← All topics

Topic

Cybersecurity

Every week, Bowl of Data tracks the vulnerabilities, exploits, and threat intelligence worth acting on — what to patch before it becomes someone else's headline. Here is every issue's security coverage, newest first.

44 items · 12 issues

Week 30 · 2026

Read the issue →

Week 29 · 2026

Read the issue →
  • Lessons Learned from CISA’s Recent GitHub Leak

    CISA recently released a postmortem regarding a six-month exposure of internal credentials on GitHub caused by a contractor's error. The report details failures in incident notification response and the complexities of rotating secrets within large-scale federal environments.

    Cybersecurity Krebs on Security Source ↗
  • Microsoft Patches a Record 570 Security Flaws

    Microsoft's latest Patch Tuesday includes a record 570 security fixes, highlighting a surge in vulnerabilities found via AI-assisted research. The update addresses several critical flaws and zero-days that are actively being exploited by malicious actors.

    Cybersecurity Krebs on Security Source ↗
  • Critical NGINX vulnerability discovered: hackers can attempt to crash servers or even gain code execution

    A critical security flaw has been identified in NGINX that allows unauthenticated attackers to trigger a heap buffer overflow using crafted HTTP requests. This vulnerability can lead to server crashes or potentially remote code execution under specific system configurations.

    Cybersecurity Reddit r/cybersecurity Source ↗

Week 28 · 2026

Read the issue →
  • Extract, Knock Offline, and Take Over Bluetooth Devices with Just a Laptop

    The Whisper_Bully tool demonstrates a sophisticated three-stage attack against Bluetooth Fast Pair devices. It leverages a specific vulnerability to bypass privacy randomization, followed by L2CAP flooding and connection hijacking.

    Cybersecurity Reddit r/cybersecurity Source ↗
  • Windows Service - Playbook & Detection Strategies

    This technical report details multiple methods for abusing Windows Services to achieve persistence and elevated privileges. It covers everything from traditional binary path modification to advanced techniques involving SDDL manipulation and service recovery hijacking.

    Cybersecurity Reddit r/netsec Source ↗
  • Why a five-minute sniff test is your secret supply chain defense

    The article advocates for a proactive 'sniff test' methodology to validate the integrity of SBOMs in containerized environments. It highlights how identifying omissions like unpinned packages or missing dependencies is crucial for preventing supply chain attacks.

    Cybersecurity The New Stack Source ↗

Week 27 · 2026

Read the issue →

Week 26 · 2026

Read the issue →

Week 25 · 2026

Read the issue →

Week 24 · 2026

Read the issue →

Week 23 · 2026

Read the issue →

Week 22 · 2026

Read the issue →
  • Update on Quantinuum’s IPO Filing

    Quantinuum submitted an amended S-1A filing for its Initial Public Offering, finalizing its valuation and share structure. Crucially, the filing also detailed a significant non-binding agreement with the U.S. Department of Commerce for up to $100 million under the CHIPS Act, focusing on advanced quantum hardware development.

    Cybersecurity Quantum Computing Report Source ↗

Week 21 · 2026

Read the issue →
  • Lasers in moon craters could create a lunar GPS system

    Researchers propose utilizing ultrastable lasers placed in permanently shadowed lunar craters to create a self-sufficient navigation system, effectively functioning as a lunar GPS. This method leverages the extreme cold and vacuum of these craters to stabilize precision optical cavities, which is critical for future Artemis missions and lunar infrastructure development.

    Cybersecurity Space.com Source ↗
  • GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security

    GhostTree is a sophisticated attack technique utilizing NTFS junctions to create recursive, branching file path loops. By generating an effectively infinite number of valid paths, it can cause directory scanning tools and EDR products to hang, thereby allowing malicious files to remain unexamined.

