Articles
Long-form writing on tech, culture, and the edges of the internet.
A postcard breached a warship
A 5 dollar Bluetooth tracker hidden in a postcard broadcast a 585 million dollar warship's position for 24 hours. The control that failed was classification.
Binding 65535 ports is the easy part
Architecture and evasion realities of an LLM honeypot binding all 65535 ports - TPROXY, latency tiers, fingerprint defence, and detection traps.
CISA flagged a 17-year-old Excel flaw
A 17 year old Excel flaw is being actively exploited and flagged by US cyber defence. Operator analysis of what failed, why, and what must change.
Engineering teams keep granting agents production database writes
AI agent vulnerabilities are systems engineering failures, not security failures. The fix is architectural containment, not better prompts or guardrails.
Itron's 8-K names an IT intrusion
Itron disclosed an internal IT breach. Technical analysis of attack vectors, supply chain blast radius, and what utility defenders should assume.
Kuwait put a listening post in your pocket
Kuwait's mandated cybersecurity app is not a privacy issue. It is surveillance architecture that relocates the identity boundary inside the device.
Lagos published guidelines, not controls
Lagos cybersecurity guidelines describe intent, not enforcement. An operator analysis of why policy without system-level controls does not stop attackers.
License audit caught a six-week account takeover
A six-week account takeover surfaced in a license audit that never checked access legitimacy. Why that gap is a control failure, not a breach.
Pick offense or defense
Two paths into infosec - offense and defense - broken down at the mechanism level. Foundation, tooling, telemetry, and the divergence point.
The helpdesk chat window is the breach
Microsoft Teams helpdesk impersonation succeeds because identity verification is placed at the channel boundary, not at the credential action.
The power adapter was the attack
A WiFi camera concealed in a hotel power adapter transmitted to a foreign server. The boundary failed at the physical layer.
Your CAC has never checked who you are
A CAC verifies a certificate's cryptographic validity, not the person holding it. How trust delegation and assumption drift open the gap in DoD PKI.