Tag
AWS
Every AWS story we've curated in Bowl of Data, newest issue first — part of our weekly digest across AI, security, blockchain, and engineering.
Week 30 · 2026
Read the issue →-
Joint Study by AWS, NVIDIA, LBNL, and NASA Establishes Framework for Quantum-HPC Integration
Researchers from AWS, NVIDIA, LBNL, and NASA have developed a framework to guide infrastructure decisions for quantum-classical integration. The model helps determine when quantum hardware requires physical co-location with supercomputers versus when remote cloud connectivity is sufficient.
Week 29 · 2026
Read the issue →-
@asyncapi/specs (2.7M weekly downloads) got compromised today via a malicious CI commit
An attacker compromised AsyncAPI repositories to publish malicious npm packages that deploy the Miasma RAT credential stealer. The attack impacts millions of weekly downloads and utilizes advanced obfuscation and multi-channel C2 infrastructure.
Week 24 · 2026
Read the issue →-
For the 2nd time in weeks, Microsoft packages laced with credential stealer
Threat actors have successfully compromised dozens of Microsoft-owned repositories to deploy the Miasma malware via supply-chain attacks. The malware is designed to steal cloud credentials and spread laterally through developer environments by exploiting AI coding agents.
Week 23 · 2026
Read the issue →-
Red Hat npm packages compromised to steal developer credentials
More than 30 Red Hat npm packages were compromised in a supply-chain attack using the Miasma malware to steal developer credentials. The attack was executed via a compromised GitHub account and targeted various cloud and infrastructure secrets.
Week 22 · 2026
Read the issue →-
What scanners are actually trying against AI infrastructure
This report details the rising trend of opportunistic scanning targeting AI-related services and infrastructure. It highlights specific threats to unauthenticated Ollama instances and the use of coordinated sweeps to harvest AI API keys from configuration files.
Week 21 · 2026
Read the issue →-
Iran demands Big Tech pay fees for undersea Internet cables in Strait of Hormuz
Iran's demands for fees on undersea cables in the Strait of Hormuz have severely disrupted global internet connectivity and halted major repair efforts. As a result, tech companies and Gulf nations are urgently pivoting to developing overland fiber routes to ensure continued data flow between the Gulf and Europe.
-
Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments
Pathfinding Labs is a new resource offering over 100 intentionally vulnerable AWS environments for security professionals. It enables red and blue teams to practice exploiting complex, real-world misconfigurations and validate the effectiveness of their detection and CSPM tools.
-
Iran demands Big Tech pay fees for undersea Internet cables in Strait of Hormuz
Iran's demands for fees on undersea cables in the Strait of Hormuz have severely disrupted global internet connectivity and halted major repair efforts. As a result, tech companies and Gulf nations are urgently pivoting to developing overland fiber routes to ensure continued data flow between the Gulf and Europe.
-
America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames
The US Cybersecurity and Infrastructure Security Agency (CISA) was found to have left a massive GitHub repository containing plain-text credentials and infrastructure secrets public for six months. The leak, discovered by a GitGuardian researcher, exposed access to critical systems like AWS, Azure, and Kubernetes, highlighting severe internal security lapses.
Week 20 · 2026
Read the issue →-
Postmortem: TanStack npm supply-chain compromise
An attacker successfully compromised 42 TanStack npm packages by chaining GitHub Actions cache poisoning with OIDC token extraction. The breach allowed for the unauthorized publication of malicious versions that could exfiltrate sensitive cloud and infrastructure credentials.
Free weekly digest
Get next Saturday’s issue in your inbox
The week’s most relevant AI, security, blockchain, and engineering stories — curated, summarised, and reviewed by humans. No spam, unsubscribe anytime.
Subscribe — it’s free