Showing 100 articles max
Black & White Path
Black & White Path
May 27, 2026 · Information Security

From White‑Hat to Banned Outlaw: The Rapid Fall of a Security Researcher

An anonymous researcher with a legitimate MSRC account publicly released multiple Windows 0‑day exploits after his reports were ignored, leading to swift bans on GitHub and GitLab, sparking a heated debate over platform policies, coordinated disclosure failures, and the broader breakdown of the bug‑bounty ecosystem.

Bug BountyGitHubGitLab
0 likes · 9 min read
From White‑Hat to Banned Outlaw: The Rapid Fall of a Security Researcher
Black & White Path
Black & White Path
May 27, 2026 · Information Security

Five AD Permission Misconfigurations That Let Attackers Escalate to Domain Admin Without Exploits

The article explains how misconfigured Active Directory DACL entries enable five distinct privilege‑escalation paths—ForceChangePassword, FullControl on Domain Admins, DCSync, WriteMembers, and GUID‑based ACE writes—demonstrating each step with impacket commands, showing detection events, and offering concrete defense recommendations.

Active DirectoryBloodHoundDACL
0 likes · 17 min read
Five AD Permission Misconfigurations That Let Attackers Escalate to Domain Admin Without Exploits
Java Architect Essentials
Java Architect Essentials
May 26, 2026 · Information Security

A 3‑Year‑Tested Unified Multi‑Account Login Architecture

The article walks through a company’s three‑year‑old unified multi‑account login design, covering phone‑code registration, optimized password‑optional login, third‑party OAuth integration, a split user‑base/auth schema, its pros and cons, and a carrier‑based one‑click login flow that reduces login time from seconds to milliseconds.

Database DesignMulti-Account AuthenticationThird-Party OAuth
0 likes · 13 min read
A 3‑Year‑Tested Unified Multi‑Account Login Architecture
Code Mala Tang
Code Mala Tang
May 26, 2026 · Information Security

Claude Code Now Detects Security Flaws While You Write: Anthropic’s Three‑Layer Security‑Guidance Plugin

Anthropic’s security‑guidance plugin adds three progressive layers of automated security checks—instant string‑pattern matching, end‑of‑turn diff review, and deep commit‑time analysis—to Claude Code, letting the AI catch and fix common vulnerabilities as you code without blocking your workflow.

AI coding assistantAnthropicClaude Code
0 likes · 15 min read
Claude Code Now Detects Security Flaws While You Write: Anthropic’s Three‑Layer Security‑Guidance Plugin
Smart Workplace Lab
Smart Workplace Lab
May 26, 2026 · Information Security

When Employees Secretly Use External AI: A Practical Guide to Enterprise AI Security Governance

The article explains why blanket bans on external AI backfire, introduces a red‑yellow‑green data‑classification routing system with mandatory pre‑masking and audit logs, and provides a three‑step protocol to securely integrate AI while maintaining compliance and business continuity.

AI governanceCompliancedata classification
0 likes · 6 min read
When Employees Secretly Use External AI: A Practical Guide to Enterprise AI Security Governance
Tencent Technical Engineering
Tencent Technical Engineering
May 26, 2026 · Information Security

AI Era Vulnerability Benchmark Revamp: 3,632 CVE Insights & VulnGym Release

Analyzing 3,632 high‑severity GitHub Advisory reports from 2025‑2026, the authors reveal a sharp rise in business‑logic flaws—especially in high‑star projects—prompting a redesign of vulnerability‑detection benchmarks, and introduce VulnGym, a real‑project, white‑box dataset with 400+ paths and detailed entry‑point, trace, and critical‑operation annotations.

AI securityBusiness Logic BugsOpen Source
0 likes · 17 min read
AI Era Vulnerability Benchmark Revamp: 3,632 CVE Insights & VulnGym Release
Architects' Tech Alliance
Architects' Tech Alliance
May 26, 2026 · Information Security

How Sugon Cloud’s “3D Secure Computation” Delivers Seamless Security for Financial Institutions

Facing the 2025‑2026 regulatory deadline, Sichuan Rural Commercial Union Bank migrated its core services to Sugon Cloud’s “3D Secure Computation” platform, achieving full‑link encryption with only a 4.4% performance overhead and proving that hardware‑based security can be both compliant and virtually invisible to users.

