RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

The door Mythos left unlocked
privileged accessidentity boundary

The door Mythos left unlocked

Mythos is an identity management failure. Privileged access boundaries were not enforced. Lateral movement reached sensitive data.

5 min read
Typosquatted Microsoft AI packages harvest developer credentials
supply-chaincredential-theft

Typosquatted Microsoft AI packages harvest developer credentials

How attackers weaponised typosquatted Microsoft AI tooling to harvest OpenAI, HuggingFace, AWS, and Azure credentials from developer workstations.

6 min read
Your CA just picked sides
lets-encryptcertificate-authority

Your CA just picked sides

Let's Encrypt restricts certificate issuance in US sanctioned territories. The CA is now conditional. Operator response and dependency inventory required.

7 min read
Your supply chain isn't compromised. It's working.
supply chainpackage registry

Your supply chain isn't compromised. It's working.

Microsoft's open-source developer tools executed credential-stealing code through normal package resolution. The control plane never inspected what was returned.

7 min read
Antibody catalogs are unsanitized user input
supply chainbioinformatics security

Antibody catalogs are unsanitized user input

Thermo Fisher antibody metadata manipulation is a supply chain attack against bioinformatics pipelines - not a data integrity issue. Here is the mechanism.

6 min read
CVE-2024-3400 shipped exploited before the advisory
vulnerability managementdetection engineering

CVE-2024-3400 shipped exploited before the advisory

Why the gap between CVE disclosure and production detection is structural - and where attackers operate inside it.

6 min read
Cypherpunk frees the key schedule twice
use-after-freecryptographic-libraries

Cypherpunk frees the key schedule twice

UAF in the Cypherpunk Library's context teardown - CWE-416, heap reuse, sandbox-free RCE path, and why EDR misses the corruption stage.

6 min read
Massachusetts bans precise geolocation sales
privacy legislationlocation data

Massachusetts bans precise geolocation sales

Massachusetts banned the sale of precise location data. The statute kills a commercial attack vector and creates real telemetry gaps for defenders.

6 min read
Motorola bricked your routers
vendor riskthird-party governance

Motorola bricked your routers

A board-level read on the Motorola router event: vendor authority over fielded equipment is a primary risk vector, and silence is the visible control failure.

9 min read
NovaMind reframes breach disclosure as system design
incident responsebreach disclosure

NovaMind reframes breach disclosure as system design

After a thousand breaches, the gap between compromise and disclosure is widening. The fix is treating disclosure as a pipeline, not a crisis.

9 min read
Pentagon raises Israel espionage threat to highest level
board governancecounterintelligence risk

Pentagon raises Israel espionage threat to highest level

The Pentagon's elevated Israeli espionage threat exposes how access controls built on allied trust drift silently from current risk posture.

7 min read
Texas data centers failed the voltage test
identity-boundaryaccess-control

Texas data centers failed the voltage test

Texas grid voltage failures at data center and crypto sites expose the same admission-without-enforcement gap every identity boundary already has.

7 min read