voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]EUVD Bot » 🤖 🌐
@EUVD_Bot@mastodon.social

🚨 EUVD-2026-45276

📊 Score: 9.9/10 (CVSS v3.1)
📦 Product: Langflow OSS
🏢 Vendor: IBM
📅 Updated: 2026-07-17

📝 IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's unsafe pickle.loads() function to deserialize cached objects from disk without validatio...

🔗 euvd.enisa.europa.eu/vulnerabi

    [?]EUVD Bot » 🤖 🌐
    @EUVD_Bot@mastodon.social

    🚨 EUVD-2026-45274

    📊 Score: 8.7/10 (CVSS v3.1)
    📦 Product: pimcore, pimcore
    🏢 Vendor: pimcore
    📅 Updated: 2026-07-17

    📝 Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, the columnConfigAction endpoint in bundles/CustomReportsBundle/src/Controller/Reports/CustomReportController.php passes malicious SQL configuration t...

    🔗 euvd.enisa.europa.eu/vulnerabi

      [?]EUVD Bot » 🤖 🌐
      @EUVD_Bot@mastodon.social

      🚨 EUVD-2026-45273

      📊 Score: 8.1/10 (CVSS v3.1)
      📦 Product: pimcore, pimcore
      🏢 Vendor: pimcore
      📅 Updated: 2026-07-17

      📝 Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, Pimcore's WebDAV asset endpoint exposes a MOVE operation through /asset/webdav{path} without an authentication plugin in bundles/CoreBundle/src/Contr...

      🔗 euvd.enisa.europa.eu/vulnerabi

        [?]EUVD Bot » 🤖 🌐
        @EUVD_Bot@mastodon.social

        🚨 EUVD-2026-45272

        📊 Score: 9.8/10 (CVSS v3.1)
        📦 Product: Langflow OSS
        🏢 Vendor: IBM
        📅 Updated: 2026-07-17

        📝 IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypasses API key validation when the WEBHOOK_AUTH_ENABLE configura...

        🔗 euvd.enisa.europa.eu/vulnerabi

          [?]EUVD Bot » 🤖 🌐
          @EUVD_Bot@mastodon.social

          🚨 EUVD-2026-45270

          📊 Score: 9.9/10 (CVSS v3.1)
          📦 Product: Langflow OSS
          🏢 Vendor: IBM
          📅 Updated: 2026-07-17

          📝 IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve full system compromise with Langflow service permissions.

          🔗 euvd.enisa.europa.eu/vulnerabi

            [?]EUVD Bot » 🤖 🌐
            @EUVD_Bot@mastodon.social

            🚨 EUVD-2026-45269

            📊 Score: 9.9/10 (CVSS v3.1)
            📦 Product: Langflow OSS
            🏢 Vendor: IBM
            📅 Updated: 2026-07-17

            📝 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validation in the APIRequest component. A path traversal vulnerability exists when the "Save to File" feature is en...

            🔗 euvd.enisa.europa.eu/vulnerabi

              [?]EUVD Bot » 🤖 🌐
              @EUVD_Bot@mastodon.social

              🚨 EUVD-2026-45268

              📊 Score: 5.3/10 (CVSS v3.1)
              📦 Product: Verify Identity Access Container, Security Verify Access, Verify Identity Access (+1 more)
              🏢 Vendor: IBM
              📅 Updated: 2026-07-17

              📝 IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.  This information could be us...

              🔗 euvd.enisa.europa.eu/vulnerabi

                [?]urlDNA.io :verified: » 🤖 🌐
                @urldna@infosec.exchange

                Possible Phishing 🎣
                on: ⚠️hxxps[:]//profeco-gob-mx[.]weebly[.]com
                🧬 Analysis at: urldna.io/scan/6a59e12c3b77500

                  [?]/G|T|R|O|N|I|X\ :python: :emacs: :nix: :linux: » 🌐
                  @gtronix@infosec.exchange

                  [?]Miguel Afonso Caetano » 🌐
                  @remixtures@tldr.nettime.org

                  “U.S. prosecutors have accused a Florida man of uploading fake video games that contained malware to Steam, the popular PC games platform. Once victims downloaded and installed the games, the malware was designed to infect their computers, steal their passwords and other data, and drain their crypto wallets, according to a criminal complaint.

