Articles
Long-form writing on tech, culture, and the edges of the internet.
CISA admin pushed GovCloud keys to GitHub
A CISA administrator committed AWS GovCloud credentials to GitHub. The failure is the issuance model, not the commit.
CISA pushed GovCloud keys to GitHub
Technical analysis of a CISA admin leaking AWS GovCloud keys on GitHub - exposure mechanics, CloudTrail detection paths, and residual session risk post-rotation.
GitHub-distributed VSCode extension executed unsanctioned code
A board-level brief on the compromised VSCode extension distributed through GitHub: what it exposed, what control did not function, and what must be true.
GitHub pulls the account, the repos live on
A board-level analysis of GitHub's ban on a researcher publishing Windows zero-days alongside violent threats, and what it reveals about disclosure risk.
ShinyHunters dumps 94GB of 7-Eleven franchisee data
ShinyHunters leaked 94GB of 7-Eleven franchisee data after extortion refusal. Technical analysis of TTPs, info-stealer-to-SaaS pipeline, and franchise IT exposure.
The agent reads the page and obeys
How Playwright-driven AI agents change the web's threat model: prompt injection, session hijacking, broken CAPTCHAs, and what to do this quarter.
The refund letter addressed to Dear [Name]
Why ChatGPT's first output is a draft, not a deliverable, and what production AI systems actually require beyond the prompt.
The smooth line hiding a noisy benchmark
The METR AI time horizons graph contains structural errors that mislead teams building agents, automation, and AI workflows. Here is what it actually shows.
The WhatsApp breach was not a breach
Technical analysis of the WhatsApp dataset incident: contact discovery oracle abuse, rate-limit bypass, MITRE T1589.002, and the downstream attack surface.
Willison's lethal trifecta exfiltrates Claude uploads
Technical analysis of indirect prompt injection against Claude AI agents - exfiltration mechanics, ATT&CK mapping, telemetry gaps, residual exposure.
Your file renames are a security control
CVE-2025-48095 in 7-Zip exposes the governance gap around utility software that processes untrusted input without formal ownership or version control.
Your SSD is leaking what you're doing
How websites can use SSD response timing as a covert channel to infer user activity, and what browsers and users can do about it.