RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

Cooldown does not fix the resolver
supply-chainruby

Cooldown does not fix the resolver

Bundler 2.6 cooldown defers new gem versions to interrupt published-and-pulled supply chain attacks. The resolver's trust model is the systemic exposure.

6 min read
Editorial independence is a failed control
supply chain securitythreat intelligence

Editorial independence is a failed control

UK media failed to disclose defence sector ties in nearly 60 percent of cases. The disclosure gap is an information supply chain vulnerability - and it is exploitable.

6 min read
Europe maps GNSS jammers mid-attack
GNSS interferencelocation-based security

Europe maps GNSS jammers mid-attack

Powerful GNSS interference over Europe exposes location-based controls as ineffective. Unauthenticated positional data is not a security boundary.

6 min read
Korea's KCSC mandates server-side image parsers
vulnerability-researchimage-processing

Korea's KCSC mandates server-side image parsers

Korea's mandatory AI image scanning forces every forum into a multi-layer parser and ML pipeline. The CVE surface and exploitation paths that result.

7 min read
memcpy walks off the end of the receiver
rsyncCVE-2024-12084

memcpy walks off the end of the receiver

rsync shipped six CVEs in January 2025. LLMs did not write new bugs - they compressed variant discovery, harness generation, and vulnerable deployment.

6 min read
Meta enabled ADB on deprecated Portals
identity managementlifecycle policy

Meta enabled ADB on deprecated Portals

Meta enabled ADB on deprecated Portal devices. Lifecycle status was decoupled from access surface. The mechanism, the pattern, and the operator position.

6 min read
Meta ships ADB-enabled firmware to deprecated Portals
portalmeta

Meta ships ADB-enabled firmware to deprecated Portals

Meta deprecated Portal devices with ADB enabled and patches stopped. Unpatched Android cameras and microphones now sit as permanent network exposure.

7 min read
Meta's chatbot handed out accounts
identity-managementai-security

Meta's chatbot handed out accounts

Meta confirmed thousands of Instagram accounts compromised via AI chatbot abuse. The chatbot was treated as a boundary it could not hold.

7 min read
Netherlands restricts DigiD to European operator
identitysupply-chain

Netherlands restricts DigiD to European operator

Dutch government restricts DigiD operation to a European vendor. Jurisdiction changes. The single-vendor identity concentration risk does not.

6 min read
One vendor, one subpoena, one reach
cloudflarevoidzero

One vendor, one subpoena, one reach

Cloudflare's VoidZero acquisition collapses the vendor boundary between build tooling and edge runtime. Attestation reduces to self-reporting.

6 min read
Spanish police flagged GrapheneOS as suspicion
grapheneosthreat-intelligence

Spanish police flagged GrapheneOS as suspicion

Authorities treating GrapheneOS as a targeting signal inverts threat intel logic and exposes the wrong population to scrutiny. The mechanism breakdown.

6 min read
Switching payment processors is a security event
payment securityidentity boundary

Switching payment processors is a security event

Gov.uk replaced Stripe with Adyen. The processor moved. The trust boundary moved. What that means for identity, access, and control enforcement.

7 min read