BlackTree Security · Infrastructure · Automation · AI

BlackTree — Independent Technology Analysis

BlackTree Editorial

Independent technology intelligence Analysis · Technical guides · Homelab · Legacy systems

Security, systems and emerging technology

Know the signal behind the incident.

Independent analysis for the people who build, secure and operate technology, with the clarity to inform action and the technical depth to earn trust.

Evidence-linked Operational context Independent

DriveWealth Breach Notice May Name the Broker Behind the App

Verify the broker relationship through the investing service you already use.

Read the article ↗

Current reporting

Latest intelligence

View all articles ↗

The SonicWall Gateway Can Proxy Requests Before Login

SonicWall has fixed four vulnerabilities in SMA1000 models 6210, 7210 and 8200v. The most urgent, CVE-2026-102255, is a pre-authentication server-side request forgery flaw in Appliance WorkPlace. A remote unauthenticated attacker could make the appliance issue requests, reach internal functionality and perform unauthorised operations. SonicWall assigns it a CVSS score of 10.0. The vendor provides no workaround and says there is currently no evidence that the October vulnerabilities are being exploited. This is an urgent patch advisory, not confirmation of a breach or campaign. The appliance becomes a confused deputy The risk is not simply that an outside request reaches the gateway. The gateway can become the intermediary that sends another request from a more trusted position. Controls that assume the appliance is a legitimate source may therefore see the request differently from one arriving directly from the internet. SonicWall has not published the internal functions or destinations that can be reached in every deployment. The advisory also does not say that the unauthenticated path produces code execution. Defenders should not turn a maximum score into a broader claim than the evidence supports. Four flaws share one fixed release CVE-2026-102255 is the unauthenticated forward-proxy SSRF. CVE-2026-102256 is operating-system command injection. Under specific conditions, an authenticated administrator can execute arbitrary operating-system commands. CVE-2026-102257 is a post-authentication Zip Slip flaw in the Appliance Management Console that can result in remote code execution. CVE-2026-102258 is stored cross-site scripting. Under specific conditions, an authenticated administrator can store and potentially execute JavaScript in the Appliance Management…

7 Oct 2026 · 2 min read

Opening the Coding Test Was the Execution Step

Unit 42's Blinder Tunnel report traces an Iranian-nexus operation targeting one person in Iraqi critical infrastructure. Infrastructure staging began in November 2025, recruitment in March 2026 and a fake Dubai Airports coding…

7 Oct 2026 · 1 min read

Arizona Court Cyberattack

Arizona Courts says that on 24 September 2026 attackers copied backup files holding information on approximately 1.3 million people in its Fines/Fees and Restitution Enforcement (FARE) programme. The dataset includes names, case…

7 Oct 2026 · 1 min read

KB5124010 Can Close Legacy AC-3 Apps

Microsoft added an AC-3 issue to KB5124010 on 3 October. Some apps may refuse to start or shut unexpectedly when using Windows' built-in Dolby Digital decoder. Windows 11 24H2, 25H2 and 26H2…

7 Oct 2026 · 1 min read

WordPress XSS Leaves Backdoors

Two WordPress flaws are being exploited. Patchstack links one payload to WPC Product Bundles and Ninja Forms. The WPC flaw is CVE-2026-93836; the Ninja Forms flaw is CVE-2026-94504. The administrator view is…

7 Oct 2026 · 2 min read

Revised reporting

Recently updated

View all articles

Geographic context

Regional intelligence

Browse all articles ↗

Coverage leaders

Vendor intelligence

Browse all articles ↗

Practical archive

Lab &
Legacy

Field-tested guidance for keeping older systems useful, secure and reliable long after mainstream documentation has moved on. Practical fixes, automation and deployment notes are drawn from real environments and written for the operators who still maintain them.