RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

Torvalds declares Linux security list unmanageable
linux securityvulnerability disclosure

Torvalds declares Linux security list unmanageable

Linus Torvalds says AI bug hunters have made the Linux security list unmanageable. An operator read on what failed at the intake boundary.

7 min read
A few bytes spill onto the next heap chunk
nginxcve-2026-42945

A few bytes spill onto the next heap chunk

Technical writeup of CVE-2026-42945, the NGINX rewrite module heap overflow, plus what it means for LLM deployments sitting behind the proxy.

6 min read
A handle, a token, a SYSTEM shell
windows kerneltrust models

A handle, a token, a SYSTEM shell

MiniPlasma is not a kernel defect. It is the externally visible behaviour of a trust model that confuses reference with verification.

7 min read
An avatar walked through Face ID
biometric authenticationboard risk

An avatar walked through Face ID

A Face ID bypass using an avatar reduces the assurance of every business process that treats biometric success as proof of human presence.

8 min read
An NGINX worker just crashed in production
NGINXCVE-2026-42945

An NGINX worker just crashed in production

Board-level briefing on NGINX CVE-2026-42945: confirmed in-the-wild exploitation, edge exposure, control failure at runtime, and what must be established.

9 min read
Audi faces scrutiny over myAudi platform exposure
connected vehiclesboard governance

Audi faces scrutiny over myAudi platform exposure

A board-level view of the myAudi connected vehicle security concern: exposure, control failure, and the conditions directors must now enforce.

8 min read
?auth=YWRtaW46MTEK and a million open cameras
IoT securityCVE analysis

?auth=YWRtaW46MTEK and a million open cameras

Technical breakdown of the auth bypass, P2P relay, and default-credential failures that exposed over a million IP cameras and baby monitors.

6 min read
Better AI isn't what separates winning deployments.
AI deploymentLLM engineering

Better AI isn't what separates winning deployments.

Stanford studied 51 AI deployments and found a 71 vs 40 productivity gap. The difference was pipeline design, not model choice.

8 min read
Eight months building a Burp Suite replacement
open source security toolsburp suite alternative

Eight months building a Burp Suite replacement

An honest write-up of building Interceptor, an open-source Burp Suite alternative - license choices, attacker math, defender economics, and what got cut.

6 min read
Lapsus$ proved push bombing in 2022
MFA fatigueEntra ID

Lapsus$ proved push bombing in 2022

MFA fatigue attacks against Microsoft Authenticator: T1621 mechanics, number matching, AiTM proxy gaps, token theft, and the Entra ID telemetry that catches it.

6 min read
Linux security intake is overwhelmed
Linux kernelvulnerability disclosure

Linux security intake is overwhelmed

Linus Torvalds says AI-generated reports have made the Linux kernel security list almost entirely unmanageable. A board-level read on the exposure.

9 min read
LLM agent shipped first attributed zero-day
2FA bypasszero-day

LLM agent shipped first attributed zero-day

Technical breakdown of the first AI-discovered zero-day 2FA bypass: state-confusion in IdP step-three cookie issuance, exploit path, and detection gaps.

6 min read