Black & White Path
Author

Black & White Path

We are the beacon of the cyber world, a stepping stone on the road to security.

386
Articles
0
Likes
654
Views
0
Comments
Recent Articles

Latest from Black & White Path

100 recent articles max
Black & White Path
Black & White Path
May 24, 2026 · Information Security

How a Cat Meme Helped a 22‑Year‑Old Student Take Down the Kimwolf Botnet

A 22‑year‑old college student used a simple cat meme to gain the trust of a mysterious hacker, uncovered critical DNS and ADB vulnerabilities in the Kimwolf residential‑proxy botnet, and collaborated with security experts to dismantle a network that once controlled nearly two million devices.

Case studyDDoSKimWolf
0 likes · 14 min read
How a Cat Meme Helped a 22‑Year‑Old Student Take Down the Kimwolf Botnet
Black & White Path
Black & White Path
May 23, 2026 · Information Security

kn-live-dbg: A Debugger‑Like Windows Kernel Live Debugging Tool

kn-live-dbg is a lightweight, debugger‑styled Windows kernel memory browser that uses a kernel driver and a user‑mode TUI to read/write virtual and physical memory, enumerate callbacks, parse symbols, and even provide AI‑assisted command planning, offering a faster alternative to WinDbg for specific security research tasks.

AI assistantDbgHelpKernel Driver
0 likes · 12 min read
kn-live-dbg: A Debugger‑Like Windows Kernel Live Debugging Tool
Black & White Path
Black & White Path
May 23, 2026 · Information Security

GopherTrunk: A Pure‑Go Cluster Radio Scanner Supporting All Major Protocols (P25, DMR, TETRA, NXDN)

GopherTrunk is an open‑source, pure‑Go cluster radio scanner that decodes control channels for ten major digital trunking protocols—including P25, DMR, TETRA, NXDN—and amateur modes, offering zero‑dependency binaries, cross‑platform support, multiple UI options, and advanced DSP pipelines for physical‑penetration testing and radio security research.

DSPGoSDR
0 likes · 15 min read
GopherTrunk: A Pure‑Go Cluster Radio Scanner Supporting All Major Protocols (P25, DMR, TETRA, NXDN)
Black & White Path
Black & White Path
May 23, 2026 · Backend Development

Open‑Source MQTT WeChat Mini‑Program v5.2 Adds Battery Monitoring

This guide shows how to use MQTT to integrate lithium‑ion battery voltage, state‑of‑charge and health data from an ESP8266 into Home Assistant and a WeChat mini‑program, providing configuration examples, JSON payloads, and links to the fully open‑source repositories.

Battery MonitoringESP8266Home Assistant
0 likes · 4 min read
Open‑Source MQTT WeChat Mini‑Program v5.2 Adds Battery Monitoring
Black & White Path
Black & White Path
May 23, 2026 · Information Security

Telegram’s MTProto Design Flaw Lets Trackers Bypass VPNs and Proxies

A technical review reveals that Telegram’s MTProto protocol exposes a permanent 64‑bit device identifier (auth_key_id) in clear text, enabling passive observers—including ISPs, mobile carriers, and state surveillance—to track users across app restarts, IP changes, VPNs, and even Tor, rendering secret chats and PFS ineffective.

MTProtoTelegramauth_key_id
0 likes · 11 min read
Telegram’s MTProto Design Flaw Lets Trackers Bypass VPNs and Proxies
Black & White Path
Black & White Path
May 22, 2026 · Information Security

NGINX Poolslip 0‑Day RCE: Should You Panic?

A newly disclosed nginx‑poolslip 0‑day RCE affecting NGINX 1.31.0 targets the internal memory‑pool, requires a rare non‑default configuration, and while no public PoC exists, analysis of 4,000 real configurations found none exploitable, prompting specific mitigation steps.

0dayNginxRCE
0 likes · 9 min read
NGINX Poolslip 0‑Day RCE: Should You Panic?
Black & White Path
Black & White Path
May 22, 2026 · Information Security

How KAIDO RAT v3.0 Redefines Bank Malware with Modular PIX Hijacking and AI Credential Harvesting

KAIDO RAT v3.0, a .NET 9‑based modular malware suite with over 60 plugins, targets Brazil's PIX payment system, injects malicious QR codes, locks user devices, harvests AI platform credentials, and employs advanced evasion techniques, while the article also offers detailed defense recommendations.

.NET 9AI credential theftBanking malware
0 likes · 8 min read
How KAIDO RAT v3.0 Redefines Bank Malware with Modular PIX Hijacking and AI Credential Harvesting
Black & White Path
Black & White Path
May 22, 2026 · Information Security

GitHub Breach Aftermath: Data Sold to LAPSUS$ for $95,000

After TeamPCP posted a $50,000 offer for 4,000 private GitHub repositories, the data was transferred to LAPSUS$, the price doubled to $95,000, and the breach highlighted a supply‑chain attack chain that now threatens infrastructure credentials and prompts urgent self‑audit steps.

Data BreachGitHubLAPSUS$
0 likes · 9 min read
GitHub Breach Aftermath: Data Sold to LAPSUS$ for $95,000