Topic
Cybersecurity
Every week, Bowl of Data tracks the vulnerabilities, exploits, and threat intelligence worth acting on — what to patch before it becomes someone else's headline. Here is every issue's security coverage, newest first.
Week 30 · 2026
Read the issue →-
Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25
Using an advanced multi-agent LLM approach, a researcher discovered a critical zero-day vulnerability in WordPress that allows for pre-authentication RCE. The exploit chain leverages the WordPress batch API to trigger an SQL injection, which is then escalated to full system control.
Week 29 · 2026
Read the issue →-
Lessons Learned from CISA’s Recent GitHub Leak
CISA recently released a postmortem regarding a six-month exposure of internal credentials on GitHub caused by a contractor's error. The report details failures in incident notification response and the complexities of rotating secrets within large-scale federal environments.
-
Microsoft Patches a Record 570 Security Flaws
Microsoft's latest Patch Tuesday includes a record 570 security fixes, highlighting a surge in vulnerabilities found via AI-assisted research. The update addresses several critical flaws and zero-days that are actively being exploited by malicious actors.
-
Critical NGINX vulnerability discovered: hackers can attempt to crash servers or even gain code execution
A critical security flaw has been identified in NGINX that allows unauthenticated attackers to trigger a heap buffer overflow using crafted HTTP requests. This vulnerability can lead to server crashes or potentially remote code execution under specific system configurations.
Week 28 · 2026
Read the issue →-
Extract, Knock Offline, and Take Over Bluetooth Devices with Just a Laptop
The Whisper_Bully tool demonstrates a sophisticated three-stage attack against Bluetooth Fast Pair devices. It leverages a specific vulnerability to bypass privacy randomization, followed by L2CAP flooding and connection hijacking.
-
Windows Service - Playbook & Detection Strategies
This technical report details multiple methods for abusing Windows Services to achieve persistence and elevated privileges. It covers everything from traditional binary path modification to advanced techniques involving SDDL manipulation and service recovery hijacking.
-
Why a five-minute sniff test is your secret supply chain defense
The article advocates for a proactive 'sniff test' methodology to validate the integrity of SBOMs in containerized environments. It highlights how identifying omissions like unpinned packages or missing dependencies is crucial for preventing supply chain attacks.
Week 27 · 2026
Read the issue →-
CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451) - watchTowr Labs
Security researchers at watchTowr have identified a critical memory overread vulnerability, CVE-2026-8451, affecting Citrix NetScaler appliances. The flaw allows for unauthorized memory disclosure when the device is configured as a SAML Identity Provider.
-
It’s 37oC, And All We Can Think About Is ColdFusion (Adobe ColdFusion Security Bulletin APSB26-68 CVE Bonanza) - watchTowr Labs
This technical report details a series of critical vulnerabilities in Adobe ColdFusion, highlighted by an exploit in the RDS module. The analysis demonstrates how unvalidated input in the RDS protocol allowed for arbitrary file system access.
-
Auditing OpenReception: 16 CVEs in an end-to-end encrypted appointment booking platform (unauthenticated admin creation, account takeover, E2E bypass)
An audit of the OpenReception medical booking platform uncovered 16 vulnerabilities, featuring critical flaws in authorization logic. These exploits allow attackers to escalate privileges to global administrator and compromise the platform's core end-to-end encryption feature.
-
Aikido acquires Root to backport open source fixes without forcing upgrades
Aikido Security has completed a $70 million acquisition of Root to introduce automated backporting of security patches. The move aims to remediate critical vulnerabilities in existing open source dependencies without forcing developers to undergo complex version upgrades.
-
What is a quantum computer good for? Absolutely nothing — yet
The article examines the discrepancy between the massive financial and political hype surrounding quantum computing and its current lack of practical utility. It highlights ongoing debates between corporate claims of progress and academic skepticism regarding hardware capabilities.
Week 26 · 2026
Read the issue →-
CISA warns of max severity Ubiquiti flaws exploited in attacks
CISA is mandating rapid patching for critical vulnerabilities in Ubiquiti and Lantronix hardware that are currently being exploited by attackers. These flaws range from access control bypasses to remote command injection, posing a significant risk of full system compromise.
-
Fraunhofer IPMS Unveils Q-Dice Quantum Random Number Generator for Enterprise Security
Fraunhofer IPMS has unveiled Q-Dice, a high-speed quantum random number generator designed to secure networks against classical and quantum threats. The platform offers both hardware appliances for data centers and an API-driven cloud service for on-demand entropy.
-
Infleqtion Launches America’s Quantum Space Initiative to Accelerate the Future of Quantum-Enabled Space Infrastructure
Infleqtion has unveiled America’s Quantum Space Initiative, a multi-partner effort to advance quantum-enabled space infrastructure. The initiative seeks to integrate quantum sensing and computing into next-generation space missions for defense and commercial use.
