Articles
Long-form writing on tech, culture, and the edges of the internet.
Nginx patched. Assume breach.
NGINX issued the nginx-poolslip patch. Operator analysis of what is confirmed, what is not, and what must change at the proxy boundary.
Passkeys authenticate the moment, not the session
MFA, passkeys, and trusted IP authenticate the login moment. They do not extend to the session, the token, or the actions that follow.
Reputation is not a control
Harvard.edu and 140 other domains reported compromised. Why reputation-based controls fail when trusted origins are turned against their consumers.
Twelve bytes walked out of the sandbox
CVE-2026-40369 reduced a browser sandbox escape to twelve bytes. Analysis of what failed, why it failed, and what must change at the architecture layer.
Workflows are code, not config
CI workflow modification executes under repository trust. The control surface is the file. The boundary is the weakest identity allowed to merge.
Your endpoint agent is the intrusion vector.
Two Microsoft Defender vulnerabilities are under active exploitation. One grants full SYSTEM. CISA deadline June 3. What to verify now.
The zero-day wasn't the failure.
Luxembourg's national telecoms network collapsed from one Huawei zero-day. The failure was architectural, not vendor-specific. Concentration was the control gap.
Your BitLocker bypass mitigation fixes nothing yet
Microsoft shipped a mitigation for CVE-2026-45585 YellowKey BitLocker bypass. What is confirmed, what is not, and what operators must verify.
Your privacy settings are decoration.
Privacy is no longer a default state. A former black hat defines what failed, why it failed, and what operators must now assume.
Bitsight found 6,000 unauthenticated fuel gauges online
6,000 Automatic Tank Gauges are exposed to the internet with no authentication. The protocol, the owners, and why the fix isn't technical.
CISA pushed passwords to a public repo
A top cyberdefense agency published credentials in a public GitHub repository. A control analysis of what failed and what must now be true.
Cloudflare's CISO spent two weeks breaking Mythos
Cloudflare's CISO red-teamed Anthropic's Mythos LLM. The findings on harness design, memory persistence, and tool allowlists matter more than the model itself.