Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Certighost (CVE-2026-54121): impersonar un Domain Controller vía AD CS
9 min read

Certighost: any user could become your Domain Controller. The question isn't whether you patched, it's whether you've audited your AD CS

Certighost (CVE-2026-54121) let an unprivileged domain user impersonate a Domain Controller via Active Directory Certificate Services and take over the entire domain. Microsoft patched it on July 14; a working PoC has been public since July 24. The mechanism in one sentence, why AD CS is the escalation surface almost nobody audits, and the plan for today: patch, inventory your CAs, machine account quota to zero, and audit templates.

Microsoft retira el SMS como MFA en Entra ID: passkeys por defecto
7 min read

Microsoft is retiring SMS for MFA: in February 2027 Entra ID stops sending them. The strange part is that it lasted this long

On July 13 Microsoft announced that Entra ID will stop providing SMS and voice calls as an authentication method: passkeys by default from September 1 and full retirement on February 1, 2027, with no opt-out. Anyone insisting on SMS will have to contract and pay their own telecom provider. The full timeline, why SMS was never a serious second factor, and the plan we would apply to any tenant.

Check Point SmartConsole
Zero-day CVE-2026-16232 · exposed management
9 min read

The Check Point zero-day wasn't after your firewall: it was after its console

CVE-2026-16232: an authentication bypass in SmartConsole allowed logging into the server that governs all your Check Point gateways as an administrator, with no credentials. It was exploited before the patch existed and CISA gave three days to remediate. Why the management plane is a bigger prize than the firewall itself, and the checklist that applies even without Check Point.

SharePoint 2016/2019
Unsupported since Jul 14; no ESU
9 min read

SharePoint 2016 and 2019 just ran out of patches, and this time there's no extension you can pay for

On July 14 SharePoint Server 2016 and 2019 fell out of extended support, and Microsoft offers no ESU: there is no paid extension. A year ago ToolShell compromised over 400 organizations attacking on-prem SharePoint that was still receiving patches. The three real ways out, and the fourth one almost nobody offers you.

FakeGit
7,600 fake repos; your AI is the target
8 min read

Malware no longer fools you: it fools your AI. FakeGit and its 7,600 fake GitHub repositories

The FakeGit campaign seeded GitHub with 7,600 fake repositories; roughly 200 of them alone account for over 14 million malware downloads. The news isn't the volume: more than 800 posed as MCP servers and AI skills, and the assistants recommended them on their own. It has a name now: agentbaiting.

Romania's land registry
Wiped; saved by the out-of-reach copy
8 min read

Romania's land registry was wiped, backups included. It was saved by the copy the attacker couldn't touch

On July 14 an attacker got into Romania's ANCPI with valid credentials, failed to extort the agency, and wiped the land registry database plus every backup within reach. A week with no property sales or mortgages nationwide. The difference between incident and catastrophe was one copy beyond his reach.