Black & White Path
Author

Black & White Path

We are the beacon of the cyber world, a stepping stone on the road to security.

611
Articles
0
Likes
3.4k
Views
0
Comments
Recent Articles

Latest from Black & White Path

100 recent articles max
Black & White Path
Black & White Path
Jul 24, 2026 · Information Security

How an AI‑Powered Loop Hunt Discovered Over 200 Real Bugs in Six Months

A security researcher turned his traditional manual code‑review process into a continuous AI‑driven loop, building the raptor‑loop‑hunt Claude skill that automatically generates, validates, and records vulnerabilities, ultimately uncovering more than 200 confirmed bugs across dozens of real codebases in half a year.

AI securityClaude Codeadversarial verification
0 likes · 6 min read
How an AI‑Powered Loop Hunt Discovered Over 200 Real Bugs in Six Months
Black & White Path
Black & White Path
Jul 24, 2026 · Information Security

How ENCFORGE Ransomware Exploits Langflow’s CVE‑2025‑3248 to Hijack AI Models

Sysdig’s threat team uncovered that the JADEPUFFER group leveraged the unauthenticated RCE in Langflow (CVE‑2025‑3248, CVSS 9.8) to deploy a Go‑based ransomware, ENCFORGE, which encrypts up to 180 AI/ML file formats, performs rapid container‑escape attacks via the Docker socket, and demands ransom through a reused email address.

AES-256-CTRAI ransomwareCVE-2025-3248
0 likes · 12 min read
How ENCFORGE Ransomware Exploits Langflow’s CVE‑2025‑3248 to Hijack AI Models
Black & White Path
Black & White Path
Jul 24, 2026 · Information Security

How Kimi K3 Uncovered Multiple Redis Zero‑Day RCE Bugs in Just 27 Minutes

In July 2026, the AI model Kimi K3 from Moonshot AI discovered and generated working remote‑code‑execution exploits for four Redis versions within 27 minutes, detailing a double‑free Stream NACK flaw and a TDigest heap overflow, and providing open‑source PoC scripts and defense guidance.

AI Vulnerability DiscoveryRedisexploit
0 likes · 9 min read
How Kimi K3 Uncovered Multiple Redis Zero‑Day RCE Bugs in Just 27 Minutes
Black & White Path
Black & White Path
Jul 23, 2026 · Information Security

Anthropic Launches Claude Security in Open Beta, Signaling an Emerging AI Security Empire

Anthropic's Claude Security, built on Claude Opus 4.7, entered open beta on April 30, offering enterprise AI‑driven code vulnerability scanning and automated patch generation, and completing a three‑product security suite that also includes Claude Code and Claude Cowork, with broader implications for blue‑team operations and AI‑enabled threat landscapes.

AI securityAnthropicClaude Security
0 likes · 8 min read
Anthropic Launches Claude Security in Open Beta, Signaling an Emerging AI Security Empire
Black & White Path
Black & White Path
Jul 22, 2026 · Information Security

How Windows Tracks You: Inside the GDID Identifier and Extraction Tool

The article explains the Global Device Identifier (GDID) embedded in every Windows machine, how it is stored in the registry, used across Microsoft services, and how researchers can extract or attempt to spoof it with the GDID‑Extractor tool, revealing a four‑layer defense and privacy implications.

Device IdentifierGDIDTool
0 likes · 18 min read
How Windows Tracks You: Inside the GDID Identifier and Extraction Tool
Black & White Path
Black & White Path
Jul 22, 2026 · Information Security

US Cyber Shield vs China’s Protective Net: Detailed Comparison of 2026 Cyber Defense Exercises

The 2026 Cyber Shield exercise, the U.S. Department of Defense’s largest non‑classified cyber‑defense drill, focused on OT and power‑grid security, while China’s Protective Net emphasized real‑world attack‑defense and rapid remediation, highlighting differing goals, scopes, and international collaboration between the two nations.

Cyber ShieldOT securityProtective Net
0 likes · 7 min read
US Cyber Shield vs China’s Protective Net: Detailed Comparison of 2026 Cyber Defense Exercises
Black & White Path
Black & White Path
Jul 22, 2026 · Information Security

How swift-section Extracts Private iOS Swift Interfaces from Mach‑O Binaries

The swift-section tool reads __swift5_ sections in iOS Mach‑O binaries, parses Swift ABI metadata, demangles symbols, and generates a complete Swift interface file, revealing private framework designs such as DesignLibrary without accessing source code, a valuable capability for security researchers.

Mach-OReverse EngineeringSwift ABI
0 likes · 4 min read
How swift-section Extracts Private iOS Swift Interfaces from Mach‑O Binaries