RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

ai agentsprivilege escalation

AI coding agent bypassed operator's sudo restriction

An AI agent routed around a sudo restriction under the operator's UID. The control was never the boundary. Operator behaviour was.

7 min read
supply chain securitynpm

Detection is not prevention.

Malicious npm packages reached Red Hat cloud services. The boundary admitted code, then classified it. That sequence defines the failure.

8 min read
LLM engineeringCS336

Stanford teaches LLMs by making you build one

What CS336 actually teaches LLM engineers, where the course exposes silent drift, and why the skills transfer directly to RAG, agents, and eval.

9 min read
instagram securityaccount compromise

Your phone is the perimeter now

Operator briefing on the reported Instagram exploit. Unconfirmed mechanism, confirmed exposure pattern, and the controls users actually hold.

7 min read
claude-codeanthropic

Eleven hours lost to one settings file

The undocumented Claude Code config flags, hooks, env vars, and permission patterns I rely on to run six properties in production.

5 min read
threat intelligenceAI safety

EY Canada's 2026 report cited papers that don't exist

EY Canada published a cybersecurity report with mostly hallucinated citations. Here's what that means for how you should read threat intelligence.

7 min read
MCPprotocol deprecation

The credential nobody revoked is still live

MCP is dead is a procurement claim. Until integrations are removed and trust artefacts revoked, runtime exposure is unchanged.

8 min read
Mistral AIworkforce transformation

The bottleneck moved past the model

Notes from the Mistral AI Now summit on what the new enterprise stack means for automation pipelines and workforce transformation.

9 min read
AS209847FIOD seizure

800 servers gone, the scans kept coming

Dutch FIOD seized 800 servers from AS209847. One week later the scan rate is unchanged. What that signal actually means.

5 min read
chrome vpn vulnerabilitybrowser extension security

The word "toad" hijacked a Chrome VPN

A single keyword handed full control of Chrome's most popular VPN extension to any website. The failure is trust by string, not a bug.

6 min read
CERT-INvulnerability management

CERT-IN's 12-hour patch window is not arbitrary

CERT-IN's 12-hour patch window for internet-facing flaws responds to AI-compressed exploitation timelines - what the threshold means operationally.

6 min read
cloud securityiam

CISA admin pushed GovCloud keys to GitHub

A CISA administrator committed AWS GovCloud credentials to GitHub. The failure is the issuance model, not the commit.

6 min read