RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

Shai-Hulud worm compromises 314 npm packages
supply-chainnpm

Shai-Hulud worm compromises 314 npm packages

Shai-Hulud npm worm hits 314 more packages via compromised maintainer accounts. Mechanism, telemetry gaps, and residual exposure analyzed.

5 min read
Six thousand fuel gauges answer every stranger
systems driftindustrial control systems

Six thousand fuel gauges answer every stranger

Six thousand exposed fuel gauges are not a vulnerability. They are a trust model that outlived the wire it was built on.

7 min read
Sub-JEPA tightens the prediction signal
Sub-JEPAJEPA

Sub-JEPA tightens the prediction signal

Sub-JEPA is a small loss-side fix to LeCun's world models that consistently improves performance. Here's how it works, where it fails, and why it matters.

11 min read
The agency was the breach.
secret-managementgithub-security

The agency was the breach.

A US cybersecurity agency published digital keys to a public GitHub repository. The exposure defines the failure class. Recovery requires rotation.

7 min read
The disassembler is now a free download
reverse-engineeringopen-source-security

The disassembler is now a free download

An open source disassembler and decompiler release removes the cost filter defenders implicitly priced into attacker capability. The model needs correction.

7 min read
The IIS virtual directory that won't stop bleeding
exchange-serverzero-day

The IIS virtual directory that won't stop bleeding

Technical analysis of the Exchange Server zero-day, the frontend-to-backend trust boundary it abuses, and what fires in EDR and IIS telemetry.

6 min read
The patch shipped. The install didn't.
windows 11patch management

The patch shipped. The install didn't.

Microsoft confirmed Windows 11 security updates are failing to install. Patch state is now a claim, not a measurement. Verify out-of-band.

8 min read
Torvalds declares Linux security list unmanageable
linux securityvulnerability disclosure

Torvalds declares Linux security list unmanageable

Linus Torvalds says AI bug hunters have made the Linux security list unmanageable. An operator read on what failed at the intake boundary.

7 min read
A few bytes spill onto the next heap chunk
nginxcve-2026-42945

A few bytes spill onto the next heap chunk

Technical writeup of CVE-2026-42945, the NGINX rewrite module heap overflow, plus what it means for LLM deployments sitting behind the proxy.

6 min read
A handle, a token, a SYSTEM shell
windows kerneltrust models

A handle, a token, a SYSTEM shell

MiniPlasma is not a kernel defect. It is the externally visible behaviour of a trust model that confuses reference with verification.

7 min read
An avatar walked through Face ID
biometric authenticationboard risk

An avatar walked through Face ID

A Face ID bypass using an avatar reduces the assurance of every business process that treats biometric success as proof of human presence.

8 min read
An NGINX worker just crashed in production
NGINXCVE-2026-42945

An NGINX worker just crashed in production

Board-level briefing on NGINX CVE-2026-42945: confirmed in-the-wild exploitation, edge exposure, control failure at runtime, and what must be established.

9 min read