Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Sala de centralita telefónica con operadoras conectando llamadas: el servicio que resuelve nombres y por el que pasa todo el mundo
8 min read

The DNS server you have to patch is your domain controller

CVE-2026-62878 scores 9.8: a stack-based buffer overflow in Windows DNS, no authentication and no user interaction. Microsoft's bulletin lists sixteen affected products and all sixteen require a reboot. In many of the networks we come across, that machine is also the one validating everybody's passwords, which is why it hasn't been rebooted in months — sometimes years. What the bulletin actually says, what goes down while it boots, and the checks we run before the window.

Cajones de un fichero de biblioteca con sus portaetiquetas vacíos: el directorio sigue estando en el sitio de siempre y la fuente de autoridad se está moviendo a la nube

Warning: Undefined array key "read_time" in /var/www/html/public/blog.php on line 3284
min read

Entra Connect: the date that stops your sync, and the date that just emails you

On 30 September 2026, any Entra Connect synchronisation running below version 2.5.79.0 stops working. This is not the Cloud Sync migration: it is a separate thing, and it is the only one of the two with a fixed date. The migration runs in waves, allows exceptions and has no announced retirement date. What exactly breaks when sync stops (hint: not email — the offboarding that never reaches the cloud), why auto-upgrade fails to save precisely the servers that need it, and the eight rows in Microsoft's own comparison table that decide whether you can move to Cloud Sync yet.

Escalera de evacuación atornillada a la fachada del edificio del que tiene que sacarte: la copia que depende de lo que protege
8 min read

Your backup server sits inside the domain it has to restore

In June, Veeam fixed a 9.4-out-of-10 flaw that let "an authenticated domain user" run code on the backup server. According to third-party technical analysis, on a workgroup server that flaw never came into existence. The difference is not in the code: it is in who your backup server asks whether you can be trusted. What it actually checks, why this is the sixth flaw with the same description in little over a year, the circular dependency nobody draws in the recovery plan, what taking the server out of the domain really costs, and the cases where we would not do it.

Certighost (CVE-2026-54121): impersonar un Domain Controller vía AD CS
8 min read

Certighost: any user could become your Domain Controller. The question isn't whether you patched, it's whether you've audited your AD CS

Certighost (CVE-2026-54121) let an unprivileged domain user impersonate a Domain Controller via Active Directory Certificate Services and take over the entire domain. Microsoft patched it on July 14; a working PoC has been public since July 24. The mechanism in one sentence, why AD CS is the escalation surface almost nobody audits, and the plan for today: patch, inventory your CAs, machine account quota to zero, and audit templates.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN