We have released a few new security review criteria included in our Security policies.
User Registration Without Limits, included in:
Security for Enterprise
Server-side Payload Injection, included in:
Security for Enterprise
Security for AppExchange
Insecure sharing to external users included in:
Security for Enterprise