Performance OptimizationSugon Cloudcloud security
0 likes · 5 min read
How Sugon Cloud’s “3D Secure Computation” Delivers Seamless Security for Financial Institutions
Black & White Path
Black & White Path
May 26, 2026 · Information Security

How Attackers Rewrote 700+ Laravel Git Tags to Steal CI/CD Secrets

On the night of May 22 2026, an attacker with organization-level push credentials force-pushed every tag of four Laravel-Lang packages to a malicious fork, exploited Composer's files autoload to run a three-second payload, and exfiltrated cloud and CI/CD secrets, prompting a detailed forensic analysis and remediation guide.

CI/CD SecretsComposerGit Tag Hijacking
0 likes · 13 min read
How Attackers Rewrote 700+ Laravel Git Tags to Steal CI/CD Secrets
SuanNi
SuanNi
May 25, 2026 · Information Security

Claude Mythos Finds Over 10,000 Critical Bugs in Weeks – Glasswing Project Shocks Security World

Anthropic's Claude Mythos preview model, deployed in the Glasswing project, uncovered more than 10,000 high‑severity vulnerabilities across core software in just weeks, validated by independent researchers, while highlighting the massive gap between rapid AI‑driven bug discovery and the slower human patching process.

AI securityClaude MythosGlasswing
0 likes · 11 min read
Claude Mythos Finds Over 10,000 Critical Bugs in Weeks – Glasswing Project Shocks Security World
Shuge Unlimited
Shuge Unlimited
May 25, 2026 · Information Security

Why Securing AI Agents Is a Nightmare: How Many Are Struggling?

The article analyzes the security challenges of large‑scale AI agents, explains why fine‑grained permission design is essential, critiques existing protocols like MCP, A2A, and CLI/GUI automation, and details the new ATH three‑party trusted handshake with code examples and a Python demo.

A2AAI agentsATH protocol
0 likes · 26 min read
Why Securing AI Agents Is a Nightmare: How Many Are Struggling?
Black & White Path
Black & White Path
May 24, 2026 · Information Security

How StubZero Exposed a Google Cloud Production RCE and Earned $148,337

A researcher discovered an unauthenticated debug endpoint in Google Cloud that leaked protobuf definitions, turned it into a "req2proto as a Service", abused Stubby RPC permissions, chained several API calls to achieve full remote code execution, and received a $148,337 bug‑bounty.

API SecurityBug BountyGoogle Cloud
0 likes · 22 min read
How StubZero Exposed a Google Cloud Production RCE and Earned $148,337
Black & White Path
Black & White Path
May 24, 2026 · Information Security

AI‑Driven DeepSeek XML Error Injection Bypasses WAF, Dumps 19 DBs in 2 Hours

In a production‑environment penetration test, the researcher leveraged DeepSeek V4 Pro via a custom Claude Code bridge to craft an XML‑parsing‑error‑based Boolean blind SQL injection that evaded WAF keyword filters, allowing character‑by‑character extraction of all 19 database names within two hours at a cost of only ¥1.4.

DeepSeekSQL injectionWAF bypass
0 likes · 10 min read
AI‑Driven DeepSeek XML Error Injection Bypasses WAF, Dumps 19 DBs in 2 Hours
IT Services Circle
IT Services Circle
May 24, 2026 · Information Security

Fired, He Deleted 96 Government Databases in Minutes and Asked AI How to Clear Logs

Just five minutes after being terminated, twin brothers with prior fraud convictions used SQL commands to drop 96 U.S. government databases, queried AI on log‑clearing techniques, and exposed critical failures in the company's off‑boarding process, leading to a high‑profile federal investigation and legal fallout.

AIIncident ResponseInformation Security
0 likes · 9 min read
Fired, He Deleted 96 Government Databases in Minutes and Asked AI How to Clear Logs