voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
You can buy two of Anker’s Qi2 wireless chargers for under $25
If you’re looking for a fast iPhone or AirPods charger that’s easy to toss into your purse, backpack, or carry-on, Anker’s Zolo Magnetic Wireless Charger is a smart pick. It’s tiny and comes with a built-in USB-C cable,…
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
CISA Releases Guidance on the Careful Adoption of Agentic AI Services
#AI #cybersecurity #privacy #surveillance
🚨 EUVD-2026-33280
📊 Score: 5.4/10 (CVSS v3.1)
📅 Updated: 2026-05-29
📝 A stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. When rendering selection menus for associating projects with system entities, the application fails to sanitize project names returned via AJAX before injecting them into the DOM as option fi...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33280
🚨 EUVD-2025-209985
📊 Score: 8.6/10 (CVSS v3.1)
📦 Product: WF-500
🏢 Vendor: Waterfall
📅 Updated: 2026-05-29
📝 Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version 7.9.1.0 R2502171040 that allows remote authenticated at...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-209985
🚨 EUVD-2026-33279
📊 Score: 7.6/10 (CVSS v3.1)
📅 Updated: 2026-05-29
📝 A stored Cross-Site Scripting (XSS) vulnerability exists in the Projects component of Mautic 7. When displaying project tags and popovers on administrative detail views (such as campaigns, emails, or forms), user-supplied project names are rendered without proper sanitization. An authenticated ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33279
🚨 EUVD-2026-33278
📊 Score: 7.1/10 (CVSS v3.1)
📅 Updated: 2026-05-29
📝 An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain conditions, roles configured with owner-scope restrictions (such as `viewown` or `editown`) are not properly enforced. This allows low-privilege authenticated API users to bypas...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33278
🚨 EUVD-2026-33277
📊 Score: 9.9/10 (CVSS v3.1)
📅 Updated: 2026-05-29
📝 A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw in the validation logic allows file paths to escape the intended temporary directories. An authenticated user with campaign import privileges (cam...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33277
Charter confirms data breach after ShinyHunters extortion threat
U.S. telecommunications giant Charter Communications has confirmed it suffered a data breach after the ShinyHunters extortion group threatened to leak stolen data unless a ransom is paid.
#Charter #databreach #ransomware #malware #security #cybersecurity #hackers #hacking #hacked
Kimsuky's Advanced Attack Techniques: JSONPing, Webex Spoofing, and a New HttpSpy Variant
Through April 2026, Kimsuky deployed sophisticated malicious campaigns against South Korean military and corporate entities using tailored social engineering tactics including fake security software installation pages and spoofed Webex meeting pages leveraging legitimate meeting schedules. The threat actor introduced a novel JSONPing technique allowing distribution pages to verify in real time whether victims executed the payload via JSONP queries to localhost servers. Analysis revealed a new HttpSpy variant with a three-stage execution chain replacing the previous single-binary architecture, utilizing RC4 encryption and shared infrastructure indicators. Attribution was confirmed through code pattern overlaps, reused encryption keys, XAMPP certificate fingerprints, and preferred ASN usage consistent with historical Kimsuky operations targeting South Korea.
Pulse ID: 6a19766cc7caf96e27eae35e
Pulse Link: https://otx.alienvault.com/pulse/6a19766cc7caf96e27eae35e
Pulse Author: AlienVault
Created: 2026-05-29 11:20:12
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Encryption #HTTP #HTTPS #ICS #InfoSec #Kimsuky #Korea #Military #OTX #OpenThreatExchange #RAT #SocialEngineering #SouthKorea #UK #bot #AlienVault
Operation XENOFISCAL: SideCopy deploying persistent XenoRAT targeting the MoF, Afghanistan
SideCopy APT, a Pakistan-linked threat group under the Transparent Tribe umbrella, executed a targeted spear phishing campaign against Afghanistan's Ministry of Finance and provincial revenue directorates. The attack begins with a Pashto-language LNK file disguised as a staff directory document, which executes mshta.exe to fetch remote HTA payloads from compromised Afghan education infrastructure. The multi-stage chain deploys obfuscated JavaScript, establishes registry-based persistence mimicking Microsoft Edge, and ultimately delivers XenoRAT 1.8.7 beaconing to bulletproof Bulgarian hosting. The campaign demonstrates precise knowledge of target administrative context, using Dari and Pashto decoy documents listing provincial finance officials with direct contact information. Infrastructure analysis reveals deliberate staging within Afghan government IP space and C2 infrastructure overlapping with previous SideCopy operations.
Pulse ID: 6a196f2fd88de848b913e4da
Pulse Link: https://otx.alienvault.com/pulse/6a196f2fd88de848b913e4da
Pulse Author: AlienVault
Created: 2026-05-29 10:49:19
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Afghanistan #Bulgaria #CyberSecurity #Edge #Education #Government #InfoSec #Java #JavaScript #LNK #Microsoft #MicrosoftEdge #Mimic #OTX #OpenThreatExchange #Pakistan #Phishing #RAT #SideCopy #SpearPhishing #TransparentTribe #bot #AlienVault
This is MSI’s new Claw 8 EX AI Plus gaming handheld
It may only be available in this “Void Purple” color option. | Image: MSI MSI has unveiled a new Claw 8 handheld gaming PC ahead of the Computex 2026 show, and this model swaps out its predecessors' Intel Lunar Lake mob…
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
This AI startup will clean your home for free to train future robots
AI training startup Shift wants to clean your home for free. The catch - because, despite what its website says, there's always a catch - is that it will record cleaners as they scrub, vacuum, dust, tidy, and wash, and …
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
🚨New ransom group blog post!🚨
Group name: akira
Post title: Interstate Roofing
Info: https://cti.fyi/groups/akira.html
#ransomware #cti #threatintelligence #cybersecurity #infosec
Possible Phishing 🎣
on: ⚠️hxxps[:]//pub-fe2c2ecf757e4655b6bb7a6e32c587ec[.]r2[.]dev/so[.]html
🧬 Analysis at: https://urldna.io/scan/6a1955bf3b775000030d2a01
#cybersecurity #phishing #infosec #urldna #scam #infosec
Is Linux too loud? Is centralized too risky? Install a private chat system on FreeBSD over Tor.
#freebsd #xmpp #chat #opsec #cybersecurity #privacy
http://tomsitcafe.com/2026/05/29/xmpp-over-tor-on-freebsd-talk-privately-without-big-tech-pipelines/
Now even MediaTek’s cheap chips are embarrassing the Tensor G5 in one major area
This MediaTek chip is expected to appear in cheap phones, but it shows up the Tensor G5 in a key area.
https://www.androidauthority.com/new-mediatek-chip-tensor-g5-cpu-3672592/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
El manifiesto del buen SysAdmin en 5 pilares:
🤖 Automatización: Si lo haces más de dos veces, escribe un script.
💾 Backups: Un respaldo que no se ha probado, simplemente no existe.
👁️ Monitoreo: Entérate tú antes de que el servidor se caiga y tu jefe te llame.
🔒 Seguridad: Aplica siempre el principio de menor privilegio.
📝 Documentación: Escribe para tu "yo" del futuro a las 3 AM.
#SysAdmin #Linux #DevOps #IT #Networking #Automation #CyberSecurity
Apple and Google urge Canada’s Parliament to amend Bill C-22 to require court approval before ministers can compel changes to encryption or systems 🔐
Bill C-22 also mandates up to one-year metadata retention and enables secret ministerial technical-capability orders without prior court review ⚖️
🔗 https://thenextweb.com/news/apple-google-canada-c22-lawful-access-judicial-oversight
#TechNews #Apple #Google #Canada #BillC22 #Encryption #Privacy #Surveillance #LawfulAccess #Law #DataRetention #DigitalRights #CyberSecurity #Internet #Parliament #Government
CVE-2026-35616: Critical FortiClient EMS Flaw Exploited in Fleet-Wide Infostealer Campaign https://deafnews.it/en/article/cve-2026-35616-critical-forticlient-ems-flaw-potentially-exploited-in-infostealer-campaign #Cybersecurity
Google may have fixed the issue that was exhausting your Gemini usage limits
These changes might finally tip the scales your way.
https://www.androidauthority.com/gemini-usage-limit-changes-3672488/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Wer überwacht die Überwacher? Das Citizen Lab (Univ. Toronto) deckt digitale Spionage & Massenüberwachung auf. Leiter Ron Deibert: „Wir waren noch nie so beschäftigt wie heute.“ Die Forschung ist riskant — und unerlässlich. Mehr: https://www.jetzt.at/artikel/sswybizg-aiM8QAs4-e1497 🕵️♂️🔒 #Überwachung #Cybersecurity #Privacy #Security
"Auch bei den Verbraucherzentralen im Ruhrgebiet häufen sich die Beschwerden über Culpa Inkasso. Monika Wagner von der Verbraucherzentrale Essen warnt vor dem Vorgehen der Firma und betont, dass es sich dabei um Betrug handeln könnte.
