Tech · Culture · Fiction
Article CVE-2026-3854 puts GitHub inside your trust boundary
CVE-2026-3854 enables RCE on GitHub.com and Enterprise Server. Why platform compromise becomes customer compromise across identity, secrets, and artefacts.
A postcard breached a warship
A 5 dollar Bluetooth tracker hidden in a postcard broadcast a 585 million dollar warship's position for 24 hours. The control that failed was classification.
Binding 65535 ports is the easy part
Architecture and evasion realities of an LLM honeypot binding all 65535 ports - TPROXY, latency tiers, fingerprint defence, and detection traps.
CISA flagged a 17-year-old Excel flaw
A 17 year old Excel flaw is being actively exploited and flagged by US cyber defence. Operator analysis of what failed, why, and what must change.
Engineering teams keep granting agents production database writes
AI agent vulnerabilities are systems engineering failures, not security failures. The fix is architectural containment, not better prompts or guardrails.
Lagos published guidelines, not controls
Lagos cybersecurity guidelines describe intent, not enforcement. An operator analysis of why policy without system-level controls does not stop attackers.
Pick offense or defense
Two paths into infosec - offense and defense - broken down at the mechanism level. Foundation, tooling, telemetry, and the divergence point.
The Wire — latest
All →- AI Agent Surfaces 38 Bugs in OpenEMR, Exposing Health Record Attack Surface
- AI-Assisted Reverse Engineering Surfaces High-Severity GitHub Flaw
- Anthropic's Mythos Disclosure Rattles Japanese Financial Sector
- Compromised SAP-linked npm packages exfiltrate developer credentials
- cPanel Auth Bypass Flaw Lets Attackers Hijack Hosting Servers — Patch Now
- cPanel/WHM emergency patch closes 9.8-severity auth bypass in hosting control panels
- DPRK Operators Lean on AI-Generated npm Payloads and Shell Companies in Latest Campaign
- Exposure management platforms: what buyers should demand vs. what vendors actually ship
- Iran strikes on AWS facilities push Pure DC to freeze Gulf data center buildout
- Judge rejects Bankman-Fried's bid for new trial, calls conspiracy theory baseless
Stay in the loop
New writing delivered when it's ready. No schedule, no spam.