RC RANDOM CHAOS

detection engineering

76 posts

htop is a reconnaissance surface
Article

htop is a reconnaissance surface

How htop and top expose Linux resource contention - OOM-killer steering, D-state telemetry gaps, niced miners, and PID exhaustion mapped to MITRE T1562 and T1499.

Alibaba bans Claude Code across its engineering org
Article

Alibaba bans Claude Code across its engineering org

Alibaba's reported ban on Claude Code is a trust decision, not a CVE. Why an agentic coding tool's sanctioned egress is also its exfiltration path.

Locale decides the payload
Article

Locale decides the payload

The en-GB locale isn't a vulnerability - it's a selector. How attackers use Accept-Language and OS locale checks to filter delivery and gate detonation.

Spain rips Palantir out of its data pipelines
Article

Spain rips Palantir out of its data pipelines

Spain's Palantir blacklist is a supply chain concentration risk - a privileged vendor data plane mapped to MITRE T1199, and why customer telemetry stays blind.

Log4Shell executed exactly as written
Article

Log4Shell executed exactly as written

Log4Shell, xz-utils, and Spring4Shell weren't isolated bugs. They were composition failures in systems too deep for anyone to fully read. The disease is complexity.

Read the mark hidden in your bot's requests
Article

Read the mark hidden in your bot's requests

Steganographic request marking as a targeted reconnaissance primitive: how invisible-Unicode carriers survive into logs and why SIEM normalization goes blind.

Schrems II broke US data transfers, July 2020
Article

Schrems II broke US data transfers, July 2020

Schrems II (CJEU C-311/18) makes US-hosted EDR telemetry on EU endpoints a restricted transfer. Why data residency now degrades detection fidelity.

#gerpar trended this week; PartitionAlloc already answers it
Article

#gerpar trended this week; PartitionAlloc already answers it

A. Shah (REDLINE) tests the trending #gerpar Chromium heap-overflow claim against PartitionAlloc, CFI, the V8 sandbox, and renderer isolation.

Mythos AI cleared for distribution, no validation report
Article

Mythos AI cleared for distribution, no validation report

REDLINE breaks down the security risk in releasing Mythos AI to trusted US organizations: not the model, the missing adversarial validation and zero prompt-level telemetry.

California registers 3D printers it can't instrument
Article

California registers 3D printers it can't instrument

California's 3D printer registry concentrates reconnaissance data on a fleet of uninstrumented endpoints. The real gap is telemetry and data governance.

No one hacked the NSA
Article

No one hacked the NSA

The NSA's Mythos access loss wasn't a breach - it was a control-plane revocation by a third party. A supply chain availability failure with no patch.

One bearer token, replayed from a residential proxy
Article

One bearer token, replayed from a residential proxy

How attackers abuse OAuth 2.0 at scale via consent phishing, device code flow, and service principal credentials - and why endpoint EDR sees none of it.