RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

CISA admin pushed GovCloud keys to GitHub
cloud securityiam

CISA admin pushed GovCloud keys to GitHub

A CISA administrator committed AWS GovCloud credentials to GitHub. The failure is the issuance model, not the commit.

6 min read
CISA pushed GovCloud keys to GitHub
aws-govcloudcredential-leak

CISA pushed GovCloud keys to GitHub

Technical analysis of a CISA admin leaking AWS GovCloud keys on GitHub - exposure mechanics, CloudTrail detection paths, and residual session risk post-rotation.

6 min read
GitHub-distributed VSCode extension executed unsanctioned code
software supply chaindeveloper security

GitHub-distributed VSCode extension executed unsanctioned code

A board-level brief on the compromised VSCode extension distributed through GitHub: what it exposed, what control did not function, and what must be true.

8 min read
GitHub pulls the account, the repos live on
vulnerability disclosureplatform governance

GitHub pulls the account, the repos live on

A board-level analysis of GitHub's ban on a researcher publishing Windows zero-days alongside violent threats, and what it reveals about disclosure risk.

7 min read
ShinyHunters dumps 94GB of 7-Eleven franchisee data
shinyhuntersdata-extortion

ShinyHunters dumps 94GB of 7-Eleven franchisee data

ShinyHunters leaked 94GB of 7-Eleven franchisee data after extortion refusal. Technical analysis of TTPs, info-stealer-to-SaaS pipeline, and franchise IT exposure.

6 min read
The agent reads the page and obeys
AI agentsPlaywright

The agent reads the page and obeys

How Playwright-driven AI agents change the web's threat model: prompt injection, session hijacking, broken CAPTCHAs, and what to do this quarter.

6 min read
The refund letter addressed to Dear [Name]
LLM engineeringAI systems

The refund letter addressed to Dear [Name]

Why ChatGPT's first output is a draft, not a deliverable, and what production AI systems actually require beyond the prompt.

8 min read
The smooth line hiding a noisy benchmark
AI benchmarksLLM engineering

The smooth line hiding a noisy benchmark

The METR AI time horizons graph contains structural errors that mislead teams building agents, automation, and AI workflows. Here is what it actually shows.

9 min read
The WhatsApp breach was not a breach
whatsappcontact-discovery

The WhatsApp breach was not a breach

Technical analysis of the WhatsApp dataset incident: contact discovery oracle abuse, rate-limit bypass, MITRE T1589.002, and the downstream attack surface.

6 min read
Willison's lethal trifecta exfiltrates Claude uploads
prompt injectionLLM security

Willison's lethal trifecta exfiltrates Claude uploads

Technical analysis of indirect prompt injection against Claude AI agents - exfiltration mechanics, ATT&CK mapping, telemetry gaps, residual exposure.

6 min read
Your file renames are a security control
cybersecurity governancevulnerability management

Your file renames are a security control

CVE-2025-48095 in 7-Zip exposes the governance gap around utility software that processes untrusted input without formal ownership or version control.

7 min read
Your SSD is leaking what you're doing
cybersecurityprivacy

Your SSD is leaking what you're doing

How websites can use SSD response timing as a covert channel to infer user activity, and what browsers and users can do about it.

7 min read