Black & White Path
Author

Black & White Path

We are the beacon of the cyber world, a stepping stone on the road to security.

344
Articles
0
Likes
244
Views
0
Comments
Recent Articles

Latest from Black & White Path

100 recent articles max
Black & White Path
Black & White Path
May 11, 2026 · Industry Insights

Garmin, Chuyka and the New Low‑Cost Drone Defense for Europe

Europe’s anti‑drone market is shifting toward low‑cost RF detection like Ukraine’s Chuyka system, spurred by EU funding and rising threats, while larger multi‑sensor solutions compete; the analysis explores policy drivers, market dynamics, and how Garmin could fill the mid‑budget niche.

ChuykaEuropean securityGarmin
0 likes · 10 min read
Garmin, Chuyka and the New Low‑Cost Drone Defense for Europe
Black & White Path
Black & White Path
May 10, 2026 · Information Security

Bypassing Traditional WMIExec Detection with a File‑less WMI Lateral Movement Technique

The article dissects a stealthy, file‑less WMI lateral movement method that avoids the obvious Win32_Process.Create signature by hijacking stopped LocalSystem services, leveraging the LOLBIN ScriptRunner.exe to execute remote SMB scripts, automatically restoring the service and leaving minimal forensic traces.

Detection EvasionFileless AttackLOLBIN
0 likes · 7 min read
Bypassing Traditional WMIExec Detection with a File‑less WMI Lateral Movement Technique
Black & White Path
Black & White Path
May 9, 2026 · Information Security

Dirty Frag: A New Deterministic Linux Page‑Cache Write Vulnerability for Stable Root Escalation

Dirty Frag is a newly disclosed Linux kernel page‑cache write bug that combines xfrm‑ESP and RxRPC primitives to deterministically corrupt struct sk_buff‑frag, allowing an unprivileged local user to gain root without race conditions, works across major distributions, and can be mitigated by disabling the affected modules.

Dirty FragLinux kernelLocal Privilege Escalation
0 likes · 9 min read
Dirty Frag: A New Deterministic Linux Page‑Cache Write Vulnerability for Stable Root Escalation
Black & White Path
Black & White Path
May 9, 2026 · Information Security

Ollama ‘Bleeding Llama’ Vulnerability Puts 300K Servers at Risk of Sensitive Data Exposure

A critical CVE‑2026‑7482 flaw in Ollama’s model quantization pipeline, dubbed “Bleeding Llama,” allows unauthenticated attackers to craft GGUF files that read beyond buffer limits, potentially leaking prompts, API keys and other confidential data from over 300,000 internet‑exposed servers, with mitigation requiring an upgrade to version 0.17.1 and stricter network controls.

AI securityBleeding LlamaCVE-2026-7482
0 likes · 5 min read
Ollama ‘Bleeding Llama’ Vulnerability Puts 300K Servers at Risk of Sensitive Data Exposure
Black & White Path
Black & White Path
May 9, 2026 · Information Security

AutoPentestX: An Automated Linux Penetration Testing Toolkit for Faster Red‑Team Assessments

AutoPentestX is an open‑source, Linux‑focused automated penetration testing framework that integrates tools like Nmap, Nikto, SQLMap and Metasploit into a single command workflow, stores results in SQLite, generates detailed PDF reports, and includes installation, usage instructions, legal compliance notes, and future development plans.

AutomationLinuxMetasploit
0 likes · 7 min read
AutoPentestX: An Automated Linux Penetration Testing Toolkit for Faster Red‑Team Assessments
Black & White Path
Black & White Path
May 9, 2026 · Industry Insights

2025 Chinese Cybersecurity Stocks: Quality Trends, Bright Spots and Red Flags

A comprehensive analysis of 21 Chinese network‑security listed firms in 2025 reveals a sector‑wide decline in revenue and gross profit, highlights three firms with positive gross‑profit growth, exposes severe receivables and cash‑flow risks, and details two ST‑alert cases that signal both operational collapse and governance failure.

ChinaST alertscash flow
0 likes · 27 min read
2025 Chinese Cybersecurity Stocks: Quality Trends, Bright Spots and Red Flags
Black & White Path
Black & White Path
May 9, 2026 · Information Security

Kaspersky Exposes DAEMON Tools Supply Chain Attack Infecting Over 100,000 Users

In May 2026, Kaspersky revealed that the official Windows installer for DAEMON Tools Lite versions 12.5.0.2421‑12.5.0.2434 had been compromised for nearly a month, allowing attackers to inject signed back‑door binaries, establish C2 communication, deliver staged payloads—including a QUIC RAT—to thousands of victims across more than a hundred countries, with high‑value targets primarily in Russia, Belarus and Thailand, before a patched version 12.6.0.2445 was released.

C2DAEMON ToolsKaspersky
0 likes · 7 min read
Kaspersky Exposes DAEMON Tools Supply Chain Attack Infecting Over 100,000 Users