RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

Face ID was never the control
face id bypassbiometric security

Face ID was never the control

A reported Face ID bypass via avatar collapses the liveness assumption. Every downstream control trusting the boolean inherits the failure.

7 min read
Fragnesia is already loose
fragnesialinux privilege escalation

Fragnesia is already loose

Fragnesia Linux privilege escalation has a public PoC. The kernel trust boundary is conditional on patch state. What must now be true.

8 min read
Kernel bug leaks the SSH host key file
linux kernelssh security

Kernel bug leaks the SSH host key file

A Linux kernel flaw disclosed this month can expose SSH host keys. What failed, what it exposes, and what operators must now make true.

7 min read
Microsoft confirms Exchange zero-day under active exploitation
exchange zero-daymicrosoft exchange

Microsoft confirms Exchange zero-day under active exploitation

Microsoft confirmed an Exchange zero-day under active exploitation. Operator-level analysis of what failed, what is exposed, and what must now be true.

7 min read
NGINX rewrite module bleeds memory
nginxcve-2026-42945

NGINX rewrite module bleeds memory

CVE-2026-42945 places a heap buffer overflow inside NGINX's rewrite module, on the request path. Defect class confirmed. Impact not confirmed.

7 min read
Patched Microsoft is still exploitable Microsoft
pwn2ownmicrosoft exchange

Patched Microsoft is still exploitable Microsoft

Exchange and Windows 11 were exploited on day two of Pwn2Own. Operator briefing on what is confirmed, what is not, and what must change.

6 min read
Stealth Playwright breaks your bot detection
cybersecurityred-team

Stealth Playwright breaks your bot detection

A circulating stealth Playwright Firefox build is reported to pass antibot and captcha, exposing the limits of any control that delegates verification to the client.

6 min read
Stop counting findings
pentestpenetration testing

Stop counting findings

Pentest reports are calibrated to finding count, not exploitability. The metric the buyer evaluates becomes the work product.

6 min read
The malware leaked itself, not the defenders.
cryptostealermalware analysis

The malware leaked itself, not the defenders.

Needle cryptostealer shipped with a plaintext API key in the Rust binary. One string exposed 1932 victims and the withdrawal config.

6 min read
The patch is the payload
linux kernelprivilege escalation

The patch is the payload

Three critical Linux kernel LPE findings in two weeks, one introduced by a fix. The defect is the patch pathway, not the bug.

8 min read
Third party broke kernel LPE embargo
kernel-securityvulnerability-disclosure

Third party broke kernel LPE embargo

A kernel LPE entered public circulation when a third party broke the disclosure embargo. The control under review was the agreement, not the patch.

7 min read
Attacker code ran on Foxconn's floor
ransomwarefoxconn

Attacker code ran on Foxconn's floor

Foxconn ransomware breakdown: what failed, why scale is not a control, and why continuous validation of identity and execution is the only defence.

6 min read