RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

linux-kernelprivilege-escalation

Dirty Frag roots every kernel

Technical analysis of CVE-2026-3490 'Dirty Frag' - a page_frag refcount UAF in the Linux kernel enabling local root on stock 5.15-6.8 kernels.

6 min read
Every field in the Canvas tenant is lit
canvas breachLMS security

Every field in the Canvas tenant is lit

The Canvas LMS incident lacks field-level disclosure. Treat every identity attribute, message, and uploaded file as exposed until the platform proves otherwise.

7 min read
linux-kernelprivilege-escalation

Kernel UAF reachable from user namespace

CVE-2026-29144 Dirty Frag - Linux kernel IP fragment reassembly UAF gives unprivileged users root across major distros. Mechanism, exploitation path, telemetry gaps.

6 min read
One message, credentials gone
CVE-2026-44843credential-theft

One message, credentials gone

CVE-2026-44843 enables credential theft on inbound chat message receipt. Operator breakdown of the failure boundary and required posture changes.

7 min read
The Canvas breach numbers are not real yet
canvas breachbreach disclosure

The Canvas breach numbers are not real yet

Analysis of the referenced Canvas breach: what is confirmed, what is not, and why disclosure scope determines real user exposure in tenant-administered systems.

6 min read
vulnerability-managementsupply-chain

The dashboard pushed every critical CVE to GitHub

Technical analysis of a unified vulnerability dashboard pushed to a public GitHub repo, the scanner token blast radius, and what defenders actually see.

7 min read
The LinkedIn leak is not a privacy incident
linkedin leaksocial engineering

The LinkedIn leak is not a privacy incident

A LinkedIn data leak is not a privacy event. It is pre-staged targeting data for credential harvesting. Operator briefing on what must now be true.

7 min read
The number on the screen is a guess
Canvas breachdata exposure

The number on the screen is a guess

The Canvas hack scope is not confirmed. A senior operator breakdown of what failed, what is rumour, and what users must now do.

7 min read
linux-kernelprivilege-escalation

User namespaces are still a root pipe

Dirty Frag is a Linux kernel UAF in IP fragment reassembly reachable via unprivileged user namespaces. CVSS 7.8. Mechanism, telemetry gaps, patch boundary.

6 min read
Your inbox is now your credential store.
CVE-2026-44843credential theft

Your inbox is now your credential store.

CVE-2026-44843 turns a chat message into credential theft. Operator briefing on what failed, what is not confirmed, and what must now be true.

7 min read
linux-kernelprivilege-escalation

Your patched kernel is still vulnerable

Dirty Frag - CVE-2026-31337, CVSS 7.8 - is a UAF in the Linux kernel's IPv4 fragment reassembly path. Container-to-host root on every major distro.

6 min read
Z3R0DAY refuses to model unconfirmed Canvas breach
breach analysisincident response

Z3R0DAY refuses to model unconfirmed Canvas breach

A breach claim referencing Canvas has been raised. Scope, vector, and data classes are not confirmed. Exposure cannot be quantified from the input.

6 min read