                  On Tuesday, the FBI arrested Zyaire Wilkins, a 21-year-old Florida resident and student. On Wednesday, prosecutors accused him and a number of unnamed co-conspirators of hacking crimes. Over the past two years, Wilkins and his partners allegedly published several malware-laden video games on Steam, including BlockBlasters, Dashverse, Lampy, Lunara, and PirateFi. Using that malware, says the FBI, Wilkins and his accomplices infected around 8,000 victims, and then hacked around 80 cryptocurrency wallets to steal at least $220,000 worth of crypto.

                  Wilkins and the others marketed their malicious video games on Discord, LinkedIn, and Telegram, according to the authorities.”

                  techcrunch.com/2026/07/17/fbi-

                    [?]ChiefGyk3D » 🌐
                    @chiefgyk3d@social.chiefgyk3d.com

                    Ever wonder how AI impacts security? 🤯 This short dives into Google's AI use, NASA's security protocols, and the scary reality of ransomware – plus how to protect your data. Check it out!

                    youtube.com/watch?v=91iDsX0Cejs

                    🔴 LIVE

                    Alt...🔴 LIVE

                      [?]TechWire ⚡ » 🤖 🌐
                      @techwire@social.gamefan.net

                      Got money to burn? Check out this Messi-themed Galaxy Z Fold 8 Ultra

                      Only 19 people will own this Messi-themed Galaxy Z Fold 8 Ultra.

                      androidauthority.com/messi-the

                      [Android Authority]

                        [?]Daniel Marsh » 🤖 🌐
                        @danielmarsh@social.thepixelspulse.com

                        A new OpenSSL vulnerability, dubbed 'HollowByte' by Okta's Red Team, allows an 11-byte payload to cause severe server memory exhaustion and heap fragmentation. Despite its significant impact on critical services like NGINX and Apache, OpenSSL controversially classified it as a "bug or hardening" fix, declining to issue a CVE. This decision complicates security efforts, as vulnerable systems may not be…

                        tpp.blog/1l4e57i

                        🤖 This post was AI-generated.

                          [?]Hugo | DevOps | Cybersecurity » 🌐
                          @hugovalters@mastodon.social

                          [?]TechWire ⚡ » 🤖 🌐
                          @techwire@social.gamefan.net

                          Florida man arrested for allegedly stealing over $200,000 in crypto using Steam game malware

                          A final hearing will take place in June. | The Verge / Beatrice Sala Federal authorities have arrested a Florida man suspected of stealing at least $220,000 in crypto through malware-infected Steam games, as reported ea…

                          theverge.com/games/967174/stea

                          [The Verge]

                            [?]TechWire ⚡ » 🤖 🌐
                            @techwire@social.gamefan.net

                            Galaxy Unpacked is just days away, but this latest massive leak won’t wait

                            Take a drink from the fire hose with these non-stop Samsung foldable leaks.

                            androidauthority.com/samsung-f

                            [Android Authority]

                              [?]EUVD Bot » 🤖 🌐
                              @EUVD_Bot@mastodon.social

                              🚨 EUVD-2026-45200

                              📊 Score: n/a
                              📦 Product: Events Booking extension for Joomla
                              🏢 Vendor: joomdonation.com
                              📅 Updated: 2026-07-17

                              📝 The Joomla extension Events Booking is vulnerable to an unauthenticated user enumeration that allows to retrieve account usernames and email addresses.

                              🔗 euvd.enisa.europa.eu/vulnerabi

                                [?]EUVD Bot » 🤖 🌐
                                @EUVD_Bot@mastodon.social

                                🚨 EUVD-2026-45199

                                📊 Score: 7.1/10 (CVSS v3.1)
                                📦 Product: maybe
                                🏢 Vendor: maybe-finance
                                📅 Updated: 2026-07-17

                                📝 Maybe through 0.6.0 contains a missing authorization vulnerability that allows authenticated low-privilege member-role users to access and modify global hosting settings by exploiting unprotected show and update actions in the Settings::HostingsControlle...

                                🔗 euvd.enisa.europa.eu/vulnerabi

                                  [?]urlDNA.io :verified: » 🤖 🌐
                                  @urldna@infosec.exchange

                                  Possible Phishing 🎣
                                  on: ⚠️hxxps[:]//onetimefstip[.]weebly[.]com
                                  🧬 Analysis at: urldna.io/scan/6a59c51c3b77500

                                    [?]EUVD Bot » 🤖 🌐
                                    @EUVD_Bot@mastodon.social

                                    🚨 EUVD-2026-45198

                                    📊 Score: n/a
                                    📦 Product: Events Booking extension for Joomla
                                    🏢 Vendor: joomdonation.com
                                    📅 Updated: 2026-07-17

                                    📝 The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection.

                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                      [?]EUVD Bot » 🤖 🌐
                                      @EUVD_Bot@mastodon.social

                                      🚨 EUVD-2026-45197

                                      📊 Score: 7.1/10 (CVSS v3.1)
                                      📦 Product: TheHive
                                      🏢 Vendor: TheHive-Project
                                      📅 Updated: 2026-07-17

                                      📝 TheHive through 4.1.24 contains a broken object-level authorization vulnerability in the attachment download endpoints that allows any authenticated user to access attachments belonging to other organizations by supplying a content-hash identifier. A...

                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                        [?]EUVD Bot » 🤖 🌐
                                        @EUVD_Bot@mastodon.social

                                        🚨 EUVD-2026-45196

                                        📊 Score: 6.9/10 (CVSS v3.1)
                                        📦 Product: TheHive
                                        🏢 Vendor: TheHive-Project
                                        📅 Updated: 2026-07-17

                                        📝 TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by sending a GET request to the /api/status endpoint, which lacks authentication en...

                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                          [?]EUVD Bot » 🤖 🌐
                                          @EUVD_Bot@mastodon.social

                                          🚨 EUVD-2026-45195

                                          📊 Score: 5.3/10 (CVSS v3.1)
                                          📦 Product: dendrite
                                          🏢 Vendor: matrix-org
                                          📅 Updated: 2026-07-17

                                          📝 Dendrite through 0.13.8 contains an improper access control vulnerability in the syncapi /context endpoint (syncapi/routing/context.go) that allows authenticated local users to access post-leave room state events by exploiting a flawed membership check t...

                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                            [?]EUVD Bot » 🤖 🌐
                                            @EUVD_Bot@mastodon.social

                                            🚨 EUVD-2026-45194

                                            📊 Score: 6.9/10 (CVSS v3.1)
                                            📦 Product: dendrite
                                            🏢 Vendor: matrix-org
                                            📅 Updated: 2026-07-17

                                            📝 Dendrite through 0.13.8 contains a server-side request forgery vulnerability that allows unauthenticated attackers to cause the server to open outbound TLS connections to arbitrary hosts and ports by supplying an unvalidated serverName parameter to the l...

                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                              [?]EUVD Bot » 🤖 🌐
                                              @EUVD_Bot@mastodon.social

                                              🚨 EUVD-2026-45193

                                              📊 Score: n/a
                                              📦 Product: Mojo::JWT
                                              🏢 Vendor: JBERGER
                                              📅 Updated: 2026-07-17

                                              📝 Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison.

                                              The decode() method compares the supplied signature to the recomputed HMAC with Perl's eq operator, which stops at the first differing byte, so the comparison time...

                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                [?]EUVD Bot » 🤖 🌐
                                                @EUVD_Bot@mastodon.social

                                                🚨 EUVD-2026-45187

                                                📊 Score: 8.5/10 (CVSS v3.1)
                                                📦 Product: Firebase Studio
                                                🏢 Vendor: Google Cloud
                                                📅 Updated: 2026-07-17

                                                📝 Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an attacker to download other users' deployed source code and access sensitive data via unauthorized GCS URL signing requests.

                                                T...

                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                  [?]EUVD Bot » 🤖 🌐
                                                  @EUVD_Bot@mastodon.social

                                                  🚨 EUVD-2026-45186

                                                  📊 Score: 7.1/10 (CVSS v3.1)
                                                  📦 Product: osTicket, osTicket
                                                  🏢 Vendor: osticket
                                                  📅 Updated: 2026-07-17

                                                  📝 osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leading to Insecure Direct Object Reference (IDOR) in the AJAX ticket-management subsystem.

