RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

A project name is not a threat model
project glasswingsecurity reporting

A project name is not a threat model

Project Glasswing has been named but not defined. Without stated scope, identity model, or controls, no security assessment is possible.

5 min read
CISA is holding the leak with its hands
CISAdata leak

CISA is holding the leak with its hands

CISA is in containment mode after a data leak. What containment actually means, what failed, and why the assurance claim is now suspended.

7 min read
Deleting the link does not recall the file
access controldata exposure

Deleting the link does not recall the file

A file accessible without authentication is a file in distribution. Removing the link does not revoke access already granted.

7 min read
FaceTec stores non-rotatable identity material
biometric-securityidentity-verification

FaceTec stores non-rotatable identity material

A senior operator's position on the storage of non-rotatable biometric templates by ID verification vendors, and the exposure that condition creates.

7 min read
Harvard.edu among 141 hosts serving ClickFix lures
web-compromiseseo-poisoning

Harvard.edu among 141 hosts serving ClickFix lures

Technical analysis of the campaign that weaponised harvard.edu and 140 other legitimate sites - entry vectors, TDS chain, MITRE mapping, EDR telemetry.

6 min read
Malicious VSCode extension shipped through official Marketplace
supply chainvscode

Malicious VSCode extension shipped through official Marketplace

Technical analysis of a compromised VSCode extension reaching GitHub credentials: extension host privileges, MITRE ATT&CK mapping, telemetry gaps.

6 min read
Megalodon hijacked 55,000 GitHub repos via token replay
github-securitysupply-chain

Megalodon hijacked 55,000 GitHub repos via token replay

Megalodon compromised 55,000+ GitHub repositories through PAT harvesting, pull_request_target abuse, and OAuth scope inheritance. Technical breakdown.

7 min read
The sandbox was never the hard part
CVE-2026-40369Chromium

The sandbox was never the hard part

CVE-2026-40369 is a 12-byte Mojo IPC overflow in Chromium that converts renderer RCE into browser-process code execution on the host.

6 min read
Your valid credentials are the breach.
supply-chaingithub-actions

Your valid credentials are the breach.

Technical analysis of a coordinated GitHub Actions workflow compromise across 5,561 repositories, with detection guidance for audit log and EDR telemetry.

6 min read
AI is making attackers worse, not better.
AI securitythreat intelligence

AI is making attackers worse, not better.

Defender telemetry through 2026 shows model-mediated attackers produce more volume, less variance, weaker adaptation. Substitution is not uplift.

6 min read
CVSS 5.5 is lying to you
linux kernelprivilege escalation

CVSS 5.5 is lying to you

A nine-year-old Linux kernel flaw enables root command execution. CVSS 5.5 understates the outcome. Patch scope and operator action.

7 min read
GitHub shipped optional hardening as a control
github breachidentity security

GitHub shipped optional hardening as a control

The GitHub breach follows a documented class of failure. The mechanism is identity issuance separated from validation. The industry chose documentation over enforcement.

6 min read