All Posts

How VPN Detection Works and the Protocol Stack Built to Outrun It
Governments are increasingly targeting VPNs after age verification laws. Learn how Deep Packet Inspection works and why Shadowsocks etc are needed

GhostLock (CVE-2026-43499): a fifteen-year-old rtmutex bug just handed root to anyone with a shell
GhostLock (CVE-2026-43499) is a 15-year rtmutex use-after-free giving root to any local Linux user. Full technical breakdown of the exploit chain

Accenture, 888, and the Anatomy of a Believable Breach Claim
Threat actor "888" claims 35GB of Accenture source code, SSH keys, and Azure tokens. A technical breakdown of the claim, the credentials, and what's actually verified

The blog is getting a video series. First one drops next week
The first video in a new cybersecurity and networking course series is free and ad supported. Full library access requires membership. Watch it next week

GitHub’s “Verified” Commit Isn’t Unique, and Its AI Agent Will Leak Your Private Repos If You Ask Nicely
New CMU research shows GitHub's Verified commit badge isn't a unique fingerprint, plus how GitLost tricks GitHub's AI agent into leaking private repos

Januscape (CVE-2026-53359): The 16-Year-Old KVM Bug That Lets a Guest VM Take Down Its Host
CVE-2026-53359, dubbed Januscape, is a 16-year-old KVM use-after-free letting guest VMs crash or escalate into the host. Here's the full technical breakdown

GoDaddy Is Quietly Fighting for WHOIS Privacy, and Almost No One’s Paying Attention
Delhi High Court ordered registrars to end default WHOIS privacy. GoDaddy's 5,000-page appeal explains why, and how it collides with RDAP's 2025 rollout

UK Green Paper Would Force YouTube, Meta and TikTok to Rank BBC and ITV Above Independent Creators
The UK's Green Paper would force YouTube, Meta and TikTok to rank BBC and ITV news higher. Here's the actual mechanism, timeline and legal status

Bad Epoll: Inside CVE-2026-46242, the Race Condition an AI Model Read Right Past
Learn how Bad Epoll (CVE-2026-46242) enables Linux root access through an epoll race condition, why AI missed it, exploit details, impact, and mitigation