-
Chinese cybersecurity company 360 unveils “China's version of Mythos”, and Yitianzhen, to automate cyber defense
360 Security Technology introduced two new AI models, Tulongfeng and Yitianzhen, to automate cyber offensive and defensive operations. The company aims to bridge the technological gap with US-based AI by focusing on scalable, automated defense systems.
Week 25 · 2026
Read the issue →-
SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon
Researchers have identified a critical vulnerability chain called SearchLeak that allows attackers to exfiltrate enterprise data via Microsoft 365 Copilot. By combining prompt injection with an HTML race condition and Bing-based SSRF, attackers can bypass security controls with a single click.
-
Your Privacy My Cloak: Backdoor Attacks on Differentially Private Federated Learning
This paper challenges the assumption that Differential Privacy enhances Federated Learning security against backdoor attacks. The authors present 'Ring', an attack mechanism that leverages DP noise to conceal malicious updates from detection systems.
-
The first unpatchable iPhone exploit in six years targets chips still running Apple's latest iOS
Security researchers have identified a new unpatchable bootROM exploit named usbliter8 that affects several older Apple devices. The vulnerability stems from how USB controllers manage data packets, allowing for persistent hardware-level exploits.
-
Salesforce Data Thefts Continue via Klue App Compromise
A supply chain attack targeting Klue's market intelligence platform allowed threat actors to steal Salesforce customer data through OAuth token abuse. The Icarus extortion group is identified as the primary actor behind this recent wave of CRM-focused breaches.
-
Sandia National Laboratories and Quantinuum Validate 98-Qubit Helios Trapped-Ion Framework
Researchers have successfully validated the Helios 98-qubit trapped-ion quantum processor, showcasing industry-leading gate fidelities and advanced architectural features. The system's real-time control stack allows for complex algorithmic execution that challenges even the most powerful classical supercomputing architectures.
-
Accenture to Acquire Majority Stake in Dragos, All of runZero, NetRise in $4.1 Billion OT Cybersecurity Push
Accenture has announced a massive $4.1 billion initiative to dominate the OT cybersecurity market by acquiring stakes in Dragos, runZero, and NetRise. This strategic expansion focuses on providing comprehensive protection for critical infrastructure and industrial environments.
Week 24 · 2026
Read the issue →-
Signal Alums Reveal ‘Encrypted Spaces,’ a System for Making Private Collaboration Apps
Former Signal engineers have unveiled Encrypted Spaces, a framework for building end-to-end encrypted collaborative platforms. The system uses zero-knowledge proofs to allow servers to manage and verify data changes without ever accessing the underlying unencrypted information.
-
CISA Tells US Agencies to Fix Security Bugs in as Little as 3 Days Thanks to AI Threats
CISA has implemented a new directive forcing federal civilian agencies to remediate high-risk vulnerabilities in as little as three days. This rapid response requirement is a direct reaction to the increased ability of threat actors to use AI for automated bug hunting and exploitation.
Week 23 · 2026
Read the issue →-
Unauthenticated RCE as QSECOFR via IBM i Management Central — port 5555, client-controlled verify flag, no credentials required (V7R4 and earlier)
A critical pre-authentication remote code execution vulnerability has been discovered in IBM i Management Central. The flaw allows unauthorized attackers to execute commands with full system privileges by exploiting a custom binary protocol.
-
Quantum Error Correction with Toric Code at Atom Computing
Atom Computing has successfully demonstrated complete quantum error correction using neutral atom qubits and the toric code. This breakthrough enables the real-time detection and replacement of lost qubits, marking a major step toward scalable quantum computing.
Week 22 · 2026
Read the issue →-
Update on Quantinuum’s IPO Filing
Quantinuum submitted an amended S-1A filing for its Initial Public Offering, finalizing its valuation and share structure. Crucially, the filing also detailed a significant non-binding agreement with the U.S. Department of Commerce for up to $100 million under the CHIPS Act, focusing on advanced quantum hardware development.
Week 21 · 2026
Read the issue →-
Lasers in moon craters could create a lunar GPS system
Researchers propose utilizing ultrastable lasers placed in permanently shadowed lunar craters to create a self-sufficient navigation system, effectively functioning as a lunar GPS. This method leverages the extreme cold and vacuum of these craters to stabilize precision optical cavities, which is critical for future Artemis missions and lunar infrastructure development.
-
GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security
GhostTree is a sophisticated attack technique utilizing NTFS junctions to create recursive, branching file path loops. By generating an effectively infinite number of valid paths, it can cause directory scanning tools and EDR products to hang, thereby allowing malicious files to remain unexamined.
