RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

access governancehealthcare breach

The record count is not the breach

A board-level brief on the healthcare data breach: access governance did not hold at runtime, and assurance must now be proven, not assumed.

8 min read
board governancenation-state risk

US extradites alleged Chinese state hacker

An extradition in an alleged state-aligned cyber matter shifts the standard of care boards will be measured against in disclosure and litigation.

7 min read
Wiper hits Venezuelan cyberattack victims
wiper malwaredestructive attack

Wiper hits Venezuelan cyberattack victims

A wiper identified in the Venezuelan cyberattack resets the threat profile from intrusion to destruction. What failed, what it exposes, what must change.

7 min read
Your perimeter is not absorbing this
openemrcve disclosure

Your perimeter is not absorbing this

AISLE published 38 CVEs against OpenEMR. What the volume confirms, what remains unconfirmed, and what operators must verify per deployment.

6 min read
AI economicsLLM engineering

AI costs more than humans

Nvidia says AI costs more than human workers. The real issue is architecture, not compute price. Here is how to fix the unit economics.

9 min read
cat is now an exploit
MAD Bugsterminal security

cat is now an exploit

MAD Bugs establishes that cat readme.txt is not a passive read. The terminal is an interpreter and untrusted bytes are program input.

7 min read
Chat message steals your credentials
CVE-2026-44843credential theft

Chat message steals your credentials

CVE-2026-44843 reduces credential theft to message receipt. The failure is identity boundary enforcement, not chat parsing. Operator breakdown.

6 min read
Copilot's new 27x Opus multiplier breaks your budget
github copilotllm cost governance

Copilot's new 27x Opus multiplier breaks your budget

Copilot's 9x Sonnet and 27x Opus multipliers turned model selection into a governed engineering decision. Most teams have no routing layer.

8 min read
linux-kernelprivilege-escalation

CVE-2026-31337: Dirty Frag roots every major distro

Technical analysis of CVE-2026-31337 'Dirty Frag': a Linux kernel UAF in IP fragment reassembly giving local root across major distros.

5 min read
CVE-2026-44843 turns one message into credential theft
cve-2026-44843credential-theft

CVE-2026-44843 turns one message into credential theft

CVE-2026-44843 collapses the boundary between chat message receipt and credential disclosure. What failed, what is not confirmed, and what must change.

6 min read
linux-kernelprivilege-escalation

Dirty Frag roots every kernel

Technical analysis of CVE-2026-3490 'Dirty Frag' - a page_frag refcount UAF in the Linux kernel enabling local root on stock 5.15-6.8 kernels.

6 min read
Every field in the Canvas tenant is lit
canvas breachLMS security

Every field in the Canvas tenant is lit

The Canvas LMS incident lacks field-level disclosure. Treat every identity attribute, message, and uploaded file as exposed until the platform proves otherwise.

7 min read