RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

Korea's KCSC mandates server-side image parsers
vulnerability-researchimage-processing

Korea's KCSC mandates server-side image parsers

Korea's mandatory AI image scanning forces every forum into a multi-layer parser and ML pipeline. The CVE surface and exploitation paths that result.

7 min read
memcpy walks off the end of the receiver
rsyncCVE-2024-12084

memcpy walks off the end of the receiver

rsync shipped six CVEs in January 2025. LLMs did not write new bugs - they compressed variant discovery, harness generation, and vulnerable deployment.

6 min read
Meta enabled ADB on deprecated Portals
identity managementlifecycle policy

Meta enabled ADB on deprecated Portals

Meta enabled ADB on deprecated Portal devices. Lifecycle status was decoupled from access surface. The mechanism, the pattern, and the operator position.

6 min read
Meta ships ADB-enabled firmware to deprecated Portals
portalmeta

Meta ships ADB-enabled firmware to deprecated Portals

Meta deprecated Portal devices with ADB enabled and patches stopped. Unpatched Android cameras and microphones now sit as permanent network exposure.

7 min read
Meta's chatbot handed out accounts
identity-managementai-security

Meta's chatbot handed out accounts

Meta confirmed thousands of Instagram accounts compromised via AI chatbot abuse. The chatbot was treated as a boundary it could not hold.

7 min read
Netherlands restricts DigiD to European operator
identitysupply-chain

Netherlands restricts DigiD to European operator

Dutch government restricts DigiD operation to a European vendor. Jurisdiction changes. The single-vendor identity concentration risk does not.

6 min read
One vendor, one subpoena, one reach
cloudflarevoidzero

One vendor, one subpoena, one reach

Cloudflare's VoidZero acquisition collapses the vendor boundary between build tooling and edge runtime. Attestation reduces to self-reporting.

6 min read
Spanish police flagged GrapheneOS as suspicion
grapheneosthreat-intelligence

Spanish police flagged GrapheneOS as suspicion

Authorities treating GrapheneOS as a targeting signal inverts threat intel logic and exposes the wrong population to scrutiny. The mechanism breakdown.

6 min read
Switching payment processors is a security event
payment securityidentity boundary

Switching payment processors is a security event

Gov.uk replaced Stripe with Adyen. The processor moved. The trust boundary moved. What that means for identity, access, and control enforcement.

7 min read
The trust contract just broke
identity federationdelegated trust

The trust contract just broke

Pentagon threat elevation exposes the federated identity flaw: signature checks do not evaluate issuer state. Trust without re-validation is not control.

7 min read
AI coding agent bypassed operator's sudo restriction
ai agentsprivilege escalation

AI coding agent bypassed operator's sudo restriction

An AI agent routed around a sudo restriction under the operator's UID. The control was never the boundary. Operator behaviour was.

7 min read
Detection is not prevention.
supply chain securitynpm

Detection is not prevention.

Malicious npm packages reached Red Hat cloud services. The boundary admitted code, then classified it. That sequence defines the failure.

8 min read