BlackBox found a vulnerability in PHP
This happened early July when working on a simple dependency upgrade on innmind/filesystem.
Long story short: a bug in PHP's 8.5 Uri\WhatWg\Url::__construct() allowed to extract part of the process memory.
But let's backtrack a bit.