BlackTree Security · Infrastructure · Automation · AI

BlackTree — Independent Technology Analysis

BlackTree Editorial

Independent technology intelligence Analysis · Technical guides · Homelab · Legacy systems

Security, systems and emerging technology

Know the signal behind the incident.

Independent analysis for the people who build, secure and operate technology, with the clarity to inform action and the technical depth to earn trust.

Evidence-linked Operational context Independent

Attackers Copied Every Incoming Belnet Email for Two Months

A supplier zero-day let attackers copy every incoming email sent to Belnet and one customer for more than two months.

Read the article ↗

Current reporting

Latest intelligence

View all articles ↗

One Link Could Make Your WordPress Admin Create the Attacker’s Account

Patchstack has demonstrated how one crafted link can make a logged-in WordPress administrator create an attacker-controlled admin account. The affected Elementor Website Builder releases are 4.3.0 and 4.3.1; version 4.3.2 fixes the issue.

The vulnerability record identifies CVE-2026-62062 as a CVSS 8.8 cross-site request forgery flaw. The attacker needs no site account, but the victim must already be logged in with sufficient permissions.

The technical analysis describes a check that trusts the string elementor/v1/events/ anywhere in a request URI. An attacker-controlled query can therefore bypass the normal REST nonce check. Other authorised REST routes are in scope, not only Elementor routes. The hidden component defaults on for sites first installed with Elementor 3.32.0 or later. The reviewed disclosure does not confirm malicious exploitation.

For a site owner, the important distinction is between closing the request path and removing changes already made through it. Updating a plugin does not itself explain who created each administrator, whether credentials were changed or which settings were altered. Record those questions in the incident review instead of treating a successful update screen as proof that the site is clean.

Agencies managing many customer sites should verify the installed release on each site and assign responsibility for account review. A shared maintenance account can otherwise obscure which person was browsing when a suspicious request occurred.

BlackTree previously covered a separate Elementor Pro file-upload vulnerability. That issue and CVE-2026-62062 are not the same flaw. The new lesson is about shared authentication hooks: code intended to exempt one plugin route…

26 Sep 2026 · 2 min read

Microsoft Traces Four Ransomware Brands to One Repeating Playbook

Microsoft tracks Storm-2570 across incidents ending in Qilin, DragonForce, Anubis and BERT ransomware. The affiliate changes payloads while repeatedly using similar tools before encryption. That makes its earlier behaviour a useful target…

26 Sep 2026 · 2 min read

Your Salesforce Agent Could Have Sent the Phish in Slack

Salesforce has changed the defaults for a demonstrated phishing path through Agentforce and Slack. Zenity's SalesBleed research shows how malicious instructions in a public CRM lead could make an agent send a…

26 Sep 2026 · 2 min read

How a Public iCloud Calendar Became a macOS Malware Loader

A public calendar can carry hostile instructions without the calendar application being vulnerable. Kaspersky's MacSync investigation describes a malicious downloader that deliberately feeds public iCloud calendar content to a shell. Apple Calendar…

26 Sep 2026 · 2 min read

An Open Docker Port Gave Attackers Their Own AI Operator

ThreatDown's Carbonato investigation describes attackers taking over hosts through Docker APIs exposed without authentication. The campaign then installs an AI agent to help the operator work on the compromised machine. The entry…

26 Sep 2026 · 2 min read

Revised reporting

Recently updated

View all articles

Geographic context

Regional intelligence

Browse all articles ↗

Coverage leaders

Vendor intelligence

Browse all articles ↗

Practical archive

Lab &
Legacy

Field-tested guidance for keeping older systems useful, secure and reliable long after mainstream documentation has moved on. Practical fixes, automation and deployment notes are drawn from real environments and written for the operators who still maintain them.