RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

The smooth line hiding a noisy benchmark
AI benchmarksLLM engineering

The smooth line hiding a noisy benchmark

The METR AI time horizons graph contains structural errors that mislead teams building agents, automation, and AI workflows. Here is what it actually shows.

9 min read
The WhatsApp breach was not a breach
whatsappcontact-discovery

The WhatsApp breach was not a breach

Technical analysis of the WhatsApp dataset incident: contact discovery oracle abuse, rate-limit bypass, MITRE T1589.002, and the downstream attack surface.

6 min read
Willison's lethal trifecta exfiltrates Claude uploads
prompt injectionLLM security

Willison's lethal trifecta exfiltrates Claude uploads

Technical analysis of indirect prompt injection against Claude AI agents - exfiltration mechanics, ATT&CK mapping, telemetry gaps, residual exposure.

6 min read
Your file renames are a security control
cybersecurity governancevulnerability management

Your file renames are a security control

CVE-2025-48095 in 7-Zip exposes the governance gap around utility software that processes untrusted input without formal ownership or version control.

7 min read
Your SSD is leaking what you're doing
cybersecurityprivacy

Your SSD is leaking what you're doing

How websites can use SSD response timing as a covert channel to infer user activity, and what browsers and users can do about it.

7 min read
Your VPN extension trusts every website you visit
browser securityvpn

Your VPN extension trusts every website you visit

A hardcoded trigger word in a million-install Chrome VPN extension let any website disable the tunnel, change exit nodes, and read open tabs.

6 min read
YouTube built a checkbox, not a detector
deepfakesyoutube

YouTube built a checkbox, not a detector

YouTube's automatic AI-generated video label is a disclosure system, not a detector. Here's what it actually does for cybersecurity and what it doesn't.

6 min read
94GB sits on a leak site
ShinyHuntersdata breach

94GB sits on a leak site

ShinyHunters published a 94GB dataset tied to 7-Eleven franchisee systems after extortion refusal. What failed, why, and what must now be true.

7 min read
A renamed file walks past the heap boundary
7-ZipCVE-2026-48095

A renamed file walks past the heap boundary

CVE-2026-48095 is a 7-Zip NTFS heap overflow triggered through renamed files. Operator breakdown of what failed, why, and what must now be true.

7 min read
Biometrics outlive the breach
biometric datavendor risk

Biometrics outlive the breach

Biometric data held by identity verification providers is non-revocable; board exposure persists regardless of any confirmed incident.

8 min read
CISA administrator published GovCloud keys to GitHub
GovCloudaccess control

CISA administrator published GovCloud keys to GitHub

A CISA administrator's publication of AWS GovCloud keys to public GitHub exposes the gap between cloud segregation policy and runtime control.

8 min read
Franchises leak because franchises federate
shinyhuntersretail-security

Franchises leak because franchises federate

ShinyHunters leaked 94GB from a 7-Eleven franchisee after extortion refusal. The structural reasons franchise retail keeps ending up in leak listings.

6 min read