RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

The seed money didn't kill that repo.
incident-analysisosint

The seed money didn't kill that repo.

An AI OSS tool repo archived overnight after a 73M seed round. The targeting, scrub, and OSINT operation are not confirmed. What the facts actually support.

7 min read
A broken boot is not a breach
asahi-linuxmacos

A broken boot is not a breach

macOS 27 beta stops Asahi Linux booting. Not a confirmed breach: a demonstration that the assumed boundary between OS domains was never enforced.

8 min read
A reverse shell dressed as a Firefox patch
AURArch Linux

A reverse shell dressed as a Firefox patch

Inside the 2025 AUR compromise: how CHAOS RAT shipped in fake browser packages, why update automation made it worse, and how to audit PKGBUILDs in 30 seconds.

7 min read
Boot loop or recovery picker, never m1n1
asahi-linuxapple-silicon

Boot loop or recovery picker, never m1n1

macOS 27 beta breaks Asahi Linux boot on Apple Silicon. Why it is a boot regression, not a UEFI vulnerability, and where real bootkits actually hide.

7 min read
Boundary change, not version bump
wasiruntime-isolation

Boundary change, not version bump

WASI 0.3 shifts IPC to shared memory. If runtime isolation is not enforced, your trust boundary does not exist. An operator briefing on what must change.

8 min read
Our incident report was a vendor blog post
production-incidentsanthropic-api

Our incident report was a vendor blog post

Anthropic's invisible-guardrails apology misses the point: production agents need output contracts, audit ledgers, and sentinel checks, not model-default trust.

6 min read
Our repair agent patched the wrong file four times
claude-codepost-mortem

Our repair agent patched the wrong file four times

A Claude Code repair agent patched the wrong file four times in 31 hours. Why agents anchor on tracebacks, and the prompt rewrite that fixed it.

7 min read
Same commit, two builds, checksums that disagree
supply chain securitysoftware provenance

Same commit, two builds, checksums that disagree

A commit hash guarantees the repository, not the software. How build pipelines resolve trust once at the reference and inherit it against changed content.

7 min read
The scan isn't the story
ai agentsexecution context

The scan isn't the story

An AI agent with unchecked access bankrupted its operator. The failure was the execution context, not the scan. A breakdown of the boundary that never held.

8 min read
31 seconds per 100 lines
claude-codeproduction-incidents

31 seconds per 100 lines

38,412 lines of Claude-generated code, 11 incidents, one 11-day silent failure: why generation speed without verification slows your platform down.

7 min read
AWS Bedrock puts Anthropic inside your data path
aws bedrockanthropic

AWS Bedrock puts Anthropic inside your data path

AWS Bedrock's required data sharing with Anthropic redefines the trust boundary for third-party LLMs. What failed, why, and what must now be true.

8 min read
DeepSeek-R1 escapes its release boundary
DeepSeek-R1model release security

DeepSeek-R1 escapes its release boundary

DeepSeek-R1's open reproduction proves a release model with zero enforcement points: anyone can obtain and run the capability. A control failure briefing.

9 min read