Tag
Docker
Every Docker story we've curated in Bowl of Data, newest issue first — part of our weekly digest across AI, security, blockchain, and engineering.
Week 28 · 2026
Read the issue →-
Why a five-minute sniff test is your secret supply chain defense
The article advocates for a proactive 'sniff test' methodology to validate the integrity of SBOMs in containerized environments. It highlights how identifying omissions like unpinned packages or missing dependencies is crucial for preventing supply chain attacks.
Week 27 · 2026
Read the issue →-
Auditing OpenReception: 16 CVEs in an end-to-end encrypted appointment booking platform (unauthenticated admin creation, account takeover, E2E bypass)
An audit of the OpenReception medical booking platform uncovered 16 vulnerabilities, featuring critical flaws in authorization logic. These exploits allow attackers to escalate privileges to global administrator and compromise the platform's core end-to-end encryption feature.
Week 26 · 2026
Read the issue →-
Kuma: compiling PyTorch models into self-contained WebGPU executables [P]
Kuma introduces a way to run trained PyTorch models live in the browser by compiling them into a specialized '.iph' format. By leveraging WebGPU and embedded WGSL shaders, it eliminates the need for server-side inference or heavy runtime dependencies.
Week 23 · 2026
Read the issue →-
Red Hat npm packages compromised to steal developer credentials
More than 30 Red Hat npm packages were compromised in a supply-chain attack using the Miasma malware to steal developer credentials. The attack was executed via a compromised GitHub account and targeted various cloud and infrastructure secrets.
Week 22 · 2026
Read the issue →-
What scanners are actually trying against AI infrastructure
This report details the rising trend of opportunistic scanning targeting AI-related services and infrastructure. It highlights specific threats to unauthenticated Ollama instances and the use of coordinated sweeps to harvest AI API keys from configuration files.
Week 20 · 2026
Read the issue →-
Official CheckMarx Jenkins package compromised with infostealer
The TeamPCP hacker group has compromised the Checkmarx Jenkins AST plugin by leveraging credentials stolen from a previous Trivy scanner breach. This supply-chain attack allows for the delivery of credential-stealing malware to developer environments.
Free weekly digest
Get next Saturday’s issue in your inbox
The week’s most relevant AI, security, blockchain, and engineering stories — curated, summarised, and reviewed by humans. No spam, unsubscribe anytime.
Subscribe — it’s free