RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

Meta's chatbot worked exactly as designed.
AI securityidentity systems

Meta's chatbot worked exactly as designed.

Meta's AI chatbot enabled mass Instagram account takeover by resolving conversational framing into identity actions through sanctioned internal workflows.

7 min read
Motorola signed its own kill switch
firmware-securitysupply-chain

Motorola signed its own kill switch

Motorola's silent firmware push bricked its WiFi router line. The mechanism is identical to AcidRain. Here is what failed and why it repeats.

6 min read
Nothing broke when your router died
delegated trustsystems failure analysis

Nothing broke when your router died

Motorola's routers stopped as a class not from damage but because every device resolved a shared reference that no longer meant what it once did.

8 min read
Q1 2026: Iranian crews living off P2P
p2p-abuseaccount-takeover

Q1 2026: Iranian crews living off P2P

Compromised P2P accounts are driving lateral movement and exfiltration in Israeli orgs. The fabric, not the platform, is the C2 channel.

6 min read
Steam's I/O thread is holding a dead pointer
vulnerability researchmemory corruption

Steam's I/O thread is holding a dead pointer

Transport-layer race condition in Valve's GameNetworkingSockets creates a remote UAF primitive that sits below session crypto and evades EDR telemetry.

6 min read
The 64KB segment where every overflow rewrote a free list pointer
memory corruptionheap exploitation

The 64KB segment where every overflow rewrote a free list pointer

Win16's Local Heap overflow defines the metadata corruption class that still drives modern browser and kernel exploitation in 2026.

5 min read
The chatbot answered the door for attackers
prompt-injectioninstagram

The chatbot answered the door for attackers

Meta's Instagram chatbot abuse case is a prompt injection and confused deputy failure. Technical breakdown of the vector, telemetry gap, and residual exposure.

6 min read
The .docx in your webmail preview pane
ooxmlbrowser-security

The .docx in your webmail preview pane

Browser-side OOXML rendering converts trusted document parsers into renderer-context exploit primitives. The detection stack does not see the boundary cross.

6 min read
There is no Linear kernel CVE
linearsaas-security

There is no Linear kernel CVE

Linear's speed comes from a local-first sync engine, not a kernel-memory exploit. The fabricated CVE framing is wrong. The real exposure is elsewhere.

6 min read
Thirty years of weaponizing fork-exec
linux-securityprocess-injection

Thirty years of weaponizing fork-exec

fork+exec inherits file descriptors, environment, and capabilities by default. That inheritance is the bug class behind Shellshock, runc CVE-2019-5736, and Symbiote.

6 min read
A binary that hands kernel hooks to anyone
ebpfzeroserve

A binary that hands kernel hooks to anyone

Zeroserve packages kernel-adjacent execution surface under userspace pipelines. The artifact crosses a privilege boundary the pipeline was not scoped to see.

7 min read
Contractor PAT leaked 270GB of Times source
supply chain securitycredential exposure

Contractor PAT leaked 270GB of Times source

The 2024 NYT source code leak was not a credential breach. It was a credential sprawl chain. The mechanism, telemetry gaps, and what still applies.

6 min read