voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]TechWire ⚡ » 🤖 🌐
@techwire@social.gamefan.net

Report: iOS 27 to revamp the AirPods settings UI

While a dedicated ‘AirPods’ app does not seem to be on the cards, AirPods Pro. Bloomberg says iOS 27 will significantly change the layout of the AirPods menu in Settings app. The new design will be ‘more functional, bet…

9to5mac.com/2026/05/24/report-

[9to5Mac]

    [?]urlDNA.io :verified: » 🤖 🌐
    @urldna@infosec.exchange

    Possible Phishing 🎣
    on: ⚠️hxxps[:]//zyyj97[.]webwave[.]dev
    🧬 Analysis at: urldna.io/scan/6a1495ff3b77500

      [?]EUVD Bot » 🤖 🌐
      @EUVD_Bot@mastodon.social

      🚨 EUVD-2026-31726

      📊 Score: 5.3/10 (CVSS v3.1)
      📦 Product: Student Grades Management System
      🏢 Vendor: SourceCodester
      📅 Updated: 2026-05-25

      📝 A security flaw has been discovered in SourceCodester Student Grades Management System 1.0. This affects an unknown part. The manipulation results in cross-site request forgery. The attack can be executed remotely. The exploit...

      🔗 euvd.enisa.europa.eu/vulnerabi

        [?]EUVD Bot » 🤖 🌐
        @EUVD_Bot@mastodon.social

        🚨 EUVD-2026-31727

        📊 Score: 7.2/10 (CVSS v3.1)
        📦 Product: Webmail, Webmail
        🏢 Vendor: Roundcube
        📅 Updated: 2026-05-25

        📝 Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.

        🔗 euvd.enisa.europa.eu/vulnerabi

          [?]EUVD Bot » 🤖 🌐
          @EUVD_Bot@mastodon.social

          🚨 EUVD-2026-31723

          📊 Score: 5.3/10 (CVSS v3.1)
          📦 Product: GamiPress
          🏢 Vendor: Ruben Garcia
          📅 Updated: 2026-05-25

          📝 Missing Authorization vulnerability in Ruben Garcia GamiPress allows Exploiting Incorrectly Configured Access Control Security Levels.

          This issue affects GamiPress: from n/a through 7.6.3.

          🔗 euvd.enisa.europa.eu/vulnerabi

            [?]EUVD Bot » 🤖 🌐
            @EUVD_Bot@mastodon.social

            🚨 EUVD-2026-31724

            📊 Score: 3.7/10 (CVSS v3.1)
            📦 Product: Webmail, Webmail
            🏢 Vendor: Roundcube
            📅 Updated: 2026-05-25

            📝 Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass.

            🔗 euvd.enisa.europa.eu/vulnerabi

              [?]EUVD Bot » 🤖 🌐
              @EUVD_Bot@mastodon.social

              🚨 EUVD-2026-31725

              📊 Score: 6.5/10 (CVSS v3.1)
              📦 Product: Webmail, Webmail
              🏢 Vendor: Roundcube
              📅 Updated: 2026-05-25

              📝 In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information disclosure or access-control bypass.

              🔗 euvd.enisa.europa.eu/vulnerabi

                [?]EUVD Bot » 🤖 🌐
                @EUVD_Bot@mastodon.social

                🚨 EUVD-2026-31720

                📊 Score: 6.5/10 (CVSS v3.1)
                📦 Product: Webmail, Webmail
                🏢 Vendor: Roundcube
                📅 Updated: 2026-05-25

                📝 In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for URLs pointing to local/private destinations, which may lead to information disclosure or privilege escalation via a text/html em...

                🔗 euvd.enisa.europa.eu/vulnerabi

                  [?]EUVD Bot » 🤖 🌐
                  @EUVD_Bot@mastodon.social

                  🚨 EUVD-2026-31721

                  📊 Score: 5.1/10 (CVSS v3.1)
                  📦 Product: Student Grades Management System
                  🏢 Vendor: SourceCodester
                  📅 Updated: 2026-05-25

                  📝 A vulnerability was identified in SourceCodester Student Grades Management System 1.0. Affected by this issue is some unknown functionality of the file students.php. The manipulation of the argument Remarks leads to cross site...

                  🔗 euvd.enisa.europa.eu/vulnerabi

                    [?]EUVD Bot » 🤖 🌐
                    @EUVD_Bot@mastodon.social

                    🚨 EUVD-2026-31717

                    📊 Score: 7.5/10 (CVSS v3.1)
                    📦 Product: Webmail, Webmail
                    🏢 Vendor: Roundcube
                    📅 Updated: 2026-05-25

                    📝 Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16 and 1.7.1.)

                    🔗 euvd.enisa.europa.eu/vulnerabi

                      [?]EUVD Bot » 🤖 🌐
                      @EUVD_Bot@mastodon.social

                      🚨 EUVD-2026-31718

                      📊 Score: 7.2/10 (CVSS v3.1)
                      📦 Product: Webmail, Webmail
                      🏢 Vendor: Roundcube
                      📅 Updated: 2026-05-25

                      📝 Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local networ...

                      🔗 euvd.enisa.europa.eu/vulnerabi

                        [?]EUVD Bot » 🤖 🌐
                        @EUVD_Bot@mastodon.social

                        🚨 EUVD-2026-31719

                        📊 Score: 8.1/10 (CVSS v3.1)
                        📦 Product: Webmail, Webmail
                        🏢 Vendor: Roundcube
                        📅 Updated: 2026-05-25

                        📝 Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.

                        🔗 euvd.enisa.europa.eu/vulnerabi

                          [?]EUVD Bot » 🤖 🌐
                          @EUVD_Bot@mastodon.social

                          🚨 EUVD-2026-31722

                          📊 Score: 5.3/10 (CVSS v3.1)
                          📦 Product: Student Grades Management System
                          🏢 Vendor: SourceCodester
                          📅 Updated: 2026-05-25

                          📝 A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected by this vulnerability is the function getClassroomStudents/removeStudentFromClassroom of the file classroom.php. Executing a manip...

                          🔗 euvd.enisa.europa.eu/vulnerabi

                            [?]TechWire ⚡ » 🤖 🌐
                            @techwire@social.gamefan.net

                            iOS 27 could offer native integration with Google Cast and other streaming protocols

                            In response to the European Union’s Digital Markets Act (DMA), Apple is reportedly working on the ability to replace AirPlay with other third-party streaming protocols at a system level. This feature may only roll out i…

                            9to5mac.com/2026/05/24/ios-27-

                            [9to5Mac]

                              [?]TechWire ⚡ » 🤖 🌐
                              @techwire@social.gamefan.net

                              Apple Intelligence image models to boast ‘major’ visual upgrades in iOS 27: report

                              According to this weekend’s Power On newsletter, Apple’s image generation models – used in Genmoji and Image Playground – will be receiving a ‘big boost’ in visual quality. Currently, they’re far from anything to write …

                              9to5mac.com/2026/05/24/apple-i

                              [9to5Mac]

                                [?]urlDNA.io :verified: » 🤖 🌐
                                @urldna@infosec.exchange

                                Possible Phishing 🎣
                                on: ⚠️hxxps[:]//netflix-clone-psi-cyan[.]vercel[.]app
                                🧬 Analysis at: urldna.io/scan/6a1487e33b77500

                                  [?]deafnews » 🤖 🌐
                                  @deafnews@infosec.exchange

                                  Researcher Chaotic Eclipse has disclosed three Windows zero-day vulnerabilities following May 2026 Patch Tuesday. Only one of six flaws in this cycle is patched. deafnews.it/en/article/windows

                                    [?]TechWire ⚡ » 🤖 🌐
                                    @techwire@social.gamefan.net

                                    Ferrari reveals its first EV, with design help from Jony Ive

                                    The Ferrari Luce will start at €550,000 in Italy, but US pricing hasn’t been announced. | Image: Ferrari After months of teasers, Ferrari is offering the first full view of its Luce electric vehicle. The Luce is notable…

                                    theverge.com/transportation/93

                                    [The Verge]

                                      [?]gtbarry » 🌐
                                      @gtbarry@mastodon.social

                                      Law enforcement shuts down VPN service used by two dozen ransomware gangs

                                      An international coalition of law enforcement agencies took down First VPN, a popular virtual private network service used by cybercriminals, and arrested its administrator

                                      techcrunch.com/2026/05/21/law-

                                        [?]EUVD Bot » 🤖 🌐
                                        @EUVD_Bot@mastodon.social

                                        🚨 EUVD-2026-31700

                                        📊 Score: 6.9/10 (CVSS v3.1)
                                        📦 Product: StudentManagementSystem
                                        🏢 Vendor: yashpokharna2555
                                        📅 Updated: 2026-05-25

                                        📝 A security vulnerability has been detected in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. This affects the function confirm_logged_in of the file student_trans.php. Such manipulation of the argu...

                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                          [?]BeyondMachines :verified: » 🤖 🌐
                                          @beyondmachines1@infosec.exchange

                                          State of (in)security - Week 21, 2026

                                          During the week of May 18–25, 2026, there were 18 advisories and 23 incidents impacting over 2 million individuals. Healthcare is the hardest-hit industry and the Matferline breach (703,000 student records) is the largest incident. Key threats are actively exploited vulnerabilities in NGINX, Drupal, Microsoft Defender, and ASUS routers, alongs supply chain attacks on Laravel-Lang and NPM packages, and ransomware incidents affecting schools, hospitality, and financial firms.

                                          **Patch Chrome/Chromium browsers immediately (two critical flaws plus others affecting Edge, Opera, Brave, Vivaldi) and audit any builds using @antv, echarts-for-react, or Laravel-Lang Composer packages from May 19–22, 2026 onward, since these supply-chain compromises may have already stolen CI/CD credentials. Also prioritize patching NGINX, Drupal, and Trend Micro Apex One — all actively exploited and commonly found in public-facing platform stacks.**

                                          beyondmachines.net/event_detai

                                            [?]EUVD Bot » 🤖 🌐
                                            @EUVD_Bot@mastodon.social

                                            🚨 EUVD-2026-31701

                                            📊 Score: 6.9/10 (CVSS v3.1)
                                            📦 Product: StudentManagementSystem
                                            🏢 Vendor: yashpokharna2555
                                            📅 Updated: 2026-05-25

                                            📝 A weakness has been identified in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. The impacted element is an unknown function of the file /success.php. This manipulation of the argument User causes ...

                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                              [?]TechWire ⚡ » 🤖 🌐
                                              @techwire@social.gamefan.net

                                              We never travel without these useful gadgets - here's why

                                              Traveling soon? Scoop up these nifty gadgets ahead of summer travels - and some are on sale for Memorial Day.

                                              zdnet.com/article/travel-gadge

                                              [ZDNet]

                                                [?]TechWire ⚡ » 🤖 🌐
                                                @techwire@social.gamefan.net

                                                6 pet deals you don't want to miss this Memorial Day weekend, including robot litter boxes

                                                I have two cats. These are the pet tech products I own and recommend or plan to buy while these Memorial Day deals last.

                                                zdnet.com/article/pet-deals-me

                                                [ZDNet]

                                                  [?]N_{Dario Fadda} » 🌐
                                                  @nuke@poliversity.it

                                                  Operazione Saffron: smantellata First VPN, il servizio criminale usato da 25 gang ransomware

                                                  insicurezzadigitale.com/operaz

                                                    [?]N_{Dario Fadda} » 🌐
                                                    @nuke@poliversity.it

                                                    Laravel-Lang compromessa: oltre 700 versioni PHP infettate da uno stealer cross-platform

                                                    insicurezzadigitale.com/larave

                                                      [?]Alex Jimenez » 🌐
                                                      @AlexJimenez@mas.to

                                                      Anthropic's Claude Mythos found 10,000 critical vulnerabilities in one month. The patches can't keep up.

                                                      thenextweb.com/news/anthropic-

                                                        [?]urlDNA.io :verified: » 🤖 🌐
                                                        @urldna@infosec.exchange

                                                        Possible Phishing 🎣
                                                        on: ⚠️hxxps[:]//bit[.]ly/3M599ox
                                                        🧬 Analysis at: urldna.io/scan/6a07f39a3b77500

                                                          [?]CyberNetsecIO » 🌐
                                                          @netsecio@mastodon.social

                                                          📰 NIST Drafts New Guidance for Ransomware Response and Recovery in Manufacturing Sector

                                                          🏭 NIST has released draft guidance (SP 1800-41) to help the manufacturing sector improve ransomware response and recover operational technology (OT) networks.

                                                          🌐 cyber[.]netsecops[.]io

                                                          🔗 cyber.netsecops.io/articles/ni

                                                            [?]CyberNetsecIO » 🌐
                                                            @netsecio@mastodon.social

                                                            📰 Taiwan Government Agencies Reported 726 Cybersecurity Incidents in Past Year

                                                            🇹🇼 Taiwan's government reports 726 cybersecurity incidents last year. Unauthorized intrusion was the top attack type (68.6%). Key threats identified include supply chain risk and 'bring-your-own-driver' attacks. ...

                                                            🌐 cyber[.]netsecops[.]io

                                                            🔗 cyber.netsecops.io/articles/ta

                                                              [?]CyberNetsecIO » 🌐
                                                              @netsecio@mastodon.social

                                                              📰 Ransomware Evolves in 2026: Attackers Adopt Post-Quantum Crypto and Encryptionless Extortion

                                                              Ransomware in 2026 is evolving. 📈 A new Kaspersky report reveals attackers are using Post-Quantum Crypto, shifting to data leak extortion, and deploying 'EDR killers' to bypass defenses.

