🚨 Researchers found an indirect prompt injection flaw abusing Google Gemini via calendar invites.
A hidden prompt in an event could trigger Gemini, when asked about a schedule, to summarize private meetings into a new calendar entry—visible to attackers in some enterprise setups.
No user action required.
🔗 Read → https://t.co/3N9NcQGOdU
🚨 BREAKING: NYSE announces new tokenization platform.
Here's what they're building:
A completely new trading venue with:
• 24/7 operations (no market hours)
• Instant settlement (not T+1)
• Stablecoin-based funding (not bank wires)
• "Tokens natively issued as digital securities"
Not retrofitting the existing exchange.
Not adding blockchain to the back office.
An entirely new venue.
---
Think about what this means:
NYSE will run two exchanges.
The old one: 9:30-4:00 EST, T+1 settlement, bank wires.
The new one: 24/7, instant settlement, stablecoin rails.
They're not choosing between traditional and digital.
They're operating both in parallel.
---
How does this compare to others?
Everyone else is building infrastructure to tokenize existing assets:
• DTCC tokenizes existing custodied securities
• State Street tokenizes MMFs and ETFs
• Nasdaq amends rules for tokenized trading alongside traditional
NYSE is building a new way to bring equities on-chain AND the venue to trade them.
This puts them in competition with Figure's OPEN and Superstate.
Native digital issuance. Native digital trading.
---
Tokenized stocks enable a world where:
• Settlement happens on-chain
• Custody lives in wallets, not DTCC
• Trading never stops
• Capital formation happens in stablecoins
The question for every institution:
Are you digitizing your existing business or building the business that replaces it?
NYSE just answered: both.
---
#fintech #tokenization #infrastructure #digitalassets #stablecoins
OSINT BIBLE
Social Networks
Geoint & Images
Domain / IP / DNS
Deep & Dark Web
Automation (Python)
Report Templates
AI Intelligence
Facial Recognition
and more.
https://t.co/NchlM7HXYv
Contributor @rangelbarrerax
⚠️ Cloudflare Zero-Day Vulnerability Enables Any Host Access Bypassing Protections
Source: https://t.co/BBJAp1bRZq
A critical zero-day vulnerability in Cloudflare's Web Application Firewall (WAF) allowed attackers to bypass security controls and directly access protected origin servers through a certificate validation path.
The requests targeting the /.well-known/acme-challenge/ directory could reach origins even when customer-configured WAF rules explicitly blocked all other traffic.
The vulnerability was detected while reviewing applications where WAF configurations blocked global access and permitted only specific sources.
#CybersecurityNews #vulnerabilitynews
🚨 15,000 #Jenkins servers are exposed to a critical RCE flaw (CVE-2025-53652) in the Git Parameter plugin. Researchers warn attackers could fully compromise vulnerable systems.
🔗 https://t.co/D5vRHGCOfS
#CyberSecurity#Vulnerability#InfoSec#RCE
This week in #DeFi: GMX hit with $42M exploit via reentrancy vuln—hacker returned $40M after 10% white-hat bounty offered. Venn Network saved $10M by securing thousands of smart contracts from a potential Lazarus Group attack.
🛡️ FedRAMP isn’t just for big enterprises anymore.
A cybersecurity startup breaks down how it cleared FedRAMP Moderate—on startup speed.
💰 Cost: $1M+
⏱️ Time: 12+ months
📚 Lessons: Align early, integrate security, avoid federal-only forks.
Here’s how they did it ↓ https://t.co/pqO1U9Yskg
🔥The assets held in DAO treasuries have increased twice since the beginning of 2023. DAO treasuries have currently set a record with $ 25.1 billion. 🕶️
#DefiNews#DeFi#CryptoNews#Crypto#Hack#SCAM#DAO
1/ 𝗧𝗵𝗲 𝗦𝗲𝗰����𝗿𝗶𝘁𝘆 𝗥𝗶𝘀𝗸𝘀 𝗼𝗳 𝗠𝗶𝘀𝘀𝗶𝗻𝗴 𝗣𝗿𝗲𝗰𝗼𝗻𝗱𝗶𝘁𝗶𝗼𝗻 𝗖𝗵𝗲𝗰𝗸𝘀!🔒
Precondition checks are designed to ensure that a particular operation is valid before a #smartcontract executes it.
Meet the 15 most influential women entrepreneurs in Web3! From Nicole Muniz to Caitlin Long and more, these women are leading the way in blockchain, NFTs, the metaverse and cryptocurrency. https://t.co/rK2kgrBTqI
#PeckShieldAlert After 647 days, @UraniumFinance hacker started move 2250 ETH (~$3.35m) stolen funds into @TornadoCash. On April 28, 2021, the hacker drained approximately $50 million worth of tokens from Uranium's “pair contracts”. https://t.co/mBhMxmAdS5