RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

The extension on your dock just shipped malware
vscodesupply chain

The extension on your dock just shipped malware

A compromised VSCode extension reached GitHub. Breakdown of the trust boundary that failed and what developer endpoints actually expose.

7 min read
The watermark proves almost nothing useful
AI safetydigital forensics

The watermark proves almost nothing useful

OpenAI's adoption of Google's SynthID watermark is a useful but partial signal. Here's what it actually means for forensics and security teams.

6 min read
What a $5 VPS honeypot taught me
honeypotthreat intelligence

What a $5 VPS honeypot taught me

An open-source honeypot probe database queryable via curl, HTTP, and MCP - what it catches, why it helps small defenders, and where the risks actually sit.

6 min read
Your bot defenses just failed
board riskcontrol effectiveness

Your bot defenses just failed

A board-level view of how a stealth Playwright build erodes the assurance value of anti-bot and CAPTCHA controls across the business.

7 min read
Zero-click chains broke the user-in-the-loop model
zero-clickmalware

Zero-click chains broke the user-in-the-loop model

Zero-click malware does not need user action. It needs a reachable parser. What fails, why it fails, and what must be true.

6 min read
Baby monitors exposed one million streams
IoT securitybaby monitor exposure

Baby monitors exposed one million streams

One million baby monitors and cameras were viewable by unauthorised parties. What it reveals about IoT enforcement and the owner-side blindness behind it.

7 min read
BitLocker isn't protecting what you think
bitlockerencryption

BitLocker isn't protecting what you think

A systems-level look at what a BitLocker backdoor claim actually means for enterprise security, and how to respond without panic or dismissal.

6 min read
CISA contractor leaked GovCloud keys to GitHub
aws-govcloudsupply-chain-security

CISA contractor leaked GovCloud keys to GitHub

Technical analysis of a CISA contractor's leaked AWS GovCloud admin keys on GitHub - blast radius, IAM persistence paths, CloudTrail detections, supply-chain tail.

6 min read
Contractor pushed the boundary keys
govcloudcredential exposure

Contractor pushed the boundary keys

A CISA contractor pushed AWS GovCloud admin keys to a public GitHub repo. The credential format, not the contractor, is the failed control.

6 min read
Hugging Face revived PapersWithCode in early 2025
LLM engineeringAI infrastructure

Hugging Face revived PapersWithCode in early 2025

Hugging Face's PapersWithCode revival restores the verification substrate LLM engineering teams lost, reshaping pipelines and AI workforce roles.

8 min read
I built Burp Suite in Rust
burp suiteweb security

I built Burp Suite in Rust

Technical breakdown of an open-source Burp Suite alternative - proxy core, fuzzer, scanner depth, Collaborator gap, and what it means for vuln research.

6 min read
Mandiant clocked exploit window at 21 days
vulnerability managementpatch sla

Mandiant clocked exploit window at 21 days

Mean time-to-exploit is 21 days. Vulnerability programs built on 30, 60, or 90 day SLAs are no longer enforced inside the threat window.

7 min read