RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

Willison's lethal trifecta exfiltrates Claude uploads
prompt injectionLLM security

Willison's lethal trifecta exfiltrates Claude uploads

Technical analysis of indirect prompt injection against Claude AI agents - exfiltration mechanics, ATT&CK mapping, telemetry gaps, residual exposure.

6 min read
Your file renames are a security control
cybersecurity governancevulnerability management

Your file renames are a security control

CVE-2025-48095 in 7-Zip exposes the governance gap around utility software that processes untrusted input without formal ownership or version control.

7 min read
Your SSD is leaking what you're doing
cybersecurityprivacy

Your SSD is leaking what you're doing

How websites can use SSD response timing as a covert channel to infer user activity, and what browsers and users can do about it.

7 min read
Your VPN extension trusts every website you visit
browser securityvpn

Your VPN extension trusts every website you visit

A hardcoded trigger word in a million-install Chrome VPN extension let any website disable the tunnel, change exit nodes, and read open tabs.

6 min read
YouTube built a checkbox, not a detector
deepfakesyoutube

YouTube built a checkbox, not a detector

YouTube's automatic AI-generated video label is a disclosure system, not a detector. Here's what it actually does for cybersecurity and what it doesn't.

6 min read
94GB sits on a leak site
ShinyHuntersdata breach

94GB sits on a leak site

ShinyHunters published a 94GB dataset tied to 7-Eleven franchisee systems after extortion refusal. What failed, why, and what must now be true.

7 min read
A renamed file walks past the heap boundary
7-ZipCVE-2026-48095

A renamed file walks past the heap boundary

CVE-2026-48095 is a 7-Zip NTFS heap overflow triggered through renamed files. Operator breakdown of what failed, why, and what must now be true.

7 min read
Biometrics outlive the breach
biometric datavendor risk

Biometrics outlive the breach

Biometric data held by identity verification providers is non-revocable; board exposure persists regardless of any confirmed incident.

8 min read
CISA administrator published GovCloud keys to GitHub
GovCloudaccess control

CISA administrator published GovCloud keys to GitHub

A CISA administrator's publication of AWS GovCloud keys to public GitHub exposes the gap between cloud segregation policy and runtime control.

8 min read
Franchises leak because franchises federate
shinyhuntersretail-security

Franchises leak because franchises federate

ShinyHunters leaked 94GB from a 7-Eleven franchisee after extortion refusal. The structural reasons franchise retail keeps ending up in leak listings.

6 min read
Hacker publishes dataset naming WhatsApp users
identity riskboard governance

Hacker publishes dataset naming WhatsApp users

A board-level brief on the WhatsApp dataset drop: why identity exposure sits outside owned systems, what remains unconfirmed, and what must hold going forward.

8 min read
nginx-poolslip is mostly rumor
nginxCVE-2026-9256

nginx-poolslip is mostly rumor

CVE-2026-9256 nginx-poolslip operator briefing: what is confirmed, what is not, and the standing control gap the identifier exposes.

8 min read