RC RANDOM CHAOS

detection engineering

82 posts

The string you validated no longer exists
Article

The string you validated no longer exists

Unicode transliteration is a Turing-complete rewrite engine at every trust boundary. CVE-2024-4577, Django CVE-2019-19844, and Trojan Source show why.

A valid go.sum hash proves nothing
Article

A valid go.sum hash proves nothing

Argegy is not a CVE. It's a Go supply chain claim against go-ethereum - module trust, init() execution, T1195, and where telemetry goes blind.

Kalshi ships an unauthenticated oracle
Article

Kalshi ships an unauthenticated oracle

Kalshi resolves contracts against unauthenticated public news feeds - an oracle-manipulation flaw that lets crafted narratives move regulated markets.

Not a pricing problem
Article

Not a pricing problem

Why security automation like Splunk SOAR and ML triage costs more than the engineer it replaced: systems execute on referenced trust, not verification.

Vectra lifted bearer tokens off Teams disk
Article

Vectra lifted bearer tokens off Teams disk

Why Microsoft Teams session tokens leak between workspace and consumer accounts, how bearer-token replay bypasses MFA, and what fires - and doesn't - in telemetry.

dd writes raw sectors below the filesystem
Article

dd writes raw sectors below the filesystem

Why the Unix dd command is a real security primitive: raw block writes below the filesystem, wiper TTPs, exfiltration, and the telemetry gap defenders miss.

htop is a reconnaissance surface
Article

htop is a reconnaissance surface

How htop and top expose Linux resource contention - OOM-killer steering, D-state telemetry gaps, niced miners, and PID exhaustion mapped to MITRE T1562 and T1499.

Alibaba bans Claude Code across its engineering org
Article

Alibaba bans Claude Code across its engineering org

Alibaba's reported ban on Claude Code is a trust decision, not a CVE. Why an agentic coding tool's sanctioned egress is also its exfiltration path.

Locale decides the payload
Article

Locale decides the payload

The en-GB locale isn't a vulnerability - it's a selector. How attackers use Accept-Language and OS locale checks to filter delivery and gate detonation.

Spain rips Palantir out of its data pipelines
Article

Spain rips Palantir out of its data pipelines

Spain's Palantir blacklist is a supply chain concentration risk - a privileged vendor data plane mapped to MITRE T1199, and why customer telemetry stays blind.

Log4Shell executed exactly as written
Article

Log4Shell executed exactly as written

Log4Shell, xz-utils, and Spring4Shell weren't isolated bugs. They were composition failures in systems too deep for anyone to fully read. The disease is complexity.

Read the mark hidden in your bot's requests
Article

Read the mark hidden in your bot's requests

Steganographic request marking as a targeted reconnaissance primitive: how invisible-Unicode carriers survive into logs and why SIEM normalization goes blind.