Black & White Path
Author

Black & White Path

We are the beacon of the cyber world, a stepping stone on the road to security.

386
Articles
0
Likes
657
Views
0
Comments
Recent Articles

Latest from Black & White Path

100 recent articles max
Black & White Path
Black & White Path
May 26, 2026 · Information Security

How Attackers Rewrote 700+ Laravel Git Tags to Steal CI/CD Secrets

On the night of May 22 2026, an attacker with organization-level push credentials force-pushed every tag of four Laravel-Lang packages to a malicious fork, exploited Composer's files autoload to run a three-second payload, and exfiltrated cloud and CI/CD secrets, prompting a detailed forensic analysis and remediation guide.

CI/CD SecretsComposerGit Tag Hijacking
0 likes · 13 min read
How Attackers Rewrote 700+ Laravel Git Tags to Steal CI/CD Secrets
Black & White Path
Black & White Path
May 24, 2026 · Information Security

How StubZero Exposed a Google Cloud Production RCE and Earned $148,337

A researcher discovered an unauthenticated debug endpoint in Google Cloud that leaked protobuf definitions, turned it into a "req2proto as a Service", abused Stubby RPC permissions, chained several API calls to achieve full remote code execution, and received a $148,337 bug‑bounty.

API securityBug BountyGoogle Cloud
0 likes · 22 min read
How StubZero Exposed a Google Cloud Production RCE and Earned $148,337
Black & White Path
Black & White Path
May 24, 2026 · Information Security

AI‑Driven DeepSeek XML Error Injection Bypasses WAF, Dumps 19 DBs in 2 Hours

In a production‑environment penetration test, the researcher leveraged DeepSeek V4 Pro via a custom Claude Code bridge to craft an XML‑parsing‑error‑based Boolean blind SQL injection that evaded WAF keyword filters, allowing character‑by‑character extraction of all 19 database names within two hours at a cost of only ¥1.4.

DeepSeekPenetration TestingSQL Injection
0 likes · 10 min read
AI‑Driven DeepSeek XML Error Injection Bypasses WAF, Dumps 19 DBs in 2 Hours
Black & White Path
Black & White Path
May 24, 2026 · Industry Insights

Why Microsoft Shelved Claude Code After a $50 B AI Bet: The Rising Cost Crisis

The article examines Microsoft’s $50 billion investment in Anthropic’s Claude Code, its rapid internal adoption, the subsequent cancellation due to unpredictable token‑based expenses, and similar cost overruns at Uber, highlighting a broader AI token‑economics paradox that forces enterprises to rethink large‑scale AI deployments.

AI CostAI budgetingAnthropic
0 likes · 11 min read
Why Microsoft Shelved Claude Code After a $50 B AI Bet: The Rising Cost Crisis
Black & White Path
Black & White Path
May 24, 2026 · Information Security

WhatsApp’s 3 Billion User Data Leak: Encryption Myths Shattered

In May 2026 a hacker named NormalLeVrai released roughly 3 billion WhatsApp records on the dark web, prompting a Texas lawsuit against Meta, a public accusation by Telegram’s Pavel Durov, and a detailed technical analysis exposing gaps between WhatsApp’s end‑to‑end encryption theory and its real‑world implementation, followed by risk assessments and mitigation advice for enterprises and individuals.

Data BreachEnd-to-End EncryptionSignal Protocol
0 likes · 15 min read
WhatsApp’s 3 Billion User Data Leak: Encryption Myths Shattered