BlackTree Security · Infrastructure · Automation · AI

BlackTree — Independent Technology Analysis

BlackTree Editorial

Independent technology intelligence Analysis · Technical guides · Homelab · Legacy systems

Security, systems and emerging technology

Know the signal behind the incident.

Independent analysis for the people who build, secure and operate technology, with the clarity to inform action and the technical depth to earn trust.

Evidence-linked Operational context Independent

RedFlick Gives Star Blizzard a Shorter Route From Phishing to Persistence

Star Blizzard’s RedFlick campaigns turn an email reply into a path toward a protected archive. Defenders need to distinguish mail exposure from endpoint execution.

Read the article ↗

Current reporting

Latest intelligence

View all articles ↗

wolfSSL 5.9.4 Puts Trust State on the Patch Checklist

wolfSSL 5.9.4 makes a simple “version updated” sign-off inadequate. Its vendor notes list 11 vulnerabilities: three High, four Medium and four Low. The release heading says 25 September; GitHub shows publication on 27 September. Exposure depends on the deployed application's build and behaviour. What does the release cover? The High group concerns trusted-peer key matching (CVE-2026-93302), multiple OCSP stapling (CVE-2026-89102) and non-default Raw Public Key support (CVE-2026-89136). Each has its own prerequisites; the first two also depend on particular API use. The OCSP case can leave a certificate in a reused context's trust store. The Medium entries cover a conditional handshake flaw (CVE-2026-93304), name constraints (CVE-2026-89133, CVE-2026-89134) and shared certificate-manager contamination (CVE-2026-89135). The Low group covers shutdown use-after-free (CVE-2026-15442), combined OCSP/CRL checks (CVE-2026-94417), small-certificate verification with a permissive date callback (CVE-2026-94418) and legacy session references (CVE-2026-94419). Several paths can retain trust state after a connection ends. Build an exposure decision around the application BlackTree analysis: Start with the product owner, not a vulnerability score. Identify services and devices that ship wolfSSL, including statically linked copies. Record the linked library version, build settings and certificate-verification APIs from the actual deployed artefact. A package manifest that says “wolfSSL present” cannot tell you whether a conditional feature was compiled or used. Split the review into three questions. Does the application authenticate a remote peer with the affected TLS or DTLS path? Does its build enable the relevant feature, such as trusted-peer certificates, multi-response OCSP, Raw Public Key, combined revocation checks or legacy session…

1 Oct 2026 · 3 min read

TeamViewer Fixed a Flaw That Could Override Your Session Permissions

TeamViewer's 29 September bulletin fixes five High-severity flaws in Full Client and Host, including a remote-session permission bypass. The current corrected version is 15.82; older branches need the platform-specific legacy fixes. The…

30 Sep 2026 · 3 min read

One Encoded URL Can Hand Attackers Cisco SD-WAN Admin Access

A crafted HTTP request can give attackers administrator-level API access to Cisco Catalyst SD-WAN Manager without a login. Cisco says the flaw is already being exploited. Cisco disclosed CVE-2026-76504 on 30 September…

30 Sep 2026 · 4 min read

The VPN Server Your Firebox Trusts Could Hand It Root Commands

WatchGuard has patched 15 vulnerabilities across supported Fireware OS branches. The most serious one turns an expected trust relationship inside out: a hostile remote VPN server can send configuration that a connecting…

30 Sep 2026 · 6 min read

Revised reporting

Recently updated

View all articles

Geographic context

Regional intelligence

Browse all articles ↗

Coverage leaders

Vendor intelligence

Browse all articles ↗

Practical archive

Lab &
Legacy

Field-tested guidance for keeping older systems useful, secure and reliable long after mainstream documentation has moved on. Practical fixes, automation and deployment notes are drawn from real environments and written for the operators who still maintain them.