RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

Your SSD is leaking what you're doing
cybersecurityprivacy

Your SSD is leaking what you're doing

How websites can use SSD response timing as a covert channel to infer user activity, and what browsers and users can do about it.

7 min read
Your VPN extension trusts every website you visit
browser securityvpn

Your VPN extension trusts every website you visit

A hardcoded trigger word in a million-install Chrome VPN extension let any website disable the tunnel, change exit nodes, and read open tabs.

6 min read
YouTube built a checkbox, not a detector
deepfakesyoutube

YouTube built a checkbox, not a detector

YouTube's automatic AI-generated video label is a disclosure system, not a detector. Here's what it actually does for cybersecurity and what it doesn't.

6 min read
94GB sits on a leak site
ShinyHuntersdata breach

94GB sits on a leak site

ShinyHunters published a 94GB dataset tied to 7-Eleven franchisee systems after extortion refusal. What failed, why, and what must now be true.

7 min read
A renamed file walks past the heap boundary
7-ZipCVE-2026-48095

A renamed file walks past the heap boundary

CVE-2026-48095 is a 7-Zip NTFS heap overflow triggered through renamed files. Operator breakdown of what failed, why, and what must now be true.

7 min read
Biometrics outlive the breach
biometric datavendor risk

Biometrics outlive the breach

Biometric data held by identity verification providers is non-revocable; board exposure persists regardless of any confirmed incident.

8 min read
CISA administrator published GovCloud keys to GitHub
GovCloudaccess control

CISA administrator published GovCloud keys to GitHub

A CISA administrator's publication of AWS GovCloud keys to public GitHub exposes the gap between cloud segregation policy and runtime control.

8 min read
Franchises leak because franchises federate
shinyhuntersretail-security

Franchises leak because franchises federate

ShinyHunters leaked 94GB from a 7-Eleven franchisee after extortion refusal. The structural reasons franchise retail keeps ending up in leak listings.

6 min read
Hacker publishes dataset naming WhatsApp users
identity riskboard governance

Hacker publishes dataset naming WhatsApp users

A board-level brief on the WhatsApp dataset drop: why identity exposure sits outside owned systems, what remains unconfirmed, and what must hold going forward.

8 min read
nginx-poolslip is mostly rumor
nginxCVE-2026-9256

nginx-poolslip is mostly rumor

CVE-2026-9256 nginx-poolslip operator briefing: what is confirmed, what is not, and the standing control gap the identifier exposes.

8 min read
Researchers silently exfiltrate files from Claude sessions
AI securityprompt injection

Researchers silently exfiltrate files from Claude sessions

A live demo shows files inside Claude AI chats can be silently exfiltrated. Operator briefing on what failed, what it exposes, and what must change.

9 min read
The agent is the breach
board governanceAI risk

The agent is the breach

A board-level assessment of the Microsoft Copilot Cowork file exfiltration: control failure, exposure model, and the conditions that must hold for in-tenant agents.

9 min read