BlackTree Security · Infrastructure · Automation · AI

BlackTree — Independent Technology Analysis

BlackTree Editorial

Independent technology intelligence Analysis · Technical guides · Homelab · Legacy systems

Security, systems and emerging technology

Know the signal behind the incident.

Independent analysis for the people who build, secure and operate technology, with the clarity to inform action and the technical depth to earn trust.

Evidence-linked Operational context Independent

Snowflake Ends Broad Gen1 Advice; SPCS Remains Constrained

Warehouses improved. SPCS remains constrained.

Read the article ↗

Current reporting

Latest intelligence

View all articles ↗

A Patient Code Did Not Make IQVIA’s Health Database Anonymous

Italy's privacy regulator focused on linkability, detailed records and the controller's real role. On 23 September, the Italian Garante ordered a €7 million fine against IQVIA Solutions Italy. It found that a stable patient code, combined with detailed health and location records, did not make the database anonymous. The project covered about one million patients of 800 GPs. IQVIA argued that the data was anonymous and its role narrower. The regulator rejected those positions and treated the company as controller from collection. A separate free-text issue included direct identifiers for about 3,370 patients, around 3,080 with health information. That is not evidence that all one million records were directly exposed or that an external attacker was involved. Before relying on anonymity, test the actual attributes, linkability, extraction path, controller role, lawful basis and DPIA evidence. This is an editorial inference from the case, not a new universal checklist. The 120-day compliance clock begins on notification, whose date is unknown. The fine was imposed; payment and judicial finality are unverified. For wider context, read our European Health Data Space guide. Source: Italian Garante order No. 710, decided 23 September 2026; announcement, dated 2 October 2026.

10 Oct 2026 · 1 min read

AhsayCBS 10.3.4 Was Still Affected

Apply 10.3.4.45, restrict management access and investigate earlier exposure. Ahsay's 10 October critical alert says 10.3.4.0 did not fully address CVE-2026-105133 and CVE-2026-105134. Version 10 partners should install the partner-only 10.3.4.45 hotfix…

10 Oct 2026 · 2 min read

Advantest Confirms Personal Data Extraction

Advantest's 6 October notice says attackers extracted data, including the recipient's personal information, during its February ransomware incident. It does not describe a new October attack or give an affected total. The…

10 Oct 2026 · 2 min read

Check the Certificates, Not Just DNS

Audit certificates after DNS recovery. Attackers hijacked .gh, .sl and .as third-party registry infrastructure, obtaining unauthorised certificates; Google systems were unaffected. A registry compromise sits above an individual registrar account. Recovering DNS…

10 Oct 2026 · 1 min read

Validate GitHub Advisory Provenance

GitHub added five nullable SecurityAdvisory GraphQL fields on 2 October, according to the current reference. That nullability is the decision boundary. Schema availability alone is not enough to retire a retrieval path.…

10 Oct 2026 · 2 min read

Revised reporting

Recently updated

View all articles

Geographic context

Regional intelligence

Browse all articles ↗

Coverage leaders

Vendor intelligence

Browse all articles ↗

Practical archive

Lab &
Legacy

Field-tested guidance for keeping older systems useful, secure and reliable long after mainstream documentation has moved on. Practical fixes, automation and deployment notes are drawn from real environments and written for the operators who still maintain them.