Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Torres de telecomunicaciones entre la niebla: la red móvil privada que comparten empresas que no se conocen
9 min read

They crossed from a wind farm to a power plant turbine through the grid operator's private APN

On 8 August CERT Polska published its analysis of the 29 December 2025 attack on a Polish combined heat and power plant. The attacker got in through a FortiGate with no multi-factor authentication, hopped to a cellular router, crossed the distribution operator's private APN and put three families of Siemens PLCs into STOP mode. The report does not cite a single CVE in the whole chain: what it describes is a mobile network we all call private in which any device could talk to any other.

Paso fronterizo vacío con la barrera levantada: la frontera de datos europea sigue dibujada y el tráfico pasa igual
8 min read

Three settings decide whether Claude processes your documents in Copilot, and one was decided by your tenant's creation date

Microsoft turned Anthropic models on by default in Microsoft 365 Copilot, but not in the EU. There are three separate settings with three different defaults, one of them depends on whether the tenant was created before or after 25 March 2026, and Microsoft's own documentation sends you to the Message Center to find out yours. What each source says, what cannot be inferred from them, and the twenty-minute review.

Pulsador de parada de emergencia en una pared: el nodo que se apaga a sí mismo para que el clúster pueda seguir
7 min read

Proxmox HA does not prevent downtime: it shortens it (and sometimes causes it)

Proxmox VE's own documentation sets the ceiling: about 2 minutes of error detection and failover, and no more than 99.999% availability. What really happens when a node dies (a cold start, not a live migration), why a healthy node reboots itself 60 seconds after losing quorum, the requirements everybody skips, and when we do not deploy HA at all.

Cuadro eléctrico con filas de interruptores automáticos: apagar cosas una a una antes de que pase lo importante
8 min read

DeadLock does not break your antivirus: it stops it like any other service

On 10 August Microsoft published its breakdown of the DeadLock encryptor. The interesting part is not the cryptography: it is the list of things it switches off before encrypting anything. Defender stopped like a service, shadow copies gone, domain controller services halted and — this is the one almost nobody looks at — event log channels not cleared but disabled in the registry.

Panel de salidas de una estación con horarios anunciados: el papel promete tiempos y el hierro tarda lo que tarda

Warning: Undefined array key "read_time" in /var/www/html/public/blog.php on line 2519
min read

RTO and RPO without the fluff: two numbers signed but never calculated

Almost every continuity plan carries an RPO and an RTO written with great confidence and calculated with none. What those two numbers actually promise, why your real RPO is the one of your last verified backup, the four clocks inside an RTO, and the arithmetic that dismantles a "four hours" sitting on a 1 Gbps link.

Pasillo frío de un centro de datos entre dos filas de racks cerrados: los aparatos que están delante de todo y casi nunca aparecen en el inventario de parcheo

Warning: Undefined array key "read_time" in /var/www/html/public/blog.php on line 2519
min read

By the time CISA flagged LoadMaster, the patch had been out for 64 days

CISA added CVE-2026-8037 to its Known Exploited Vulnerabilities catalog on 7 August and set the deadline for the 10th. Progress had shipped the patch on 4 June. In between: a public PoC on 29 June and forty days of exploitation attempts. If your patch queue is ordered by the KEV catalog, you are late by design — here is the clock you should actually be watching.

Fichero de archivo de madera con un cajón abierto lleno de tarjetas catalogadas: dónde vive de verdad cada documento y quién puede abrir el cajón

Warning: Undefined array key "read_time" in /var/www/html/public/blog.php on line 2519
min read

That recording lives in the OneDrive of someone who no longer works here

At the end of September, Microsoft moves whiteboards created in Teams channels out of the creator's OneDrive and into the channel's SharePoint site. It is a small change that concedes a large problem: much of a company's collective work lives inside one individual's personal account. Where each recording actually lands, why the deletion clock starts the day you delete the account rather than the day the person leaves, and why leaving the account blocked "just in case" is not the plan you think it is.

Terminal de contenedores nevada con grúas portuarias y miles de contenedores apilados: la cadena de suministro por la que viaja el código que instalas
10 min read

ChainDrop: 444 npm packages compromised and not a single patch to apply

On 4 August, between 09:35 and 13:20 UTC, a worm spread by itself across 444 npm packages, stealing the credentials it needed to keep spreading. The first malicious version went out through the legitimate pipeline, carrying a valid provenance signature. And there is a trap that inverts the correct reflex: revoking the stolen token is exactly what fires the next payload. What to look for in your lockfiles, in what order to rotate, and why there is no fixed version to install here.

Sala de control con una pared de pantallas mostrando paneles y mapas mientras varias personas los observan: el panel que todo el mundo mira y nadie mantiene
10 min read

Metabase: the data dashboard that was also the keyring

On 3 August, attackers walked into Metabase instances through the "forgot my password" endpoint, unauthenticated, with a CVSS of 10.0. Framework and Tally have already told their users. What an attacker takes from a compromised BI dashboard is not the charts: it is the credentials for every connected database, stored unencrypted unless somebody turned encryption on by hand. Which versions are in range, why this hole never shows up in your CVE feed, and why patching is the easy half of the job.

Un MacBook abierto visto desde arriba sobre un escritorio con una libreta y un lápiz: el equipo de trabajo donde alguien pega un comando dictado por una web
8 min read

The macOS malware that exploits nothing: you paste it in yourself

On 6 August, Huntress published its analysis of a Go-based credential stealer for macOS that had been sitting inside a monitored Mac for three months. There is no CVE, no exploit and nothing to patch: the chain starts with a web page dictating a command and a user pasting it into Terminal. What that command does line by line, why Gatekeeper never gets involved, what it actually takes from a company (Keychain, session cookies, browser passwords) and why the warning Apple added in macOS 26.4 is a speed bump rather than a wall.

Cajones de un fichero de biblioteca con sus portaetiquetas vacíos: el directorio sigue estando en el sitio de siempre y la fuente de autoridad se está moviendo a la nube

Warning: Undefined array key "read_time" in /var/www/html/public/blog.php on line 2519
min read

Entra Connect: the date that stops your sync, and the date that just emails you

On 30 September 2026, any Entra Connect synchronisation running below version 2.5.79.0 stops working. This is not the Cloud Sync migration: it is a separate thing, and it is the only one of the two with a fixed date. The migration runs in waves, allows exceptions and has no announced retirement date. What exactly breaks when sync stops (hint: not email — the offboarding that never reaches the cloud), why auto-upgrade fails to save precisely the servers that need it, and the eight rows in Microsoft's own comparison table that decide whether you can move to Cloud Sync yet.

Operadoras de centralita telefónica atendiendo llamadas: quien decide si reseteas una contraseña sigue siendo una persona al otro lado del teléfono
8 min read

Nobody exploited anything: who verifies it is you before resetting your MFA

Sounding convincing is not proof of identity, and in many organisations it is the only thing asked for. On 7 August Levi Strauss told the SEC that corporate information was taken from three company computers through social engineering: the work we use to measure security — patch, update, reboot — would have changed nothing. The joint CISA and FBI advisory on Scattered Spider says the targets are large companies and their contracted IT help desks, and that includes us. Why 65% of initial access now arrives through identity, why passkeys will not save you if the desk can enrol a new factor, and the eight things we ask of a reset procedure.

Sala llena de ordenadores encendidos y funcionando con normalidad: los certificados de Secure Boot caducaron en junio y ningún equipo dejó de arrancar
7 min read

Secure Boot expired in June and nothing broke. That is the problem

On 24 and 27 June, two of the certificates Microsoft has used to sign the boot chain since 2011 expired. Not a single machine went down: Microsoft states plainly that the device keeps starting and updating normally. What stops is something else — revocations, the boot manager, early-boot mitigations — and it raises no alert at all. A third date is still open: 19 October. How to check in two minutes whether your Windows estate, your Linux servers and — this is the one nobody looks at — your virtual machines already carry the 2023 certificates.

