RC RANDOM CHAOS

detection engineering

84 posts

ScStoragePathFromUrl overflows the stack on PROPFIND
Article

ScStoragePathFromUrl overflows the stack on PROPFIND

CVE-2017-7269 turns an unpatched IIS 6.0 WebDAV server into pre-auth RCE. The exploit primitive, the telemetry blind spot, and the residual exposure.

GrapheneOS Android 17 degrades every exploit primitive
Article

GrapheneOS Android 17 degrades every exploit primitive

GrapheneOS's Android 17 port: how sync MTE, hardened_malloc, and a hardened kernel degrade mobile exploit chains-and why failed attempts are the loudest telemetry.

Removing curl and wget stops nothing
Article

Removing curl and wget stops nothing

Bash /dev/tcp opens TCP sockets and sends HTTP with no curl or wget, evading process-name detection while leaving cleartext on the wire.

Contagious Interview ends at npm install
Article

Contagious Interview ends at npm install

How DPRK actors turn LinkedIn job offers into code execution via npm postinstall hooks, what BeaverTail steals, and why developer endpoints stay blind.

NetScaler trusts snprintf, leaks adjacent heap memory
Article

NetScaler trusts snprintf, leaks adjacent heap memory

Why 'silent' vulnerabilities like Citrix Bleed (CVE-2023-4966) are already exploited at the network edge, what they produce in telemetry, and where defenders are blind.

Ring 0, fed a stranger's save file
Article

Ring 0, fed a stranger's save file

The US directive suspending Fable 5 and Mythos 5, analyzed: why game clients are privileged code, how asset and netcode bugs work, and why trust is the flaw.

OpenCV 5.0 made adversarial perturbations transferable
Article

OpenCV 5.0 made adversarial perturbations transferable

OpenCV 5's bit-exact numerics and expanded encoder control shrink the attacker's modelling error against deepfake detectors. The exposure is structural.

Sixty-three days to patch a forked parser
Article

Sixty-three days to patch a forked parser

Technical breakdown of the FrontierOS RCE: a forked XML parser, an unpatched two-year-old CVE, and the fork-tracking failure that shipped it.

CVE-2024-3400 shipped exploited before the advisory
Article

CVE-2024-3400 shipped exploited before the advisory

Why the gap between CVE disclosure and production detection is structural - and where attackers operate inside it.

Cypherpunk frees the key schedule twice
Article

Cypherpunk frees the key schedule twice

UAF in the Cypherpunk Library's context teardown - CWE-416, heap reuse, sandbox-free RCE path, and why EDR misses the corruption stage.

The integration is the attack surface
Article

The integration is the attack surface

Pentagon raised Israeli collection risk to top tier. The technical exposure is supply chain privilege inherited from vendor software, not espionage.

The .docx in your webmail preview pane
Article

The .docx in your webmail preview pane

Browser-side OOXML rendering converts trusted document parsers into renderer-context exploit primitives. The detection stack does not see the boundary cross.