← All topics

Topic

Software Engineering

Every week, Bowl of Data tracks the tools, frameworks, and open-source releases that change how we build software. Here is every issue's engineering coverage, newest first.

26 items · 11 issues

Week 30 · 2026

Read the issue →

Week 29 · 2026

Read the issue →

Week 28 · 2026

Read the issue →
  • Bad Epoll: The bug missed by Mythos

    The article details the discovery of CVE-2026-46242, a critical race-condition bug in the Linux kernel's epoll subsystem. This vulnerability enables local privilege escalation to root on various platforms including Android.

    Software Engineering Reddit r/netsec Source ↗
  • Google pays 250K for Linux vulnerability allowing guest VM escapes

    Researcher Hyunwoo Kim discovered a high-severity use-after-free vulnerability in the Linux KVM subsystem called Januscape. This flaw enables untrusted guest VMs to break out of their isolation and potentially take control of the host operating system.

    Software Engineering Reddit r/cybersecurity Source ↗
  • Lessons from CISA’s Cyber Incident

    CISA released an after-action report regarding a credential leak caused by a contractor's use of a personal GitHub repository. The agency successfully mitigated the exposure without loss of mission data and is implementing stricter development environment guardrails.

    Software Engineering Reddit r/cybersecurity Source ↗

Week 27 · 2026

Read the issue →
  • Program-as-Weights: A Programming Paradigm for Fuzzy Functions

    The researchers present Program-as-Weights (PAW), a paradigm that shifts LLM usage from expensive per-input API calls to a 'compile-once, run-locally' model using neural adapters. This approach allows small, specialized models to outperform massive foundation models on specific fuzzy tasks while maintaining high efficiency and privacy.

    Software Engineering arXiv Source ↗
  • Program-as-Weights: A Programming Paradigm for Fuzzy Functions

    The researchers present Program-as-Weights (PAW), a paradigm that shifts LLM usage from expensive per-input API calls to a 'compile-once, run-locally' model using neural adapters. This approach allows small, specialized models to outperform massive foundation models on specific fuzzy tasks while maintaining high efficiency and privacy.

    Software Engineering arXiv Source ↗

Week 25 · 2026

Read the issue →

Week 24 · 2026

Read the issue →

Week 23 · 2026

Read the issue →
  • Red Hat npm packages compromised to steal developer credentials

    More than 30 Red Hat npm packages were compromised in a supply-chain attack using the Miasma malware to steal developer credentials. The attack was executed via a compromised GitHub account and targeted various cloud and infrastructure secrets.

    Software Engineering BleepingComputer Source ↗
  • Enter the WasmForge: Compiling Sliver into WebAssembly

    WasmForge is a novel loader designed to wrap offensive security tools in WebAssembly to evade EDR detection. It achieves this by providing a custom runtime environment that bridges WASM modules to native host APIs without requiring changes to the original tool's source code.

    Software Engineering Reddit r/netsec Source ↗

Week 22 · 2026

Read the issue →

Week 21 · 2026

Read the issue →

Week 20 · 2026

Read the issue →

Week 19 · 2026

Read the issue →