Tag
Windows
Every Windows story we've curated in Bowl of Data, newest issue first — part of our weekly digest across AI, security, blockchain, and engineering.
Week 36 · 2026
Read the issue →-
39 New Methods That Compromise Passkey Authentication
While passkeys offer strong cryptographic protection against phishing, researchers have identified 39 methods to bypass this security by targeting the surrounding ecosystem. These attacks focus on exploiting operating systems, synchronization services, and enrollment workflows rather than breaking the underlying protocol.
Week 33 · 2026
Read the issue →-
DeadLock ransomware uses blockchain to resist infrastructure takedown
DeadLock ransomware has introduced a highly resilient infrastructure by leveraging blockchain technology to host command-and-control instructions. This decentralized approach aims to prevent the permanent removal of their communication channels and data leak sites by authorities.
Week 31 · 2026
Read the issue →-
AI Agent Drives Espionage Attack on Thai Ministry of Finance
An autonomous AI agent was used to facilitate a sophisticated espionage campaign against the Thai Ministry of Finance. The attack utilized advanced post-exploitation tools and targeted big data infrastructure, though it was ultimately detected due to exposed attacker directories.
-
OSReward: Instituting Standardized Evaluation for Cross-Platform Computer-Use Reward Models
Researchers have developed OSReward to address the lack of standardized evaluation for reward models used by computer-using agents. The study identifies critical failure modes in existing VLM judges and introduces the OS-Shepherd model series as a cost-effective, high-accuracy alternative.
Week 29 · 2026
Read the issue →-
Microsoft Patches a Record 570 Security Flaws
Microsoft's latest Patch Tuesday includes a record 570 security fixes, highlighting a surge in vulnerabilities found via AI-assisted research. The update addresses several critical flaws and zero-days that are actively being exploited by malicious actors.
Week 23 · 2026
Read the issue →-
Enter the WasmForge: Compiling Sliver into WebAssembly
WasmForge is a novel loader designed to wrap offensive security tools in WebAssembly to evade EDR detection. It achieves this by providing a custom runtime environment that bridges WASM modules to native host APIs without requiring changes to the original tool's source code.
Week 21 · 2026
Read the issue →-
GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security
GhostTree is a sophisticated attack technique utilizing NTFS junctions to create recursive, branching file path loops. By generating an effectively infinite number of valid paths, it can cause directory scanning tools and EDR products to hang, thereby allowing malicious files to remain unexamined.
Free weekly digest
Get next Saturday’s issue in your inbox
The week’s most relevant AI, security, blockchain, and engineering stories — curated, summarised, and reviewed by humans. No spam, unsubscribe anytime.
Subscribe — it’s free