Flux
Couleur d'accent
CVE-2026-47212: Twilio Notifier Webhook Parser Never Verifies the X-Twilio-Signature HMAC: Unauthenticated Webhook Event Injection

CVE-2026-47212: Twilio Notifier Webhook Parser Never Verifies the X-Twilio-Signature HMAC: Unauthenticated Webhook Event Injection

Affected versions Symfony versions >=6.4, =7.0, =8.0, <8.0.12 of the Symfony Twilio Notifier component are affected by this security issue. The issue has been fixed in Symfony 6.4.40, 7.4.12, 8.0.12. Description The…

Symfony Blog
CVE-2026-45754: Mailjet and LOX24 Webhook Parsers Never Verify the Configured Secret: Unauthenticated Event Injection

CVE-2026-45754: Mailjet and LOX24 Webhook Parsers Never Verify the Configured Secret: Unauthenticated Event Injection

Affected versions Symfony versions >=6.4, =7.0, =8.0, <8.0.12 of the Symfony Lox24 Notifier and Symfony Mailjet Mailer components are affected by this security issue. The issue has been fixed in Symfony 6.4.40, 7.4.12,…

Symfony Blog
Gemini 3.5 Flash: more expensive, but Google plan to use it for everything

Gemini 3.5 Flash: more expensive, but Google plan to use it for everything

Today at Google I/O, Google released Gemini 3.5 Flash. This one skipped the -preview modifier and went straight to general availability, and Google appear to be using it for a whole lot of their key products: 3.5 Flash is available today to billions of people globally: For everyone via the Gemini app and AI Mode in Google Search For developers in our agent-first development platform Google Antigravity and Gemini API in Google AI Studio and Android Studio For enterprises in Gemini Enterprise…

Simon Willison's Weblog
Popular Go Decimal Library Targeted by Long-Running Typosquat with DNS Backdoor

Popular Go Decimal Library Targeted by Long-Running Typosquat with DNS Backdoor

Socket's Threat Research Team identified a malicious Go module published as github.com/shopsprint/decimal, a typosquat of the widely used github.com/shopspring/decimal arbitrary precision arithmetic library. The typosquatted module has been present on the Go ecosystem since 2017-11-08 and was weaponized on 2023-08-19 when version v1.3.3 added a malicious init() function that opens a DNS TXT record command and control channel to a threat actor controlled subdomain on a free dynamic DNS provider.…

Socket
AI Artifact Catalogs: Durable Standards Worth Institutional Investment

AI Artifact Catalogs: Durable Standards Worth Institutional Investment

Companies everywhere are trying to leverage AI to boost internal productivity metrics. Some, like Ramp and Intercom, are succeeding. Many are failing. To make matters more complicated, the narrative around what tooling enables these gains is constantly shifting. For software engineers, auto-complete via GitHub Copilot was the bleeding-edge tool of choice in 2024. Then it […]

O'Reilly Radar — AI/ML
Esc