voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
🎁 Lone attacker published 14 malicious npm packages mimicking popular OpenSearch, Elasticsearch libraries
「 A single npm user on Thursday published 14 malicious packages within a four-hour window, all mimicking popular OpenSearch, Elasticsearch, DevOps, and environment-configuration libraries, according to Microsoft 」
https://www.theregister.com/security/2026/05/29/14-malicious-npm-packages-impersonated-opensearch-elasticsearch-libraries/5248792
🔴 CVE-2026-44650 - Critical (9.1)
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, POST /api/extensions/delete endpoint accepts ex...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44650/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Possible Phishing 🎣
on: ⚠️hxxps[:]//facetakpcikas[.]weebly[.]com/
🧬 Analysis at: https://urldna.io/scan/6a1979963b775000030d2ed0
#cybersecurity #phishing #infosec #urldna #scam #infosec
🟠 CVE-2026-42929 - High (8.3)
Danelec MacGregor Voyage Data Recorder
includes default accounts with hard-coded credentials.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-42929/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
TP-Link announces its first consumer Wi-Fi 8 roadmap — Archer 8 routers scheduled to arrive in October 2026, pending FCC approval
TP-Link announced today the roadmap for its next-generation platform of Wi-Fi 8 (802.11bn) products.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
🖲️ #Cybersecurity #Ciberseguridad #Ciberseguranca #Security #Seguridad #Seguranca #News #Noticia #Noticias #Tecnologia #Technology
⚫ Ransomware Actors Show Up In Person to Steal Law Firm Data
🔗 https://www.darkreading.com/cyberattacks-data-breaches/ransomware-actors-steal-law-firm-data
The FBI warned that the extortion gang Silent Ransom Group is targeting law firms and socially engineering its way into servers and databases.
Trailing-edge foundry roadmaps for GlobalFoundries, UMC, and SMIC — mature node chipmakers each pursue differing strategies and…
We explore Globalfoundries, UMC, and SMIC's individual trailing-edge roadmaps, as each company is pursuing a fundamentally different strategy shaped by geography, regulation, and technology choices.
https://www.tomshardware.com/tech-industry/semiconductors/the-trailing-edge-foundry-roadmap-examined
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
🚨New ransom group blog post!🚨
Group name: krybit
Post title: ecci-srl.com
Info: https://cti.fyi/groups/krybit.html
#ransomware #cti #threatintelligence #cybersecurity #infosec
Possible Phishing 🎣
on: ⚠️hxxps[:]//vdhcfg545cvcdfd[.]weebly[.]com/
🧬 Analysis at: https://urldna.io/scan/6a1989173b775000030d30af
#cybersecurity #phishing #infosec #urldna #scam #infosec
'Call of Duty Modern Warfare 4' developer promises PC focus — Infinity Ward promises extensive optimization and is dropping older consoles
Call of Duty Modern Warfare 4 drops older consoles and promises extensive optimization and PC-specific options
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
🚨 EUVD-2026-33431
📊 Score: 6.3/10 (CVSS v3.1)
📦 Product: FastGPT
🏢 Vendor: labring
📅 Updated: 2026-05-29
📝 FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, the JavaScript sandbox worker at projects/code-sandbox/src/pool/worker.ts:356 blocks dynamic import() with the regex /\bimport\s*\(/.test(code). JavaScript syntax accepts a block comment betwee...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33431
🚨 EUVD-2026-33430
📊 Score: 7.7/10 (CVSS v3.1)
📦 Product: FastGPT
🏢 Vendor: labring
📅 Updated: 2026-05-29
📝 FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allows an authenticated attacker to bypass the global isInternalAddress network protection and make arbitrary HTTP GET requests to internal ne...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33430
🚨 EUVD-2026-33429
📊 Score: 2.9/10 (CVSS v3.1)
📦 Product: nanomq
🏢 Vendor: nanomq
📅 Updated: 2026-05-29
📝 NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In 0.24.8 and earlier, quic_stream_recv can dereference a null substream pointer when a substream is in reopen state. The code finishes the AIO with error but does not return before locking ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33429
🚨 EUVD-2026-33428
📊 Score: 4.5/10 (CVSS v3.1)
📦 Product: nanomq
🏢 Vendor: nanomq
📅 Updated: 2026-05-29
📝 NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to 0.24.14, aio->prov_data is stored as nni_quic_conn* during dialing, but read as ex_quic_conn* during dialer close. This type confusion causes invalid object interpretation and leads...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33428