-
Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments
Pathfinding Labs is a new resource offering over 100 intentionally vulnerable AWS environments for security professionals. It enables red and blue teams to practice exploiting complex, real-world misconfigurations and validate the effectiveness of their detection and CSPM tools.
-
Discord rolls out end-to-end encryption on voice, video calls
Discord has implemented mandatory end-to-end encryption (E2EE) for all voice and video communication across its platform. This major update extends the DAVE protocol to secure DMs, group chats, and live streams, significantly boosting user privacy.
-
Quantinuum and Synopsys Partner to Integrate Quantum Algorithms into Engineering Simulation Workflows
Quantinuum and Synopsys announced a strategic partnership to embed quantum algorithms directly into industrial engineering simulation software. This initiative aims to overcome the computational limits of classical high-performance computing by providing quantum-native solvers for complex physical modeling.
-
Cyber resilience defines SME competitiveness
Cybercriminals are increasingly operating as professional, profit-driven enterprises, utilizing automation and AI to execute rapid attacks against SMEs. To mitigate this risk, businesses must pivot from simple technical compliance to building deep, operational cyber resilience across their entire supply chain.
-
Russia's plan to advertise on rockets and spacecraft takes off
Roscosmos has introduced amendments allowing advertising on its space assets starting in 2026 to boost private investment. This move is a response to severe financial losses incurred due to Western sanctions and reflects the ongoing operational challenges facing the Russian space program.
Week 20 · 2026
Read the issue →-
Postmortem: TanStack npm supply-chain compromise
An attacker successfully compromised 42 TanStack npm packages by chaining GitHub Actions cache poisoning with OIDC token extraction. The breach allowed for the unauthorized publication of malicious versions that could exfiltrate sensitive cloud and infrastructure credentials.
-
Dead.Letter (CVE-2026-45185) How XBOW found an unauthenticated RCE on Exim
Researchers have identified a critical unauthenticated remote code execution vulnerability in the Exim mail server, tracked as CVE-2026-45185. The bug stems from a use-after-free condition during TLS shutdown when GnuTLS is employed.
-
Official CheckMarx Jenkins package compromised with infostealer
The TeamPCP hacker group has compromised the Checkmarx Jenkins AST plugin by leveraging credentials stolen from a previous Trivy scanner breach. This supply-chain attack allows for the delivery of credential-stealing malware to developer environments.
-
Gartner: GenAI has broken traditional cybersecurity awareness – what comes next?
The rapid adoption of Generative AI is expanding the human risk surface through shadow AI and advanced, AI-augmented external attacks. To mitigate these evolving threats, cybersecurity leaders must move beyond traditional awareness training toward behavior-driven security culture programs.
Week 19 · 2026
Read the issue →-
DigiCert: Misissued code signing certificates
Threat actors compromised DigiCert support endpoints by sending malicious attachments through a customer chat channel. This breach enabled the unauthorized retrieval of certificate initialization codes, resulting in the misissuance of 60 code signing certificates.
-
Popular DAEMON Tools software infected – supply chain attack ongoing since April 8, 2026
Attackers compromised legitimate DAEMON Tools installers to distribute trojanized, digitally signed binaries that execute malicious code upon system startup. The campaign utilizes an initial information collector to profile victims before deploying advanced payloads like the QUIC RAT for targeted exploitation.
-
Palo Alto Firewall Zero-Day Under Active Exploitation
A critical buffer overflow vulnerability in Palo Alto Networks' PAN-OS is under active exploitation, allowing for unauthenticated root access. Organizations are advised to restrict access to the User-ID Authentication Portal to trusted networks until an emergency patch is released.
-
CVE-2026-32710 MariaDB JSON_SCHEMA_VALID heap buffer overflow leading to RCE
A heap buffer overflow in MariaDB's JSON schema validation allows authenticated attackers to escalate privileges and execute arbitrary code. Users should upgrade to the patched versions 11.4.10 or 11.8.6 immediately.
-
Bypassing Bitlocker under 5 min using downgrade attack on CVE-2025-48804
This article explains how a downgrade attack can bypass BitLocker encryption by leveraging unrevoked legacy certificates in the Secure Boot process. By loading a vulnerable boot manager, an attacker with physical access can gain access to a decrypted OS volume.
-
CVE-2026-42511 Breakdown: RCE in FreeBSD
AISLE has identified a critical, long-standing remote command execution vulnerability in FreeBSD's dhclient. This flaw enables attackers on the same local network to gain root privileges by exploiting improper sanitization of DHCP protocol data.
Free weekly digest
Get next Saturday’s issue in your inbox
The week’s most relevant AI, security, blockchain, and engineering stories — curated, summarised, and reviewed by humans. No spam, unsubscribe anytime.
Subscribe — it’s free