Articles
Long-form writing on tech, culture, and the edges of the internet.
Meta paused employee tracking after its own leak
Meta paused an internal employee tracking program after a data leak. The access boundary around the collected data was set at the program, not the identity.
No patch is coming for this
usbliter8 is a critical SecureROM defect on Apple A12 and A13 silicon. Read-only memory means it cannot be patched at the anchor. What that now requires.
OpenSSH turns every authenticated session into a pivot
How SSH local, remote, and dynamic port forwarding becomes pivot infrastructure for lateral movement and exfiltration, and what it leaves in telemetry.
Ransomware spreading through trusted accounts
A novel ransomware variant spread through compromised accounts, exposing identity - not the perimeter - as the boundary that must be enforced at runtime.
Seven years after checkm8, the A12 falls too
Usbliter8 is a SecureROM boot exploit for A12/A13 iPhones. What it can and cannot do, who it threatens, and how to reduce your exposure.
Someone else's hand pulled the plug on Mythos
NSA lost Mythos access through a vendor dispute, not a breach. The failure is a single-vendor enforcement point that can be revoked without intrusion.
The locked printer still phones home
AB 2047 restricts who may hold a 3D printer but leaves firmware, update, and network trust unverified. A custody control acting on the wrong layer.
The most expensive incident this year stole nothing.
A Codex logging defect can write terabytes to local SSDs, turning a function assumed low-consequence into a board-level availability and cost exposure.
The patch opens the attack window.
The Coming Loop is the collapsing gap between vulnerability disclosure and mass exploitation of internet-facing appliances - and why edge telemetry stays blind.
Better models won't fix your AI failures
A Google engineer was fired over a working Workspace CLI. The real failure: no operational layer to absorb the AI capability employees already build.
DayBreak doesn't make your systems vulnerable
A capable security model like DayBreak doesn't add new risk - it exposes that your agent controls were calibrated for a model too weak to exploit them.
Europol's second database ran unwatched for years
A board-level analysis of Europol's unsafeguarded secondary database and the European Commission oversight gap that did not constrain it for years.