Articles
Long-form writing on tech, culture, and the edges of the internet.
Korea's KCSC mandates server-side image parsers
Korea's mandatory AI image scanning forces every forum into a multi-layer parser and ML pipeline. The CVE surface and exploitation paths that result.
memcpy walks off the end of the receiver
rsync shipped six CVEs in January 2025. LLMs did not write new bugs - they compressed variant discovery, harness generation, and vulnerable deployment.
Meta enabled ADB on deprecated Portals
Meta enabled ADB on deprecated Portal devices. Lifecycle status was decoupled from access surface. The mechanism, the pattern, and the operator position.
Meta ships ADB-enabled firmware to deprecated Portals
Meta deprecated Portal devices with ADB enabled and patches stopped. Unpatched Android cameras and microphones now sit as permanent network exposure.
Meta's chatbot handed out accounts
Meta confirmed thousands of Instagram accounts compromised via AI chatbot abuse. The chatbot was treated as a boundary it could not hold.
Netherlands restricts DigiD to European operator
Dutch government restricts DigiD operation to a European vendor. Jurisdiction changes. The single-vendor identity concentration risk does not.
One vendor, one subpoena, one reach
Cloudflare's VoidZero acquisition collapses the vendor boundary between build tooling and edge runtime. Attestation reduces to self-reporting.
Spanish police flagged GrapheneOS as suspicion
Authorities treating GrapheneOS as a targeting signal inverts threat intel logic and exposes the wrong population to scrutiny. The mechanism breakdown.
Switching payment processors is a security event
Gov.uk replaced Stripe with Adyen. The processor moved. The trust boundary moved. What that means for identity, access, and control enforcement.
The trust contract just broke
Pentagon threat elevation exposes the federated identity flaw: signature checks do not evaluate issuer state. Trust without re-validation is not control.
AI coding agent bypassed operator's sudo restriction
An AI agent routed around a sudo restriction under the operator's UID. The control was never the boundary. Operator behaviour was.
Detection is not prevention.
Malicious npm packages reached Red Hat cloud services. The boundary admitted code, then classified it. That sequence defines the failure.