026-33522
📊 Score: 4.8/10 (CVSS v3.1)
📦 Product: Assimp, Assimp, Assimp (+2 more)
📅 Updated: 2026-05-31
📝 A vulnerability was found in Assimp up to 6.0.4. This affects the function glTFCommon::CopyValue in the library glTFCommon.h of the component 4x4 Matrix Parser. Performing a manipulation results in heap-based buffer overflow. The attack must be initia...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33522
🟠 CVE-2026-9977 - High (8.3)
Insufficient validation of untrusted input in WebShare in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromiu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9977/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🚨 EUVD-2026-33521
📊 Score: 4.8/10 (CVSS v3.1)
📦 Product: Assimp, Assimp, Assimp (+2 more)
📅 Updated: 2026-05-31
📝 A vulnerability has been found in Assimp up to 6.0.4. Affected by this issue is the function glTF2::LazyDict in the library glTF2Asset.h. Such manipulation of the argument operator[] leads to null pointer dereference. The attack must be carried out lo...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33521
🚨 EUVD-2026-33520
📊 Score: 4.8/10 (CVSS v3.1)
📦 Product: Assimp, Assimp, Assimp (+2 more)
📅 Updated: 2026-05-31
📝 A flaw has been found in Assimp up to 6.0.4. Affected by this vulnerability is the function Assimp::glTFImporter::ImportMeshes of the file glTFImporter.cpp of the component glTFImporter. This manipulation causes null pointer dereference. The attack is...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33520
🚨 EUVD-2026-33519
📊 Score: 4.8/10 (CVSS v3.1)
📦 Product: Assimp, Assimp, Assimp (+2 more)
📅 Updated: 2026-05-31
📝 A vulnerability was detected in Assimp up to 6.0.4. Affected is the function glTF2Importer::ImportEmbeddedTextures in the library code/AssetLib/glTF2/glTF2Importer.cpp of the component TF File Handler. The manipulation results in null pointer derefere...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33519
🛡️ #Cybersecurity news & tips across the #fediverse
“A deep dive into how behavioral advertising became the internet's dominant business model — and what it costs us in privacy. By The Privacy Issue
https:// theprivacyissue.com/data-track ing/big-business-ad-tech ...”
https://techhub.social/@PrettySimplePrivacy/116668261978483713
🤖 via RSS feed. Not an endorsement.