It's starting to look a lot like Christ^WHackMas
Why shouldn't I share my own content? Here's a shameless plug for my article on the JWT Algorithm Confusion Vulnerability I found in a C library.
Check out this excellent write-up by the Assenote team on how an obscure PHP footgun led to RCE in Craft CMS.
The latest edition of AppSec eZine is here! Read issue #566.