RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

Opened the dashboard at 23:47
claude-codeanthropic-api

Opened the dashboard at 23:47

Microsoft cancelled Claude Code subscriptions. Here's the production audit one indie operator ran on $847/mo of Anthropic spend.

6 min read
The word "toad" hijacked a Chrome VPN
chrome vpn vulnerabilitybrowser extension security

The word "toad" hijacked a Chrome VPN

A single keyword handed full control of Chrome's most popular VPN extension to any website. The failure is trust by string, not a bug.

6 min read
CERT-IN's 12-hour patch window is not arbitrary
CERT-INvulnerability management

CERT-IN's 12-hour patch window is not arbitrary

CERT-IN's 12-hour patch window for internet-facing flaws responds to AI-compressed exploitation timelines - what the threshold means operationally.

6 min read
CISA admin pushed GovCloud keys to GitHub
cloud securityiam

CISA admin pushed GovCloud keys to GitHub

A CISA administrator committed AWS GovCloud credentials to GitHub. The failure is the issuance model, not the commit.

6 min read
CISA pushed GovCloud keys to GitHub
aws-govcloudcredential-leak

CISA pushed GovCloud keys to GitHub

Technical analysis of a CISA admin leaking AWS GovCloud keys on GitHub - exposure mechanics, CloudTrail detection paths, and residual session risk post-rotation.

6 min read
GitHub-distributed VSCode extension executed unsanctioned code
software supply chaindeveloper security

GitHub-distributed VSCode extension executed unsanctioned code

A board-level brief on the compromised VSCode extension distributed through GitHub: what it exposed, what control did not function, and what must be true.

8 min read
GitHub pulls the account, the repos live on
vulnerability disclosureplatform governance

GitHub pulls the account, the repos live on

A board-level analysis of GitHub's ban on a researcher publishing Windows zero-days alongside violent threats, and what it reveals about disclosure risk.

7 min read
ShinyHunters dumps 94GB of 7-Eleven franchisee data
shinyhuntersdata-extortion

ShinyHunters dumps 94GB of 7-Eleven franchisee data

ShinyHunters leaked 94GB of 7-Eleven franchisee data after extortion refusal. Technical analysis of TTPs, info-stealer-to-SaaS pipeline, and franchise IT exposure.

6 min read
The agent reads the page and obeys
AI agentsPlaywright

The agent reads the page and obeys

How Playwright-driven AI agents change the web's threat model: prompt injection, session hijacking, broken CAPTCHAs, and what to do this quarter.

6 min read
The refund letter addressed to Dear [Name]
LLM engineeringAI systems

The refund letter addressed to Dear [Name]

Why ChatGPT's first output is a draft, not a deliverable, and what production AI systems actually require beyond the prompt.

8 min read
The smooth line hiding a noisy benchmark
AI benchmarksLLM engineering

The smooth line hiding a noisy benchmark

The METR AI time horizons graph contains structural errors that mislead teams building agents, automation, and AI workflows. Here is what it actually shows.

9 min read
The WhatsApp breach was not a breach
whatsappcontact-discovery

The WhatsApp breach was not a breach

Technical analysis of the WhatsApp dataset incident: contact discovery oracle abuse, rate-limit bypass, MITRE T1589.002, and the downstream attack surface.

6 min read