Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
EWS en Exchange Online: la fecha límite real para escribir la lista de aplicaciones permitidas es el 31 de agosto de 2026
8 min read

EWS shuts down in October, but your deadline is 31 August

On 1 October Exchange Online starts disabling EWS, and on 1 April 2027 it disables it for good, with no re-enablement. But one detail turns the calendar on its head: from October, leaving EWSEnabled set to True with an empty allowed-application list starts to mean "block everything", and if you do not write that list before the end of August, in September Microsoft writes it for you based on whatever it saw running. What to look at in the usage report, the exact commands, why that automatic list fails both by omission and by excess, and the gaps Graph still does not cover according to Microsoft's own roadmap.

Informe de ransomware 2026: 1,7 millones de dólares de coste medio de recuperación por incidente
7 min read

Restoring is not recovering: two in three recover from backup and nearly half still pay

Sophos's annual ransomware report (2,158 IT leaders across 17 countries, Spain included) brings the biggest backup rebound in the series: 66% of victims whose data was encrypted recovered from backup, twelve points above the 54% of 2025. At the same time 48% paid, and the average cost of recovering rose 11% to $1.7 million with the ransom excluded. Why the two numbers do not contradict each other, the note on method about the two medians almost nobody is reading correctly, what is inside that bill, and the five things worth timing before the bad day.

NIS2 en España: la ley sin publicar y el cuestionario de proveedor que ya está en tu correo
8 min read

NIS2 in Spain: the law is not here yet, your customer's questionnaire is

As of 29 July 2026 the Spanish law transposing NIS2 still has not been published in the official gazette: the text was approved by the Council of Ministers in January 2025 at first reading and is still a draft bill, and on 8 July the European Commission decided to refer Spain to the Court of Justice of the EU asking for penalties. That does not mean NIS2 is not affecting you: it means it will not arrive via an inspector, but via your largest customer's procurement department. What already applies today with no transposition needed, what those supplier questionnaires really ask, and what we would do with ninety days ahead of us.

CVE-2025-68686: el parche de FortiOS que se saltaba con una barra de más
8 min read

Patching is not cleaning: FortiOS and the extra slash

On 27 July, CISA added a FortiOS flaw to its exploited-vulnerabilities catalogue with a deadline attached: 10 August. CVE-2025-68686 opens no new door: it reopens the one Fortinet believed it had closed in April 2025, and it does so with one extra slash in the path. The story of the symbolic link in the language-files folder, the patch that was a string comparison, the 7.2, 7.0 and 6.4 branches left with no fix at all, and why patching is an action while being clean is a conclusion you have to prove.

CVE-2026-16812 en el VeloCloud Orchestrator: el orquestador SD-WAN expuesto por diseño
7 min read

Your WAN orchestrator is on the internet by design: VeloCloud's 10.0

CVE-2026-16812 is an unauthenticated command injection in the on-premises VeloCloud Orchestrator: CVSS 10.0, exploited before a patch existed, and in CISA's KEV catalogue the same day with three days to fix it. Arista's advisory says the console is exposed by default and that no configuration prevents that exposure; a few lines further down it recommends restricting access to the web interface to trusted administrative networks. Both are true, and the bad day is decided in the distance between them.

CVE-2026-14266 en 7-Zip: por qué en la mayoría de los PCs de empresa el mejor parche es desinstalarlo
6 min read

The best patch for 7-Zip is uninstalling it (on most of your PCs)

CVE-2026-14266 is a heap overflow in 7-Zip's XZ decoder: it affects version 21.07 and every release up to 26.01. With no public exploit and no known exploitation, it is not an emergency. But that is two code-execution flaws in two months, the program updates by hand, and Windows 11 has opened .7z and .rar natively since 2023. Before updating two hundred machines, it is worth checking how many actually need it.

Cl0p extorsiona sin cifrar: campaña contra PTC Windchill y FlexPLM
7 min read

Cl0p didn't encrypt a single file: extortion walks in through the app nobody watches

Cl0p is exploiting a critical vulnerability in PTC Windchill and FlexPLM (CVE-2026-12569, CVSS 9.3) to steal engineering data and extort without encrypting anything. The patch had existed since June 17; the wave of extortion emails arrived a month later. Why your backups can't undo a theft, what the Accellion→MOVEit→Oracle EBS pattern teaches (2,700+ organizations in a single campaign), and the five things we would do this week.

Microsoft retira el SMS como MFA en Entra ID: passkeys por defecto
7 min read

Microsoft SMS MFA end of life: Entra ID stops sending texts in February 2027

On July 13 Microsoft announced that Entra ID will stop providing SMS and voice calls as an authentication method: passkeys by default from September 1 and full retirement on February 1, 2027, with no opt-out. Anyone insisting on SMS will have to contract and pay their own telecom provider. The full timeline, why SMS was never a serious second factor, and the plan we would apply to any tenant.

Check Point SmartConsole
Zero-day CVE-2026-16232 · exposed management
8 min read

The Check Point zero-day wasn't after your firewall: it was after its console

CVE-2026-16232: an authentication bypass in SmartConsole allowed logging into the server that governs all your Check Point gateways as an administrator, with no credentials. It was exploited before the patch existed and CISA gave three days to remediate. Why the management plane is a bigger prize than the firewall itself, and the checklist that applies even without Check Point.

SharePoint 2016/2019
Unsupported since Jul 14; no ESU
8 min read

SharePoint 2016 and 2019 just ran out of patches, and this time there's no extension you can pay for

On July 14 SharePoint Server 2016 and 2019 fell out of extended support, and Microsoft offers no ESU: there is no paid extension. A year ago ToolShell compromised over 400 organizations attacking on-prem SharePoint that was still receiving patches. The three real ways out, and the fourth one almost nobody offers you.

  • 1
  • 2

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN