Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Sala de servidores en penumbra con un armario de red abierto y una etiqueta de inventario despegada colgando de un cable
7 min read

Your documentation is lying to you. And so are your validations

A document does not age: it expires, and it does so silently. Markdown cannot tell the difference between what you checked, what can be checked, and what you assumed, so six months later all three read the same. We tell the real case that led us to build validated-memory: evidence states, supersession without deletion, and freshness probes with three answers instead of two. Released as open source under Apache-2.0.

Percha de pared en la entrada de personal de una oficina con decenas de tarjetas de acceso colgadas de cordones y varios ganchos vacíos
8 min read

The directory holds more records than the company has employees

McDonald's reports just over 150,000 employees in its annual filing. The batch of its corporate directory put up for sale this week holds 1.7 million records. We placed the leaked counts next to the declared headcounts of seven companies, and the result is not a story about carelessness: it is about what a Microsoft Entra ID directory actually contains, who can read all of it with any ordinary password, and why the switch that closes it is one the vendor itself advises against touching.

Puesto de trabajo vacío de noche en una oficina pequeña: portátil cerrado, teclado mecánico, taza fría y flexo encendido
10 min read

Five days, an issue title and a Jira token

On 17 August Wiz described how it pulled a Jira token out of Snowflake by opening an issue on a public repository: the issue title was the exploit. The line that allowed it had gone in five days earlier, in a change meant to tidy the code up, and it replaced the safe pattern that GitHub's own documentation recommends in writing. What failed in the review chain, why the "if" that looked like a filter filtered nothing, and what we look at in a pipeline.

Estante metálico de una sala técnica con una fila de cartuchos de cinta en sus cajas y una unidad de cinta montada en rack
9 min read

The Microsoft 365 backup that never leaves Microsoft

Microsoft 365 Backup restores a SharePoint site in under twenty minutes, costs $0.15 per protected GB per month and keeps a year of restore points. Its own documentation also says the data never crosses the Microsoft 365 trust boundary, that the storage is append-only rather than immutable, and that deleting the backups is not blocked. Which scenario that covers, which it does not, and the two new dependencies that appear the day you switch it on.

Mesa de una oficina administrativa a última hora: archivadores de anillas, una calculadora de sobremesa y un archivador metálico con un cajón abierto
8 min read

5% more for paying monthly: what changes on 1 October, and when not to switch

From 1 October 2026 Microsoft will add a 5% uplift to CSP software subscriptions on annual terms billed monthly: it names Windows Server, SQL Server, CALs and System Center, and leaves the list open. The product does not change; the price of money does. The full arithmetic — that 5% works out at borrowing at roughly 11% a year — why your date is not 1 October but each line's renewal date, and the cases where moving is not worth it.

Varios miniordenadores en una bandeja de rack conectados a un panel de parcheo: máquinas pequeñas alojadas y accesibles desde la red
8 min read

They came in on port 5900 and left with root: the miner was the least of it

In mid-August the Dutch cyber security centre warned that the macOS Screen Sharing flaw is being exploited on Macs with port 5900 open to the internet, and that in every reported case the attacker got root and left a Monero miner behind. Apple had already shipped the patch on 6 August. What exactly breaks in CVE-2026-65400, why classic hardening did not cover this hole, and the list almost no company has: what listens from outside.

Una tormenta de verano avanzando sobre el desierto, origen del fallo de refrigeración que apagó 5.000 servidores
8 min read

Your servers can be switched off by someone you never signed anything with

On 13 August more than 5,000 servers were powered off in a building in Phoenix, taking down the websites, email and DNS of thousands of companies. The decision to shut down was the right one; what is interesting is the chain the order came down, because the end customer sits at the bottom of it with no contract with whoever decides. What to ask about the building your hardware lives in, and why DNS took down people who were not even there.

Un parquímetro con el indicador EXPIRED en rojo y un coche todavía aparcado detrás: la fecha ha pasado y no ha cambiado nada visible
9 min read

Proxmox VE 8 goes end of life in August: Debian will keep patching you, the hypervisor will not

Proxmox's official table says 2026-08 and does not give a day. What tends to fall outside the headline is that Debian 12's extended support runs to June 2028 through the usual channel, so apt will keep installing real patches on an unsupported node. What exactly freezes, how to check it, the order of the upgrade to 9.2, and why forcing it in August can be worse than being late.

Sala de reuniones vacía con las sillas recogidas: en agosto la alerta salta igual, pero la sala donde se decide está cerrada
8 min read

Three days to patch, and the third one lands on a Saturday

Since CISA changed its deadlines on 10 June, 42 of the 48 vulnerabilities it has added come with three days to fix them. We counted the weekdays over the catalog file itself: not a single 2026 entry was published on a Saturday or Sunday, and thirteen of those three-day deadlines expire exactly there. In August, with half the staff away, the bottleneck is who signs off that a server can be isolated at three in the morning.

