voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
🚨 EUVD-2026-45276
📊 Score: 9.9/10 (CVSS v3.1)
📦 Product: Langflow OSS
🏢 Vendor: IBM
📅 Updated: 2026-07-17
📝 IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's unsafe pickle.loads() function to deserialize cached objects from disk without validatio...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45276
🚨 EUVD-2026-45274
📊 Score: 8.7/10 (CVSS v3.1)
📦 Product: pimcore, pimcore
🏢 Vendor: pimcore
📅 Updated: 2026-07-17
📝 Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, the columnConfigAction endpoint in bundles/CustomReportsBundle/src/Controller/Reports/CustomReportController.php passes malicious SQL configuration t...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45274
🚨 EUVD-2026-45273
📊 Score: 8.1/10 (CVSS v3.1)
📦 Product: pimcore, pimcore
🏢 Vendor: pimcore
📅 Updated: 2026-07-17
📝 Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, Pimcore's WebDAV asset endpoint exposes a MOVE operation through /asset/webdav{path} without an authentication plugin in bundles/CoreBundle/src/Contr...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45273
🚨 EUVD-2026-45272
📊 Score: 9.8/10 (CVSS v3.1)
📦 Product: Langflow OSS
🏢 Vendor: IBM
📅 Updated: 2026-07-17
📝 IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypasses API key validation when the WEBHOOK_AUTH_ENABLE configura...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45272
🚨 EUVD-2026-45270
📊 Score: 9.9/10 (CVSS v3.1)
📦 Product: Langflow OSS
🏢 Vendor: IBM
📅 Updated: 2026-07-17
📝 IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve full system compromise with Langflow service permissions.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45270
🚨 EUVD-2026-45269
📊 Score: 9.9/10 (CVSS v3.1)
📦 Product: Langflow OSS
🏢 Vendor: IBM
📅 Updated: 2026-07-17
📝 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validation in the APIRequest component. A path traversal vulnerability exists when the "Save to File" feature is en...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45269
🚨 EUVD-2026-45268
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Verify Identity Access Container, Security Verify Access, Verify Identity Access (+1 more)
🏢 Vendor: IBM
📅 Updated: 2026-07-17
📝 IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be us...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45268
Possible Phishing 🎣
on: ⚠️hxxps[:]//profeco-gob-mx[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a59e12c3b775000045d37d5
#cybersecurity #phishing #infosec #urldna #scam #infosec
“U.S. prosecutors have accused a Florida man of uploading fake video games that contained malware to Steam, the popular PC games platform. Once victims downloaded and installed the games, the malware was designed to infect their computers, steal their passwords and other data, and drain their crypto wallets, according to a criminal complaint.
On Tuesday, the FBI arrested Zyaire Wilkins, a 21-year-old Florida resident and student. On Wednesday, prosecutors accused him and a number of unnamed co-conspirators of hacking crimes. Over the past two years, Wilkins and his partners allegedly published several malware-laden video games on Steam, including BlockBlasters, Dashverse, Lampy, Lunara, and PirateFi. Using that malware, says the FBI, Wilkins and his accomplices infected around 8,000 victims, and then hacked around 80 cryptocurrency wallets to steal at least $220,000 worth of crypto.
Wilkins and the others marketed their malicious video games on Discord, LinkedIn, and Telegram, according to the authorities.”
Ever wonder how AI impacts security? 🤯 This short dives into Google's AI use, NASA's security protocols, and the scary reality of ransomware – plus how to protect your data. Check it out! #Ransomware #Cybersecurity #DataProtection
Got money to burn? Check out this Messi-themed Galaxy Z Fold 8 Ultra
Only 19 people will own this Messi-themed Galaxy Z Fold 8 Ultra.
https://www.androidauthority.com/messi-themed-galaxy-z-fold-8-ultra-3688966/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
A new OpenSSL vulnerability, dubbed 'HollowByte' by Okta's Red Team, allows an 11-byte payload to cause severe server memory exhaustion and heap fragmentation. Despite its significant impact on critical services like NGINX and Apache, OpenSSL controversially classified it as a "bug or hardening" fix, declining to issue a CVE. This decision complicates security efforts, as vulnerable systems may not be…
🤖 This post was AI-generated.
And still we only provide 100% accurate and tested data https://www.valtersit.com/methodology/ #hackers #cybersecurity #infosec #devops #devsecops #linux #ubuntu #git #github #gitlab #developer #developers #DevelopmentProjects #redteam #blueteam #cybersecuritynews #cybersecuritytips
Florida man arrested for allegedly stealing over $200,000 in crypto using Steam game malware
A final hearing will take place in June. | The Verge / Beatrice Sala Federal authorities have arrested a Florida man suspected of stealing at least $220,000 in crypto through malware-infected Steam games, as reported ea…
https://www.theverge.com/games/967174/steam-game-malware-cryptostealer-arrest
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Galaxy Unpacked is just days away, but this latest massive leak won’t wait
Take a drink from the fire hose with these non-stop Samsung foldable leaks.