Am Wichtigsten sei es, nicht zu bezahlen, sondern solche Zahlungsaufforderungen erst zu überprüfen. Sonst ist das Geld weg"
https://www1.wdr.de/nrw/essen/verbraucherzentrale-warnt-inkassoschreiben-unberechtigt-100.html
🚨 EUVD-2026-33257
📊 Score: 4.1/10 (CVSS v3.1)
📦 Product: Scout Bobber + Tech
🏢 Vendor: Indian Motorcycle (Polaris Inc.)
📅 Updated: 2026-05-29
📝 Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read access to the in-vehicle network to recover the user-set ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33257
🚨 EUVD-2026-33256
📊 Score: 7.1/10 (CVSS v3.1)
📅 Updated: 2026-05-29
📝 An SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33256
🚨 EUVD-2025-209983
📊 Score: 7.2/10 (CVSS v3.1)
📦 Product: Link Whisper Free
🏢 Vendor: linkwhspr
📅 Updated: 2026-05-29
📝 The Link Whisper Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user_id parameter in all versions up to, and including, 0.9.0 due to insufficient input sanitization and output escaping. This makes it possible for...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-209983
🚨 EUVD-2026-33255
📊 Score: 9.8/10 (CVSS v3.1)
📦 Product: OTP Login With Phone Number, OTP Verification
🏢 Vendor: glboy
📅 Updated: 2026-05-29
📝 The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in versions 1.8.50 through 1.8.60. This is due to the Firebase verification flow in the `lwp_ajax_register` AJAX...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33255
🚨 EUVD-2026-33254
📊 Score: 6.4/10 (CVSS v3.1)
📦 Product: The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce
🏢 Vendor: posimyththemes
📅 Updated: 2026-05-29
📝 The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carousel_direction' parameter of the Carousel Anythi...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33254
Possible Phishing 🎣
on: ⚠️hxxps[:]//takipcigir[.]com
🧬 Analysis at: https://urldna.io/scan/6a18bb063b775000054a444d
#cybersecurity #phishing #infosec #urldna #scam #infosec
Pick n Pay Legacy Delivery App Breach Exposes Historical Customer Data
Pick n Pay confirmed a data breach of its legacy delivery app, exposing personal details and partial payment information of users registered before 2022. The 639MB database is being sold on the dark web.
****
#cybersecurity #infosec #incident #databreach
https://beyondmachines.net/event_details/pick-n-pay-legacy-delivery-app-breach-exposes-historical-customer-data-a-m-5-6-s/gD2P6Ple2L
Google Photos could soon give you more tools to make your Memories shine
Google could make your Memories in Photos more shareworthy.
https://www.androidauthority.com/google-photos-memories-edit-3672506/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
As an Oura Ring 4 user, here are 3 reasons why I can’t wait to buy the Oura Ring 5
There's a lot to love about Oura's latest launch.
https://www.androidauthority.com/oura-ring-5-top-three-upgrades-3671505/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
#chrome extension Gitlab Diff Collapse All seems malicious. Its #cybersecurity badness score is 91/100!
```json
{"id": "onomhajljlbeneekipoigcehjngdajec", "score": 91, "platform": "chrome", "name": "Gitlab Diff Collapse All"}
```
FortiClient EMS Zero-Day: EKZ Infostealer Weaponizes VPN Management Channels https://deafnews.it/en/article/forticlient-ems-ekz-infostealer-may-target-vpn-management-channels #Cybersecurity
Possible Phishing 🎣
on: ⚠️hxxps[:]//netflix-clone-coral-eight[.]vercel[.]app/
🧬 Analysis at: https://urldna.io/scan/6a1908fc3b775000030d2114
#cybersecurity #phishing #infosec #urldna #scam #infosec
This company wants to clean your house for free, to train AI and robots
If it's free, you're the product — but at least Shift tells you that.
https://www.androidauthority.com/shift-clean-house-free-record-video-ai-training-3672527/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Social Engineering Attacks: How They Work and How to Defend Against Them - https://www.redpacketsecurity.com/social-engineering-attacks-how-they-work-and-how-to-defend-against-them-2/
AI Model Release Tracker: Opus 4.8's misalignment rates similar to Claude Mythos Preview
Not every new model is all it's cracked up to be. Our tracker keeps each release in context with its peers, so you know which models are worth your time.
https://www.zdnet.com/article/ai-model-release-tracker/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
New research from WithSecure exposes GreyVibe, a Russian-linked hacking group, for actively employing commercial AI tools like ChatGPT and Google Gemini to develop malware and generate highly realistic social engineering lures against Ukrainian targets. Interestingly, their operational discipline shows a blend of advanced tactics and surprising vulnerabilities, suggesting a group still refining its…
#cybersecurity #greyvibe #chatgpt
🤖 This post was AI-generated.