                                                              🌐 cyber[.]netsecops[.]io

                                                              🔗 cyber.netsecops.io/articles/ra

                                                                [?]CyberNetsecIO » 🌐
                                                                @netsecio@mastodon.social

                                                                📰 Critical Unauthenticated SQLi Flaw in Drupal Core Hits PostgreSQL Sites

                                                                🚨 CRITICAL vulnerability in Drupal Core (CVE-2026-9082)! Unauthenticated SQL injection affects sites using PostgreSQL, allowing for potential RCE. Patch immediately!

                                                                🌐 cyber[.]netsecops[.]io

                                                                🔗 cyber.netsecops.io/articles/cr

                                                                  [?]TechWire ⚡ » 🤖 🌐
                                                                  @techwire@social.gamefan.net

                                                                  The top 10 Memorial Day deals our readers keep buying (No. 3 is tiny yet functional)

                                                                  Memorial Day weekend is wrapping up soon, but these are the deals our readers can't get enough of.

                                                                  zdnet.com/article/memorial-day

                                                                  [ZDNet]

                                                                    [?]EUVD Bot » 🤖 🌐
                                                                    @EUVD_Bot@mastodon.social

                                                                    🚨 EUVD-2026-31668

                                                                    📊 Score: 6.9/10 (CVSS v3.1)
                                                                    📦 Product: miniclawd
                                                                    🏢 Vendor: FoundDream
                                                                    📅 Updated: 2026-05-25

                                                                    📝 A security vulnerability has been detected in FoundDream miniclawd up to 2d65665046e2222eeea76cafc8570ed546a8c125. Affected by this issue is the function ExecTool.execute of the file /src/tools/exec.ts. Such manipulation leads to os command injection. T...

                                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                                      [?]EUVD Bot » 🤖 🌐
                                                                      @EUVD_Bot@mastodon.social

                                                                      🚨 EUVD-2026-31666

                                                                      📊 Score: 5.3/10 (CVSS v3.1)
                                                                      📦 Product: Employee Management System
                                                                      🏢 Vendor: code-projects
                                                                      📅 Updated: 2026-05-25

                                                                      📝 A weakness has been identified in code-projects Employee Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /process/applyleaveprocess.php. This manipulation of the argument ID causes sql in...

                                                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                                                        [?]EUVD Bot » 🤖 🌐
                                                                        @EUVD_Bot@mastodon.social

                                                                        🚨 EUVD-2026-31669

                                                                        📊 Score: n/a
                                                                        📦 Product: Apache Airflow Fab Provider
                                                                        🏢 Vendor: Apache Software Foundation
                                                                        📅 Updated: 2026-05-25

                                                                        📝 Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or lat...

                                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                                          [?]gtbarry » 🌐
                                                                          @gtbarry@mastodon.social

                                                                          Bluesky Says Kremlin Is Hacking Its Platform to Spread Propaganda

                                                                          Russian propaganda on Bluesky first became notable during Germany’s elections last year, when the Kremlin sought to bolster Germany’s far right, led by the Alternative for Germany party, known as AfD.

                                                                          nytimes.com/2026/05/21/busines

                                                                            [?]EUVD Bot » 🤖 🌐
                                                                            @EUVD_Bot@mastodon.social

                                                                            🚨 EUVD-2026-31667

                                                                            📊 Score: 5.3/10 (CVSS v3.1)
                                                                            📦 Product: Employee Management System
                                                                            🏢 Vendor: code-projects
                                                                            📅 Updated: 2026-05-25

                                                                            📝 A security flaw has been discovered in code-projects Employee Management System 1.0. Affected is an unknown function of the file /psubmit.php. The manipulation of the argument pid results in sql injection. It is possible to launch th...

                                                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                                                              [?]EUVD Bot » 🤖 🌐
                                                                              @EUVD_Bot@mastodon.social

                                                                              🚨 EUVD-2026-31662

                                                                              📊 Score: 5.3/10 (CVSS v3.1)
                                                                              📦 Product: Lifetime
                                                                              🏢 Vendor: OutSystems
                                                                              📅 Updated: 2026-05-25

                                                                              📝 OutSystems Lifetime is vulnerable to Authorization Bypass Through User-Controlled Key vulnerability in ApplicationID parameter. Any authenticated user, can read the Change Log containing actions performed by other users as well as application name of any...

                                                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                [?]EUVD Bot » 🤖 🌐
                                                                                @EUVD_Bot@mastodon.social

                                                                                🚨 EUVD-2026-31665

                                                                                📊 Score: 5.3/10 (CVSS v3.1)
                                                                                📦 Product: Employee Management System
                                                                                🏢 Vendor: code-projects
                                                                                📅 Updated: 2026-05-25

                                                                                📝 A vulnerability was identified in code-projects Employee Management System 1.0. This impacts an unknown function of the file /changepassemp.php. The manipulation leads to sql injection. It is possible to initiate the attack remotely....

                                                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                  Back to top - More...