the grugq's newsletter

Subscribe
Archives
November 20, 2025

November 20, 2025

November 20, 2025

https://risky.biz/BTN145/


The https://t.co/OpFfwtJCLm post by @xoreipeip shows how prepared statements can be exploited in NodeJS using mysql and mysql2 packages leading to SQLi! 🪄
So use of prepared statement might not be the ultimate solution here 🥵

as a side note, @xoreipeip later found this…

— Soroush Dalili (@irsdl) November 19, 2025


Breaking News🚨:The Japanese court orders Cloudflare to pay damages

Four major publishing companies—Kodansha, Shueisha, Shogakukan, and KADOKAWA—filed a lawsuit against Cloudflare, claiming that it provided a network service that enabled the large-scale distribution of data to a… pic.twitter.com/15TpLFz51N

— おはよ!まいぶらざー (@OhayoMybrother) November 19, 2025


Here are 30 great essays about biology. I consider these to be my "personal canon," and think that they are all basically perfect in their own ways, despite being different in form and style. All have shaped my own writing considerably.

I'm not including links here, but you can…

— Niko McCarty. (@NikoMcCarty) November 18, 2025


Pixnapping is an Android vulnerability discovered by researchers that allows apps to steal passwords, one-time codes, and other confidential information from the screen without any special permissions from the operating system.https://t.co/H2GrYCEWil pic.twitter.com/cSxBbbM1dv

— blackorbird (@blackorbird) November 19, 2025


https://www.atlanticcouncil.org/in-depth-research-reports/report/building-the-digital-front-line/


https://www.theregister.com/2025/11/19/whatsapp_enumeration_flaw/

Big deal, I’ve known my WhatsApp number for years!


Don't miss what's next. Subscribe to the grugq's newsletter:

Start the conversation:

Be the first to share your thoughts

X