Articles
Long-form writing on tech, culture, and the edges of the internet.
Your VPN extension trusts every website you visit
A hardcoded trigger word in a million-install Chrome VPN extension let any website disable the tunnel, change exit nodes, and read open tabs.
YouTube built a checkbox, not a detector
YouTube's automatic AI-generated video label is a disclosure system, not a detector. Here's what it actually does for cybersecurity and what it doesn't.
94GB sits on a leak site
ShinyHunters published a 94GB dataset tied to 7-Eleven franchisee systems after extortion refusal. What failed, why, and what must now be true.
A renamed file walks past the heap boundary
CVE-2026-48095 is a 7-Zip NTFS heap overflow triggered through renamed files. Operator breakdown of what failed, why, and what must now be true.
Biometrics outlive the breach
Biometric data held by identity verification providers is non-revocable; board exposure persists regardless of any confirmed incident.
CISA administrator published GovCloud keys to GitHub
A CISA administrator's publication of AWS GovCloud keys to public GitHub exposes the gap between cloud segregation policy and runtime control.
Franchises leak because franchises federate
ShinyHunters leaked 94GB from a 7-Eleven franchisee after extortion refusal. The structural reasons franchise retail keeps ending up in leak listings.
Hacker publishes dataset naming WhatsApp users
A board-level brief on the WhatsApp dataset drop: why identity exposure sits outside owned systems, what remains unconfirmed, and what must hold going forward.
nginx-poolslip is mostly rumor
CVE-2026-9256 nginx-poolslip operator briefing: what is confirmed, what is not, and the standing control gap the identifier exposes.
Researchers silently exfiltrate files from Claude sessions
A live demo shows files inside Claude AI chats can be silently exfiltrated. Operator briefing on what failed, what it exposes, and what must change.
The agent is the breach
A board-level assessment of the Microsoft Copilot Cowork file exfiltration: control failure, exposure model, and the conditions that must hold for in-tenant agents.
The boundary no longer holds
A board-level brief on CVE-2026-40369, the twelve-byte browser sandbox escape, and the control assumptions senior leadership must now revisit.