https://www.androidauthority.com/samsung-foldables-leak-3688825/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
🚨 EUVD-2026-45200
📊 Score: n/a
📦 Product: Events Booking extension for Joomla
🏢 Vendor: joomdonation.com
📅 Updated: 2026-07-17
📝 The Joomla extension Events Booking is vulnerable to an unauthenticated user enumeration that allows to retrieve account usernames and email addresses.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45200
🚨 EUVD-2026-45199
📊 Score: 7.1/10 (CVSS v3.1)
📦 Product: maybe
🏢 Vendor: maybe-finance
📅 Updated: 2026-07-17
📝 Maybe through 0.6.0 contains a missing authorization vulnerability that allows authenticated low-privilege member-role users to access and modify global hosting settings by exploiting unprotected show and update actions in the Settings::HostingsControlle...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45199
Possible Phishing 🎣
on: ⚠️hxxps[:]//onetimefstip[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a59c51c3b775000045d34e7
#cybersecurity #phishing #infosec #urldna #scam #infosec
🚨 EUVD-2026-45198
📊 Score: n/a
📦 Product: Events Booking extension for Joomla
🏢 Vendor: joomdonation.com
📅 Updated: 2026-07-17
📝 The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45198
🚨 EUVD-2026-45197
📊 Score: 7.1/10 (CVSS v3.1)
📦 Product: TheHive
🏢 Vendor: TheHive-Project
📅 Updated: 2026-07-17
📝 TheHive through 4.1.24 contains a broken object-level authorization vulnerability in the attachment download endpoints that allows any authenticated user to access attachments belonging to other organizations by supplying a content-hash identifier. A...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45197
🚨 EUVD-2026-45196
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: TheHive
🏢 Vendor: TheHive-Project
📅 Updated: 2026-07-17
📝 TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by sending a GET request to the /api/status endpoint, which lacks authentication en...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45196
🚨 EUVD-2026-45195
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: dendrite
🏢 Vendor: matrix-org
📅 Updated: 2026-07-17
📝 Dendrite through 0.13.8 contains an improper access control vulnerability in the syncapi /context endpoint (syncapi/routing/context.go) that allows authenticated local users to access post-leave room state events by exploiting a flawed membership check t...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45195
🚨 EUVD-2026-45194
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: dendrite
🏢 Vendor: matrix-org
📅 Updated: 2026-07-17
📝 Dendrite through 0.13.8 contains a server-side request forgery vulnerability that allows unauthenticated attackers to cause the server to open outbound TLS connections to arbitrary hosts and ports by supplying an unvalidated serverName parameter to the l...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45194
🚨 EUVD-2026-45193
📊 Score: n/a
📦 Product: Mojo::JWT
🏢 Vendor: JBERGER
📅 Updated: 2026-07-17
📝 Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison.
The decode() method compares the supplied signature to the recomputed HMAC with Perl's eq operator, which stops at the first differing byte, so the comparison time...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45193
🚨 EUVD-2026-45187
📊 Score: 8.5/10 (CVSS v3.1)
📦 Product: Firebase Studio
🏢 Vendor: Google Cloud
📅 Updated: 2026-07-17
📝 Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an attacker to download other users' deployed source code and access sensitive data via unauthorized GCS URL signing requests.
T...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45187
🚨 EUVD-2026-45186
📊 Score: 7.1/10 (CVSS v3.1)
📦 Product: osTicket, osTicket
🏢 Vendor: osticket
📅 Updated: 2026-07-17
📝 osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leading to Insecure Direct Object Reference (IDOR) in the AJAX ticket-management subsystem.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45186
🚨 EUVD-2026-45192
📊 Score: 7.1/10 (CVSS v3.1)
📦 Product: dendrite
🏢 Vendor: matrix-org
📅 Updated: 2026-07-17
📝 Dendrite through 0.13.8 contains an improper authorization vulnerability in the Matrix Client-Server API that allows any authenticated local user to delete third-party identifier bindings belonging to other users by submitting an arbitrary address and me...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45192
🚨 EUVD-2026-45191
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Enterprise Server, Enterprise Server, Enterprise Server (+2 more)
🏢 Vendor: GitHub
📅 Updated: 2026-07-17
📝 A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with write access to any repository to read metadata from private repositories they d...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45191
🚨 EUVD-2026-45190
📊 Score: n/a
📦 Product: HTTP::Date
🏢 Vendor: OALDERS
📅 Updated: 2026-07-17
📝 HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date.
parse_date() matches the date string against a chain of alternative regexes, and str2time() delegates to it. Several of these patterns place unbounded quantif...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45190
🚨 EUVD-2026-45189
📊 Score: 8.6/10 (CVSS v3.1)
📦 Product: Enterprise Server, Enterprise Server, Enterprise Server (+2 more)
🏢 Vendor: GitHub
📅 Updated: 2026-07-17
📝 A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updater container to write files to arbitrary repository ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45189
🚨 EUVD-2026-45188
📊 Score: 5.7/10 (CVSS v3.1)
📦 Product: Enterprise Server, Enterprise Server, Enterprise Server (+2 more)
🏢 Vendor: GitHub
📅 Updated: 2026-07-17
📝 A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to cause service disruption by supplying a repository release notes configuration file co...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45188
All About Women’s Care Data Breach Affects Approximately 12,000 Individuals
All About Women’s Care disclosed a data breach affecting 12,000 individuals after an unauthorized actor accessed its network and acquired files containing personal and health information. The attacker shared sample files as part of an extortion communication, and the practice implemented additional security measures and established a dedicated call center to assist affected individuals.
****
#cybersecurity #infosec #incident #databreach
https://beyondmachines.net/event_details/all-about-womens-care-data-breach-affects-approximately-12000-individuals-6-q-g-6-o/gD2P6Ple2L
CVE-2026-59117 - Integer overflow in Wraparound Windows Terminal enables network-based RCE. CVSS 7.5. No patch available. Monitor systems and restrict network access. #CVE #infosec #cybersecurity
Sony Xperia 10 VIII reveals new details in FCC filing
Sony's Xperia 10 VIII feels closer than ever after stop by FCC.
https://www.androidauthority.com/sony-xperia-10-viii-fcc-filing-3688858/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
ACR Stealer: Two observed intrusion chains amid increased threat activity
Between late April and mid-June 2026, Microsoft observed heightened ACR Stealer activity targeting enterprise environments through ClickFix social engineering lures. This information-stealing malware, associated with Amatera Stealer rebranding and offered as malware-as-a-service, deployed through two distinct campaigns. The first utilized WebDAV-delivered payloads with Python loaders and blockchain-based command-and-control resolution. The second employed a fileless approach using MSHTA and steganography-concealed payloads within images. Both campaigns harvested browser credentials, authentication tokens, and sensitive documents from compromised systems. Threat actors leveraged obfuscated PowerShell scripts, scheduled task persistence, and in-memory execution techniques to evade detection. Notable tactics included masquerading as legitimate software updates, utilizing Windows DPAPI for credential decryption, and targeting PDF and Microsoft 365 documents. The blockchain dead-drop technique enabled dynamic i...
Pulse ID: 6a59832ac2ebd9e525a462b9
Pulse Link: https://otx.alienvault.com/pulse/6a59832ac2ebd9e525a462b9
Pulse Author: AlienVault
Created: 2026-07-17 01:19:38
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Browser #CyberSecurity #ICS #InfoSec #Malware #MalwareAsAService #Microsoft #OTX #OpenThreatExchange #PDF #PowerShell #Python #SocialEngineering #Steganography #Windows #bot #AlienVault
☕ #Cybersecurity #Ciberseguridad #Ciberseguranca #Security #Seguridad #Seguranca #News #Noticia #Noticias #Tecnologia #Technology
🟣 El Modo IA de Google enfrenta críticas por sus respuestas a niños y adolescentes
🔗 https://es.wired.com/articulos/el-modo-ia-de-google-enfrenta-criticas-por-sus-respuestas-a-ninos-y-adolescentes
Las funciones de IA de Google Search podrían generar más problemas de aprendizaje y agravar las crisis emocionales de los jóvenes que usan el buscador como medio de
#chrome extension Void Wallet seems malicious. Its #cybersecurity badness score is 93/100!
```json
{"id": "jcagmaielnbegpjigikgkoofaljmnaal", "score": 93, "platform": "chrome", "name": "Void Wallet"}
```
Just read the ACM paper "Why AI slop matters", which argues that AI slop has cultural value even if its denigrated the way Kitsch was in the 1930s by the proponents of the avant garde. They don't argue that it is good, rather that the consumers want it.
Which may be true for videos of family members, but not for OSS projects getting AI slop CVE reports or pull requests. Only the authors want them.
https://dl.acm.org/doi/10.1145/3786777
#ai #foss #cybersecurity
🚨 EUVD-2026-45164
📊 Score: 5.5/10 (CVSS v3.1)
📅 Updated: 2026-07-17
📝 A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The issue occurs when a delegated administrator updates an OIDC identity provider using a masked client secret sentinel value. Due to improper validation, Keycloak reuses the existi...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45164
🚨 EUVD-2026-45163
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: CIPster
🏢 Vendor: liftoff-sr
📅 Updated: 2026-07-17
📝 A vulnerability has been found in liftoff-sr CIPster up to 632336d414ef708a542377c1aa8d6fdb7c70a760. Affected by this issue is the function CipAppPath::deserialize_symbolic of the file source/src/cip/cipepath.cc. Such manipulation leads to out-of-bounds r...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45163
🚨 EUVD-2026-45162
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Hospital Management System
🏢 Vendor: itsourcecode
📅 Updated: 2026-07-17
📝 A vulnerability was detected in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /prescriptionorderdetail.php. The manipulation of the argument delid results in sql injection. The attack can be ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45162