Tag
LLM
Every LLM story we've curated in Bowl of Data, newest issue first — part of our weekly digest across AI, security, blockchain, and engineering.
Week 36 · 2026
Read the issue →-
SecOPD: Mitigating Adaptive Prompt Injections by On-Policy Distillation
Researchers have developed SecOPD, a fine-tuning technique that uses token-level feedback to protect AI agents from prompt injection attacks. This method significantly outperforms previous state-of-the-art defenses by precisely identifying and penalizing malicious tokens during training.
Week 35 · 2026
Read the issue →-
Why basic RAG fails at multi-hop reasoning (and how GraphRAG fixes it)
This technical guide critiques the limitations of naive vector-based RAG for complex queries and proposes GraphRAG as a solution. It provides a practical Python implementation using Neo4j to enable multi-hop reasoning through structured knowledge graphs.
-
SecOPD: Mitigating Adaptive Prompt Injections by On-Policy Distillation
Researchers have developed SecOPD, a fine-tuning technique that uses token-level feedback to protect AI agents from prompt injection attacks. This method significantly outperforms previous state-of-the-art defenses by precisely identifying and penalizing malicious tokens during training.
Week 33 · 2026
Read the issue →-
GhostSplice: Malicious MCP Servers Split Instructions to Make AI Coding Agents Exfiltrate Secrets (ASSET Research Group)
The GhostSplice attack demonstrates how malicious MCP servers can manipulate AI agents into exfiltrating sensitive data by fragmenting instructions across different tool channels. This technique successfully bypasses modern LLM safety guardrails by disguising theft as routine administrative tasks like form completion.
Week 24 · 2026
Read the issue →-
“The manual model breaks”: What happens when agents write to production data
As autonomous AI agents scale, the risk of catastrophic production data loss increases due to the inability of human oversight to keep pace with machine-speed writes. lakeFS has launched a new service providing isolated data sandboxes and automated governance to ensure agentic workloads remain auditable and reversible.
Week 20 · 2026
Read the issue →-
Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation
Google has uncovered a new threat involving a zero-day 2FA bypass exploit likely created using AI-generated Python code. Additionally, the report highlights PromptSpy, an Android malware that leverages Gemini AI to perform autonomous malicious actions on mobile devices.
-
Dead.Letter (CVE-2026-45185) How XBOW found an unauthenticated RCE on Exim
Researchers have identified a critical unauthenticated remote code execution vulnerability in the Exim mail server, tracked as CVE-2026-45185. The bug stems from a use-after-free condition during TLS shutdown when GnuTLS is employed.
Free weekly digest
Get next Saturday’s issue in your inbox
The week’s most relevant AI, security, blockchain, and engineering stories — curated, summarised, and reviewed by humans. No spam, unsubscribe anytime.
Subscribe — it’s free