                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                    [?]EUVD Bot » 🤖 🌐
                                                    @EUVD_Bot@mastodon.social

                                                    🚨 EUVD-2026-45192

                                                    📊 Score: 7.1/10 (CVSS v3.1)
                                                    📦 Product: dendrite
                                                    🏢 Vendor: matrix-org
                                                    📅 Updated: 2026-07-17

                                                    📝 Dendrite through 0.13.8 contains an improper authorization vulnerability in the Matrix Client-Server API that allows any authenticated local user to delete third-party identifier bindings belonging to other users by submitting an arbitrary address and me...

                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                      [?]EUVD Bot » 🤖 🌐
                                                      @EUVD_Bot@mastodon.social

                                                      🚨 EUVD-2026-45191

                                                      📊 Score: 5.3/10 (CVSS v3.1)
                                                      📦 Product: Enterprise Server, Enterprise Server, Enterprise Server (+2 more)
                                                      🏢 Vendor: GitHub
                                                      📅 Updated: 2026-07-17

                                                      📝 A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with write access to any repository to read metadata from private repositories they d...

                                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                                        [?]The New Oil » 🤖 🌐
                                                        @thenewoil@mastodon.thenewoil.org

                                                        [?]EUVD Bot » 🤖 🌐
                                                        @EUVD_Bot@mastodon.social

                                                        🚨 EUVD-2026-45190

                                                        📊 Score: n/a
                                                        📦 Product: HTTP::Date
                                                        🏢 Vendor: OALDERS
                                                        📅 Updated: 2026-07-17

                                                        📝 HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date.

                                                        parse_date() matches the date string against a chain of alternative regexes, and str2time() delegates to it. Several of these patterns place unbounded quantif...

                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                          [?]EUVD Bot » 🤖 🌐
                                                          @EUVD_Bot@mastodon.social

                                                          🚨 EUVD-2026-45189

                                                          📊 Score: 8.6/10 (CVSS v3.1)
                                                          📦 Product: Enterprise Server, Enterprise Server, Enterprise Server (+2 more)
                                                          🏢 Vendor: GitHub
                                                          📅 Updated: 2026-07-17

                                                          📝 A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updater container to write files to arbitrary repository ...

                                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                                            [?]EUVD Bot » 🤖 🌐
                                                            @EUVD_Bot@mastodon.social

                                                            🚨 EUVD-2026-45188

                                                            📊 Score: 5.7/10 (CVSS v3.1)
                                                            📦 Product: Enterprise Server, Enterprise Server, Enterprise Server (+2 more)
                                                            🏢 Vendor: GitHub
                                                            📅 Updated: 2026-07-17

                                                            📝 A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to cause service disruption by supplying a repository release notes configuration file co...

                                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                                              [?]BeyondMachines :verified: » 🤖 🌐
                                                              @beyondmachines1@infosec.exchange

                                                              All About Women’s Care Data Breach Affects Approximately 12,000 Individuals

                                                              All About Women’s Care disclosed a data breach affecting 12,000 individuals after an unauthorized actor accessed its network and acquired files containing personal and health information. The attacker shared sample files as part of an extortion communication, and the practice implemented additional security measures and established a dedicated call center to assist affected individuals.

                                                              ****

                                                              beyondmachines.net/event_detai

                                                                [?]Hugo | DevOps | Cybersecurity » 🌐
                                                                @hugovalters@mastodon.social

                                                                CVE-2026-59117 - Integer overflow in Wraparound Windows Terminal enables network-based RCE. CVSS 7.5. No patch available. Monitor systems and restrict network access.

                                                                valtersit.com/cve/CVE-2026-591

                                                                  [?]TechWire ⚡ » 🤖 🌐
                                                                  @techwire@social.gamefan.net

                                                                  Sony Xperia 10 VIII reveals new details in FCC filing

                                                                  Sony's Xperia 10 VIII feels closer than ever after stop by FCC.

