Articles
Long-form writing on tech, culture, and the edges of the internet.
Q1 2026: Iranian crews living off P2P
Compromised P2P accounts are driving lateral movement and exfiltration in Israeli orgs. The fabric, not the platform, is the C2 channel.
Steam's I/O thread is holding a dead pointer
Transport-layer race condition in Valve's GameNetworkingSockets creates a remote UAF primitive that sits below session crypto and evades EDR telemetry.
The 64KB segment where every overflow rewrote a free list pointer
Win16's Local Heap overflow defines the metadata corruption class that still drives modern browser and kernel exploitation in 2026.
The chatbot answered the door for attackers
Meta's Instagram chatbot abuse case is a prompt injection and confused deputy failure. Technical breakdown of the vector, telemetry gap, and residual exposure.
The .docx in your webmail preview pane
Browser-side OOXML rendering converts trusted document parsers into renderer-context exploit primitives. The detection stack does not see the boundary cross.
There is no Linear kernel CVE
Linear's speed comes from a local-first sync engine, not a kernel-memory exploit. The fabricated CVE framing is wrong. The real exposure is elsewhere.
Thirty years of weaponizing fork-exec
fork+exec inherits file descriptors, environment, and capabilities by default. That inheritance is the bug class behind Shellshock, runc CVE-2019-5736, and Symbiote.
A binary that hands kernel hooks to anyone
Zeroserve packages kernel-adjacent execution surface under userspace pipelines. The artifact crosses a privilege boundary the pipeline was not scoped to see.
Contractor PAT leaked 270GB of Times source
The 2024 NYT source code leak was not a credential breach. It was a credential sprawl chain. The mechanism, telemetry gaps, and what still applies.
Cooldown does not fix the resolver
Bundler 2.6 cooldown defers new gem versions to interrupt published-and-pulled supply chain attacks. The resolver's trust model is the systemic exposure.
Editorial independence is a failed control
UK media failed to disclose defence sector ties in nearly 60 percent of cases. The disclosure gap is an information supply chain vulnerability - and it is exploitable.
Europe maps GNSS jammers mid-attack
Powerful GNSS interference over Europe exposes location-based controls as ineffective. Unauthenticated positional data is not a security boundary.