← All topics

Topic

Cybersecurity

Every week, Bowl of Data tracks the vulnerabilities, exploits, and threat intelligence worth acting on — what to patch before it becomes someone else's headline. Here is every issue's security coverage, newest first.

54 items · 17 issues

Week 36 · 2026

Read the issue →
  • From Patch to Exploit; Using Claude Code to reverse engineer an n-day in Papercut NG

    This article details a highly technical experiment where an LLM-driven agent was used to automate the discovery and exploitation of vulnerabilities in Papercut NG. By leveraging patch diffing and automated infrastructure, the AI developed a full proof-of-concept for unauthenticated code execution.

    Cybersecurity Reddit r/netsec Source ↗
  • 39 New Methods That Compromise Passkey Authentication

    While passkeys offer strong cryptographic protection against phishing, researchers have identified 39 methods to bypass this security by targeting the surrounding ecosystem. These attacks focus on exploiting operating systems, synchronization services, and enrollment workflows rather than breaking the underlying protocol.

    Cybersecurity BleepingComputer Source ↗
  • CyberFactory: Scaling Cyber Security Capabilities with Instances from the Wild

    Researchers have developed CyberFactory, a unified framework that automates the creation of high-quality cybersecurity training data from real-world vulnerabilities. By using agentic trajectories to train the OpenAegis model, they achieved state-of-the-art performance in vulnerability detection and patching.

    Cybersecurity HuggingFace Papers Source ↗

Week 35 · 2026

Read the issue →

Week 34 · 2026

Read the issue →

Week 33 · 2026

Read the issue →
  • Building a practical path to post-quantum cryptography

    The transition to post-quantum cryptography is a gradual evolution driven by the potential for quantum computers to break current encryption standards. Organizations are encouraged to adopt methodical modernization strategies, following government-led implementation timelines and leveraging new hardware-based cryptographic accelerators.

    Cybersecurity MIT Technology Review Source ↗

Week 32 · 2026

Read the issue →

Week 31 · 2026

Read the issue →

Week 30 · 2026

Read the issue →

Week 29 · 2026

Read the issue →

Week 28 · 2026

Read the issue →
  • Independent Labs Crack Google’s Secret Cryptography Work

    Researchers at Google recently discovered a way to break 256-bit ECC encryption with much lower qubit counts than expected, but withheld their exact method using zero-knowledge proofs. The startup Eigen Labs successfully bypassed this secrecy by using AI agents and crowdsourcing to develop an even more efficient attack circuit.

    Cybersecurity Reddit r/QuantumComputing Source ↗
  • Extract, Knock Offline, and Take Over Bluetooth Devices with Just a Laptop

    The Whisper_Bully tool demonstrates a sophisticated three-stage attack against Bluetooth Fast Pair devices. It leverages a specific vulnerability to bypass privacy randomization, followed by L2CAP flooding and connection hijacking.

    Cybersecurity Reddit r/cybersecurity Source ↗
  • Windows Service - Playbook & Detection Strategies

    This technical report details multiple methods for abusing Windows Services to achieve persistence and elevated privileges. It covers everything from traditional binary path modification to advanced techniques involving SDDL manipulation and service recovery hijacking.

    Cybersecurity Reddit r/netsec Source ↗
  • Lessons from CISA’s Cyber Incident

    CISA released an after-action report regarding a credential leak caused by a contractor's use of a personal GitHub repository. The agency successfully mitigated the exposure without loss of mission data and is implementing stricter development environment guardrails.

    Cybersecurity Reddit r/cybersecurity Source ↗
  • Why a five-minute sniff test is your secret supply chain defense

    The article advocates for a proactive 'sniff test' methodology to validate the integrity of SBOMs in containerized environments. It highlights how identifying omissions like unpinned packages or missing dependencies is crucial for preventing supply chain attacks.

    Cybersecurity The New Stack Source ↗

Week 27 · 2026

Read the issue →

Week 26 · 2026

Read the issue →

Week 25 · 2026

Read the issue →

Week 24 · 2026

Read the issue →

Week 23 · 2026

Read the issue →

Week 21 · 2026

Read the issue →

Week 20 · 2026

Read the issue →

Week 19 · 2026

Read the issue →
  • DigiCert: Misissued code signing certificates

    Threat actors compromised DigiCert support endpoints by sending malicious attachments through a customer chat channel. This breach enabled the unauthorized retrieval of certificate initialization codes, resulting in the misissuance of 60 code signing certificates.

    Cybersecurity Reddit r/netsec Source ↗
  • Popular DAEMON Tools software infected – supply chain attack ongoing since April 8, 2026

    Attackers compromised legitimate DAEMON Tools installers to distribute trojanized, digitally signed binaries that execute malicious code upon system startup. The campaign utilizes an initial information collector to profile victims before deploying advanced payloads like the QUIC RAT for targeted exploitation.

    Cybersecurity Reddit r/netsec Source ↗
  • Palo Alto Firewall Zero-Day Under Active Exploitation

    A critical buffer overflow vulnerability in Palo Alto Networks' PAN-OS is under active exploitation, allowing for unauthenticated root access. Organizations are advised to restrict access to the User-ID Authentication Portal to trusted networks until an emergency patch is released.

    Cybersecurity Reddit r/cybersecurity Source ↗
  • CVE-2026-32710 MariaDB JSON_SCHEMA_VALID heap buffer overflow leading to RCE

    A heap buffer overflow in MariaDB's JSON schema validation allows authenticated attackers to escalate privileges and execute arbitrary code. Users should upgrade to the patched versions 11.4.10 or 11.8.6 immediately.

    Cybersecurity Reddit r/cybersecurity Source ↗
  • Bypassing Bitlocker under 5 min using downgrade attack on CVE-2025-48804

    This article explains how a downgrade attack can bypass BitLocker encryption by leveraging unrevoked legacy certificates in the Secure Boot process. By loading a vulnerable boot manager, an attacker with physical access can gain access to a decrypted OS volume.

    Cybersecurity Reddit r/netsec Source ↗
  • CVE-2026-42511 Breakdown: RCE in FreeBSD

    AISLE has identified a critical, long-standing remote command execution vulnerability in FreeBSD's dhclient. This flaw enables attackers on the same local network to gain root privileges by exploiting improper sanitization of DHCP protocol data.

    Cybersecurity Reddit r/netsec Source ↗