Articles
Long-form writing on tech, culture, and the edges of the internet.
OpenCV 5.0 made adversarial perturbations transferable
OpenCV 5's bit-exact numerics and expanded encoder control shrink the attacker's modelling error against deepfake detectors. The exposure is structural.
Refusal bypass isn't the scary part
What broke when I ran a self-modifying pen test agent through Foundry's harness: $47 burned in 3 hours, a strategy ossification loop, and the registry fix.
Sixty-three days to patch a forked parser
Technical breakdown of the FrontierOS RCE: a forked XML parser, an unpatched two-year-old CVE, and the fork-tracking failure that shipped it.
The door Mythos left unlocked
Mythos is an identity management failure. Privileged access boundaries were not enforced. Lateral movement reached sensitive data.
Typosquatted Microsoft AI packages harvest developer credentials
How attackers weaponised typosquatted Microsoft AI tooling to harvest OpenAI, HuggingFace, AWS, and Azure credentials from developer workstations.
Your CA just picked sides
Let's Encrypt restricts certificate issuance in US sanctioned territories. The CA is now conditional. Operator response and dependency inventory required.
Your supply chain isn't compromised. It's working.
Microsoft's open-source developer tools executed credential-stealing code through normal package resolution. The control plane never inspected what was returned.
Antibody catalogs are unsanitized user input
Thermo Fisher antibody metadata manipulation is a supply chain attack against bioinformatics pipelines - not a data integrity issue. Here is the mechanism.
CVE-2024-3400 shipped exploited before the advisory
Why the gap between CVE disclosure and production detection is structural - and where attackers operate inside it.
Cypherpunk frees the key schedule twice
UAF in the Cypherpunk Library's context teardown - CWE-416, heap reuse, sandbox-free RCE path, and why EDR misses the corruption stage.
Massachusetts bans precise geolocation sales
Massachusetts banned the sale of precise location data. The statute kills a commercial attack vector and creates real telemetry gaps for defenders.
Motorola bricked your routers
A board-level read on the Motorola router event: vendor authority over fielded equipment is a primary risk vector, and silence is the visible control failure.