RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

Meta paused employee tracking after its own leak
identity-access-managementdata-leak

Meta paused employee tracking after its own leak

Meta paused an internal employee tracking program after a data leak. The access boundary around the collected data was set at the program, not the identity.

7 min read
No patch is coming for this
secureroma12-a13

No patch is coming for this

usbliter8 is a critical SecureROM defect on Apple A12 and A13 silicon. Read-only memory means it cannot be patched at the anchor. What that now requires.

8 min read
OpenSSH turns every authenticated session into a pivot
ssh-tunnelinglateral-movement

OpenSSH turns every authenticated session into a pivot

How SSH local, remote, and dynamic port forwarding becomes pivot infrastructure for lateral movement and exfiltration, and what it leaves in telemetry.

7 min read
Ransomware spreading through trusted accounts
ransomwareidentity security

Ransomware spreading through trusted accounts

A novel ransomware variant spread through compromised accounts, exposing identity - not the perimeter - as the boundary that must be enforced at runtime.

7 min read
Seven years after checkm8, the A12 falls too
iPhone securitySecureROM

Seven years after checkm8, the A12 falls too

Usbliter8 is a SecureROM boot exploit for A12/A13 iPhones. What it can and cannot do, who it threatens, and how to reduce your exposure.

7 min read
Someone else's hand pulled the plug on Mythos
single-vendor dependencylayered defense

Someone else's hand pulled the plug on Mythos

NSA lost Mythos access through a vendor dispute, not a breach. The failure is a single-vendor enforcement point that can be revoked without intrusion.

7 min read
The locked printer still phones home
3d-printer-securityfirmware-trust

The locked printer still phones home

AB 2047 restricts who may hold a 3D printer but leaves firmware, update, and network trust unverified. A custody control acting on the wrong layer.

8 min read
The most expensive incident this year stole nothing.
operational risksystem availability

The most expensive incident this year stole nothing.

A Codex logging defect can write terabytes to local SSDs, turning a function assumed low-consequence into a board-level availability and cost exposure.

7 min read
The patch opens the attack window.
vulnerability-managementmass-exploitation

The patch opens the attack window.

The Coming Loop is the collapsing gap between vulnerability disclosure and mass exploitation of internet-facing appliances - and why edge telemetry stays blind.

6 min read
Better models won't fix your AI failures
enterprise AIshadow IT

Better models won't fix your AI failures

A Google engineer was fired over a working Workspace CLI. The real failure: no operational layer to absorb the AI capability employees already build.

12 min read
DayBreak doesn't make your systems vulnerable
AI agent securityLLM orchestration

DayBreak doesn't make your systems vulnerable

A capable security model like DayBreak doesn't add new risk - it exposes that your agent controls were calibrated for a model too weak to exploit them.

10 min read
Europol's second database ran unwatched for years
europoloversight failure

Europol's second database ran unwatched for years

A board-level analysis of Europol's unsafeguarded secondary database and the European Commission oversight gap that did not constrain it for years.

8 min read