Tag
Go
Every Go story we've curated in Bowl of Data, newest issue first — part of our weekly digest across AI, security, blockchain, and engineering.
Week 23 · 2026
Read the issue →-
Enter the WasmForge: Compiling Sliver into WebAssembly
WasmForge is a novel loader designed to wrap offensive security tools in WebAssembly to evade EDR detection. It achieves this by providing a custom runtime environment that bridges WASM modules to native host APIs without requiring changes to the original tool's source code.
Week 21 · 2026
Read the issue →-
Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments
Pathfinding Labs is a new resource offering over 100 intentionally vulnerable AWS environments for security professionals. It enables red and blue teams to practice exploiting complex, real-world misconfigurations and validate the effectiveness of their detection and CSPM tools.
Week 19 · 2026
Read the issue →-
We probed 6,000 web apps for Stripe webhook signature checks. 1,542 don't bother
A security scan discovered that 25% of 6,000 web applications fail to verify Stripe webhook signatures, allowing for unauthorized payment bypass. This flaw enables attackers to forge successful payment events and upgrade account statuses without actual charges.
-
Bleeding Llama: Critical Unauthenticated Memory Leak in Ollama (CVE-2026–7482)
A critical vulnerability in Ollama allows unauthenticated attackers to trigger an out-of-bounds heap read via malicious GGUF files. This exploit can expose sensitive information like user messages and system prompts by leaking them into newly created model files.
Free weekly digest
Get next Saturday’s issue in your inbox
The week’s most relevant AI, security, blockchain, and engineering stories — curated, summarised, and reviewed by humans. No spam, unsubscribe anytime.
Subscribe — it’s free