BlackTree Security · Infrastructure · Automation · AI

BlackTree — Independent Technology Analysis

BlackTree Editorial

Independent technology intelligence Analysis · Technical guides · Homelab · Legacy systems

Security, systems and emerging technology

Know the signal behind the incident.

Independent analysis for the people who build, secure and operate technology, with the clarity to inform action and the technical depth to earn trust.

Evidence-linked Operational context Independent

ASOS Says Contact Details May Be Affected

Check official channels.

Read the article ↗

Current reporting

Latest intelligence

View all articles ↗

Eight Atlassian Products Could Expose Known Files

Atlassian's 5 October advisory for CVE-2026-21589 affects eight self-managed products. An unauthenticated attacker knowing a file's exact path and name can read it within the web-application root. Directories cannot be listed. The advisory describes file access, not code execution. Cloud is patched; Atlassian found no exploitation evidence. Inventory installations; use the fix matrix. Patch precisely Until patched, restrict internet access or use the all-product WAF/proxy rule. Tomcat RewriteValve covers only Confluence, Jira Service Management, Jira Software, Bamboo and Crowd. Bitbucket uses urlrewrite.xml; Crucible and Fisheye use the all-product option.

6 Oct 2026 · 1 min read

Salesforce MCE User Domain Change Affects Some New Senders

A 4 October change narrows sender verification. Salesforce's Marketing Cloud Engagement User Domain notice applies to organisations that created User Domains since 1 February 2026 without a domain verified for their account.…

6 Oct 2026 · 1 min read

Dental Images Instruct AI

Controlled tests expose answer flips and limits. A study published 3 October 2026 embedded text in 270 dental X-rays and tested four vision-language models across 58,320 calls. In a repeat benchmark, pooled…

6 Oct 2026 · 1 min read

Fiddler Classic Could Elevate the Wrong Signed Helper

Progress's advisory fixes CVE-2026-77805, a Windows privilege-escalation flaw in Fiddler Classic before 6.0.20262.10021. Fiddler accepted an allowed publisher signature without verifying the exact helper. A low-privileged local attacker must replace a helper…

6 Oct 2026 · 1 min read

Two Jira 10.1 Products Reach Support End on 9 October

Check both products before 9 October. Atlassian's end-of-support policy lists 9 October 2026 for Jira Software 10.1 and Jira Service Management 10.1. It is a support deadline, not a service outage. Check…

6 Oct 2026 · 1 min read

Revised reporting

Recently updated

View all articles

Geographic context

Regional intelligence

Browse all articles ↗

Coverage leaders

Vendor intelligence

Browse all articles ↗

Practical archive

Lab &
Legacy

Field-tested guidance for keeping older systems useful, secure and reliable long after mainstream documentation has moved on. Practical fixes, automation and deployment notes are drawn from real environments and written for the operators who still maintain them.