🚨 EUVD-2026-33427
📊 Score: 9.9/10 (CVSS v3.1)
📦 Product: cpp-httplib
🏢 Vendor: yhirose
📅 Updated: 2026-05-29
📝 cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's server parses an incoming request, it applies percent-decoding to every header value except Location and Referer. The validity check (is...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33427
🚨 EUVD-2026-33426
📊 Score: 8.7/10 (CVSS v3.1)
📦 Product: cpp-httplib
🏢 Vendor: yhirose
📅 Updated: 2026-05-29
📝 cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, When the server has called Server::set_trusted_proxies() with a non-empty trusted-proxy list, an attacker can send an HTTP request that includes an X-Forwa...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33426
🚨 EUVD-2026-33425
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: cpp-httplib
🏢 Vendor: yhirose
📅 Updated: 2026-05-29
📝 cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.43.4, negative chunk-size in chunked Transfer-Encoding causes unbounded memory allocation and process crash. The ChunkedDecoder::read_payload function in cpp-htt...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33425
🚨 EUVD-2026-33423
📊 Score: 3.3/10 (CVSS v3.1)
📦 Product: rizin
🏢 Vendor: rizinorg
📅 Updated: 2026-05-29
📝 Rizin is a UNIX-like reverse engineering framework and command-line toolset. There is a heap-buffer-overflow in librz/bin/format/omf/omf.c. This vulnerability is fixed by commit e6d0937c8a083e23ed76ccfb9f631cdc50c7af47.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33423
🚨 EUVD-2026-33422
📊 Score: 8.7/10 (CVSS v3.1)
📦 Product: formie, formie
🏢 Vendor: verbb
📅 Updated: 2026-05-29
📝 Formie is a Craft CMS plugin for creating forms. Prior to 2.2.21 and 3.1.26, unauthenticated users could modify existing submissions by posting a known or guessed submission ID to formie/submissions/save-submission. This vulnerability is fixed in 2.2.21...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33422
🚨 EUVD-2026-33421
📊 Score: 9.8/10 (CVSS v3.1)
📦 Product: formie, formie
🏢 Vendor: verbb
📅 Updated: 2026-05-29
📝 Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) that were evaluated as Twig during submission handling, which could lead to s...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33421
🚨 EUVD-2026-33418
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: laravel-medialibrary
🏢 Vendor: spatie
📅 Updated: 2026-05-29
📝 Spatie Laravel Media Library before version 11.23.0 contains a server-side request forgery vulnerability that allows remote attackers to cause the server to issue arbitrary outbound HTTP requests by passing user-controlled URLs to the addMediaFro...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33418
🔴 CVE-2026-45372 - Critical (9.9)
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's server parses an incoming request, it applies percent-decoding to every header value except Location and Referer. The validity ch...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45372/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-44285 - High (7.7)
FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allows an authenticated attacker to bypass the global isInternalAddress network protection and make arbitrary HTTP GET requests to ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44285/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-44420 - High (8.8)
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side clipboard (cliprdr) channel by sending a CB_CLIP_CAPS PDU with a too-small c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44420/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
5 best practices for migrating to a new CRM
Switching CRMs risks data loss and workflow disruption. These five best practices keep things on track.
https://www.zdnet.com/article/5-best-practices-for-migrating-to-a-new-crm/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
Google’s Gemini Spark is ready to run your digital errands while your phone is off
You can now give Gemini Spark a task, turn off everything, and it still gets the job done.
https://www.androidauthority.com/google-rolls-out-gemini-spark-3672796/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Possible Phishing 🎣
on: ⚠️hxxps[:]//creditoman-bc[.]om/SignIn
🧬 Analysis at: https://urldna.io/scan/6a1963a83b775000030d2bca
#cybersecurity #phishing #infosec #urldna #scam #infosec
I tried different Android Auto weather apps - these 3 are best for storm nerds like me
There aren't many weather apps for Android Auto, but the ones I found work very well.
https://www.zdnet.com/article/best-android-auto-weather-apps/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
🚨 EUVD-2018-21906
📊 Score: 5.1/10 (CVSS v3.1)
📦 Product: Wikidforum
🏢 Vendor: wikidforum
📅 Updated: 2026-05-29
📝 Wikidforum 2.20 contains a cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted HTML in the reply_text parameter. Attackers can post comments containing JavaScript code through the rpc...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-21906
🚨 EUVD-2018-21905
📊 Score: 8.6/10 (CVSS v3.1)
📦 Product: Free MP3 CD Ripper
🏢 Vendor: Commentcamarche
📅 Updated: 2026-05-29
📝 Free MP3 CD Ripper 2.8 contains a stack-based buffer overflow vulnerability in WMA file processing that allows local attackers to bypass DEP protection via structured exception handling manipulation. Attackers can craft a malicious WMA fil...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-21905
🚨 EUVD-2018-21904
📊 Score: 8.8/10 (CVSS v3.1)
📦 Product: Zechat
🏢 Vendor: Bylancer
📅 Updated: 2026-05-29
📝 Zechat 1.5 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the uname parameter. Attackers can send crafted requests to profile.php with UNION-based SQL injection payl...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-21904
🚨 EUVD-2026-33330
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: TEW-432BRP
🏢 Vendor: TRENDnet
📅 Updated: 2026-05-29
📝 A security flaw has been discovered in TRENDnet TEW-432BRP 3.10B20. This affects the function formSetPortTr of the file /goform/formSetPortTr. Performing a manipulation of the argument special_name results in stack-based buffer overflow. It is possible t...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33330
🚨 EUVD-2026-33323
📊 Score: 7.2/10 (CVSS v3.1)
📦 Product: mcp-security
🏢 Vendor: spring-ai-community
📅 Updated: 2026-05-29
📝 mcp-security provides Security and Authorization support for Model Context Protocol in Spring AI. Prior to 0.1.9, the mcp-security framework fails to implement the mandatory SSRF mitigations outlined in the Model Context Protocol (MCP) secur...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33323
🟠 CVE-2026-35630 - High (8)
OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to enforce configured approver identity. Non-approver users can click approval buttons to resolve pending exec or plugin approval ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-35630/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-35674 - High (8.8)
OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped clients to execute privileged commands. Attackers with operator.write scope can deliver commands through inherited external routes to...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-35674/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-32905 - High (8.3)
OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows non-owner authorized chat senders to issue device-pairing bootstrap codes without proper scope validation. Attackers with chat co...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-32905/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
How Ferrari bungled the design of its first EV
For nearly 80 years, Ferrari occupied a unique cultural space where its cars were aspirational, even for people who resented those who could afford them. The price, the exclusivity, and the opacity of the buying process…
https://www.theverge.com/transportation/939226/ferrari-luce-design-terrible-ev-jony-ive-apple
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
LLM Agent Conducts Autonomous Post-Exploitation via Marimo RCE https://deafnews.it/en/article/llm-agent-conducts-autonomous-post-exploitation-via-marimo-rce #Cybersecurity
Carnival e il paradosso della cybersecurity moderna: milioni di record rubati attraverso un solo dipendente
#CyberSecurity
https://insicurezzadigitale.com/carnival-e-il-paradosso-della-cybersecurity-moderna-milioni-di-record-rubati-attraverso-un-solo-dipendente/
ChatGPT is retiring this beloved legacy model in June
The GPT-4 family is on its way out.
https://www.androidauthority.com/chatgpt-4-5-o3-retired-3672713/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Cybersecurity Shifts from Risk to Acceleration, Connection
The World Economic Forum's 2025 survey reveals a stark reality: 72% of organizations are facing increased cyber risks, with ransomware remaining a top threat - forcing us to rethink how we keep information safe in an AI-driven world. It's time to shift from traditional risk management to practical, accelerated solutions.
#Cybersecurity #RiskManagement #Ai #Ransomware #EmergingThreats
Oh no! 😱 Someone dared to use your unassuming little #open-source project for phishing?! 😲 That's like realizing your homemade #lemonade #stand has become the headquarters for a global crime syndicate. 🍋💻 Maybe next time, include a "no phish zone" sign in your code. 🐟🚫
https://andrej.sh/posts/phishing-through-my-open-source-project #phishing #crime-syndicate #no-phish-zone #cybersecurity #HackerNews #ngated
Possible Phishing 🎣
on: ⚠️hxxps[:]//desmondcooper6[.]wixsite[.]com/atllt
🧬 Analysis at: https://urldna.io/scan/6a1995b83b775000030d3265
#cybersecurity #phishing #infosec #urldna #scam #infosec
Scammers Are Using Your Real #Hotel Reservations to Trick You With Spear-Phishing Attacks
https://www.wired.com/story/hundreds-of-hotels-caught-up-in-vacation-booking-scams/