Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Armario de llaves metálico abierto en el pasillo de servicio de una oficina, con dos hileras de llaves colgadas de sus ganchos
7 min read

They deleted the backups at both data centres

Joint advisory AA26-222A, published on 10 August 2026 by six agencies, records that at one Gunra victim the actors deleted backup and archived data at the primary data centre <em>and</em> at the recovery one, before and after deploying the encryptor. Another section describes how they got the key cabinet: SSH to an access control server and a symmetric key that decrypted the passwords for enterprise server accounts across the company. Our reading: two sites that accept the same credential are one site with two postal addresses. What falls outside a retention lock, and six checks for this week — two of which have to be actually run.

Portal de un edificio antiguo con una única puerta acristalada, el portero automático y los buzones metálicos
8 min read

Your identity provider is not an application: it is infrastructure

On Monday 24 August, at 03:38, a denial-of-service attack began against Norway's shared government digital platform. Ten public services went down and several had nothing wrong with them: the door everyone goes through had jammed. Digdir writes on its status page that <code>eSignering</code> was unavailable "because of the limitations in ID-porten", and also that the services were "stable with the limitations that have been put in place" — part of the outage was put there by the defenders. Why single sign-on is still the right call, what changes when the door becomes infrastructure, and the three questions that reclassify it.

Rack abierto en una sala de servidores con dos bandejas de disco a medio sacar
8 min read

10% of the VMDK is enough: the arithmetic that changes your recovery plan

The ESXi encryptor Rapid7 took apart carries a percentage parameter, and the value observed was 10: on a large VMDK it touches only a tenth of the file, and that is enough to stop it booting. Partial encryption is not new — LockFile was doing it in 2021 — but the numbers are. What it does to your response clock, why no EDR agent belongs on the hypervisor (Broadcom says in so many words that it is not supported), what the same actor does to backup services, and why swapping hypervisors is not a security control.

Fotocopiadora multifunción de oficina con la puerta de tóner abierta y la bandeja de papel a medio sacar
7 min read

August's patch broke printing in WPF apps: the three ways out, with the maths done

The 11 August .NET Framework cumulative update breaks printing and PDF export in WPF applications using Calibri, Cambria, Constantia and Corbel: <code>System.IO.FileFormatException</code> on a font Windows itself installs. Microsoft acknowledged it on the 24th, thirteen days later, and the interim workaround switches off the overflow protection that same patch had just added. We looked at what exactly it turns off, why the decision should be per application rather than per fleet, and which of the three ways out costs least in each case.

Archivadores metálicos grises de oficina, con un cajón entreabierto y unos papeles asomando
6 min read

Ransom Busters: the rescuer offering to save you is the one who encrypted you

On 18 August GuidePoint (GRIT) reported that a supposed third party calling itself "Ransom Busters" emails ransomware victims offering to delete their data for between $20,000 and $60,000. When questioned, it confirmed access to the same stolen dataset the affiliate behind the intrusion held, and the same forensic fingerprints repeated across the incidents GuidePoint worked. What really changes everything is the date: the email arrived before the incident was public. What to do with it on the first morning.

Sala de reuniones pequeña y vacía, con un altavoz de conferencia sobre la mesa, sillas desordenadas y luz natural entrando por la persiana
8 min read

Teams can now block meeting bots: it ships turned off

On 21 August Microsoft announced (MC1459141) that admins will be able to automatically block detected external bots in Teams meetings. We read the documentation for the ExternalBotAccessMode parameter: the word doing all the work is "detected", the new mode has to be assigned through policy, and it touches neither Copilot nor the assistant recording from your client's tenant. What actually decides where the transcript ends up — and when we would not switch it on.

Puesto de trabajo de una oficina vacío al amanecer, con la silla apartada, una taza fría y la persiana entreabierta
8 min read

They switched the EDR off with a reboot, and the encryption failed for lack of memory

On 4 August an Akira affiliate walked in through an MFA-less SSL VPN in roughly seven minutes and, rather than fight the EDR, rebooted the compromised host into <code>Safe Mode with Networking</code>: the agent and Defender real-time protection stopped starting. We counted the blind window against the timestamps in the Huntress report and it comes to 1 h 41 min, not the 10 minutes that circulated. The encryption did fail, but on virtual memory, not on defences.

Servidor de almacenamiento de 4U extraído sobre sus guías en una sala de servidores, con la tapa quitada y las filas de discos a la vista
9 min read

Proxmox's "protected" flag is not a lock, it's a latch

The Pay2Key ransomware shuts down the guests on a Proxmox cluster and deletes the backups using Proxmox's own API: first a <code>--protected 0</code>, then the delete. We read the pve-storage source to see why it works, and the answer is uncomfortable: clearing the latch never costs one privilege more than deleting the backup. What does raise a real boundary, and why it costs nothing.

Aparato de red de 1U extraído sobre sus guías en un rack de sala técnica, con cable de consola conectado y un carro de servicio al lado
6 min read

NetScaler CVE-2026-19490: your version doesn't tell you whether you're exposed

On 19 August Citrix published an authentication bypass scoring 9.3 out of 10 in NetScaler ADC and Gateway. Being affected does not depend on your version alone: it depends on what you have configured, and older builds need fewer conditions. How to actually answer the question, why a pre-authentication flaw leaves your MFA out of the path, and what we do in the window before the first exploit lands.