Primer plano de papel triturado con restos de texto: el recall en la nube borra el mensaje del buzón del destinatario, y ahora podrá ordenarlo otra empresa
10 min read

Cross-tenant recall: Exchange Online lets another company delete mail from your mailboxes

In mid-August Microsoft starts rolling out cross-tenant message recall in Exchange Online (MC1423106). It ships switched off, and you do not turn it on to recover your own emails: you turn it on so senders in another tenant can delete messages already delivered to your people's mailboxes. What cloud recall does today (hard delete, read messages included, retrying for up to 24 hours), why the allow list looks far too much like the list of domains invoice fraud uses, what actually protects you (retention, not the checkbox), and the logging gap almost nobody has read.

Sección de un tronco con sus anillos de crecimiento: capas acumuladas durante años, como el código del kernel donde se escondían Zapscape y SCTPhantom
8 min read

Zapscape and SCTPhantom: your Proxmox does not run Debian's kernel

Two Linux kernel flaws published this week break the two boundaries we take for granted: the virtual machine (Zapscape, CVE-2026-64561) and the container (SCTPhantom, CVE-2026-64564). Understanding them is the easy part. The hard part is answering whether the kernel your node actually boots already carries the fixes, because the versions in the advisory — 6.12.101, 7.1.6 — do not exist on your server: Proxmox does not use Debian's kernel. The exact proxmox-kernel versions that do close them (and why 7.0.14-9 is not enough), how to check in four commands, and who genuinely needs to hurry.

Fachada de un edificio residencial con balcones: en el hosting compartido, tu superficie de ataque incluye a los vecinos que no elegiste
8 min read

cPanel CVE-2026-58048: in shared hosting, your neighbour sets the risk

Any ordinary customer on a cPanel server could execute SQL as database root simply by renaming a database. The headline is the 9.4, but the figure almost nobody reads sits at the end of the vector: SC:H/SI:H/SA:H, CVSS 4.0's way of stating in writing that the damage leaves the vulnerable system. On a shared server, "the subsequent system" has a name: everybody else. What the flaw does, why its 5.6 sibling says it more plainly, what to check this week, and the honest question of whether you should flee shared hosting (not always).

Parte trasera de un rack de nodos de almacenamiento: la mejora de Fast EC se enciende pool por pool, no con la actualización
7 min read

Fast EC ships switched off: the Ceph Tentacle flag that only turns once

Ceph Tentacle ships Fast EC, the erasure coding performance work people had been waiting years for. And it arrives switched off: you enable it pool by pool, with one command, and the monitor then refuses to clear it — rolling back means draining and recreating the pool. On top of that, the "at least double" in the headline was measured with a 16K stripe unit, which is precisely what an existing pool cannot have. The conditions the monitor enforces, the half of the improvement frozen on the day you created the pool, what happens to the cluster when you flip it, and why three-way replication is still faster.

Escalera de evacuación atornillada a la fachada del edificio del que tiene que sacarte: la copia que depende de lo que protege
8 min read

Your backup server sits inside the domain it has to restore

In June, Veeam fixed a 9.4-out-of-10 flaw that let "an authenticated domain user" run code on the backup server. According to third-party technical analysis, on a workgroup server that flaw never came into existence. The difference is not in the code: it is in who your backup server asks whether you can be trusted. What it actually checks, why this is the sixth flaw with the same description in little over a year, the circular dependency nobody draws in the recovery plan, what taking the server out of the domain really costs, and the cases where we would not do it.

Vista aérea de un enlace de autopistas con múltiples caminos posibles: el tráfico puede desviarse sin que ningún enlace se caiga
8 min read

RPKI won't stop your route being hijacked: signing the origin doesn't secure the path

70.31% of internet routes now carry a valid RPKI signature, yet only 12.3% of the autonomous systems measured achieve full protection on their routes. And the hijack that actually gets used — copying your ASN into the origin and putting yourself in front of it — passes validation with a green light. What a ROA signs and what it leaves out, the four families of attack left outside, today's event counter with its small print, and the two questions worth all the others for your provider if you do not run your own AS.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN