Black & White Path
Author

Black & White Path

We are the beacon of the cyber world, a stepping stone on the road to security.

611
Articles
0
Likes
3.4k
Views
0
Comments
Recent Articles

Latest from Black & White Path

100 recent articles max
Black & White Path
Black & White Path
Aug 15, 2026 · Information Security

OKTOS: AI‑Powered Red Team Post‑Exploitation Platform Overview

OKTOS is a modular red‑team post‑exploitation platform that leverages AI assistance, BOF dynamic loading, multi‑channel asynchronous C2, and memory‑evasion techniques, offering a suite of web‑based interfaces for payload generation, session management, attack orchestration, and automated reporting, though it is presented as an unreviewed prototype.

AI assistantBOFC2
0 likes · 5 min read
OKTOS: AI‑Powered Red Team Post‑Exploitation Platform Overview
Black & White Path
Black & White Path
Aug 14, 2026 · Information Security

CVE-2026-68138: Linux Kernel qdisc Rate‑Table Race Condition Allows Local Privilege Escalation (PoC Included)

Security researchers disclosed CVE‑2026‑68138, a race‑condition flaw in the Linux kernel’s qdisc rate‑table code that lets an unprivileged user gain a root shell within seconds; it affects Linux 5.1‑7.1.5, has a publicly available PoC, and can be mitigated by applying upstream patches or disabling unprivileged namespaces.

CVE-2026-68138Linux Kernellocal privilege escalation
0 likes · 9 min read
CVE-2026-68138: Linux Kernel qdisc Rate‑Table Race Condition Allows Local Privilege Escalation (PoC Included)
Black & White Path
Black & White Path
Aug 13, 2026 · Information Security

How OpenAI’s GPT‑Red AI Red‑Team Automates Attacks in Four Steps, Outpacing Human Experts

OpenAI’s GPT‑Red model automates red‑team style prompt‑injection attacks through a four‑stage loop—goal setting, attack generation, response observation, and iterative refinement—demonstrating six‑fold safety gains over previous models and surpassing manual red‑team capabilities across multiple real‑world case studies.

AI securityGPT-RedPrompt Injection
0 likes · 29 min read
How OpenAI’s GPT‑Red AI Red‑Team Automates Attacks in Four Steps, Outpacing Human Experts
Black & White Path
Black & White Path
Aug 13, 2026 · Information Security

Master Web Reverse Engineering with the hello_js_reverse_skill

The hello_js_reverse_skill provides a comprehensive workflow for web reverse engineering and signature reconstruction, combining Camoufox anti‑detection browsing, dual‑language algorithm decryption, JS obfuscation analysis, anti‑crawling tactics, and seamless AI integration, with both AI‑chat and manual installation options.

JS obfuscationNode.jsPython
0 likes · 6 min read
Master Web Reverse Engineering with the hello_js_reverse_skill
Black & White Path
Black & White Path
Aug 13, 2026 · Information Security

Anthropic’s Mythos AI Reveals Linux Eventpoll Race Condition (CVE‑2026‑43074)

The article provides an in‑depth technical analysis of CVE‑2026‑43074, a use‑after‑free race condition in the Linux kernel’s eventpoll implementation, detailing how Anthropic’s Mythos AI discovered the flaw, the underlying RCU‑based fix, its impact, exploitation constraints, and recommended mitigation steps.

AI code auditCVE-2026-43074Linux Kernel
0 likes · 10 min read
Anthropic’s Mythos AI Reveals Linux Eventpoll Race Condition (CVE‑2026‑43074)
Black & White Path
Black & White Path
Aug 12, 2026 · Information Security

How Researchers Recovered Encrypted Reasoning Traces from Leading AI Models and Exposed Credential Leaks

A cross‑institutional team showed that encrypted reasoning blocks in Anthropic, OpenAI and Google APIs can be replayed across sessions and models, reconstructing 315,000 blocks and leaking dozens of API keys, passwords and other sensitive artifacts, highlighting a systemic security flaw in current LLM deployments.

AI model vulnerabilityAnthropicGoogle
0 likes · 7 min read
How Researchers Recovered Encrypted Reasoning Traces from Leading AI Models and Exposed Credential Leaks
Black & White Path
Black & White Path
Aug 12, 2026 · Information Security

Multiple Fixed High‑Risk EDUSRC and Corporate SRC Vulnerabilities Revealed

This article details several high‑severity vulnerabilities discovered in educational (EDUSRC) and corporate source‑code repositories, including session‑key leakage in WeChat mini‑programs, unauthorized API access, and SQL injection, and walks through the exploitation steps and how each issue was ultimately patched.

EDUSRCSQL injectionWeChat Mini Program
0 likes · 6 min read
Multiple Fixed High‑Risk EDUSRC and Corporate SRC Vulnerabilities Revealed