RC RANDOM CHAOS

detection engineering

76 posts

A SQLite underflow, and the flood behind it
Article

A SQLite underflow, and the flood behind it

AI isn't replacing defenders - it's multiplying vulnerability volume, hallucinated dependencies, and synthetic findings. The skill that survives is validation at machine rate.

AMD's Memory Encryption Blind Spot
Article

AMD's Memory Encryption Blind Spot

AMD re-enables TSME on Ryzen 9000 in July. What it stops, what it never touches, and the physical-attack telemetry gap defenders miss.

MITRE already filed your detection bypass as AML.T0015
Article

MITRE already filed your detection bypass as AML.T0015

ML malware detection is a deterministic classifier with a mappable decision boundary. Attackers exploit its learned bias. That demands more engineering.

DeepSeek dodged the Entity List, not your pipeline
Article

DeepSeek dodged the Entity List, not your pipeline

US regulators listed 100+ firms but held off on DeepSeek. The real exposure: third-party AI weights and inference as a trusted security supply chain.

ScStoragePathFromUrl overflows the stack on PROPFIND
Article

ScStoragePathFromUrl overflows the stack on PROPFIND

CVE-2017-7269 turns an unpatched IIS 6.0 WebDAV server into pre-auth RCE. The exploit primitive, the telemetry blind spot, and the residual exposure.

GrapheneOS Android 17 degrades every exploit primitive
Article

GrapheneOS Android 17 degrades every exploit primitive

GrapheneOS's Android 17 port: how sync MTE, hardened_malloc, and a hardened kernel degrade mobile exploit chains-and why failed attempts are the loudest telemetry.

Removing curl and wget stops nothing
Article

Removing curl and wget stops nothing

Bash /dev/tcp opens TCP sockets and sends HTTP with no curl or wget, evading process-name detection while leaving cleartext on the wire.

Contagious Interview ends at npm install
Article

Contagious Interview ends at npm install

How DPRK actors turn LinkedIn job offers into code execution via npm postinstall hooks, what BeaverTail steals, and why developer endpoints stay blind.

NetScaler trusts snprintf, leaks adjacent heap memory
Article

NetScaler trusts snprintf, leaks adjacent heap memory

Why 'silent' vulnerabilities like Citrix Bleed (CVE-2023-4966) are already exploited at the network edge, what they produce in telemetry, and where defenders are blind.

Ring 0, fed a stranger's save file
Article

Ring 0, fed a stranger's save file

The US directive suspending Fable 5 and Mythos 5, analyzed: why game clients are privileged code, how asset and netcode bugs work, and why trust is the flaw.

OpenCV 5.0 made adversarial perturbations transferable
Article

OpenCV 5.0 made adversarial perturbations transferable

OpenCV 5's bit-exact numerics and expanded encoder control shrink the attacker's modelling error against deepfake detectors. The exposure is structural.

Sixty-three days to patch a forked parser
Article

Sixty-three days to patch a forked parser

Technical breakdown of the FrontierOS RCE: a forked XML parser, an unpatched two-year-old CVE, and the fork-tracking failure that shipped it.