Muro de ladrillo con la publicidad pintada de un comercio que ya no existe: el nombre sigue ahí mucho después de que el negocio cerrara
8 min read

An expired .es is released in ten days. A .com can give you eighty

Infoblox published on 13 August that around 65,000 expired domains were re-registered every day during the first half of 2026: nearly 20% of all the registrations they observe. A .com calendar gives you room —up to 45 days of auto-renew grace and 30 of redemption. A .es one does not: ten days after expiry it is cancelled and available again, with no redemption, and only the administrative or billing contact can request the renewal. What the catcher is buying, what still points at that name once it is no longer yours, and when there is nothing to renew.

Centralita telefónica manual con hileras de interruptores etiquetados a mano: apagar uno era rápido; saber qué línea dejaba muda, no
9 min read

The report says "zero impacts", and that does not mean nobody uses it

Baseline Security Mode puts twenty-one settings in the Microsoft 365 admin center that used to live only in PowerShell: switching off basic authentication, EWS, ActiveX, IDCRL, Publisher. Microsoft's guidance says to turn each one on when its impact report comes back at zero. The detail that changes the reading: the Office app settings are delivered through Cloud Policy, and Windows clients below version 2510 do not send the simulation mode telemetry that feeds that report. What each switch turns off, what actually breaks when you close EWS, and the order we do it in.

Pasillo de un archivo lleno de cajas y carpetas: el SharePoint local de una empresa guarda sus documentos igual, y desde el 14 de julio ya no recibe arreglos
8 min read

Your SharePoint 2016 got its last patch on 14 July

CVE-2026-55040 lets an attacker with no credentials impersonate any user or administrator of an on-premises SharePoint. Microsoft fixed it on 14 July 2026: exactly the day SharePoint Server 2016 and 2019 went out of support. The proof of concept went public on 12 August and was seen in use the same day, but KEVintel's sensors date the first attempt to 19 July, twenty-four days earlier. Why asking whether it should have been published is the wrong argument, and what to check today on a server that will not receive any more fixes.

Tipos de imprenta de madera: PostScript nació para hablar con impresoras y sigue vivo dentro de las bibliotecas que procesan imágenes
7 min read

It was called .png and inside it was PostScript: the WordPress 7.0.4 flaw

On 12 August WordPress shipped 7.0.4 with a single fix: CVE-2026-65640, remote code execution by uploading a file that announces itself as an image and is PostScript inside. The patch reaches back to the 4.7 branch, from December 2016. For it to affect you two conditions have to hold at once, and the first one is not yours to decide. Why validating the extension does not validate what you think, what "requires Author role" really means, and how to check it in ten minutes.

Pasillo de un centro de datos: cuando el concentrador de VPN se reinicia, el acceso remoto de toda la empresa se queda fuera
6 min read

The Cisco flaw that steals nothing: it just reboots the door your people come in through

On 11 August Cisco published an advisory for ASA and Secure Firewall Threat Defense: an HTTP request against the remote access SSL VPN service makes the device reload. The CVSS vector reads C:N/I:N/A:H —nothing is leaked, nothing is altered— and two hours and twenty minutes later it was already in CISA's KEV catalog with a 14 August due date. Three days. What to check on the device, why the patch costs exactly what the attack costs, and when this does not concern you.

Interior de un disco duro abierto: el rendimiento real de un OSD de Ceph no lo marca la ficha del fabricante sino el benchmark que midió el propio OSD
7 min read

Ceph does not perform like the datasheet: it performs like the benchmark the OSD ran at boot

Since Ceph Quincy the scheduler for BlueStore OSDs is mClock, and the work ceiling it shares out does not come from the vendor datasheet: it comes from a benchmark each OSD runs at boot. If that measurement is discarded, you are left with 315 IOPS for a spinning disk and 21,500 for a solid-state one, whatever you bought. How to check what your cluster believes, which parameters stopped having any effect, and when the drive really is the problem.

Cronómetro deportivo: los cinco días entre el aviso VMSA-2026-0006 y las primeras conexiones de vCenter comprometidos a la infraestructura del atacante
6 min read

The vCenter advisory said there was no known exploitation. It held for five days

Broadcom published VMSA-2026-0006 on 29 July with no information suggesting exploitation, and that is how we quoted it here the next day. On 3 August the first compromised vCenters started connecting to attacker infrastructure, and on 12 August QUIRSO published the count: 361 victim IP addresses across 47 countries. What those numbers mean, what they do not, and the question that decides whether this concerns you: who can open a connection to your vCenter.

Sala de centralita telefónica con operadoras conectando llamadas: el servicio que resuelve nombres y por el que pasa todo el mundo
8 min read

The DNS server you have to patch is your domain controller

CVE-2026-62878 scores 9.8: a stack-based buffer overflow in Windows DNS, no authentication and no user interaction. Microsoft's bulletin lists sixteen affected products and all sixteen require a reboot. In many of the networks we come across, that machine is also the one validating everybody's passwords, which is why it hasn't been rebooted in months — sometimes years. What the bulletin actually says, what goes down while it boots, and the checks we run before the window.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN