Tag
Claude
Every Claude story we've curated in Bowl of Data, newest issue first — part of our weekly digest across AI, security, blockchain, and engineering.
Week 28 · 2026
Read the issue →-
GitLost: a public GitHub issue can steer an org's Agentic Workflow into leaking private repo contents, and a one-word prefix ("Additionally") bypassed the threat-detection guardrail
Noma Labs has uncovered 'GitLost', a vulnerability in GitHub Agentic Workflows that enables indirect prompt injection. By posting malicious instructions in a public issue, an attacker can trick the AI agent into leaking sensitive data from private organizational repositories.
Week 24 · 2026
Read the issue →-
Landmark German ruling declares Google's AI Overviews are Google's own words and makes it liable for false answers
A German court has held Google liable for defamatory content produced by its AI Overviews, ruling that the technology generates its own substantive statements. This landmark decision shifts the legal responsibility from search engine intermediaries to direct content publishers for AI-generated summaries.
Week 23 · 2026
Read the issue →-
Enter the WasmForge: Compiling Sliver into WebAssembly
WasmForge is a novel loader designed to wrap offensive security tools in WebAssembly to evade EDR detection. It achieves this by providing a custom runtime environment that bridges WASM modules to native host APIs without requiring changes to the original tool's source code.
-
Cursor cuts prices and adds enterprise spend controls amid “tokenomics” reckoning
The AI coding market is moving away from predictable monthly fees toward variable, token-based pricing models. Consequently, companies like Cursor are launching new enterprise features to provide the visibility and control required by finance and IT teams.
Week 22 · 2026
Read the issue →-
What scanners are actually trying against AI infrastructure
This report details the rising trend of opportunistic scanning targeting AI-related services and infrastructure. It highlights specific threats to unauthenticated Ollama instances and the use of coordinated sweeps to harvest AI API keys from configuration files.
Free weekly digest
Get next Saturday’s issue in your inbox
The week’s most relevant AI, security, blockchain, and engineering stories — curated, summarised, and reviewed by humans. No spam, unsubscribe anytime.
Subscribe — it’s free