voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]EUVD Bot » 🤖 🌐
@EUVD_Bot@mastodon.social

🚨 EUVD-2026-32564

📊 Score: 8.2/10 (CVSS v3.1)
📦 Product: set-get, set-get, rvf (+1 more)
🏢 Vendor: @Rvf, airjp73
📅 Updated: 2026-05-27

📝 RVF (formerly Remix Validated Form) provides easy form validation and state management for React. From 6.0.0 to before 6.0.4 and 7.0.2, setPath in @Rvf/set-get (used by @Rvf/core to flatten incoming form data into a nested objec...

🔗 euvd.enisa.europa.eu/vulnerabi

    [?]EUVD Bot » 🤖 🌐
    @EUVD_Bot@mastodon.social

    🚨 EUVD-2026-32631

    📊 Score: 7.5/10 (CVSS v3.1)
    📦 Product: MapServer
    🏢 Vendor: MapServer
    📅 Updated: 2026-05-27

    📝 MapServer is a system for developing web-based GIS applications. From 6.4.0 to before 8.6.3, msSLDParseUserStyle always calls _SLDApplyRuleValues(psRule, psLayer, 1); for any <Rule> carrying <ElseFilter/> — it assumes msSLDParseRule added one class. When...

    🔗 euvd.enisa.europa.eu/vulnerabi

      [?]EUVD Bot » 🤖 🌐
      @EUVD_Bot@mastodon.social

      🚨 EUVD-2026-32630

      📊 Score: 5.4/10 (CVSS v3.1)
      📦 Product: facturascripts
      🏢 Vendor: neorazorx
      📅 Updated: 2026-05-27

      📝 FacturaScripts is an open source accounting and invoicing software. In 2025.92 and earlier, a stored Cross-Site Scripting (XSS) vulnerability exists in the product search modal of sales (Core/Lib/AjaxForms/SalesModalHTML.php) and purchases documents...

      🔗 euvd.enisa.europa.eu/vulnerabi

        [?]EUVD Bot » 🤖 🌐
        @EUVD_Bot@mastodon.social

        🚨 EUVD-2026-32629

        📊 Score: 5.5/10 (CVSS v3.1)
        📦 Product: Wireshark, Wireshark
        🏢 Vendor: Wireshark Foundation
        📅 Updated: 2026-05-27

        📝 ROHC protocol dissector crash in Wireshark 4.6.0 to 4.6.5 and 4.4.0 to 4.4.15 allows denial of service

        🔗 euvd.enisa.europa.eu/vulnerabi

          [?]EUVD Bot » 🤖 🌐
          @EUVD_Bot@mastodon.social

          🚨 EUVD-2026-32628

          📊 Score: 8.7/10 (CVSS v3.1)
          📦 Product: relate
          🏢 Vendor: inducer
          📅 Updated: 2026-05-27

          📝 RELATE is a web-based courseware package. Prior to commit d66ba5659b459bf1ba56b7109b5f9ecf197cbefb, RELATE LMS configures its Celery workers to accept and deserialize untrusted 'pickle' data. An attacker who can reach the message broker can execute arbitrary ...

          🔗 euvd.enisa.europa.eu/vulnerabi

            [?]EUVD Bot » 🤖 🌐
            @EUVD_Bot@mastodon.social

            🚨 EUVD-2026-32627

            📊 Score: 8.7/10 (CVSS v3.1)
            📦 Product: relate
            🏢 Vendor: inducer
            📅 Updated: 2026-05-27

            📝 RELATE is a web-based courseware package. Versions prior to commit 555f0efb1c5bd7531c07cd73724d7e566a81f620 have a stored cross-site scripting vulnerability that allows any enrolled student to execute arbitrary JavaScript in an administrator's browser session...

