Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Mesa de oficina con un portátil cerrado, una llave de seguridad USB en un llavero y un teléfono móvil boca abajo
10 min read

Passkeys on 1 September: the cases that do not fit

In July we went through the timeline for the retirement of SMS and voice in Microsoft Entra ID. Five days after that post Microsoft published a FAQ, and there are now forty-eight hours to go until the first date. This is the run-through of what is still unanswered: the FAQ's "No" to the lockout question and what it says three lines further down, the self-service password reset that goes with the same move, the declared gap for B2B guests, the break-glass accounts the documentation never mentions, and why the temporary opt-out switch, which lives on the Graph beta endpoint, is not the answer we would give.

Enfriadoras de aire en la cubierta de un edificio industrial, con tubería aislada y grava, bajo cielo cubierto
11 min read

Spain's data centre decree is not decided by the 80% renewables rule: it is decided by a PUE of 1.15

On 27 August Spain opened public consultation on the draft royal decree regulating data centres. Coverage stopped at the 80% hourly renewables rule. We read all 32 pages and there are three things inside that almost nobody has reported: the surcharge scale in article 10, reaching 500% on network tolls and charges; a sentence in article 5.2(b) that leaves the customer's data outside the sovereignty the operator declares; and, in our judgement, the number that really filters projects, a PUE of 1.15 in the fourth transitional provision (with a WUE of 0.1 L/kWh), which the preamble itself acknowledges are the class "A" values proposed by the European Commission. Amazon reported a global PUE of 1.14 in 2025 and 1.15 in 2024.

Archivo de oficina con cajas y carpetas apiladas en estanterías metálicas bajo luz natural
10 min read

They are not old bugs: they are old classes of bug. We ran the numbers on CISA's catalogue

We downloaded CISA's Known Exploited Vulnerabilities catalogue and counted its 1,685 entries. Of the 201 added in 2026, 123 carry an identifier from this same year and the median gap is zero: what is old is not the individual bug but the class. We measured that too, using the file's own cwes field: CWE-20, improper input validation, tops the catalogue with 118 entries, followed by command injection and out-of-bounds write. And something turned up that we were not looking for: on 10 June directive BOD 26-04 revoked BOD 22-01, and since then 81% of what goes in arrives with a three-day deadline instead of the previous 23%.

Cuarto de impresión de una oficina con una multifunción, cajas de papel y un servidor en una estantería metálica
9 min read

PaperCut: the print server runs as SYSTEM, and nearly half the measured estate has no patch

On 27 August PaperCut confirmed active exploitation of PaperCut NG and MF. The identifiers landed the next day: CVE-2026-81578 (CVSS 8.8) and CVE-2026-82078 (CVSS 9.4), chained into unauthenticated remote code execution. Huntress watched one intrusion last under two minutes, and in their proof of concept the code executes as SYSTEM. The figure that orders everything else: 47% of the 2,500 installations Huntress tracks are on version 23 or older, for which no patch exists. What happened hour by hour, why Thursday's patch did not hold on Friday, and today's notice that turns one of the indicators into a false positive.

Sala de espera de oficina en penumbra con tres sillas grises alineadas contra la pared
8 min read

Guest Wi-Fi is a database of people (and it is not in your inventory)

Manchester Airports Group confirmed on 27 August that an unauthorised third party took customer data: email addresses, phone numbers, vehicle registrations and postcodes, from car park, lounge and Fast Track bookings and from in-airport Wi-Fi sign-ups. The company has not published how many people are affected; reporting puts it at around 8.7 million. Operations were unaffected, and that is precisely the problem: the system holding the most people is almost never at the top of your criticality list. Why the number plate is the field to watch, and the six questions worth one afternoon of inventory at your own front desk.

Rincón de oficina con una papelera metálica desbordada de papel y una destructora con el depósito lleno
9 min read

Recoverable Items: 14 days, 30 GB and the day the mailbox can no longer delete

The folder that saves you when someone empties the deleted items does not show up in Outlook, keeps things for 14 days by default and holds 30 GB. Put the mailbox on hold and the ceiling rises to 100 GB — in exchange for never draining again: things only go in. And on the day it hits that ceiling, per Microsoft's own documentation, the user cannot delete, versions stop being kept and audit entries stop being written. How to measure your headroom with two commands, how to open the drain that ships disconnected, and why a folder deleted with Shift+Delete does not come back even under litigation hold.

