Black & White Path
Author

Black & White Path

We are the beacon of the cyber world, a stepping stone on the road to security.

611
Articles
0
Likes
3.4k
Views
0
Comments
Recent Articles

Latest from Black & White Path

100 recent articles max
Black & White Path
Black & White Path
Aug 5, 2026 · Information Security

Why the $700‑per‑month Android RAT Is Flooding the Underground Market

Security firm Flare’s analysis of thousands of forum posts reveals that the BTMOB Android remote‑access trojan, originally priced at $700 per month, has evolved from a single‑operator service into a fragmented ecosystem of resale, source‑code sales, and counterfeit versions, with secondary‑market prices up to 13‑times lower than the official rates.

AndroidMalware-as-a-ServiceRAT
0 likes · 10 min read
Why the $700‑per‑month Android RAT Is Flooding the Underground Market
Black & White Path
Black & White Path
Aug 4, 2026 · Industry Insights

Qwen3.8-Max Secures Fourth Place on Frontend Code Arena Leaderboard

Alibaba's Tongyi Qianwen team announced that the flagship model Qwen3.8‑Max achieved a score of 1,668 to rank fourth on the Frontend Code Arena benchmark, trailing Claude Opus 5 (High) by just one point and staying within 37 points of the top‑scoring Claude Opus 5 (Max), while also earning strong placements across multiple sub‑domains such as Consumer Product (#2) and Gaming (#3).

AI model benchmarkClaude OpusFrontend Code Arena
0 likes · 3 min read
Qwen3.8-Max Secures Fourth Place on Frontend Code Arena Leaderboard
Black & White Path
Black & White Path
Aug 3, 2026 · Industry Insights

HackerOne Enforces Real‑Name Verification: Government ID Required for Bug Reports Starting Aug 14

HackerOne will mandate government‑issued ID verification for all bug bounty submissions from August 14, excluding minors and users on VPNs or rooted devices, sparking community outrage, raising privacy concerns, and potentially driving researchers toward gray‑market channels as regulatory pressure mounts.

Bug BountyHackerOneKYC
0 likes · 9 min read
HackerOne Enforces Real‑Name Verification: Government ID Required for Bug Reports Starting Aug 14
Black & White Path
Black & White Path
Aug 3, 2026 · Information Security

CVE‑2026‑60206: Oracle WebLogic Server SAML Authentication Bypass (CVSS 9.9) – Full POC

Oracle disclosed a critical CVE‑2026‑60206 SAML authentication bypass in WebLogic Server Core (CVSS 9.9) affecting versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0, with a publicly available Python‑based POC that supports multiple attack modes, detection scripts, and remediation guidance.

Authentication BypassCVE-2026-60206InfoSec
0 likes · 7 min read
CVE‑2026‑60206: Oracle WebLogic Server SAML Authentication Bypass (CVSS 9.9) – Full POC
Black & White Path
Black & White Path
Aug 3, 2026 · Industry Insights

India's 'Sovereign AI' Debacle: From Mistral to DeepSeek Shells

The article examines Sarvam AI’s lofty claim to build a sovereign Indian LLM, its $41 million funding, the use of Mistral and DeepSeek foundations, the government‑provided 4096 H100 GPUs, technical breakthroughs like a custom tokenizer, and the ensuing industry debate over copying versus genuine innovation.

DeepSeekIndia AIMistral
0 likes · 12 min read
India's 'Sovereign AI' Debacle: From Mistral to DeepSeek Shells
Black & White Path
Black & White Path
Aug 2, 2026 · Information Security

How Hackers Swept $38 Million Using a “Seed Lottery” Tool: In‑Depth Coldcard RNG Vulnerability Analysis

A detailed technical investigation reveals that a simple macro‑comparison bug in Coldcard firmware reduced entropy to about 40 bits, enabling attackers to enumerate seed space, derive vulnerable addresses, and steal roughly $38 million in Bitcoin within minutes, while the hardware TRNG remained unused.

ColdcardRNGSecurity
0 likes · 18 min read
How Hackers Swept $38 Million Using a “Seed Lottery” Tool: In‑Depth Coldcard RNG Vulnerability Analysis
Black & White Path
Black & White Path
Aug 2, 2026 · Information Security

How a Simple "Hello World" Flatpak App Escapes the PipeWire Sandbox to Execute Arbitrary Code

The analysis of CVE‑2026‑5674 reveals that PipeWire’s PulseAudio compatibility layer contains three independent flaws—a missing cookie verification, default‑enabled module loading, and unrestricted dlopen() paths—that together let a sandboxed Flatpak app with only audio permission write files, launch desktop applications, and run arbitrary code on the host.

CVE-2026-5674FlatpakLinux security
0 likes · 15 min read
How a Simple "Hello World" Flatpak App Escapes the PipeWire Sandbox to Execute Arbitrary Code
Black & White Path
Black & White Path
Aug 2, 2026 · Artificial Intelligence

Running a 2.8‑Trillion‑Parameter K3 Model on 4 GB VRAM with AirLLM

AirLLM introduces layer‑wise inference and per‑expert streaming to decouple VRAM usage from model size, enabling the 2.8‑trillion‑parameter Kimi K3 LLM to run on a single consumer‑grade GPU while preserving full‑precision accuracy and offering security‑focused insights.

AirLLMKimi K3Layer-wise Inference
0 likes · 9 min read
Running a 2.8‑Trillion‑Parameter K3 Model on 4 GB VRAM with AirLLM