BlackTree Security · Infrastructure · Automation · AI

BlackTree — Independent Technology Analysis

BlackTree Editorial

Independent technology intelligence Analysis · Technical guides · Homelab · Legacy systems

Security, systems and emerging technology

Know the signal behind the incident.

Independent analysis for the people who build, secure and operate technology, with the clarity to inform action and the technical depth to earn trust.

Evidence-linked Operational context Independent

This Android Ransomware Can Watch Your Screen While Demanding Payment

Mantax Otax combines ransom demands with screen monitoring and message theft. Newer Android limits broad file encryption, but not every other risk.

Read the article

Current reporting

Latest intelligence

View all articles ↗

AVEVA’s Patch Cannot Secure the Files You Forgot

A patch can close a software flaw without making the files it used to protect safe. That is the uncomfortable detail in the new AVEVA Pipeline Integrity Monitor bulletin. The vendor has fixed four vulnerabilities in its PIMBoards component, but it also tells customers to migrate old project files, protect copies they cannot migrate and require users to change passwords. Teams that stop at the software installer may leave the most durable part of the exposure behind.

AVEVA's 8 September security bulletin covers Pipeline Integrity Monitor 2025 SP1 P1, build 7.1.9580.8513, and earlier versions. The bulletin gives a date but no publication time. It directs users to the 2025 SP1 P2 security update or later. The affected component is PIMBoards. The bulletin reports no known exploitation or victims. It also makes no claim of disrupted pipeline operations.

Two findings concern the project files themselves. CVE-2026-81821 is a hardcoded encryption key: someone who can read an affected PIMBoards project file may be able to decrypt sensitive information inside it. CVE-2026-81822 concerns passwords hashed with MD5. A person with read access to an affected project file could try to recover a PIMBoards user's application password by offline guessing, potentially gaining that user's privileges. AVEVA rates both 8.3 under CVSS 4.0. The bulletin does not describe either as a standalone remote break-in. The attacker first needs a project file.

The other two findings involve the application interface. CVE-2026-81823 is missing authorisation on a subset of read-only API methods. AVEVA says an unauthenticated requester could perform reads intended…

16 Sep 2026 · 4 min read

A $4 Lost-Phone Report Could Silence Your Home Alarm

The phone was still sealed in its box. Yet after researchers reported its identifier as lost, it could not connect to the mobile network. That demonstration exposes a larger problem: the anti-theft…

16 Sep 2026 · 4 min read

GoAnywhere MFT’s ‘Secure Folder’ Had a Hidden Exit

A managed file-transfer service is supposed to be unusually clear about who can reach which files. Fortra has disclosed a flaw in GoAnywhere MFT that breaks that expectation for a specific class…

15 Sep 2026 · 4 min read

Revised reporting

Recently updated

View all articles

Geographic context

Regional intelligence

Browse all articles ↗

Coverage leaders

Vendor intelligence

Browse all articles ↗

Practical archive

Lab &
Legacy

Field-tested guidance for keeping older systems useful, secure and reliable long after mainstream documentation has moved on. Practical fixes, automation and deployment notes are drawn from real environments and written for the operators who still maintain them.