BlackTree Security · Infrastructure · Automation · AI

BlackTree — Independent Technology Analysis

BlackTree Editorial

Independent technology intelligence Analysis · Technical guides · Homelab · Legacy systems

Security, systems and emerging technology

Know the signal behind the incident.

Independent analysis for the people who build, secure and operate technology, with the clarity to inform action and the technical depth to earn trust.

Evidence-linked Operational context Independent

The Fake GitHub Download Arrived With a Microsoft-Signed EDR Killer

The repositories copied more than 40 brands. The payload then used a trusted driver to remove the tools most likely to stop it.

Read the article

Current reporting

Latest intelligence

View all articles ↗

The Login Screen on Your Security Manager Could Hand an Attacker Root

The management server decides how the firewalls behave. The log server holds the evidence used to understand what they saw. A critical Check Point flaw reaches both systems through the login process, before an attacker supplies valid credentials.

CVE-2026-91843 is a stack-based buffer overflow in Check Point Quantum Security Management. Check Point says a remote, unauthenticated attacker can execute arbitrary code as root. The CVSS 3.1 score is 9.8.

The affected roles include Security Management Server, Multi-Domain Security Management Server, Log Server and Multi-Domain Log Server. The Canadian Centre for Cyber Security lists the following supported release thresholds:

End-of-support releases are also affected according to Check Point's CVE record. CERT.LV lists patched target builds of R82.20 Take 29, R82.10 Take 28, R82 Take 28 and R81.20 Take 28. Administrators should reconcile those figures with Check Point's live support article because hotfix guidance can change.

Check Point says customers with automatic LivePatch updates enabled may already be protected. That should be verified rather than assumed. The vendor directs administrators to confirm the patch in the LivePatch inventory. If the fix cannot be applied immediately, restrict the management interface to trusted clients and networks.

No exploitation in the wild was known at the time of the advisory, and no verified public proof of concept was identified in the reviewed sources. Exposure remains consequential because the vulnerable service is the control plane for network policy and audit data.

Fixing CVE-2026-91843 closes the known login overflow. It does not prove that a previously exposed manager was untouched. The…

21 Sep 2026 · 3 min read

CISA Gave Three Linux Kernel Bugs a Three-Day Deadline

Three Linux kernel vulnerabilities entered CISA's Known Exploited Vulnerabilities catalogue on 18 September with a remediation date of 21 September. The three-day deadline is unusually short. It is also easy to misread:…

21 Sep 2026 · 3 min read

Set a Trap for the Login That Should Never Happen

The login succeeds. The tool is legitimate. The connection looks ordinary. CISA cyber-decoys guidance addresses the difficult situation in which an intruder's activity resembles authorised work, by placing assets that legitimate business…

18 Sep 2026 · 3 min read

Revised reporting

Recently updated

View all articles

Geographic context

Regional intelligence

Browse all articles ↗

Coverage leaders

Vendor intelligence

Browse all articles ↗

Practical archive

Lab &
Legacy

Field-tested guidance for keeping older systems useful, secure and reliable long after mainstream documentation has moved on. Practical fixes, automation and deployment notes are drawn from real environments and written for the operators who still maintain them.