RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

vulnerability-managementsupply-chain

The dashboard pushed every critical CVE to GitHub

Technical analysis of a unified vulnerability dashboard pushed to a public GitHub repo, the scanner token blast radius, and what defenders actually see.

7 min read
The LinkedIn leak is not a privacy incident
linkedin leaksocial engineering

The LinkedIn leak is not a privacy incident

A LinkedIn data leak is not a privacy event. It is pre-staged targeting data for credential harvesting. Operator briefing on what must now be true.

7 min read
The number on the screen is a guess
Canvas breachdata exposure

The number on the screen is a guess

The Canvas hack scope is not confirmed. A senior operator breakdown of what failed, what is rumour, and what users must now do.

7 min read
linux-kernelprivilege-escalation

User namespaces are still a root pipe

Dirty Frag is a Linux kernel UAF in IP fragment reassembly reachable via unprivileged user namespaces. CVSS 7.8. Mechanism, telemetry gaps, patch boundary.

6 min read
Your inbox is now your credential store.
CVE-2026-44843credential theft

Your inbox is now your credential store.

CVE-2026-44843 turns a chat message into credential theft. Operator briefing on what failed, what is not confirmed, and what must now be true.

7 min read
linux-kernelprivilege-escalation

Your patched kernel is still vulnerable

Dirty Frag - CVE-2026-31337, CVSS 7.8 - is a UAF in the Linux kernel's IPv4 fragment reassembly path. Container-to-host root on every major distro.

6 min read
Z3R0DAY refuses to model unconfirmed Canvas breach
breach analysisincident response

Z3R0DAY refuses to model unconfirmed Canvas breach

A breach claim referencing Canvas has been raised. Scope, vector, and data classes are not confirmed. Exposure cannot be quantified from the input.

6 min read
GTFOBins catalogues privilege misconfiguration
gtfobinsprivilege escalation

GTFOBins catalogues privilege misconfiguration

GTFOBins documents a structural property of Unix privilege: grants bind to binaries, not operations, and the gap is the escalation surface.

8 min read
The kernel commit lands. Your fleet is exposed.
linux kernel securityvulnerability management

The kernel commit lands. Your fleet is exposed.

Linux kernel CVEs publish without distro pre-notice. The exposure window opens at upstream commit, not at advisory. Measure the right number.

6 min read
The router is signing its own logs
cybersecuritynetworking

The router is signing its own logs

Iran's claim about US backdoors in networking equipment describes an exposure pattern already present. The device is an actor, not infrastructure.

6 min read
Harvey Nash priced your security staff
cybersecurity compensationtalent retention

Harvey Nash priced your security staff

Cybersecurity compensation benchmarks function as a control input. When the internal pay-band cycle runs slower than the external market, retention fails.

7 min read
RedSun turned Defender into a write primitive
windows defenderredsun

RedSun turned Defender into a write primitive

RedSun turned Windows Defender's remediation path into a SYSTEM-level write primitive. The mechanism, the class, and what it exposes.

6 min read