Black & White Path
Author

Black & White Path

We are the beacon of the cyber world, a stepping stone on the road to security.

386
Articles
0
Likes
654
Views
0
Comments
Recent Articles

Latest from Black & White Path

100 recent articles max
Black & White Path
Black & White Path
Jun 3, 2026 · Information Security

Stealing GitHub Tokens via a One‑Click VSCode WebView Exploit

The article details how a VSCode WebView vulnerability lets an attacker capture the OAuth token issued to github.dev, use keyboard‑event relay to install a malicious extension, and ultimately gain read‑write access to all of a victim’s private GitHub repositories, while also providing a PoC and mitigation steps.

ExtensionGitHub tokenOAuth
0 likes · 12 min read
Stealing GitHub Tokens via a One‑Click VSCode WebView Exploit
Black & White Path
Black & White Path
Jun 2, 2026 · Industry Insights

The Rise and Tragic Fall of Phil Katz, Father of the ZIP Format

Phil Katz, who created the ZIP compression format and became a millionaire before age 30, saw his groundbreaking work become an internet staple while his personal life spiraled into alcoholism and a lonely death in a motel, illustrating the stark contrast between technological legacy and personal tragedy.

ARC warPKZIPPhil Katz
0 likes · 6 min read
The Rise and Tragic Fall of Phil Katz, Father of the ZIP Format
Black & White Path
Black & White Path
Jun 1, 2026 · Information Security

OpenAI Enforces Phishing‑Resistant MFA for High‑Privilege AI Accounts Starting June 1 2026

On June 1 2026, OpenAI will require all researchers and defenders using its Trusted Access for Cyber (TAC) program to enable Advanced Account Security—a phishing‑resistant multi‑factor authentication—marking a shift from open model access to identity‑driven protection and reshaping the AI security landscape.

AI model securityAdvanced Account SecurityOpenAI
0 likes · 14 min read
OpenAI Enforces Phishing‑Resistant MFA for High‑Privilege AI Accounts Starting June 1 2026
Black & White Path
Black & White Path
Jun 1, 2026 · Information Security

KeyHacks: Verify Over 100 API Keys with a Single Curl Command

KeyHacks lets security engineers quickly test the validity of more than a hundred different API keys by providing ready‑made curl commands, eliminating the need to write code or read documentation and streamlining red‑team workflows.

API key validationGitHubKeyHacks
0 likes · 6 min read
KeyHacks: Verify Over 100 API Keys with a Single Curl Command
Black & White Path
Black & White Path
May 31, 2026 · Industry Insights

How a Single Bitcoin Address Brought Down the Dark‑Web King

The article recounts how hacker Kai Logan West, known as IntelBroker, abandoned his Monero‑only policy for a $250 Bitcoin payment, allowing FBI investigators to trace the transaction through KYC‑linked services and ultimately expose his identity, leading to his arrest.

BitcoinBlockchain ForensicsCrypto Crime
0 likes · 6 min read
How a Single Bitcoin Address Brought Down the Dark‑Web King
Black & White Path
Black & White Path
May 30, 2026 · Information Security

DigDeep: A Sensitive Information Mining Tool for Penetration Testing

DigDeep is a Java‑based tool that efficiently extracts nearly one hundred types of high‑, medium‑, and low‑risk sensitive data from source files across cloud, mini‑program, app, and web environments, offering recursive scanning, risk‑level filtering, deduplication, and multi‑format export to aid security audits.

DigDeepJavaPenetration Testing
0 likes · 4 min read
DigDeep: A Sensitive Information Mining Tool for Penetration Testing
Black & White Path
Black & White Path
May 30, 2026 · Information Security

Multiple Critical RCE Flaws Discovered in Notepad++ Affect Millions of Windows Users

Notepad++ has been found to contain three serious vulnerabilities—two remote‑code‑execution flaws (CVE‑2026‑48778, CVE‑2026‑48800) and a denial‑of‑service issue (CVE‑2026‑48770)—all exploiting unchecked XML configuration files, putting millions of Windows users at high risk until they apply the latest security update.

CVEConfiguration FileNotepad
0 likes · 8 min read
Multiple Critical RCE Flaws Discovered in Notepad++ Affect Millions of Windows Users
Black & White Path
Black & White Path
May 30, 2026 · Industry Insights

Why Is Google Paying Only $500 for a Critical V8 Out‑of‑Bounds Write Bug?

The article examines Google’s $500 reward for a high‑severity V8 out‑of‑bounds write vulnerability, tracing the historic decline of bug‑bounty payouts, the monopolistic role of major platforms, AI‑driven bug‑finding saturation, and the resulting challenges for security researchers both globally and in China.

AIBug BountyGoogle
0 likes · 11 min read
Why Is Google Paying Only $500 for a Critical V8 Out‑of‑Bounds Write Bug?
Black & White Path
Black & White Path
May 29, 2026 · Information Security

Zero‑Click Outlook RCE (CVE‑2026‑40361): Selecting a New Email Instantly Compromises the System

CVE‑2026‑40361 is a high‑severity, use‑after‑free vulnerability in Microsoft Outlook’s preview pane that enables remote code execution without any user interaction; the flaw, rated 8.4 CVSS and marked “Exploitation More Likely,” affects multiple Office versions and can be mitigated by immediate patching, disabling the preview pane, registry hardening, and layered email‑gateway and endpoint defenses.

CVE-2026-40361Email securityMicrosoft Office
0 likes · 14 min read
Zero‑Click Outlook RCE (CVE‑2026‑40361): Selecting a New Email Instantly Compromises the System