Black & White Path
Author

Black & White Path

We are the beacon of the cyber world, a stepping stone on the road to security.

342
Articles
0
Likes
242
Views
0
Comments
Recent Articles

Latest from Black & White Path

100 recent articles max
Black & White Path
Black & White Path
May 31, 2026 · Industry Insights

How a Single Bitcoin Address Brought Down the Dark‑Web King

The article recounts how hacker Kai Logan West, known as IntelBroker, abandoned his Monero‑only policy for a $250 Bitcoin payment, allowing FBI investigators to trace the transaction through KYC‑linked services and ultimately expose his identity, leading to his arrest.

BitcoinBlockchain ForensicsCrypto Crime
0 likes · 6 min read
How a Single Bitcoin Address Brought Down the Dark‑Web King
Black & White Path
Black & White Path
May 30, 2026 · Information Security

DigDeep: A Sensitive Information Mining Tool for Penetration Testing

DigDeep is a Java‑based tool that efficiently extracts nearly one hundred types of high‑, medium‑, and low‑risk sensitive data from source files across cloud, mini‑program, app, and web environments, offering recursive scanning, risk‑level filtering, deduplication, and multi‑format export to aid security audits.

DigDeepJavacode audit
0 likes · 4 min read
DigDeep: A Sensitive Information Mining Tool for Penetration Testing
Black & White Path
Black & White Path
May 30, 2026 · Information Security

Multiple Critical RCE Flaws Discovered in Notepad++ Affect Millions of Windows Users

Notepad++ has been found to contain three serious vulnerabilities—two remote‑code‑execution flaws (CVE‑2026‑48778, CVE‑2026‑48800) and a denial‑of‑service issue (CVE‑2026‑48770)—all exploiting unchecked XML configuration files, putting millions of Windows users at high risk until they apply the latest security update.

CVEConfiguration FileInformation Security
0 likes · 8 min read
Multiple Critical RCE Flaws Discovered in Notepad++ Affect Millions of Windows Users
Black & White Path
Black & White Path
May 30, 2026 · Industry Insights

Why Is Google Paying Only $500 for a Critical V8 Out‑of‑Bounds Write Bug?

The article examines Google’s $500 reward for a high‑severity V8 out‑of‑bounds write vulnerability, tracing the historic decline of bug‑bounty payouts, the monopolistic role of major platforms, AI‑driven bug‑finding saturation, and the resulting challenges for security researchers both globally and in China.

AIBug BountyGoogle
0 likes · 11 min read
Why Is Google Paying Only $500 for a Critical V8 Out‑of‑Bounds Write Bug?
Black & White Path
Black & White Path
May 29, 2026 · Information Security

Zero‑Click Outlook RCE (CVE‑2026‑40361): Selecting a New Email Instantly Compromises the System

CVE‑2026‑40361 is a high‑severity, use‑after‑free vulnerability in Microsoft Outlook’s preview pane that enables remote code execution without any user interaction; the flaw, rated 8.4 CVSS and marked “Exploitation More Likely,” affects multiple Office versions and can be mitigated by immediate patching, disabling the preview pane, registry hardening, and layered email‑gateway and endpoint defenses.

CVE-2026-40361Email securityMicrosoft Office
0 likes · 14 min read
Zero‑Click Outlook RCE (CVE‑2026‑40361): Selecting a New Email Instantly Compromises the System
Black & White Path
Black & White Path
May 29, 2026 · Information Security

GhostType: Open‑Source Forensic Scanner for Leaked Credentials in AI Chat Histories

GhostType is an open‑source forensic scanner that parses local conversation files from popular AI coding assistants, uses TruffleHog’s 800+ detectors plus custom regex rules to locate exposed API keys or passwords, verifies their validity in real time, and outputs detailed JSON or CSV reports for red‑team or DLP use.

AI assistantsDLPGhostType
0 likes · 3 min read
GhostType: Open‑Source Forensic Scanner for Leaked Credentials in AI Chat Histories
Black & White Path
Black & White Path
May 29, 2026 · Industry Insights

How Ignoring API Limits Led to a $500 Million AI Bill

A lack of usage caps on Claude's API caused a single employee to generate a $500 million charge in one month, exposing systemic governance gaps and prompting a broader discussion on AI cost control, token‑based billing, and practical safeguards for enterprises.

AI cost governanceAPI budgetingClaude API
0 likes · 7 min read
How Ignoring API Limits Led to a $500 Million AI Bill
Black & White Path
Black & White Path
May 28, 2026 · Information Security

SwordfishSuite: A Beginner‑Friendly Burp Alternative with Extensible Plugins

SwordfishSuite is a lightweight, open‑source web security testing platform inspired by Burp, offering an intuitive GUI, smart HTTPS proxy, a Python‑based plugin ecosystem, experimental app traffic analysis, and easy installation via GitHub releases, making it ideal for newcomers and seasoned testers alike.

App traffic analysisBurp alternativeHTTPS interception
0 likes · 6 min read
SwordfishSuite: A Beginner‑Friendly Burp Alternative with Extensible Plugins
Black & White Path
Black & White Path
May 28, 2026 · Information Security

12‑Byte Syscall in Browser Sandbox Grants SYSTEM on Windows (CVE‑2026‑40369 PoC)

The article details CVE‑2026‑40369, a Windows kernel flaw in ExpGetProcessInformation where a zero‑length buffer bypasses ProbeForWrite, allowing a browser sandbox process to write arbitrary kernel memory with a 12‑byte syscall, leading to a deterministic, fully‑reliable privilege‑escalation chain that grants SYSTEM without race conditions, and discusses detection and mitigation.

CVE-2026-40369NtQuerySystemInformationWindows kernel
0 likes · 11 min read
12‑Byte Syscall in Browser Sandbox Grants SYSTEM on Windows (CVE‑2026‑40369 PoC)