BlackTree Security · Infrastructure · Automation · AI

BlackTree — Independent Technology Analysis

BlackTree Editorial

Independent technology intelligence Analysis · Technical guides · Homelab · Legacy systems

Security, systems and emerging technology

Know the signal behind the incident.

Independent analysis for the people who build, secure and operate technology, with the clarity to inform action and the technical depth to earn trust.

Evidence-linked Operational context Independent

Attackers Are Trying to Turn a WordPress Template Bug Into Code Execution

WordPress fixed a conditional code-execution path on 22 September. Within hours, attackers were trying to turn the flaw into PHP file writes.

Read the article ↗

Current reporting

Latest intelligence

View all articles ↗

The FBI Confirms Its Jobs Portal Was Compromised but Not What Was Taken

The FBI has confirmed that its recruitment portal was compromised. It has not confirmed the attackers' biggest claim about what they took.

In a statement on 23 September, the bureau said it was investigating a cybercriminal group's claim involving fbijobs.gov and alleged impact to FBI employee personally identifiable information. The FBI said it had not yet determined whether the breach occurred through a third party or its own enterprise environment.

That is the verified boundary. The portal compromise is confirmed. The point of entry, scope of access and alleged exposure of employee data remain under investigation. Reports attributing the incident to ShinyHunters and describing a much larger trove are claims, not established facts at the time of publication.

Jobs websites are often treated as public-facing communications platforms. Their application systems are something else entirely. They can collect addresses, work histories, qualifications, demographic data, supporting documents and details that reveal an individual's interest in sensitive employment.

The FBI's own privacy impact assessment says its candidate gateway collects significant amounts of sensitive information about applicants and employees. It explicitly warns that unauthorised disclosure could compromise the identities of people applying for FBI positions.

The document describes a system in which application information is transferred between domains into an internal human-resources environment. It also describes role-based access, encryption, regular purging, audit logging and cloud-hosted components. Those controls matter, but none of them tells us which layer was compromised in this incident or what the intruder reached.

The FBI says it is working with…

24 Sep 2026 · 3 min read

Attackers Are Exploiting the System That Manages the Rest of Your Network

The system designed to control an organisation's network edge can become the attacker’s control point instead. Arista has confirmed active exploitation of CVE-2026-93952, a critical improper-input-validation flaw in on-premises VeloCloud Orchestrator. Successful…

24 Sep 2026 · 3 min read

Revised reporting

Recently updated

View all articles

Geographic context

Regional intelligence

Browse all articles ↗

Coverage leaders

Vendor intelligence

Browse all articles ↗

Practical archive

Lab &
Legacy

Field-tested guidance for keeping older systems useful, secure and reliable long after mainstream documentation has moved on. Practical fixes, automation and deployment notes are drawn from real environments and written for the operators who still maintain them.