Cuadro eléctrico industrial abierto en una sala técnica, con embarrado de cobre, magnetotérmicos en carril DIN y cableado de potencia
8 min read

Colocation is no longer negotiated in U: it is negotiated in kW

In the first half of 2026, AI cloud providers signed 420 MW of colocation capacity in Europe. In the same period a year earlier they signed 89. Powered land in the big markets costs 82% more than in 2021. None of that raises your invoice tomorrow, which is exactly why it is worth looking at today: what changes is not the price of a rack unit, it is what your contract actually measures.

Jaula de rejilla metálica cerrada con candado en una sala de datacenter compartida, con dos racks de servidores detrás
6 min read

The patch that isn't yours: what to do with Entra ID's CVE-2026-69836

On 20 August Microsoft published a critical remote code execution flaw in Entra ID, and the next day corrected the exploitation field to "No". There is nothing to install: the record says "customerActionRequired: false". What is yours is the ability to answer "were we affected?", and on an Entra ID Free licence that lasts seven days. How to read the record from Microsoft's own API, and the checklist we apply to the tenant.

Armario de red mural abierto en una oficina, con panel de parcheo, dos conmutadores de rack y un mazo de latiguillos peinado sobre el raíl lateral
9 min read

A CVE is no longer one bug: Cisco has changed the unit of measurement

On 19 August Cisco published two advisories carrying five CVEs scored 10.0 between them. They are not five bugs: each identifier groups an entire class of bugs and carries the score of the worst one in the bag. Across the four hardening advisories we reviewed the mitigation line says the same thing, "none." This is not a complaint about Cisco: it is that the unit you count vulnerabilities in has changed size, and your inventory has not noticed.

Chasis de servidor de rack abierto sobre un banco de taller, con la tapa retirada y dos disipadores de procesador a la vista entre los bancos de memoria
8 min read

Azure stops including the VMware licence: the core count nobody does

Two weeks ago we wrote that 31 October 2026 is the end of Azure VMware Solution with the licence included. Microsoft has since published its portable licensing reference, and that is where the counting rules are: how many cores each node type has, why the distributed firewall counts every host in the private cloud even the ones you are not paying for, and which date actually governs your calendar, because it is not the August 2027 one.

Cajón abierto de un fichero de tarjetas de archivo de madera en una sala de oficina, con las fichas de papel apretadas y vistas de canto
8 min read

Some people have not been able to search in Microsoft 365 since Monday. For the SLA, that is not downtime

Incident MO1456424 has been open since Monday 17 August: some Microsoft 365 users get nothing back when they search in SharePoint Online, OneDrive and Outlook. Files still open, mail still flows, and that is why the availability counter does not move. What Microsoft's advisory says word for word, why its SLA definitions of downtime leave exactly this out, and which check you need so that you find out before your users do.

Sala de archivo de una oficina con estanterías metálicas llenas de cajas de cartón y carpetas, y una caja abierta sobre una mesa de trabajo
7 min read

"The column was encrypted": pgcrypto was storing cleartext and nobody noticed

On 13 August PostgreSQL closed 28 CVEs in one go. One of them is not a buffer overflow: when OpenSSL rejected the requested cipher, pgcrypto never checked the answer and wrote the value into your "encrypted" column with a trivial XOR. Neither the INSERT nor the SELECT failed. What triggers it, why the day it broke was not the day the code was written, and which version you are really running if you install from Debian rather than PGDG.

Chasis de servidor de almacenamiento extraído sobre sus guías en un pasillo de datacenter, con dos filas de discos de 3,5 pulgadas en bandejas metálicas y un destornillador apoyado en el borde
7 min read

Ceph patches four CVEs: the package closes three, the fourth is on you

On 19 August Ceph shipped Squid 19.2.6 and Tentacle 20.2.4 tagged [URGENT]. One of the four flaws is not fixed by installing anything: it forces you to rotate every CephX key in the cluster, ten manual steps, and it leaves the cluster in HEALTH_ERR in the meantime. What is inside each CVE, why anyone holding a "mon allow r" key could read your OSD LUKS passphrases, and what we found today in Proxmox's Ceph repository.

Armario de comunicaciones de pared en una sala técnica, con un servidor de rack, un pequeño cortafuegos y un panel de parcheo con latiguillos naranjas y grises
7 min read

"Exploitation Less Likely": 126 days in the queue for CVE-2026-33824

Microsoft patched the Windows IPsec VPN flaw on 14 April with the label "Exploitation Less Likely". CISA added it to its exploited catalogue on 18 August. Between those dates sit 126 days, a Unit 42 report, and a vendor page that still has not been corrected. Our own count across Microsoft's 24 KEV entries this year, and which mitigation you cannot apply if your VPN carries remote workers.

Caja fuerte pequeña de oficina abierta sobre una repisa, con dos sobres, un juego de llaves y una memoria USB dentro
8 min read

Cloning the repository is not a GitLab backup

On 17 August GitLab shipped four out-of-band releases for a flaw that lets an unauthenticated user modify or delete public projects. The usual answer — "we have the code cloned everywhere" — is true, and it is the part you are least likely to lose. What a clone actually carries, what lives only on the server, why the secrets file is not inside the backup, and why the June fix, the one with no CVE, explains the problem better.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN