Articles
Long-form writing on tech, culture, and the edges of the internet.
Opened the dashboard at 23:47
Microsoft cancelled Claude Code subscriptions. Here's the production audit one indie operator ran on $847/mo of Anthropic spend.
The word "toad" hijacked a Chrome VPN
A single keyword handed full control of Chrome's most popular VPN extension to any website. The failure is trust by string, not a bug.
CERT-IN's 12-hour patch window is not arbitrary
CERT-IN's 12-hour patch window for internet-facing flaws responds to AI-compressed exploitation timelines - what the threshold means operationally.
CISA admin pushed GovCloud keys to GitHub
A CISA administrator committed AWS GovCloud credentials to GitHub. The failure is the issuance model, not the commit.
CISA pushed GovCloud keys to GitHub
Technical analysis of a CISA admin leaking AWS GovCloud keys on GitHub - exposure mechanics, CloudTrail detection paths, and residual session risk post-rotation.
GitHub-distributed VSCode extension executed unsanctioned code
A board-level brief on the compromised VSCode extension distributed through GitHub: what it exposed, what control did not function, and what must be true.
GitHub pulls the account, the repos live on
A board-level analysis of GitHub's ban on a researcher publishing Windows zero-days alongside violent threats, and what it reveals about disclosure risk.
ShinyHunters dumps 94GB of 7-Eleven franchisee data
ShinyHunters leaked 94GB of 7-Eleven franchisee data after extortion refusal. Technical analysis of TTPs, info-stealer-to-SaaS pipeline, and franchise IT exposure.
The agent reads the page and obeys
How Playwright-driven AI agents change the web's threat model: prompt injection, session hijacking, broken CAPTCHAs, and what to do this quarter.
The refund letter addressed to Dear [Name]
Why ChatGPT's first output is a draft, not a deliverable, and what production AI systems actually require beyond the prompt.
The smooth line hiding a noisy benchmark
The METR AI time horizons graph contains structural errors that mislead teams building agents, automation, and AI workflows. Here is what it actually shows.
The WhatsApp breach was not a breach
Technical analysis of the WhatsApp dataset incident: contact discovery oracle abuse, rate-limit bypass, MITRE T1589.002, and the downstream attack surface.