    Cybersecurity Reddit r/netsec Source ↗
  • Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments

    Pathfinding Labs is a new resource offering over 100 intentionally vulnerable AWS environments for security professionals. It enables red and blue teams to practice exploiting complex, real-world misconfigurations and validate the effectiveness of their detection and CSPM tools.

    Cybersecurity Reddit r/netsec Source ↗
  • Discord rolls out end-to-end encryption on voice, video calls

    Discord has implemented mandatory end-to-end encryption (E2EE) for all voice and video communication across its platform. This major update extends the DAVE protocol to secure DMs, group chats, and live streams, significantly boosting user privacy.

    Cybersecurity Reddit r/cybersecurity Source ↗
  • Quantinuum and Synopsys Partner to Integrate Quantum Algorithms into Engineering Simulation Workflows

    Quantinuum and Synopsys announced a strategic partnership to embed quantum algorithms directly into industrial engineering simulation software. This initiative aims to overcome the computational limits of classical high-performance computing by providing quantum-native solvers for complex physical modeling.

    Cybersecurity Quantum Computing Report Source ↗
  • Cyber resilience defines SME competitiveness

    Cybercriminals are increasingly operating as professional, profit-driven enterprises, utilizing automation and AI to execute rapid attacks against SMEs. To mitigate this risk, businesses must pivot from simple technical compliance to building deep, operational cyber resilience across their entire supply chain.

    Cybersecurity TechRadar Source ↗
  • Russia's plan to advertise on rockets and spacecraft takes off

    Roscosmos has introduced amendments allowing advertising on its space assets starting in 2026 to boost private investment. This move is a response to severe financial losses incurred due to Western sanctions and reflects the ongoing operational challenges facing the Russian space program.

    Cybersecurity Ars Technica Source ↗

Week 20 · 2026

Read the issue →

Week 19 · 2026

Read the issue →
  • DigiCert: Misissued code signing certificates

    Threat actors compromised DigiCert support endpoints by sending malicious attachments through a customer chat channel. This breach enabled the unauthorized retrieval of certificate initialization codes, resulting in the misissuance of 60 code signing certificates.

    Cybersecurity Reddit r/netsec Source ↗
  • Popular DAEMON Tools software infected – supply chain attack ongoing since April 8, 2026

    Attackers compromised legitimate DAEMON Tools installers to distribute trojanized, digitally signed binaries that execute malicious code upon system startup. The campaign utilizes an initial information collector to profile victims before deploying advanced payloads like the QUIC RAT for targeted exploitation.

    Cybersecurity Reddit r/netsec Source ↗
  • Palo Alto Firewall Zero-Day Under Active Exploitation

    A critical buffer overflow vulnerability in Palo Alto Networks' PAN-OS is under active exploitation, allowing for unauthenticated root access. Organizations are advised to restrict access to the User-ID Authentication Portal to trusted networks until an emergency patch is released.

    Cybersecurity Reddit r/cybersecurity Source ↗
  • CVE-2026-32710 MariaDB JSON_SCHEMA_VALID heap buffer overflow leading to RCE

    A heap buffer overflow in MariaDB's JSON schema validation allows authenticated attackers to escalate privileges and execute arbitrary code. Users should upgrade to the patched versions 11.4.10 or 11.8.6 immediately.

    Cybersecurity Reddit r/cybersecurity Source ↗
  • Bypassing Bitlocker under 5 min using downgrade attack on CVE-2025-48804

    This article explains how a downgrade attack can bypass BitLocker encryption by leveraging unrevoked legacy certificates in the Secure Boot process. By loading a vulnerable boot manager, an attacker with physical access can gain access to a decrypted OS volume.

    Cybersecurity Reddit r/netsec Source ↗
  • CVE-2026-42511 Breakdown: RCE in FreeBSD

    AISLE has identified a critical, long-standing remote command execution vulnerability in FreeBSD's dhclient. This flaw enables attackers on the same local network to gain root privileges by exploiting improper sanitization of DHCP protocol data.

    Cybersecurity Reddit r/netsec Source ↗