RC RANDOM CHAOS
RC RANDOM CHAOS

Tech · Culture · Fiction

Meta paused employee tracking after its own leak Article

Meta paused employee tracking after its own leak

Meta paused an internal employee tracking program after a data leak. The access boundary around the collected data was set at the program, not the identity.

The most expensive incident this year stole nothing.
Article operational risk

The most expensive incident this year stole nothing.

A Codex logging defect can write terabytes to local SSDs, turning a function assumed low-consequence into a board-level availability and cost exposure.

DayBreak doesn't make your systems vulnerable
Article AI agent security

DayBreak doesn't make your systems vulnerable

A capable security model like DayBreak doesn't add new risk - it exposes that your agent controls were calibrated for a model too weak to exploit them.

Europol's second database ran unwatched for years
Article europol

Europol's second database ran unwatched for years

A board-level analysis of Europol's unsafeguarded secondary database and the European Commission oversight gap that did not constrain it for years.

GLM-5.2 binds to a port and opens a shell
Article local LLM security

GLM-5.2 binds to a port and opens a shell

Running GLM-5.2 locally stands up a network service with host execution. The failure is untrusted input reaching an unbounded execution context.

SIGGRAPH 2023 shipped an unfuzzed ingest path
Article gaussian splatting

SIGGRAPH 2023 shipped an unfuzzed ingest path

Gaussian splats don't break browser memory protection. Their untrusted parsers do: integer overflow to OOB write in splat viewers, CWE-190 into CWE-787.

The 9.x exposure with nothing to patch
Article data leak

The 9.x exposure with nothing to patch

Why exposed DigitalOcean data needs no exploit, what defenders miss in telemetry, and how to escalate a leak responsibly.

The Wire — latest

All →

Stay in the loop

New writing delivered when it's ready. No schedule, no spam.