RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

Your API breach was working as designed
api securityauthentication

Your API breach was working as designed

API authentication failing at the request level is a trust boundary failure. Inadequate identity validation makes lateral movement a design outcome.

7 min read
Between knowing and telling
breach disclosuresystems failure analysis

Between knowing and telling

Breach disclosure clocks measure the interval after an organization notices, never the months of compromise before it. The proxy is not the fact.

7 min read
Mandatory ID is the breach, not the fix.
OSINTprivacy

Mandatory ID is the breach, not the fix.

The FCC prepaid ID mandate produces a centralized identity-resolved communications graph inside carriers with documented breach history.

7 min read
OpenCV 5.0 made adversarial perturbations transferable
adversarial-mlopencv

OpenCV 5.0 made adversarial perturbations transferable

OpenCV 5's bit-exact numerics and expanded encoder control shrink the attacker's modelling error against deepfake detectors. The exposure is structural.

6 min read
Refusal bypass isn't the scary part
claude-codeagent-observability

Refusal bypass isn't the scary part

What broke when I ran a self-modifying pen test agent through Foundry's harness: $47 burned in 3 hours, a strategy ossification loop, and the registry fix.

6 min read
Sixty-three days to patch a forked parser
vulnerability researchsupply chain security

Sixty-three days to patch a forked parser

Technical breakdown of the FrontierOS RCE: a forked XML parser, an unpatched two-year-old CVE, and the fork-tracking failure that shipped it.

6 min read
The door Mythos left unlocked
privileged accessidentity boundary

The door Mythos left unlocked

Mythos is an identity management failure. Privileged access boundaries were not enforced. Lateral movement reached sensitive data.

5 min read
Typosquatted Microsoft AI packages harvest developer credentials
supply-chaincredential-theft

Typosquatted Microsoft AI packages harvest developer credentials

How attackers weaponised typosquatted Microsoft AI tooling to harvest OpenAI, HuggingFace, AWS, and Azure credentials from developer workstations.

6 min read
Your CA just picked sides
lets-encryptcertificate-authority

Your CA just picked sides

Let's Encrypt restricts certificate issuance in US sanctioned territories. The CA is now conditional. Operator response and dependency inventory required.

7 min read
Your supply chain isn't compromised. It's working.
supply chainpackage registry

Your supply chain isn't compromised. It's working.

Microsoft's open-source developer tools executed credential-stealing code through normal package resolution. The control plane never inspected what was returned.

7 min read
Antibody catalogs are unsanitized user input
supply chainbioinformatics security

Antibody catalogs are unsanitized user input

Thermo Fisher antibody metadata manipulation is a supply chain attack against bioinformatics pipelines - not a data integrity issue. Here is the mechanism.

6 min read
CVE-2024-3400 shipped exploited before the advisory
vulnerability managementdetection engineering

CVE-2024-3400 shipped exploited before the advisory

Why the gap between CVE disclosure and production detection is structural - and where attackers operate inside it.

6 min read