                                                                  androidauthority.com/sony-xper

                                                                  [Android Authority]

                                                                    [?]OTX Bot » 🤖 🌐
                                                                    @techbot@social.raytec.co

                                                                    ACR Stealer: Two observed intrusion chains amid increased threat activity

                                                                    Between late April and mid-June 2026, Microsoft observed heightened ACR Stealer activity targeting enterprise environments through ClickFix social engineering lures. This information-stealing malware, associated with Amatera Stealer rebranding and offered as malware-as-a-service, deployed through two distinct campaigns. The first utilized WebDAV-delivered payloads with Python loaders and blockchain-based command-and-control resolution. The second employed a fileless approach using MSHTA and steganography-concealed payloads within images. Both campaigns harvested browser credentials, authentication tokens, and sensitive documents from compromised systems. Threat actors leveraged obfuscated PowerShell scripts, scheduled task persistence, and in-memory execution techniques to evade detection. Notable tactics included masquerading as legitimate software updates, utilizing Windows DPAPI for credential decryption, and targeting PDF and Microsoft 365 documents. The blockchain dead-drop technique enabled dynamic i...

                                                                    Pulse ID: 6a59832ac2ebd9e525a462b9
                                                                    Pulse Link: otx.alienvault.com/pulse/6a598
                                                                    Pulse Author: AlienVault
                                                                    Created: 2026-07-17 01:19:38

                                                                    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                                                                      [?]TierraSapiens » 🤖 🌐
                                                                      @tierrasapiens@mastodon.social


                                                                      🟣 El Modo IA de Google enfrenta críticas por sus respuestas a niños y adolescentes
                                                                      🔗 es.wired.com/articulos/el-modo

                                                                      Las funciones de IA de Google Search podrían generar más problemas de aprendizaje y agravar las crisis emocionales de los jóvenes que usan el buscador como medio de

                                                                        [?]Malicious Extension Bot » 🤖 🌐
                                                                        @malicious_browser_bot@infosec.exchange

                                                                        extension Void Wallet seems malicious. Its badness score is 93/100!

                                                                        ```json
                                                                        {"id": "jcagmaielnbegpjigikgkoofaljmnaal", "score": 93, "platform": "chrome", "name": "Void Wallet"}
                                                                        ```

                                                                          [?]Steve Loughran » 🌐
                                                                          @stevel@hachyderm.io

                                                                          Just read the ACM paper "Why AI slop matters", which argues that AI slop has cultural value even if its denigrated the way Kitsch was in the 1930s by the proponents of the avant garde. They don't argue that it is good, rather that the consumers want it.

                                                                          Which may be true for videos of family members, but not for OSS projects getting AI slop CVE reports or pull requests. Only the authors want them.
                                                                          dl.acm.org/doi/10.1145/3786777

                                                                            [?]EUVD Bot » 🤖 🌐
                                                                            @EUVD_Bot@mastodon.social

                                                                            🚨 EUVD-2026-45164

                                                                            📊 Score: 5.5/10 (CVSS v3.1)
                                                                            📅 Updated: 2026-07-17

                                                                            📝 A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The issue occurs when a delegated administrator updates an OIDC identity provider using a masked client secret sentinel value. Due to improper validation, Keycloak reuses the existi...

                                                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                                                              [?]EUVD Bot » 🤖 🌐
                                                                              @EUVD_Bot@mastodon.social

                                                                              🚨 EUVD-2026-45163

                                                                              📊 Score: 6.9/10 (CVSS v3.1)
                                                                              📦 Product: CIPster
                                                                              🏢 Vendor: liftoff-sr
                                                                              📅 Updated: 2026-07-17

                                                                              📝 A vulnerability has been found in liftoff-sr CIPster up to 632336d414ef708a542377c1aa8d6fdb7c70a760. Affected by this issue is the function CipAppPath::deserialize_symbolic of the file source/src/cip/cipepath.cc. Such manipulation leads to out-of-bounds r...

                                                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                [?]EUVD Bot » 🤖 🌐
                                                                                @EUVD_Bot@mastodon.social

                                                                                🚨 EUVD-2026-45162

                                                                                📊 Score: 5.3/10 (CVSS v3.1)
                                                                                📦 Product: Hospital Management System
                                                                                🏢 Vendor: itsourcecode
                                                                                📅 Updated: 2026-07-17

                                                                                📝 A vulnerability was detected in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /prescriptionorderdetail.php. The manipulation of the argument delid results in sql injection. The attack can be ...

                                                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                  Back to top - More...