Tag
JavaScript
Every JavaScript story we've curated in Bowl of Data, newest issue first — part of our weekly digest across AI, security, blockchain, and engineering.
Week 36 · 2026
Read the issue →-
ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain
A sophisticated ClickFix campaign is leveraging the Polygon blockchain to implement 'EtherHiding,' allowing attackers to rotate C2 servers via smart contracts. This technique makes traditional IP and domain blocking ineffective by using a distributed ledger as an attacker-controlled command center.
Week 35 · 2026
Read the issue →-
From Static to Dynamic: Benchmarking Real-World Code Review with MCR-Bench
Researchers have developed MCR-Bench to move beyond static code review evaluation by simulating the iterative nature of real-world developer interactions. The study reveals that current LLMs struggle significantly with maintaining defect state consistency across multiple rounds of code changes.
Week 31 · 2026
Read the issue →-
Sixteen strangers and a shared obfuscator: mapping the wool scene
The article maps a highly interconnected ecosystem of automation operators who share obfuscation tools, device fingerprints, and distribution networks. By analyzing Git history deletions and shared code patterns, the author proves that seemingly independent actors are part of a unified supply chain.
Week 29 · 2026
Read the issue →-
Researcher poisons open-weight AI model for under $100
Security researchers have proven that open-weight AI models can be maliciously backdoored using minimal resources and training data. This discovery highlights a critical lack of observability and verification capabilities in the current AI supply chain.
Week 27 · 2026
Read the issue →-
Program-as-Weights: A Programming Paradigm for Fuzzy Functions
The researchers present Program-as-Weights (PAW), a paradigm that shifts LLM usage from expensive per-input API calls to a 'compile-once, run-locally' model using neural adapters. This approach allows small, specialized models to outperform massive foundation models on specific fuzzy tasks while maintaining high efficiency and privacy.
Week 22 · 2026
Read the issue →-
Websites have a new way to spy on visitors: analyzing their SSD activity
A new side-channel attack named FROST allows websites to bypass browser sandboxing by analyzing SSD latency. By using deep learning to process I/O traces, attackers can fingerprint the applications and websites running on a user's device.
Free weekly digest
Get next Saturday’s issue in your inbox
The week’s most relevant AI, security, blockchain, and engineering stories — curated, summarised, and reviewed by humans. No spam, unsubscribe anytime.
Subscribe — it’s free