            🔗 euvd.enisa.europa.eu/vulnerabi

              [?]TechWire ⚡ » 🤖 🌐
              @techwire@social.gamefan.net

              Meta now lets you pay for the pleasure of using Facebook

              Facebook, Instagram, and WhatsApp are getting new paid subscriptions.

              androidauthority.com/meta-paid

              [Android Authority]

                [?]TechWire ⚡ » 🤖 🌐
                @techwire@social.gamefan.net

                You can print, slice, and engrave using this desktop crafting machine

                Upgrading to more power laser cutting tools expands the types of materials the M2 can engrave. | Image: xTool xTool has announced a new multi-purpose crafting machine that could potentially be one of the most affordable…

                theverge.com/tech/938031/xtool

                [The Verge]

                  [?]DigitalEscapeTools » 🌐
                  @xabd@mastodon.social

                  New BTMOB and Grandoreiro malware campaigns are targeting Android and Windows users with phishing, banking credential theft, and remote access capabilities.

                  Researchers say the operations are expanding across multiple regions and using increasingly stealthy delivery methods.

                  👉 digitalescapetools.com/2026/05

                    [?]urlDNA.io :verified: » 🤖 🌐
                    @urldna@infosec.exchange

                    Possible Phishing 🎣
                    on: ⚠️hxxps[:]//543434565545[.]weebly[.]com
                    🧬 Analysis at: urldna.io/scan/6a1706f93b77500

                      [?]TechWire ⚡ » 🤖 🌐
                      @techwire@social.gamefan.net

                      Valve raises Steam Deck prices by more than $200

                      Valve has significantly increased the price of the Steam Deck - but now, it's also in stock. The 512GB Steam Deck OLED now costs $789, up from $549, while the 1TB model costs $949, up from $649. As I write this, both mo…

                      theverge.com/games/938340/valv

                      [The Verge]

                        [?]CTI.FYI » 🤖 🌐
                        @CTI_FYI@infosec.exchange

                        🚨New ransom group blog post!🚨

                        Group name: chaos
                        Post title: sterlingindustries.com
                        Info: cti.fyi/groups/chaos.html

                          [?]The New Oil » 🤖 🌐
                          @thenewoil@mastodon.thenewoil.org

                          [?]TechWire ⚡ » 🤖 🌐
                          @techwire@social.gamefan.net

                          This new chip could bring Gemini Intelligence to non-flagship Android phones

                          Don't expect big upgrades elsewhere, though.

                          androidauthority.com/mid-range

                          [Android Authority]

                            [?]EUVD Bot » 🤖 🌐
                            @EUVD_Bot@mastodon.social

                            🚨 EUVD-2026-32212

                            📊 Score: 4.2/10 (CVSS v3.1)
                            📅 Updated: 2026-05-27

                            📝 A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured to accept broad redirect Uniform Resource Identifiers (URIs), a remote attacker can manipulate the authentication process by crafting a special web address. If a user cl...

                            🔗 euvd.enisa.europa.eu/vulnerabi

                              [?]urlDNA.io :verified: » 🤖 🌐
                              @urldna@infosec.exchange

                              Possible Phishing 🎣
                              on: ⚠️hxxps[:]//eateli[.]weebly[.]com/
                              🧬 Analysis at: urldna.io/scan/6a16ba613b77500

                                [?]The New Oil » 🤖 🌐
                                @thenewoil@mastodon.thenewoil.org

                                [?]gtbarry » 🌐
                                @gtbarry@mastodon.social

                                7-Eleven data breach affects over 185,000 people’s personal data

                                a data breach at convenience store chain 7-Eleven affects over 185,000 people, including their names, dates of birth, physical addresses, phone numbers and email addresses.

                                The data breach was reported in April.

                                techcrunch.com/2026/05/26/7-el

                                  [?]TechWire ⚡ » 🤖 🌐
                                  @techwire@social.gamefan.net

                                  Roku TV just landed on a portable projector for the first time, and it’s surprisingly cheap

                                  Aurzen's new EAZZE D1R air delivers built-in Roku TV and flexible power support at a budget-friendly price

                                  androidauthority.com/aurzen-ea

                                  [Android Authority]

                                    [?]Daniel Marsh » 🤖 🌐
                                    @danielmarsh@social.thepixelspulse.com

                                    A fundamental parsing issue in Starlette, dubbed BadHost (CVE-2026-48710), enables attackers to bypass authentication by manipulating the HTTP Host header. This vulnerability, with historical parallels, critically impacts AI systems built on FastAPI, vLLM, and LiteLLM, which rely on Starlette. The attack chain is surprisingly simple, making immediate patching (Starlette 1.0.1) and…

                                    tpp.blog/2e83vb7

                                    🤖 This post was AI-generated.

                                      [?]TechWire ⚡ » 🤖 🌐
                                      @techwire@social.gamefan.net

                                      The new Razr Ultra isn’t your average phone — for better and worse

                                      A fine-looking phone. I had one ask for friends, colleagues, the lady checking me in for a meeting at a large software company's headquarters, and everyone else who stopped to admire the phone I've been carrying around.…

                                      theverge.com/tech/937763/motor

                                      [The Verge]

                                        [?]urlDNA.io :verified: » 🤖 🌐
                                        @urldna@infosec.exchange

                                        Possible Phishing 🎣
                                        on: ⚠️hxxps[:]//grenoblealpflll[.]weebly[.]com/
                                        🧬 Analysis at: urldna.io/scan/6a1649e63b77500

                                          [?]The New Oil » 🤖 🌐
                                          @thenewoil@mastodon.thenewoil.org

                                          [?]TechWire ⚡ » 🤖 🌐
                                          @techwire@social.gamefan.net

                                          The AI fight brewing inside The New York Times

                                          Yellow taxis pass in front of The New York Times newspaper building. | Alexandra Schuler/dpa (Photo by Alexandra Schuler/picture alliance via Getty Images) How newsrooms should use AI - or if they should at all - has be…

                                          theverge.com/ai-artificial-int

                                          [The Verge]

                                            [?]EUVD Bot » 🤖 🌐
                                            @EUVD_Bot@mastodon.social

                                            🚨 EUVD-2026-32107

                                            📊 Score: 6.4/10 (CVSS v3.1)
                                            📦 Product: WPBakery Page Builder Addons by Livemesh
                                            🏢 Vendor: livemesh
                                            📅 Updated: 2026-05-27

                                            📝 The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `lvca_admin_ajax` AJAX action in all versions up to, and including, 3.9.4 due to missing authorization ch...

                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                              [?]EUVD Bot » 🤖 🌐
                                              @EUVD_Bot@mastodon.social

                                              🚨 EUVD-2026-32106

                                              📊 Score: 7.2/10 (CVSS v3.1)
                                              📦 Product: Booking Calendar – Event Calendar
                                              🏢 Vendor: omnivo
                                              📅 Updated: 2026-05-27

                                              📝 The HBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hb_country_iso', 'hb_usa_state_iso', and 'hb_canada_province_iso' parameters in all versions up to, and including, 2.1.6 due to insufficient input s...

                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                [?]EUVD Bot » 🤖 🌐
                                                @EUVD_Bot@mastodon.social

                                                🚨 EUVD-2026-32105

                                                📊 Score: 7.2/10 (CVSS v3.1)
                                                📦 Product: affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display
                                                🏢 Vendor: cservit
                                                📅 Updated: 2026-05-27

                                                📝 The affiliate-toolkit plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, 3.8.5. This is due to the plugin using the BladeOne templating engine's runSt...

                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                  [?]EUVD Bot » 🤖 🌐
                                                  @EUVD_Bot@mastodon.social

                                                  🚨 EUVD-2026-32104

                                                  📊 Score: 6.4/10 (CVSS v3.1)
                                                  📦 Product: WPBakery Page Builder Addons by Livemesh
                                                  🏢 Vendor: livemesh
                                                  📅 Updated: 2026-05-27

                                                  📝 The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[lvca_carousel]` and `[lvca_posts_carousel]` shortcode attributes in all versions up to, and including, ...

                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                    [?]EUVD Bot » 🤖 🌐
                                                    @EUVD_Bot@mastodon.social

                                                    🚨 EUVD-2026-32103

                                                    📊 Score: 4.9/10 (CVSS v3.1)
                                                    📦 Product: EnvíaloSimple: Email Marketing y Newsletters
                                                    🏢 Vendor: dattateccom
                                                    📅 Updated: 2026-05-27

                                                    📝 The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'orderby' parameter in all versions up to, and including, 2.4.5 due to insufficient escapin...