Puerta de acero de una sala de servidores sujeta abierta con una cuña, con un rack visible al fondo
8 min read

The bulletin said "denial of service". The exploit gives root: NetScaler CVE-2026-8452

Citrix shipped the patch on 30 June and described it as a denial of service; the CVSS vector on that same entry already showed high confidentiality impact and no privileges required. On 14 August, 45 days later, the exploit that gives unauthenticated root went public, and attacks followed within days: CISA set a 29 August deadline. How to check whether you are patched without knocking the box over (513 bytes, error 43549) and why the patch does not evict whoever already got in.

Servidores de rack idénticos apilados en un carro metálico, pendientes de montar, delante de un rack a medio poblar
8 min read

Corosync adds 650 milliseconds per node: the clock your upgraded cluster is still carrying

The time a Proxmox cluster takes to re-form membership after losing a node is not fixed: it grows by 650 ms for every node you add, and on factory values a 29-node cluster reaches 45.21 seconds — exactly where the documentation itself asks you to fix it, before the 60-second watchdog starts rebooting healthy nodes. Proxmox VE 9.2 lowered it to 125 ms, but only when the cluster is created: clusters upgraded from 8 to 9 keep the old value.

Sala de archivo con estanterías metálicas llenas de cajas de cartón y una caja sacada a medias del estante
8 min read

Microsoft 365 Archive is coming to retention policies: compliance up, availability down

This autumn, a Purview retention policy will be able to move SharePoint files into the cold tier (roadmap 561208: preview in September, GA in October). Microsoft promises cost, compliance and search; its own documentation adds that archived content is "no longer directly accessible to anyone" and lists the apps that break: Word and PowerPoint online, the mobile apps, the macOS sync client and Office builds not updated since March. A reactivated file cannot be archived again for 120 days.

Servidor de almacenamiento abierto en un rack con las bahías de discos a la vista y una unidad extraída de su carro
9 min read

In Ceph, capacity is not set by the cluster: it is set by the fullest disk

A single OSD above 95% stops writes across the whole cluster even while "ceph df" still shows dozens of free terabytes. The three default thresholds (0.85 / 0.90 / 0.95), why the mechanism that repairs switches off five points before the one that serves, and the capacity calculation with one node missing that almost nobody runs: with four nodes the ceiling is 71 points, and 67 if you want the rebuild to actually finish.

Dos routers de operador montados en un rack con latiguillos de fibra de dos colores llegando desde bandejas distintas
8 min read

Two ISPs are not redundancy if the ISP owns the IP

A second line saves what leaves the office, not what comes in: when the main one drops, the IP address changes, and with it DNS, open sessions, tunnels and third-party allow lists. The three real ways to have two paths, with 2026 figures: EUR 1,800 a year in RIPE fees, EUR 50 for the ASN, roughly 7,700 to 10,200 dollars for the /24 itself, and the ninety-second default of the BGP hold timer.

Armario de red mural con la puerta abierta en el cuarto trastero de una oficina, con cajas de cartón, una fregona y estanterías
7 min read

Gitea's flaw "requires write access". The signup form hands it to you

The CVE-2026-60004 write-up says you need write access to a repository. The official vector in the same advisory says <code>PR:N</code>, privileges required: none. Both are true, because Gitea installs with <code>DISABLE_REGISTRATION=false</code>. What that means for how you prioritise patching everything you self-host, what happened in the eleven seconds of the only public case, and the list of what to check today.

