Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Jaula de rejilla metálica cerrada con candado en una sala de datacenter compartida, con dos racks de servidores detrás
9 min read

The patch that isn't yours: what to do with Entra ID's CVE-2026-69836

On 20 August Microsoft published a critical remote code execution flaw in Entra ID, and the next day corrected the exploitation field to "No". There is nothing to install: the record says "customerActionRequired: false". What is yours is the ability to answer "were we affected?", and on an Entra ID Free licence that lasts seven days. How to read the record from Microsoft's own API, and the checklist we apply to the tenant.

Cajón abierto de un fichero de tarjetas de archivo de madera en una sala de oficina, con las fichas de papel apretadas y vistas de canto
5 min read

Some people have not been able to search in Microsoft 365 since Monday. For the SLA, that is not downtime

Incident MO1456424 has been open since Monday 17 August: some Microsoft 365 users get nothing back when they search in SharePoint Online, OneDrive and Outlook. Files still open, mail still flows, and that is why the availability counter does not move. What Microsoft's advisory says word for word, why its SLA definitions of downtime leave exactly this out, and which check you need so that you find out before your users do.

Percha de pared en la entrada de personal de una oficina con decenas de tarjetas de acceso colgadas de cordones y varios ganchos vacíos
5 min read

The directory holds more records than the company has employees

McDonald's reports just over 150,000 employees in its annual filing. The batch of its corporate directory put up for sale this week holds 1.7 million records. We placed the leaked counts next to the declared headcounts of seven companies, and the result is not a story about carelessness: it is about what a Microsoft Entra ID directory actually contains, who can read all of it with any ordinary password, and why the switch that closes it is one the vendor itself advises against touching.

Estante metálico de una sala técnica con una fila de cartuchos de cinta en sus cajas y una unidad de cinta montada en rack
9 min read

The Microsoft 365 backup that never leaves Microsoft

Microsoft 365 Backup restores a SharePoint site in under twenty minutes, costs $0.15 per protected GB per month and keeps a year of restore points. Its own documentation also says the data never crosses the Microsoft 365 trust boundary, that the storage is append-only rather than immutable, and that deleting the backups is not blocked. Which scenario that covers, which it does not, and the two new dependencies that appear the day you switch it on.

Centralita telefónica manual con hileras de interruptores etiquetados a mano: apagar uno era rápido; saber qué línea dejaba muda, no
9 min read

The report says "zero impacts", and that does not mean nobody uses it

Baseline Security Mode puts twenty-one settings in the Microsoft 365 admin center that used to live only in PowerShell: switching off basic authentication, EWS, ActiveX, IDCRL, Publisher. Microsoft's guidance says to turn each one on when its impact report comes back at zero. The detail that changes the reading: the Office app settings are delivered through Cloud Policy, and Windows clients below version 2510 do not send the simulation mode telemetry that feeds that report. What each switch turns off, what actually breaks when you close EWS, and the order we do it in.

Pasillo de un archivo lleno de cajas y carpetas: el SharePoint local de una empresa guarda sus documentos igual, y desde el 14 de julio ya no recibe arreglos
5 min read

Your SharePoint 2016 got its last patch on 14 July

CVE-2026-55040 lets an attacker with no credentials impersonate any user or administrator of an on-premises SharePoint. Microsoft fixed it on 14 July 2026: exactly the day SharePoint Server 2016 and 2019 went out of support. The proof of concept went public on 12 August and was seen in use the same day, but KEVintel's sensors date the first attempt to 19 July, twenty-four days earlier. Why asking whether it should have been published is the wrong argument, and what to check today on a server that will not receive any more fixes.

  • 1
  • 2

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN