Black & White Path
Author

Black & White Path

We are the beacon of the cyber world, a stepping stone on the road to security.

342
Articles
0
Likes
243
Views
0
Comments
Recent Articles

Latest from Black & White Path

100 recent articles max
Black & White Path
Black & White Path
May 23, 2026 · Backend Development

Open‑Source MQTT WeChat Mini‑Program v5.2 Adds Battery Monitoring

This guide shows how to use MQTT to integrate lithium‑ion battery voltage, state‑of‑charge and health data from an ESP8266 into Home Assistant and a WeChat mini‑program, providing configuration examples, JSON payloads, and links to the fully open‑source repositories.

Battery MonitoringESP8266Home Assistant
0 likes · 4 min read
Open‑Source MQTT WeChat Mini‑Program v5.2 Adds Battery Monitoring
Black & White Path
Black & White Path
May 23, 2026 · Information Security

Telegram’s MTProto Design Flaw Lets Trackers Bypass VPNs and Proxies

A technical review reveals that Telegram’s MTProto protocol exposes a permanent 64‑bit device identifier (auth_key_id) in clear text, enabling passive observers—including ISPs, mobile carriers, and state surveillance—to track users across app restarts, IP changes, VPNs, and even Tor, rendering secret chats and PFS ineffective.

MTProtoTelegramauth_key_id
0 likes · 11 min read
Telegram’s MTProto Design Flaw Lets Trackers Bypass VPNs and Proxies
Black & White Path
Black & White Path
May 22, 2026 · Information Security

NGINX Poolslip 0‑Day RCE: Should You Panic?

A newly disclosed nginx‑poolslip 0‑day RCE affecting NGINX 1.31.0 targets the internal memory‑pool, requires a rare non‑default configuration, and while no public PoC exists, analysis of 4,000 real configurations found none exploitable, prompting specific mitigation steps.

0dayRCESecurity
0 likes · 9 min read
NGINX Poolslip 0‑Day RCE: Should You Panic?
Black & White Path
Black & White Path
May 22, 2026 · Information Security

How KAIDO RAT v3.0 Redefines Bank Malware with Modular PIX Hijacking and AI Credential Harvesting

KAIDO RAT v3.0, a .NET 9‑based modular malware suite with over 60 plugins, targets Brazil's PIX payment system, injects malicious QR codes, locks user devices, harvests AI platform credentials, and employs advanced evasion techniques, while the article also offers detailed defense recommendations.

.NET 9AI credential theftBanking malware
0 likes · 8 min read
How KAIDO RAT v3.0 Redefines Bank Malware with Modular PIX Hijacking and AI Credential Harvesting
Black & White Path
Black & White Path
May 22, 2026 · Information Security

GitHub Breach Aftermath: Data Sold to LAPSUS$ for $95,000

After TeamPCP posted a $50,000 offer for 4,000 private GitHub repositories, the data was transferred to LAPSUS$, the price doubled to $95,000, and the breach highlighted a supply‑chain attack chain that now threatens infrastructure credentials and prompts urgent self‑audit steps.

GitHubInformation SecurityLAPSUS$
0 likes · 9 min read
GitHub Breach Aftermath: Data Sold to LAPSUS$ for $95,000
Black & White Path
Black & White Path
May 21, 2026 · Information Security

Inside The Gentlemen RaaS Leak: Attack‑Defense Dynamics in Modern Ransomware

The article dissects the May 2026 leak of the ransomware‑as‑a‑service group The Gentlemen, detailing its rapid rise, profit‑sharing model, edge‑device entry points, AI‑assisted tool development, supply‑chain attacks, internal breach, and concrete blue‑team mitigation recommendations.

AI-assisted MalwareAttack ChainBlue Team
0 likes · 12 min read
Inside The Gentlemen RaaS Leak: Attack‑Defense Dynamics in Modern Ransomware
Black & White Path
Black & White Path
May 21, 2026 · Operations

How to Self‑Host Gitea for Secure, Easy Project Management

This guide walks individual developers through installing Gitea—using Docker‑compose or binary packages—configuring a systemd service for automatic startup, accessing the web UI to create a repository, and linking it with IDEs to push code, providing a lightweight, self‑hosted Git platform for secure project management.

DevOpsDockerGitea
0 likes · 4 min read
How to Self‑Host Gitea for Secure, Easy Project Management