Android expands pilot for in-call scam protection for financial apps
http://security.googleblog.com/2025/12/android-expands-pilot-in-call-scam-protection-financial-apps.html
http://security.googleblog.com/2025/12/android-expands-pilot-in-call-scam-protection-financial-apps.html
Google Online Security Blog
Android expands pilot for in-call scam protection for financial apps
Posted by Aden Haussmann, Associate Product Manager and Sumeet Sharma, Play Partnerships Trust & Safety Lead Android uses the best of Goo...
❤3
Prompt Injection Inside GitHub Actions: The New Frontier of Supply Chain Attacks
https://www.aikido.dev/blog/promptpwnd-github-actions-ai-agents
https://www.aikido.dev/blog/promptpwnd-github-actions-ai-agents
www.aikido.dev
Prompt Injection Inside GitHub Actions: The New Frontier of Supply Chain Attacks
AI-driven GitHub Actions expose new prompt-injection supply chain vulnerabilities.
❤6
Release v3.6.0 · projectdiscovery/nuclei
https://github.com/projectdiscovery/nuclei/releases/tag/v3.6.0
https://github.com/projectdiscovery/nuclei/releases/tag/v3.6.0
GitHub
Release v3.6.0 · projectdiscovery/nuclei
What's Changed
✨ New Features
Write resume file specified by flag by @circleous (#6616)
Javascript Multi-Port Support by @pussycat0x (#6501)
Direct fuzzing using target URL for OpenAPI/Swagger...
✨ New Features
Write resume file specified by flag by @circleous (#6616)
Javascript Multi-Port Support by @pussycat0x (#6501)
Direct fuzzing using target URL for OpenAPI/Swagger...
❤1
Introducing audit logs in SonarQube Cloud: Enhancing compliance and security
https://www.sonarsource.com/blog/introducing-audit-logs-in-sonarqube-cloud-enhancing-compliance-and-security/
https://www.sonarsource.com/blog/introducing-audit-logs-in-sonarqube-cloud-enhancing-compliance-and-security/
Sonarsource
Introducing audit logs in SonarQube Cloud: Enhancing compliance and security
Enhance compliance and security with the new audit logs for SonarQube Cloud Enterprise plan. Get a chronological record of key IAM events, accessible via API to integrate with your SIEM tools.
❤3
When AI Turns on Its Team: Exploiting Agent-to-Agent Discovery via Prompt Injection
https://appomni.com/ao-labs/ai-agent-to-agent-discovery-prompt-injection/
https://appomni.com/ao-labs/ai-agent-to-agent-discovery-prompt-injection/
AppOmni
When AI Turns on Its Team: Exploiting Agent-to-Agent Discovery via Prompt Injection
See how prompt injection attacks work in ServiceNow to perform unauthorized actions, and how to defend against it with AppOmni AgentGuard.
❤1
How to detect React2Shell with Burp Suite
https://portswigger.net/blog/how-to-detect-react2shell-with-burp-suite
https://portswigger.net/blog/how-to-detect-react2shell-with-burp-suite
❤8👎2
SonarQube Compare Community vs Developer vs Enterprise vs Data Center
https://www.sonarsource.com/blog/sonarqube-compare-editions/
https://www.sonarsource.com/blog/sonarqube-compare-editions/
Sonarsource
SonarQube Compare Community vs Developer vs Enterprise vs Data Center
SonarQube has emerged as a leading automated code review platform that empowers development teams to achieve a high level of code quality and code security.
❤3
PyTorch tensors, neural networks and Autograd: an introduction
https://www.sonarsource.com/blog/pytorch-tensors-neural-networks-and-autograd/
https://www.sonarsource.com/blog/pytorch-tensors-neural-networks-and-autograd/
Sonarsource
PyTorch tensors, neural networks and Autograd: an introduction
This guide is designed to demystify PyTorch's core components, providing you with a solid understanding of how it empowers the creation and training of sophisticated machine learning models.
❤3
CVE-2025-55182 and CVE-2025-66478 ("React2Shell") - All you need to know
https://jfrog.com/blog/2025-55182-and-2025-66478-react2shell-all-you-need-to-know/
https://jfrog.com/blog/2025-55182-and-2025-66478-react2shell-all-you-need-to-know/
JFrog
CVE-2025-55182 and CVE-2025-66478 ("React2Shell"): All you need to know - UPDATED
Updated and latest information regarding the critical React RCE vulnerability (React2Shell CVE-2025-55182) . Learn how to detect and protect with JFrog.
