voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
Report: iOS 27 to revamp the AirPods settings UI
While a dedicated ‘AirPods’ app does not seem to be on the cards, AirPods Pro. Bloomberg says iOS 27 will significantly change the layout of the AirPods menu in Settings app. The new design will be ‘more functional, bet…
https://9to5mac.com/2026/05/24/report-ios-27-to-revamp-the-airpods-settings-ui/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
Possible Phishing 🎣
on: ⚠️hxxps[:]//zyyj97[.]webwave[.]dev
🧬 Analysis at: https://urldna.io/scan/6a1495ff3b7750000472f4f9
#cybersecurity #phishing #infosec #urldna #scam #infosec
🚨 EUVD-2026-31726
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Student Grades Management System
🏢 Vendor: SourceCodester
📅 Updated: 2026-05-25
📝 A security flaw has been discovered in SourceCodester Student Grades Management System 1.0. This affects an unknown part. The manipulation results in cross-site request forgery. The attack can be executed remotely. The exploit...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31726
🚨 EUVD-2026-31727
📊 Score: 7.2/10 (CVSS v3.1)
📦 Product: Webmail, Webmail
🏢 Vendor: Roundcube
📅 Updated: 2026-05-25
📝 Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31727
🚨 EUVD-2026-31723
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: GamiPress
🏢 Vendor: Ruben Garcia
📅 Updated: 2026-05-25
📝 Missing Authorization vulnerability in Ruben Garcia GamiPress allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects GamiPress: from n/a through 7.6.3.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31723
🚨 EUVD-2026-31724
📊 Score: 3.7/10 (CVSS v3.1)
📦 Product: Webmail, Webmail
🏢 Vendor: Roundcube
📅 Updated: 2026-05-25
📝 Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31724
🚨 EUVD-2026-31725
📊 Score: 6.5/10 (CVSS v3.1)
📦 Product: Webmail, Webmail
🏢 Vendor: Roundcube
📅 Updated: 2026-05-25
📝 In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information disclosure or access-control bypass.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31725
🚨 EUVD-2026-31720
📊 Score: 6.5/10 (CVSS v3.1)
📦 Product: Webmail, Webmail
🏢 Vendor: Roundcube
📅 Updated: 2026-05-25
📝 In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for URLs pointing to local/private destinations, which may lead to information disclosure or privilege escalation via a text/html em...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31720
🚨 EUVD-2026-31721
📊 Score: 5.1/10 (CVSS v3.1)
📦 Product: Student Grades Management System
🏢 Vendor: SourceCodester
📅 Updated: 2026-05-25
📝 A vulnerability was identified in SourceCodester Student Grades Management System 1.0. Affected by this issue is some unknown functionality of the file students.php. The manipulation of the argument Remarks leads to cross site...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31721
🚨 EUVD-2026-31717
📊 Score: 7.5/10 (CVSS v3.1)
📦 Product: Webmail, Webmail
🏢 Vendor: Roundcube
📅 Updated: 2026-05-25
📝 Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16 and 1.7.1.)
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31717
🚨 EUVD-2026-31718
📊 Score: 7.2/10 (CVSS v3.1)
📦 Product: Webmail, Webmail
🏢 Vendor: Roundcube
📅 Updated: 2026-05-25
📝 Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local networ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31718
🚨 EUVD-2026-31719
📊 Score: 8.1/10 (CVSS v3.1)
📦 Product: Webmail, Webmail
🏢 Vendor: Roundcube
📅 Updated: 2026-05-25
📝 Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31719
🚨 EUVD-2026-31722
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Student Grades Management System
🏢 Vendor: SourceCodester
📅 Updated: 2026-05-25
📝 A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected by this vulnerability is the function getClassroomStudents/removeStudentFromClassroom of the file classroom.php. Executing a manip...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31722
iOS 27 could offer native integration with Google Cast and other streaming protocols
In response to the European Union’s Digital Markets Act (DMA), Apple is reportedly working on the ability to replace AirPlay with other third-party streaming protocols at a system level. This feature may only roll out i…
https://9to5mac.com/2026/05/24/ios-27-google-cast-third-party-streaming-integration-eu/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
Apple Intelligence image models to boast ‘major’ visual upgrades in iOS 27: report
