BlackTree Security · Infrastructure · Automation · AI

BlackTree — Independent Technology Analysis

BlackTree Editorial

Independent technology intelligence Analysis · Technical guides · Homelab · Legacy systems

Security, systems and emerging technology

Know the signal behind the incident.

Independent analysis for the people who build, secure and operate technology, with the clarity to inform action and the technical depth to earn trust.

Evidence-linked Operational context Independent

Kiteworks Asked Customers to Switch Off Its Platform for Six Hours

Kiteworks recommended a six-hour shutdown after receiving credible threat intelligence. The warning was preventive, but the missing details matter.

Read the article ↗

Current reporting

Latest intelligence

View all articles ↗

Attackers Copied Every Incoming Belnet Email for Two Months

Belnet says attackers copied every incoming email sent to it and one customer from 22 July until the morning of 25 September 2026. The copied material included message contents and attachments and was transferred to external infrastructure.

Its incident notice attributes the breach to an external supplier's zero-day vulnerability. Belnet detected the incident on 24 September and says the flaw was resolved at 08:10 the following morning. Belgium's Centre for Cybersecurity is assisting. The supplier, product, actor, affected customer and message count are not named; the investigation remains open.

The practical response should follow the correspondence, not just the recipient accounts. An organisation that sent a contract, a support bundle or a recovery link needs to identify that specific material and decide whether it still creates risk. Those are examples to check, not a confirmed inventory of what was taken.

A successful delivery receipt says nothing about whether another copy exists. Likewise, containment cannot recall material already transferred elsewhere. Separate the mail service's recovery from the sender's work to revoke secrets, notify the right people and watch for convincing follow-up requests.

Build a restricted exposure list with the sending team, date, recipient and information category. Assign an owner to each item. Prioritise credentials and sensitive attachments rather than copying all affected correspondence into a new widely accessible spreadsheet. Keep the review auditable without creating another unnecessary repository of private data.

BlackTree's analysis of the recent Roundcube exploitation warning made the same operational point from a different incident: email infrastructure is not merely a communication layer.…

26 Sep 2026 · 3 min read

Microsoft Traces Four Ransomware Brands to One Repeating Playbook

Microsoft tracks Storm-2570 across incidents ending in Qilin, DragonForce, Anubis and BERT ransomware. The affiliate changes payloads while repeatedly using similar tools before encryption. That makes its earlier behaviour a useful target…

26 Sep 2026 · 2 min read

Your Salesforce Agent Could Have Sent the Phish in Slack

Salesforce has changed the defaults for a demonstrated phishing path through Agentforce and Slack. Zenity's SalesBleed research shows how malicious instructions in a public CRM lead could make an agent send a…

26 Sep 2026 · 2 min read

How a Public iCloud Calendar Became a macOS Malware Loader

A public calendar can carry hostile instructions without the calendar application being vulnerable. Kaspersky's MacSync investigation describes a malicious downloader that deliberately feeds public iCloud calendar content to a shell. Apple Calendar…

26 Sep 2026 · 2 min read

Revised reporting

Recently updated

View all articles

Geographic context

Regional intelligence

Browse all articles ↗

Coverage leaders

Vendor intelligence

Browse all articles ↗

Practical archive

Lab &
Legacy

Field-tested guidance for keeping older systems useful, secure and reliable long after mainstream documentation has moved on. Practical fixes, automation and deployment notes are drawn from real environments and written for the operators who still maintain them.