Is Your Data in the Cat's Paws?
Analysis of the 2025 KakaoPay breach exposing 40M users’ data, and why formal consent fails without AI-based DPIA and civic oversight.
Representative Foreword
The representative foreword of this blog: security now fails less at finding issues than at absorbing, sustaining, and acting on what has already been found.
This essay frames the entire site first. The posts on technical analysis, method, and governance all start from this same problem statement.

Detection, Method, Governance
Analysis of the 2025 KakaoPay breach exposing 40M users’ data, and why formal consent fails without AI-based DPIA and civic oversight.
The CVE system nearly collapsed in 2025. Who should fund public cybersecurity infrastructure when free-riding is no longer sustainable?
A satirical critique of how AI-era organizations isolate employees through async workflows and data-driven control to suppress solidarity.
A philosophical essay on human authorship and creativity in the AI era, declaring the creator’s rights over machine-generated output.
Debunking developer security myths around responsibility deflection, tech overconfidence, and risk underestimation with real-world examples.
A hands-on guide using dnsmasq to filter SVCB and HTTPS records for disabling ECH and enforcing central DNS policies. Notes that DoH requires separate network-layer policies.
Comprehensive analysis of XML-RPC security flaws including RCE, XXE, and DDoS, with mitigation strategies and a Python PoC exploit.
Citrix administrators apply security policies to each user’s VDI (Virtual Desktop Infrastructure) through Citrix Group Policy. However, certain structural vulnerabilities in Citrix CSE (Citrix Service Engine) and the Citrix VDI Agent allow for potential bypassing of these security policies.
Real cases where manipulated KPI metrics led to cybersecurity incidents, exposing the dangers of metric-driven security management.
Three common misconceptions that weaken security assessments and strategies to build repeatable, effective vulnerability evaluation.