RC RANDOM CHAOS

detection engineering

82 posts

Schrems II broke US data transfers, July 2020
Article

Schrems II broke US data transfers, July 2020

Schrems II (CJEU C-311/18) makes US-hosted EDR telemetry on EU endpoints a restricted transfer. Why data residency now degrades detection fidelity.

#gerpar trended this week; PartitionAlloc already answers it
Article

#gerpar trended this week; PartitionAlloc already answers it

A. Shah (REDLINE) tests the trending #gerpar Chromium heap-overflow claim against PartitionAlloc, CFI, the V8 sandbox, and renderer isolation.

Mythos AI cleared for distribution, no validation report
Article

Mythos AI cleared for distribution, no validation report

REDLINE breaks down the security risk in releasing Mythos AI to trusted US organizations: not the model, the missing adversarial validation and zero prompt-level telemetry.

California registers 3D printers it can't instrument
Article

California registers 3D printers it can't instrument

California's 3D printer registry concentrates reconnaissance data on a fleet of uninstrumented endpoints. The real gap is telemetry and data governance.

No one hacked the NSA
Article

No one hacked the NSA

The NSA's Mythos access loss wasn't a breach - it was a control-plane revocation by a third party. A supply chain availability failure with no patch.

One bearer token, replayed from a residential proxy
Article

One bearer token, replayed from a residential proxy

How attackers abuse OAuth 2.0 at scale via consent phishing, device code flow, and service principal credentials - and why endpoint EDR sees none of it.

Victim types the password, attacker keeps the token
Article

Victim types the password, attacker keeps the token

CVE-2023-4714 session fixation (CWE-384) explained: how attackers plant a session ID, bypass MFA, what fires in telemetry, and why rotation alone is not enough.

OpenSSH turns every authenticated session into a pivot
Article

OpenSSH turns every authenticated session into a pivot

How SSH local, remote, and dynamic port forwarding becomes pivot infrastructure for lateral movement and exfiltration, and what it leaves in telemetry.

The patch opens the attack window.
Article

The patch opens the attack window.

The Coming Loop is the collapsing gap between vulnerability disclosure and mass exploitation of internet-facing appliances - and why edge telemetry stays blind.

The verification email is a reflection primitive
Article

The verification email is a reflection primitive

Email verification flows that send mail on request become reflection primitives. Why subscription bombing passes SPF, DKIM and DMARC, and how to detect it.

torch.load runs attacker code before the first denoising step
Article

torch.load runs attacker code before the first denoising step

A diffusion inpainting model can't execute a prompt. The real RCE is pickle deserialisation in the loader, custom nodes, and the agent around it.

CORS misconfiguration is consent, not an exploit
Article

CORS misconfiguration is consent, not an exploit

CORS misconfiguration explained at the mechanism level: origin reflection, null origin, broken allowlist matching, the credentialed-read exploit path, and why it stays invisible in telemetry.