According to this weekend’s Power On newsletter, Apple’s image generation models – used in Genmoji and Image Playground – will be receiving a ‘big boost’ in visual quality. Currently, they’re far from anything to write …
https://9to5mac.com/2026/05/24/apple-image-playground-and-gemoji-to-get-major-visual-improvements/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #9to5Mac [9to5Mac]
Possible Phishing 🎣
on: ⚠️hxxps[:]//netflix-clone-psi-cyan[.]vercel[.]app
🧬 Analysis at: https://urldna.io/scan/6a1487e33b7750000472f326
#cybersecurity #phishing #infosec #urldna #scam #infosec
Researcher Chaotic Eclipse has disclosed three Windows zero-day vulnerabilities following May 2026 Patch Tuesday. Only one of six flaws in this cycle is patched. https://deafnews.it/en/article/windows-hit-by-post-patch-tuesday-zero-day-blitz #Cybersecurity
Ferrari reveals its first EV, with design help from Jony Ive
The Ferrari Luce will start at €550,000 in Italy, but US pricing hasn’t been announced. | Image: Ferrari After months of teasers, Ferrari is offering the first full view of its Luce electric vehicle. The Luce is notable…
https://www.theverge.com/transportation/937066/ferrari-luce-ev-jony-ive-marc-newson-lovefrom
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TheVerge [The Verge]
Law enforcement shuts down VPN service used by two dozen ransomware gangs
An international coalition of law enforcement agencies took down First VPN, a popular virtual private network service used by cybercriminals, and arrested its administrator
🚨 EUVD-2026-31700
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: StudentManagementSystem
🏢 Vendor: yashpokharna2555
📅 Updated: 2026-05-25
📝 A security vulnerability has been detected in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. This affects the function confirm_logged_in of the file student_trans.php. Such manipulation of the argu...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31700
State of (in)security - Week 21, 2026
During the week of May 18–25, 2026, there were 18 advisories and 23 incidents impacting over 2 million individuals. Healthcare is the hardest-hit industry and the Matferline breach (703,000 student records) is the largest incident. Key threats are actively exploited vulnerabilities in NGINX, Drupal, Microsoft Defender, and ASUS routers, alongs supply chain attacks on Laravel-Lang and NPM packages, and ransomware incidents affecting schools, hospitality, and financial firms.
**Patch Chrome/Chromium browsers immediately (two critical flaws plus others affecting Edge, Opera, Brave, Vivaldi) and audit any builds using @antv, echarts-for-react, or Laravel-Lang Composer packages from May 19–22, 2026 onward, since these supply-chain compromises may have already stolen CI/CD credentials. Also prioritize patching NGINX, Drupal, and Trend Micro Apex One — all actively exploited and commonly found in public-facing platform stacks.**
#cybersecurity #infosec #knowledge #weeklyreport
https://beyondmachines.net/event_details/state-of-in-security-week-21-2026-v-u-h-z-g/gD2P6Ple2L
🚨 EUVD-2026-31701
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: StudentManagementSystem
🏢 Vendor: yashpokharna2555
📅 Updated: 2026-05-25
📝 A weakness has been identified in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. The impacted element is an unknown function of the file /success.php. This manipulation of the argument User causes ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31701
We never travel without these useful gadgets - here's why
Traveling soon? Scoop up these nifty gadgets ahead of summer travels - and some are on sale for Memorial Day.
https://www.zdnet.com/article/travel-gadgets-guide-memorial-day-2026/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
6 pet deals you don't want to miss this Memorial Day weekend, including robot litter boxes
I have two cats. These are the pet tech products I own and recommend or plan to buy while these Memorial Day deals last.
https://www.zdnet.com/article/pet-deals-memorial-day-2026/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
Operazione Saffron: smantellata First VPN, il servizio criminale usato da 25 gang ransomware
#CyberSecurity
https://insicurezzadigitale.com/operazione-saffron-smantellata-first-vpn-il-servizio-criminale-usato-da-25-gang-ransomware/
Laravel-Lang compromessa: oltre 700 versioni PHP infettate da uno stealer cross-platform
#CyberSecurity
https://insicurezzadigitale.com/laravel-lang-compromessa-oltre-700-versioni-php-infettate-da-uno-stealer-cross-platform/
Anthropic's Claude Mythos found 10,000 critical vulnerabilities in one month. The patches can't keep up.
