RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

Your VPN extension trusts every website you visit
browser securityvpn

Your VPN extension trusts every website you visit

A hardcoded trigger word in a million-install Chrome VPN extension let any website disable the tunnel, change exit nodes, and read open tabs.

6 min read
YouTube built a checkbox, not a detector
deepfakesyoutube

YouTube built a checkbox, not a detector

YouTube's automatic AI-generated video label is a disclosure system, not a detector. Here's what it actually does for cybersecurity and what it doesn't.

6 min read
94GB sits on a leak site
ShinyHuntersdata breach

94GB sits on a leak site

ShinyHunters published a 94GB dataset tied to 7-Eleven franchisee systems after extortion refusal. What failed, why, and what must now be true.

7 min read
A renamed file walks past the heap boundary
7-ZipCVE-2026-48095

A renamed file walks past the heap boundary

CVE-2026-48095 is a 7-Zip NTFS heap overflow triggered through renamed files. Operator breakdown of what failed, why, and what must now be true.

7 min read
Biometrics outlive the breach
biometric datavendor risk

Biometrics outlive the breach

Biometric data held by identity verification providers is non-revocable; board exposure persists regardless of any confirmed incident.

8 min read
CISA administrator published GovCloud keys to GitHub
GovCloudaccess control

CISA administrator published GovCloud keys to GitHub

A CISA administrator's publication of AWS GovCloud keys to public GitHub exposes the gap between cloud segregation policy and runtime control.

8 min read
Franchises leak because franchises federate
shinyhuntersretail-security

Franchises leak because franchises federate

ShinyHunters leaked 94GB from a 7-Eleven franchisee after extortion refusal. The structural reasons franchise retail keeps ending up in leak listings.

6 min read
Hacker publishes dataset naming WhatsApp users
identity riskboard governance

Hacker publishes dataset naming WhatsApp users

A board-level brief on the WhatsApp dataset drop: why identity exposure sits outside owned systems, what remains unconfirmed, and what must hold going forward.

8 min read
nginx-poolslip is mostly rumor
nginxCVE-2026-9256

nginx-poolslip is mostly rumor

CVE-2026-9256 nginx-poolslip operator briefing: what is confirmed, what is not, and the standing control gap the identifier exposes.

8 min read
Researchers silently exfiltrate files from Claude sessions
AI securityprompt injection

Researchers silently exfiltrate files from Claude sessions

A live demo shows files inside Claude AI chats can be silently exfiltrated. Operator briefing on what failed, what it exposes, and what must change.

9 min read
The agent is the breach
board governanceAI risk

The agent is the breach

A board-level assessment of the Microsoft Copilot Cowork file exfiltration: control failure, exposure model, and the conditions that must hold for in-tenant agents.

9 min read
The boundary no longer holds
board governancebrowser security

The boundary no longer holds

A board-level brief on CVE-2026-40369, the twelve-byte browser sandbox escape, and the control assumptions senior leadership must now revisit.

9 min read