RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

Mandiant clocked 5 days in 2023
vulnerability-researchn-day-exploitation

Mandiant clocked 5 days in 2023

Mean time-to-exploit for critical CVEs has collapsed to days. The mechanism is patch diffing, n-day industrialisation, and telemetry gaps on appliances.

6 min read
Microsoft's patch cadence is not the problem
microsoft exchangezero-day

Microsoft's patch cadence is not the problem

The Exchange zero-day is the fifth in the same pattern since 2021. Why patching faster is not the fix, and what actually reduces blast radius.

6 min read
Mid-2024: a drunk LLM found a ksmbd kernel bug
linux kernelllm security

Mid-2024: a drunk LLM found a ksmbd kernel bug

How researchers used degraded LLM prompts to find a remote OOB write in the Linux kernel's ksmbd module, and what it means for kernel security.

6 min read
NGINX ships emergency patch for HTTP/3 heap overflow
nginxcve-2026-42945

NGINX ships emergency patch for HTTP/3 heap overflow

CVE-2026-42945 technical analysis: heap overflow in NGINX HTTP/3 HEADERS frame parsing, worker RCE primitive, telemetry gaps, and patch boundary.

6 min read
Patching nginx doesn't close this one
CVE-2026-42945NGINX

Patching nginx doesn't close this one

CVE-2026-42945 NGINX rewrite module heap buffer overflow: bug mechanism, exploit primitives, MITRE mapping, and EDR telemetry blind spots in worker exploitation.

6 min read
Russian hands on Polish water valves
critical infrastructureboard governance

Russian hands on Polish water valves

A board-level read on Russian-linked activity against Polish water utilities and what it means for directors governing critical services.

8 min read
Your MFA assurance just expired
board governanceauthentication risk

Your MFA assurance just expired

A board-level position on AI-developed 2FA bypass: reduced authentication assurance, category-level exposure, and the conditions required going forward.

8 min read
A new tool is not a replacement
burp suiteopen source security tools

A new tool is not a replacement

An open-source Burp alternative was built. Capability, stability, and handling of intercepted material are not confirmed. Verify before adoption.

5 min read
AI just broke 2FA at scale
2fa bypassai threats

AI just broke 2FA at scale

AI was used to develop a zero-day 2FA bypass deployed at mass scale. The control's economic assumption has been falsified in the wild.

7 min read
arXiv just raised the bar
LLM engineeringAI validation

arXiv just raised the bar

arXiv's one-year ban on unchecked LLM errors signals a shift: validation pipelines, not better prompts, now define competent AI systems.

11 min read
Attackers weaponized AI to bypass 2FA at scale
2fa bypassidentity security

Attackers weaponized AI to bypass 2FA at scale

A reported AI-developed zero-day 2FA bypass in mass use removes the assumption that 2FA terminates the account takeover chain.

7 min read
Complexity theory never said that
LLM engineeringAI systems design

Complexity theory never said that

Complexity theory does not prove human-level ML is impossible. Here is what the theorems actually say and how to design AI systems around real constraints.

8 min read