❤2
New Prompt Injection Attack Vectors Through MCP Sampling
https://unit42.paloaltonetworks.com/model-context-protocol-attack-vectors/
https://unit42.paloaltonetworks.com/model-context-protocol-attack-vectors/
Unit 42
New Prompt Injection Attack Vectors Through MCP Sampling
Model Context Protocol connects LLM apps to external data sources or tools. We examine its security implications through various attack vectors.
❤2👍1
Architecting Security for Agentic Capabilities in Chrome
http://security.googleblog.com/2025/12/architecting-security-for-agentic.html
http://security.googleblog.com/2025/12/architecting-security-for-agentic.html
Google Online Security Blog
Architecting Security for Agentic Capabilities in Chrome
Posted by Nathan Parker, Chrome security team Chrome has been advancing the web’s security for well over 15 years, and we’re committed to...
❤3👍1
HTTPS certificate industry phasing out less secure domain validation methods
http://security.googleblog.com/2025/12/https-certificate-industry-phasing-out.html
http://security.googleblog.com/2025/12/https-certificate-industry-phasing-out.html
Google Online Security Blog
HTTPS certificate industry phasing out less secure domain validation methods
Posted by Chrome Root Program Team Secure connections are the backbone of the modern web, but a certificate is only as trustworthy as the...
❤2
Privilege Escalation Vulnerability in Soledad Theme Affecting 50k+ Sites - Patchstack
https://patchstack.com/articles/privilege-escalation-vulnerability-in-soledad-theme-affecting-50k-sites/
https://patchstack.com/articles/privilege-escalation-vulnerability-in-soledad-theme-affecting-50k-sites/
Patchstack
Privilege Escalation Vulnerability in Soledad Theme Affecting 50k+ Sites - Patchstack
A privilege escalation flaw in the Soledad theme allowed Subscribers to change site settings and gain admin access. Learn how it works and why updating to 8.6.9.1 is essential.
❤4
.NET SOAPwn Flaw Opens Door for File Writes and Remote Code Execution via Rogue WSDL
https://thehackernews.com/2025/12/net-soapwn-flaw-opens-door-for-file.html?m=1
https://thehackernews.com/2025/12/net-soapwn-flaw-opens-door-for-file.html?m=1
❤2
SOAPwn: Pwning .NET Framework Applications Through HTTP Client Proxies And WSDL
https://labs.watchtowr.com/soapwn-pwning-net-framework-applications-through-http-client-proxies-and-wsdl/
https://labs.watchtowr.com/soapwn-pwning-net-framework-applications-through-http-client-proxies-and-wsdl/
watchTowr Labs
SOAPwn: Pwning .NET Framework Applications Through HTTP Client Proxies And WSDL
Welcome back! As we near the end of 2025, we are, of course, waiting for the next round of SSLVPN exploitation to occur in January (as it did in 2024 and 2025).
Weeeeeeeee. Before then, we want to clear the decks and see how much research we can publish.…
Weeeeeeeee. Before then, we want to clear the decks and see how much research we can publish.…
❤6
Introducing mrva, a terminal-first approach to CodeQL multi-repo variant analysis
https://blog.trailofbits.com/2025/12/11/introducing-mrva-a-terminal-first-approach-to-codeql-multi-repo-variant-analysis/
https://blog.trailofbits.com/2025/12/11/introducing-mrva-a-terminal-first-approach-to-codeql-multi-repo-variant-analysis/
The Trail of Bits Blog
Introducing mrva, a terminal-first approach to CodeQL multi-repo variant analysis
Our new tool mrva is a terminal-first tool for running CodeQL multi-repository variant analysis locally,allowing users to download pre-built databases, analyze them with custom queries, and view results directly in the terminal.
❤4
CVE-2025-55182: New Detection Profiles for Burp Bounty Pro
https://bountysecurity.ai/blogs/news/cve-2025-55182-react2shell-new-detection-profiles-for-burp-bounty-pro
https://bountysecurity.ai/blogs/news/cve-2025-55182-react2shell-new-detection-profiles-for-burp-bounty-pro
Bounty Security
CVE-2025-55182: New Detection Profiles for Burp Bounty Pro
CVE-2025-55182 (React2Shell): New Detection Profiles for Burp Bounty Pro
🔴 CVSS 10.0 Critical
CVE-2025-55182 (React2Shell):New Detection Profiles for Burp Bounty Pro
📅 December 11…
🔴 CVSS 10.0 Critical
CVE-2025-55182 (React2Shell):New Detection Profiles for Burp Bounty Pro
📅 December 11…
❤4