RC RANDOM CHAOS

supply chain security

46 posts

npm v12 flips the breaker on silent installs
Article

npm v12 flips the breaker on silent installs

npm v12 deprecates older versions and hardens security defaults. What the moved enforcement points expose and what must be true before the release lands.

Sixty-three days to patch a forked parser
Article

Sixty-three days to patch a forked parser

Technical breakdown of the FrontierOS RCE: a forked XML parser, an unpatched two-year-old CVE, and the fork-tracking failure that shipped it.

The integration is the attack surface
Article

The integration is the attack surface

Pentagon raised Israeli collection risk to top tier. The technical exposure is supply chain privilege inherited from vendor software, not espionage.

Contractor PAT leaked 270GB of Times source
Article

Contractor PAT leaked 270GB of Times source

The 2024 NYT source code leak was not a credential breach. It was a credential sprawl chain. The mechanism, telemetry gaps, and what still applies.

Editorial independence is a failed control
Article

Editorial independence is a failed control

UK media failed to disclose defence sector ties in nearly 60 percent of cases. The disclosure gap is an information supply chain vulnerability - and it is exploitable.

One vendor, one subpoena, one reach
Article

One vendor, one subpoena, one reach

Cloudflare's VoidZero acquisition collapses the vendor boundary between build tooling and edge runtime. Attestation reduces to self-reporting.

Detection is not prevention.
Article

Detection is not prevention.

Malicious npm packages reached Red Hat cloud services. The boundary admitted code, then classified it. That sequence defines the failure.

GitHub shipped optional hardening as a control
Article

GitHub shipped optional hardening as a control

The GitHub breach follows a documented class of failure. The mechanism is identity issuance separated from validation. The industry chose documentation over enforcement.

Reputation is not a control
Article

Reputation is not a control

Harvard.edu and 140 other domains reported compromised. Why reputation-based controls fail when trusted origins are turned against their consumers.

CISA contractor leaked GovCloud keys to GitHub
Article

CISA contractor leaked GovCloud keys to GitHub

Technical analysis of a CISA contractor's leaked AWS GovCloud admin keys on GitHub - blast radius, IAM persistence paths, CloudTrail detections, supply-chain tail.

The router is signing its own logs
Article

The router is signing its own logs

Iran's claim about US backdoors in networking equipment describes an exposure pattern already present. The device is an actor, not infrastructure.

The Roblox cheat never touched Roblox
Article

The Roblox cheat never touched Roblox

How a Roblox cheat turned into a Vercel supply chain compromise - stealer to stolen token to dependency confusion to persistent build-pipeline access.