RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

Deleting the link does not recall the file
access controldata exposure

Deleting the link does not recall the file

A file accessible without authentication is a file in distribution. Removing the link does not revoke access already granted.

7 min read
FaceTec stores non-rotatable identity material
biometric-securityidentity-verification

FaceTec stores non-rotatable identity material

A senior operator's position on the storage of non-rotatable biometric templates by ID verification vendors, and the exposure that condition creates.

7 min read
Harvard.edu among 141 hosts serving ClickFix lures
web-compromiseseo-poisoning

Harvard.edu among 141 hosts serving ClickFix lures

Technical analysis of the campaign that weaponised harvard.edu and 140 other legitimate sites - entry vectors, TDS chain, MITRE mapping, EDR telemetry.

6 min read
Malicious VSCode extension shipped through official Marketplace
supply chainvscode

Malicious VSCode extension shipped through official Marketplace

Technical analysis of a compromised VSCode extension reaching GitHub credentials: extension host privileges, MITRE ATT&CK mapping, telemetry gaps.

6 min read
Megalodon hijacked 55,000 GitHub repos via token replay
github-securitysupply-chain

Megalodon hijacked 55,000 GitHub repos via token replay

Megalodon compromised 55,000+ GitHub repositories through PAT harvesting, pull_request_target abuse, and OAuth scope inheritance. Technical breakdown.

7 min read
The sandbox was never the hard part
CVE-2026-40369Chromium

The sandbox was never the hard part

CVE-2026-40369 is a 12-byte Mojo IPC overflow in Chromium that converts renderer RCE into browser-process code execution on the host.

6 min read
Your valid credentials are the breach.
supply-chaingithub-actions

Your valid credentials are the breach.

Technical analysis of a coordinated GitHub Actions workflow compromise across 5,561 repositories, with detection guidance for audit log and EDR telemetry.

6 min read
AI is making attackers worse, not better.
AI securitythreat intelligence

AI is making attackers worse, not better.

Defender telemetry through 2026 shows model-mediated attackers produce more volume, less variance, weaker adaptation. Substitution is not uplift.

6 min read
CVSS 5.5 is lying to you
linux kernelprivilege escalation

CVSS 5.5 is lying to you

A nine-year-old Linux kernel flaw enables root command execution. CVSS 5.5 understates the outcome. Patch scope and operator action.

7 min read
GitHub shipped optional hardening as a control
github breachidentity security

GitHub shipped optional hardening as a control

The GitHub breach follows a documented class of failure. The mechanism is identity issuance separated from validation. The industry chose documentation over enforcement.

6 min read
Malicious commits breached 5,561 repositories
github securityci cd security

Malicious commits breached 5,561 repositories

5,561 GitHub repos received malicious CI/CD commits disguised as bot maintenance. The failure was identity enforcement, not exploit complexity.

5 min read
Microsoft flags password reset exploitation
password resetidentity security

Microsoft flags password reset exploitation

Microsoft confirms password reset exploitation. The reset endpoint is an authentication surface and must be controlled as one.

6 min read