                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                      [?]EUVD Bot » 🤖 🌐
                                                      @EUVD_Bot@mastodon.social

                                                      🚨 EUVD-2026-32102

                                                      📊 Score: 6.4/10 (CVSS v3.1)
                                                      📦 Product: Livemesh SiteOrigin Widgets
                                                      🏢 Vendor: livemesh
                                                      📅 Updated: 2026-05-27

                                                      📝 The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `lsow_admin_ajax` AJAX action in all versions up to, and including, 3.9.2 due to missing authorization checks and insufficient inpu...

                                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                                        [?]EUVD Bot » 🤖 🌐
                                                        @EUVD_Bot@mastodon.social

                                                        🚨 EUVD-2026-32101

                                                        📊 Score: 6.4/10 (CVSS v3.1)
                                                        📦 Product: Livemesh Addons for Beaver Builder
                                                        🏢 Vendor: livemesh
                                                        📅 Updated: 2026-05-27

                                                        📝 The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `labb_admin_ajax` AJAX action in all versions up to, and including, 3.9.2 due to missing authorization checks and ins...

                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                          [?]EUVD Bot » 🤖 🌐
                                                          @EUVD_Bot@mastodon.social

                                                          🚨 EUVD-2026-32100

                                                          📊 Score: 8.8/10 (CVSS v3.1)
                                                          📦 Product: WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager
                                                          🏢 Vendor: smub
                                                          📅 Updated: 2026-05-27

                                                          📝 The WPCode - Insert Headers and Footers + Custom Code Snippets - WordPress Code Manager plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.3...

                                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                                            [?]EUVD Bot » 🤖 🌐
                                                            @EUVD_Bot@mastodon.social

                                                            🚨 EUVD-2026-32099

                                                            📊 Score: 6.5/10 (CVSS v3.1)
                                                            📦 Product: Enable jQuery Migrate Helper
                                                            🏢 Vendor: clorith
                                                            📅 Updated: 2026-05-27

                                                            📝 The Enable jQuery Migrate Helper plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `downgrade_jquery_version()` function in all versions up to, and including, 1.4.1. This is ...

                                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                                              [?]EUVD Bot » 🤖 🌐
                                                              @EUVD_Bot@mastodon.social

                                                              🚨 EUVD-2026-32098

                                                              📊 Score: 4.3/10 (CVSS v3.1)
                                                              📦 Product: BOSH Director
                                                              🏢 Vendor: Cloud Foundry Foundation
                                                              📅 Updated: 2026-05-27

                                                              📝 When the director sends a long-running request (e.g. compile_package), the agent's reply JSON is consumed by AgentClient. inject_compile_log (line 332-339) reads response['value']['result']['compile_log_id'] and format_exception (line ...

                                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                                [?]BeyondMachines :verified: » 🤖 🌐
                                                                @beyondmachines1@infosec.exchange

                                                                BadHost Vulnerability in Starlette Framework Threatens AI Infrastructure

                                                                Starlette patched a path-poisoning vulnerability (CVE-2026-48710) that allows attackers to bypass security middleware in AI agents and Python-based servers. The flaw enables unauthorized access to sensitive credentials and internal endpoints by manipulating the HTTP Host header.

                                                                **If you're running applications built on Starlette, FastAPI, or LLM tools like vLLM, LiteLLM, or MCP servers, update Starlette to version 1.0.1 ASAP. While updating, put a reverse proxy (Nginx or Cloudflare) in front of your application to block malformed Host headers, and test your endpoints with the free scanner at BadHost.org.**

                                                                beyondmachines.net/event_detai

                                                                  [?]TechWire ⚡ » 🤖 🌐
                                                                  @techwire@social.gamefan.net

                                                                  I wanted Gemini Daily Brief to be great, but it’s kind of a mess

                                                                  I just want something that works.

                                                                  androidauthority.com/gemini-da

                                                                  [Android Authority]

                                                                    [?]Boerps ☑️ » 🌐
                                                                    @Boerps@nrw.social

                                                                    Hilfe‼️

                                                                    "Die neue „KI-Cloud“ soll nun „zur zentralen Schaltstelle für die öffentliche Verwaltung werden“, erklärt das Digitalministerium."

                                                                    netzpolitik.org/2026/fuer-250-

                                                                    und

                                                                    "KI-Einführung verursacht kritische Cloud-Sicherheitslücken"

                                                                    infopoint-security.de/check-po

                                                                      Back to top - More...