RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

Encrypted files are writing back to disk
ransomwareincident response

Encrypted files are writing back to disk

Active ransomware event analysis from an operator perspective: what failed, the underlying mechanism, and the conditions that must now hold.

7 min read
OpenAI's security plan protects nothing yet
openaivendor risk

OpenAI's security plan protects nothing yet

M. Hale on the OpenAI cybersecurity action plan: provider-stated intent is not a control, and the consumer still owns the boundary.

8 min read
CVE-2026-3854 puts GitHub inside your trust boundary
cybersecurityRCE

CVE-2026-3854 puts GitHub inside your trust boundary

CVE-2026-3854 enables RCE on GitHub.com and Enterprise Server. Why platform compromise becomes customer compromise across identity, secrets, and artefacts.

7 min read
Managed Agents pricing is an architecture decision
claude managed agentsai pricing

Managed Agents pricing is an architecture decision

Claude Managed Agents pricing isn't a cost center - it's an orchestration lever. Here's how to evaluate it against real total cost of ownership.

8 min read
ShinyHunters exfiltrated Cisco source through Trivy
supply-chaincisco-breach

ShinyHunters exfiltrated Cisco source through Trivy

ShinyHunters exfiltrated Cisco source code through Trivy. The scanner inherited the runtime's identity. The runtime held everything.

6 min read
Losing your domain isn't a technical incident.
domain securitythird-party risk

Losing your domain isn't a technical incident.

A domain transfer executed without documentation reframes the registrar as a third-party control surface the board does not directly enforce.

8 min read
You still own every decision you automated.
AI governancecybersecurity risk

You still own every decision you automated.

When automation decides in threat detection and response, the judgment moves but the accountability does not - and the organisation owns every outcome it cannot explain.

8 min read
Your second factor is a phone call
2fasession hijacking

Your second factor is a phone call

SMS 2FA on PayPal is a routing decision, not a credential. The session cookie is the boundary, and attackers have already routed around the factor.

7 min read
A license audit caught the breach
account takeoveridentity governance

A license audit caught the breach

A six-week account takeover surfaced during a license audit. The detection vector defines the control failure.

5 min read
A postcard breached a warship
physical securityiot threats

A postcard breached a warship

A 5 dollar Bluetooth tracker hidden in a postcard broadcast a 585 million dollar warship's position for 24 hours. The control that failed was classification.

5 min read
Binding 65535 ports is the easy part
honeypotdeception

Binding 65535 ports is the easy part

Architecture and evasion realities of an LLM honeypot binding all 65535 ports - TPROXY, latency tiers, fingerprint defence, and detection traps.

15 min read
CISA flagged a 17-year-old Excel flaw
excel vulnerabilitycisa advisory

CISA flagged a 17-year-old Excel flaw

A 17 year old Excel flaw is being actively exploited and flagged by US cyber defence. Operator analysis of what failed, why, and what must change.

7 min read