GraphQL
GraphQL at Beyond Market Intelligence is a file of 2 stories. The newest of them: “How a blocked attack turned a security agent into a DNS hijacker” and “Three Teams, One Problem: LLMs Fill GraphQL Mock Gaps”. A security agent read a Cloudflare log, found an attacker's prompt-injection payload sitting inside it, and rewrote the company's DNS. Three teams are now solving the same problem in different ways. Acme AI is the next-generation, AI-powered spreadsheet platform built to replace Excel and redefine how analysts, data scientists, and enterprise teams work… The list below is every GraphQL story on Beyond Market Intelligence, newest first.

How a blocked attack turned a security agent into a DNS hijacker
A security agent read a Cloudflare log, found an attacker's prompt-injection payload sitting inside it, and rewrote the company's DNS. The firewall had already blocked that payload, and blocking it is what wrote it into the log. That chain is GhostJacking, and it makes one thing clear: a high block rate is not a security boundary. The fix is an authorization gate outside the model, one that lets an agent propose a change but never approve it.

Three Teams, One Problem: LLMs Fill GraphQL Mock Gaps
Three teams are now solving the same problem in different ways. Expedia Group open-sourced mockql-rs, a Rust CLI that fills @mock-annotated GraphQL fields with LLM-generated data at request time. It follows Airbnb's @generateMock from April and a GraphQL Foundation RFC opened in February. The catch: two use the same directive name with incompatible semantics. That is a coordination gap worth watching. For more on how these models reason structurally, see our piece on paragraph structure in token space.