https://thenextweb.com/news/anthropic-glasswing-claude-mythos-10000-vulnerabilities
Possible Phishing 🎣
on: ⚠️hxxps[:]//bit[.]ly/3M599ox
🧬 Analysis at: https://urldna.io/scan/6a07f39a3b77500002605661
#cybersecurity #phishing #infosec #urldna #scam #infosec
📰 NIST Drafts New Guidance for Ransomware Response and Recovery in Manufacturing Sector
🏭 NIST has released draft guidance (SP 1800-41) to help the manufacturing sector improve ransomware response and recover operational technology (OT) networks. #NIST #Ransomware #Manufacturing #ICS #Cybersecurity
🌐 cyber[.]netsecops[.]io
📰 Taiwan Government Agencies Reported 726 Cybersecurity Incidents in Past Year
🇹🇼 Taiwan's government reports 726 cybersecurity incidents last year. Unauthorized intrusion was the top attack type (68.6%). Key threats identified include supply chain risk and 'bring-your-own-driver' attacks. #Taiwan #CyberSecurity #Govt #Threat...
🌐 cyber[.]netsecops[.]io
📰 Ransomware Evolves in 2026: Attackers Adopt Post-Quantum Crypto and Encryptionless Extortion
Ransomware in 2026 is evolving. 📈 A new Kaspersky report reveals attackers are using Post-Quantum Crypto, shifting to data leak extortion, and deploying 'EDR killers' to bypass defenses. #Ransomware #CyberSecurity #PQC #DataBreach
🌐 cyber[.]netsecops[.]io
📰 Critical Unauthenticated SQLi Flaw in Drupal Core Hits PostgreSQL Sites
🚨 CRITICAL vulnerability in Drupal Core (CVE-2026-9082)! Unauthenticated SQL injection affects sites using PostgreSQL, allowing for potential RCE. Patch immediately! #Drupal #CyberSecurity #SQLi #Vulnerability
🌐 cyber[.]netsecops[.]io
The top 10 Memorial Day deals our readers keep buying (No. 3 is tiny yet functional)
Memorial Day weekend is wrapping up soon, but these are the deals our readers can't get enough of.
https://www.zdnet.com/article/memorial-day-2026-top-sellers/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
🚨 EUVD-2026-31668
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: miniclawd
🏢 Vendor: FoundDream
📅 Updated: 2026-05-25
📝 A security vulnerability has been detected in FoundDream miniclawd up to 2d65665046e2222eeea76cafc8570ed546a8c125. Affected by this issue is the function ExecTool.execute of the file /src/tools/exec.ts. Such manipulation leads to os command injection. T...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31668
🚨 EUVD-2026-31666
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Employee Management System
🏢 Vendor: code-projects
📅 Updated: 2026-05-25
📝 A weakness has been identified in code-projects Employee Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /process/applyleaveprocess.php. This manipulation of the argument ID causes sql in...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31666
🚨 EUVD-2026-31669
📊 Score: n/a
📦 Product: Apache Airflow Fab Provider
🏢 Vendor: Apache Software Foundation
📅 Updated: 2026-05-25
📝 Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or lat...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31669
Bluesky Says Kremlin Is Hacking Its Platform to Spread Propaganda
Russian propaganda on Bluesky first became notable during Germany’s elections last year, when the Kremlin sought to bolster Germany’s far right, led by the Alternative for Germany party, known as AfD.
#bluesky #socialmedia #russia #propaganda #security #cybersecurity #hackers #hacking
https://www.nytimes.com/2026/05/21/business/bluesky-russia-hacking-accounts.html
🚨 EUVD-2026-31667
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Employee Management System
🏢 Vendor: code-projects
📅 Updated: 2026-05-25
📝 A security flaw has been discovered in code-projects Employee Management System 1.0. Affected is an unknown function of the file /psubmit.php. The manipulation of the argument pid results in sql injection. It is possible to launch th...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31667
🚨 EUVD-2026-31662
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Lifetime
🏢 Vendor: OutSystems
📅 Updated: 2026-05-25
📝 OutSystems Lifetime is vulnerable to Authorization Bypass Through User-Controlled Key vulnerability in ApplicationID parameter. Any authenticated user, can read the Change Log containing actions performed by other users as well as application name of any...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31662
🚨 EUVD-2026-31665
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Employee Management System
🏢 Vendor: code-projects
📅 Updated: 2026-05-25
📝 A vulnerability was identified in code-projects Employee Management System 1.0. This impacts an unknown function of the file /changepassemp.php. The manipulation leads to sql injection. It is possible to initiate the attack remotely....
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31665