Pasillo de un centro de datos con un rack abierto a medio poblar y un carro elevador con un servidor encima
8 min read

When NOT to migrate from VMware to Proxmox

Migrating from VMware to Proxmox is part of what we do, and there are cases where our answer is: not now. Two classic objections no longer hold — the scheduler's dynamic mode arrived with Proxmox VE 9.2 on 21 May, and Veeam 13.1 has shipped replication since 29 July. The one still standing is different: Proxmox's HA documentation describes nothing equivalent to vSphere's <em>admission control</em>, which flatly refuses to power on the machine that would break your N-1. And the <code>crs</code> factory settings decide more than people think: <code>ha=basic</code> balances by counting machines. The five cases where we tell clients to stay.

Armario de llaves metálico abierto en el pasillo de servicio de una oficina, con dos hileras de llaves colgadas de sus ganchos
7 min read

They deleted the backups at both data centres

Joint advisory AA26-222A, published on 10 August 2026 by six agencies, records that at one Gunra victim the actors deleted backup and archived data at the primary data centre <em>and</em> at the recovery one, before and after deploying the encryptor. Another section describes how they got the key cabinet: SSH to an access control server and a symmetric key that decrypted the passwords for enterprise server accounts across the company. Our reading: two sites that accept the same credential are one site with two postal addresses. What falls outside a retention lock, and six checks for this week — two of which have to be actually run.

Portal de un edificio antiguo con una única puerta acristalada, el portero automático y los buzones metálicos
8 min read

Your identity provider is not an application: it is infrastructure

On Monday 24 August, at 03:38, a denial-of-service attack began against Norway's shared government digital platform. Ten public services went down and several had nothing wrong with them: the door everyone goes through had jammed. Digdir writes on its status page that <code>eSignering</code> was unavailable "because of the limitations in ID-porten", and also that the services were "stable with the limitations that have been put in place" — part of the outage was put there by the defenders. Why single sign-on is still the right call, what changes when the door becomes infrastructure, and the three questions that reclassify it.

Rack abierto en una sala de servidores con dos bandejas de disco a medio sacar
8 min read

10% of the VMDK is enough: the arithmetic that changes your recovery plan

The ESXi encryptor Rapid7 took apart carries a percentage parameter, and the value observed was 10: on a large VMDK it touches only a tenth of the file, and that is enough to stop it booting. Partial encryption is not new — LockFile was doing it in 2021 — but the numbers are. What it does to your response clock, why no EDR agent belongs on the hypervisor (Broadcom says in so many words that it is not supported), what the same actor does to backup services, and why swapping hypervisors is not a security control.

Fotocopiadora multifunción de oficina con la puerta de tóner abierta y la bandeja de papel a medio sacar
7 min read

August's patch broke printing in WPF apps: the three ways out, with the maths done

The 11 August .NET Framework cumulative update breaks printing and PDF export in WPF applications using Calibri, Cambria, Constantia and Corbel: <code>System.IO.FileFormatException</code> on a font Windows itself installs. Microsoft acknowledged it on the 24th, thirteen days later, and the interim workaround switches off the overflow protection that same patch had just added. We looked at what exactly it turns off, why the decision should be per application rather than per fleet, and which of the three ways out costs least in each case.

Archivadores metálicos grises de oficina, con un cajón entreabierto y unos papeles asomando
6 min read

Ransom Busters: the rescuer offering to save you is the one who encrypted you

On 18 August GuidePoint (GRIT) reported that a supposed third party calling itself "Ransom Busters" emails ransomware victims offering to delete their data for between $20,000 and $60,000. When questioned, it confirmed access to the same stolen dataset the affiliate behind the intrusion held, and the same forensic fingerprints repeated across the incidents GuidePoint worked. What really changes everything is the date: the email arrived before the incident was public. What to do with it on the first morning.

Sala de reuniones pequeña y vacía, con un altavoz de conferencia sobre la mesa, sillas desordenadas y luz natural entrando por la persiana
8 min read

Teams can now block meeting bots: it ships turned off

On 21 August Microsoft announced (MC1459141) that admins will be able to automatically block detected external bots in Teams meetings. We read the documentation for the ExternalBotAccessMode parameter: the word doing all the work is "detected", the new mode has to be assigned through policy, and it touches neither Copilot nor the assistant recording from your client's tenant. What actually decides where the transcript ends up — and when we would not switch it on.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN