RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

Twelve bytes walked out of the sandbox
CVE-2026-40369browser-sandbox

Twelve bytes walked out of the sandbox

CVE-2026-40369 reduced a browser sandbox escape to twelve bytes. Analysis of what failed, why it failed, and what must change at the architecture layer.

6 min read
Workflows are code, not config
ci securitygithub actions

Workflows are code, not config

CI workflow modification executes under repository trust. The control surface is the file. The boundary is the weakest identity allowed to merge.

7 min read
Your endpoint agent is the intrusion vector.
microsoft defendercisa kev

Your endpoint agent is the intrusion vector.

Two Microsoft Defender vulnerabilities are under active exploitation. One grants full SYSTEM. CISA deadline June 3. What to verify now.

6 min read
The zero-day wasn't the failure.
telecom securityzero-day

The zero-day wasn't the failure.

Luxembourg's national telecoms network collapsed from one Huawei zero-day. The failure was architectural, not vendor-specific. Concentration was the control gap.

6 min read
Your BitLocker bypass mitigation fixes nothing yet
bitlockercve-2026-45585

Your BitLocker bypass mitigation fixes nothing yet

Microsoft shipped a mitigation for CVE-2026-45585 YellowKey BitLocker bypass. What is confirmed, what is not, and what operators must verify.

7 min read
Your privacy settings are decoration.
privacycybersecurity

Your privacy settings are decoration.

Privacy is no longer a default state. A former black hat defines what failed, why it failed, and what operators must now assume.

8 min read
Bitsight found 6,000 unauthenticated fuel gauges online
ICS securityOT security

Bitsight found 6,000 unauthenticated fuel gauges online

6,000 Automatic Tank Gauges are exposed to the internet with no authentication. The protocol, the owners, and why the fix isn't technical.

6 min read
CISA pushed passwords to a public repo
credential exposuregithub security

CISA pushed passwords to a public repo

A top cyberdefense agency published credentials in a public GitHub repository. A control analysis of what failed and what must now be true.

7 min read
Cloudflare's CISO spent two weeks breaking Mythos
AI securityLLM agents

Cloudflare's CISO spent two weeks breaking Mythos

Cloudflare's CISO red-teamed Anthropic's Mythos LLM. The findings on harness design, memory persistence, and tool allowlists matter more than the model itself.

6 min read
Discord's E2EE doesn't make your calls private
discordend-to-end encryption

Discord's E2EE doesn't make your calls private

Discord rolled out E2EE on voice and video calls. What the control covers, what it does not, and where attackers will redirect effort.

7 min read
Entra ID trades your credential for a token
cloud securityidentity and access

Entra ID trades your credential for a token

Microsoft Entra ID resolves trust at sign-in and honors bearer tokens on reference, not verification, which is how one compromised login becomes a cloud breach.

9 min read
Forge guardrails took an 8B model from 53% to 99%
AI safetyguardrails

Forge guardrails took an 8B model from 53% to 99%

A Show HN post says Forge guardrails took an 8B model from 53% to 99% on agentic tasks. Here's what that means for security and reliability.

7 min read