Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Jaula de rejilla metálica cerrada con candado en una sala de datacenter compartida, con dos racks de servidores detrás
6 min read

The patch that isn't yours: what to do with Entra ID's CVE-2026-69836

On 20 August Microsoft published a critical remote code execution flaw in Entra ID, and the next day corrected the exploitation field to "No". There is nothing to install: the record says "customerActionRequired: false". What is yours is the ability to answer "were we affected?", and on an Entra ID Free licence that lasts seven days. How to read the record from Microsoft's own API, and the checklist we apply to the tenant.

Armario de red mural abierto en una oficina, con panel de parcheo, dos conmutadores de rack y un mazo de latiguillos peinado sobre el raíl lateral
9 min read

A CVE is no longer one bug: Cisco has changed the unit of measurement

On 19 August Cisco published two advisories carrying five CVEs scored 10.0 between them. They are not five bugs: each identifier groups an entire class of bugs and carries the score of the worst one in the bag. Across the four hardening advisories we reviewed the mitigation line says the same thing, "none." This is not a complaint about Cisco: it is that the unit you count vulnerabilities in has changed size, and your inventory has not noticed.

Varios miniordenadores en una bandeja de rack conectados a un panel de parcheo: máquinas pequeñas alojadas y accesibles desde la red
8 min read

They came in on port 5900 and left with root: the miner was the least of it

In mid-August the Dutch cyber security centre warned that the macOS Screen Sharing flaw is being exploited on Macs with port 5900 open to the internet, and that in every reported case the attacker got root and left a Monero miner behind. Apple had already shipped the patch on 6 August. What exactly breaks in CVE-2026-65400, why classic hardening did not cover this hole, and the list almost no company has: what listens from outside.

Sala de reuniones vacía con las sillas recogidas: en agosto la alerta salta igual, pero la sala donde se decide está cerrada
8 min read

Three days to patch, and the third one lands on a Saturday

Since CISA changed its deadlines on 10 June, 42 of the 48 vulnerabilities it has added come with three days to fix them. We counted the weekdays over the catalog file itself: not a single 2026 entry was published on a Saturday or Sunday, and thirteen of those three-day deadlines expire exactly there. In August, with half the staff away, the bottleneck is who signs off that a server can be isolated at three in the morning.

Muro de ladrillo con la publicidad pintada de un comercio que ya no existe: el nombre sigue ahí mucho después de que el negocio cerrara
8 min read

An expired .es is released in ten days. A .com can give you eighty

Infoblox published on 13 August that around 65,000 expired domains were re-registered every day during the first half of 2026: nearly 20% of all the registrations they observe. A .com calendar gives you room —up to 45 days of auto-renew grace and 30 of redemption. A .es one does not: ten days after expiry it is cancelled and available again, with no redemption, and only the administrative or billing contact can request the renewal. What the catcher is buying, what still points at that name once it is no longer yours, and when there is nothing to renew.

Centralita telefónica manual con hileras de interruptores etiquetados a mano: apagar uno era rápido; saber qué línea dejaba muda, no
9 min read

The report says "zero impacts", and that does not mean nobody uses it

Baseline Security Mode puts twenty-one settings in the Microsoft 365 admin center that used to live only in PowerShell: switching off basic authentication, EWS, ActiveX, IDCRL, Publisher. Microsoft's guidance says to turn each one on when its impact report comes back at zero. The detail that changes the reading: the Office app settings are delivered through Cloud Policy, and Windows clients below version 2510 do not send the simulation mode telemetry that feeds that report. What each switch turns off, what actually breaks when you close EWS, and the order we do it in.

Pasillo de un archivo lleno de cajas y carpetas: el SharePoint local de una empresa guarda sus documentos igual, y desde el 14 de julio ya no recibe arreglos
8 min read

Your SharePoint 2016 got its last patch on 14 July

CVE-2026-55040 lets an attacker with no credentials impersonate any user or administrator of an on-premises SharePoint. Microsoft fixed it on 14 July 2026: exactly the day SharePoint Server 2016 and 2019 went out of support. The proof of concept went public on 12 August and was seen in use the same day, but KEVintel's sensors date the first attempt to 19 July, twenty-four days earlier. Why asking whether it should have been published is the wrong argument, and what to check today on a server that will not receive any more fixes.

Tipos de imprenta de madera: PostScript nació para hablar con impresoras y sigue vivo dentro de las bibliotecas que procesan imágenes
7 min read

It was called .png and inside it was PostScript: the WordPress 7.0.4 flaw

On 12 August WordPress shipped 7.0.4 with a single fix: CVE-2026-65640, remote code execution by uploading a file that announces itself as an image and is PostScript inside. The patch reaches back to the 4.7 branch, from December 2016. For it to affect you two conditions have to hold at once, and the first one is not yours to decide. Why validating the extension does not validate what you think, what "requires Author role" really means, and how to check it in ten minutes.

Pasillo de un centro de datos: cuando el concentrador de VPN se reinicia, el acceso remoto de toda la empresa se queda fuera
6 min read

The Cisco flaw that steals nothing: it just reboots the door your people come in through

On 11 August Cisco published an advisory for ASA and Secure Firewall Threat Defense: an HTTP request against the remote access SSL VPN service makes the device reload. The CVSS vector reads C:N/I:N/A:H —nothing is leaked, nothing is altered— and two hours and twenty minutes later it was already in CISA's KEV catalog with a 14 August due date. Three days. What to check on the device, why the patch costs exactly what the attack costs, and when this does not concern you.

Cronómetro deportivo: los cinco días entre el aviso VMSA-2026-0006 y las primeras conexiones de vCenter comprometidos a la infraestructura del atacante
6 min read

The vCenter advisory said there was no known exploitation. It held for five days

Broadcom published VMSA-2026-0006 on 29 July with no information suggesting exploitation, and that is how we quoted it here the next day. On 3 August the first compromised vCenters started connecting to attacker infrastructure, and on 12 August QUIRSO published the count: 361 victim IP addresses across 47 countries. What those numbers mean, what they do not, and the question that decides whether this concerns you: who can open a connection to your vCenter.

Cuadro eléctrico con filas de interruptores automáticos: apagar cosas una a una antes de que pase lo importante
8 min read

DeadLock does not break your antivirus: it stops it like any other service

On 10 August Microsoft published its breakdown of the DeadLock encryptor. The interesting part is not the cryptography: it is the list of things it switches off before encrypting anything. Defender stopped like a service, shadow copies gone, domain controller services halted and — this is the one almost nobody looks at — event log channels not cleared but disabled in the registry.

Pasillo frío de un centro de datos entre dos filas de racks cerrados: los aparatos que están delante de todo y casi nunca aparecen en el inventario de parcheo

Warning: Undefined array key "read_time" in /var/www/html/public/blog.php on line 3068
min read

By the time CISA flagged LoadMaster, the patch had been out for 64 days

CISA added CVE-2026-8037 to its Known Exploited Vulnerabilities catalog on 7 August and set the deadline for the 10th. Progress had shipped the patch on 4 June. In between: a public PoC on 29 June and forty days of exploitation attempts. If your patch queue is ordered by the KEV catalog, you are late by design — here is the clock you should actually be watching.

Terminal de contenedores nevada con grúas portuarias y miles de contenedores apilados: la cadena de suministro por la que viaja el código que instalas
10 min read

ChainDrop: 444 npm packages compromised and not a single patch to apply

On 4 August, between 09:35 and 13:20 UTC, a worm spread by itself across 444 npm packages, stealing the credentials it needed to keep spreading. The first malicious version went out through the legitimate pipeline, carrying a valid provenance signature. And there is a trap that inverts the correct reflex: revoking the stolen token is exactly what fires the next payload. What to look for in your lockfiles, in what order to rotate, and why there is no fixed version to install here.

Sala de control con una pared de pantallas mostrando paneles y mapas mientras varias personas los observan: el panel que todo el mundo mira y nadie mantiene
10 min read

Metabase: the data dashboard that was also the keyring

On 3 August, attackers walked into Metabase instances through the "forgot my password" endpoint, unauthenticated, with a CVSS of 10.0. Framework and Tally have already told their users. What an attacker takes from a compromised BI dashboard is not the charts: it is the credentials for every connected database, stored unencrypted unless somebody turned encryption on by hand. Which versions are in range, why this hole never shows up in your CVE feed, and why patching is the easy half of the job.

Un MacBook abierto visto desde arriba sobre un escritorio con una libreta y un lápiz: el equipo de trabajo donde alguien pega un comando dictado por una web
8 min read

The macOS malware that exploits nothing: you paste it in yourself

On 6 August, Huntress published its analysis of a Go-based credential stealer for macOS that had been sitting inside a monitored Mac for three months. There is no CVE, no exploit and nothing to patch: the chain starts with a web page dictating a command and a user pasting it into Terminal. What that command does line by line, why Gatekeeper never gets involved, what it actually takes from a company (Keychain, session cookies, browser passwords) and why the warning Apple added in macOS 26.4 is a speed bump rather than a wall.

Operadoras de centralita telefónica atendiendo llamadas: quien decide si reseteas una contraseña sigue siendo una persona al otro lado del teléfono
8 min read

Nobody exploited anything: who verifies it is you before resetting your MFA

Sounding convincing is not proof of identity, and in many organisations it is the only thing asked for. On 7 August Levi Strauss told the SEC that corporate information was taken from three company computers through social engineering: the work we use to measure security — patch, update, reboot — would have changed nothing. The joint CISA and FBI advisory on Scattered Spider says the targets are large companies and their contracted IT help desks, and that includes us. Why 65% of initial access now arrives through identity, why passkeys will not save you if the desk can enrol a new factor, and the eight things we ask of a reset procedure.

Fachada de un edificio residencial con balcones: en el hosting compartido, tu superficie de ataque incluye a los vecinos que no elegiste
8 min read

cPanel CVE-2026-58048: in shared hosting, your neighbour sets the risk

Any ordinary customer on a cPanel server could execute SQL as database root simply by renaming a database. The headline is the 9.4, but the figure almost nobody reads sits at the end of the vector: SC:H/SI:H/SA:H, CVSS 4.0's way of stating in writing that the damage leaves the vulnerable system. On a shared server, "the subsequent system" has a name: everybody else. What the flaw does, why its 5.6 sibling says it more plainly, what to check this week, and the honest question of whether you should flee shared hosting (not always).

Escalera de evacuación atornillada a la fachada del edificio del que tiene que sacarte: la copia que depende de lo que protege
8 min read

Your backup server sits inside the domain it has to restore

In June, Veeam fixed a 9.4-out-of-10 flaw that let "an authenticated domain user" run code on the backup server. According to third-party technical analysis, on a workgroup server that flaw never came into existence. The difference is not in the code: it is in who your backup server asks whether you can be trusted. What it actually checks, why this is the sixth flaw with the same description in little over a year, the circular dependency nobody draws in the recovery plan, what taking the server out of the domain really costs, and the cases where we would not do it.

Vista aérea de un enlace de autopistas con múltiples caminos posibles: el tráfico puede desviarse sin que ningún enlace se caiga
8 min read

RPKI won't stop your route being hijacked: signing the origin doesn't secure the path

70.31% of internet routes now carry a valid RPKI signature, yet only 12.3% of the autonomous systems measured achieve full protection on their routes. And the hijack that actually gets used — copying your ASN into the origin and putting yourself in front of it — passes validation with a green light. What a ROA signs and what it leaves out, the four families of attack left outside, today's event counter with its small print, and the two questions worth all the others for your provider if you do not run your own AS.

CVE-2026-34486 en Apache Tomcat: el EncryptInterceptor procesaba los mensajes del clúster aunque fallara el descifrado, un control de seguridad que falla abriendo
8 min read

If decryption fails, the message goes through anyway

The fix for the Apache Tomcat vulnerability CISA flagged as exploited on 4 August fits in a single line of code moved somewhere else. For two weeks, if decryption of a cluster message failed, Tomcat logged the error and processed the message anyway. And only 11.0.20, 10.1.53 and 9.0.116 were affected: precisely the versions carrying the patch for the previous flaw. What it means for a control to "fail open", why the log was the only signal, and what we check.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN