Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Cuarto de instalaciones de una oficina con un ordenador de sobremesa y un conmutador de red pequeño en una estantería metálica, junto a una caja de cables y material de limpieza
9 min read

Kestra, 10 out of 10: the flaw that does not need to face the internet

On 2 September 2026 CISA added seven exploited flaws to the KEV catalog. Three were perimeter appliances; another three are services your own team stood up (JFrog Artifactory, Kestra and LiteLLM), and the seventh, Starlette, nobody installed at all. The Kestra one scores 10.0 and opens because an authentication filter uses endsWith instead of an exact comparison. And the advisory says internet exposure is not required: reaching the port from inside is enough. What that changes in your patching queue.

Sala de reuniones vacía con seis portátiles cerrados sobre la mesa y cargadores enredados
10 min read

The warning came from Anthropic, not from your antivirus

On 30 August it emerged that Anthropic was warning Claude users that an infostealer had taken their browser session. Coverage treated it as an AI story. If somebody at your company got that email, it is something else: it is an infection report for a machine in your estate, signed by a supplier that is not yours and spotted through billing. We go through why MFA never even enters the picture, the five critical events that do cut a session in Microsoft Entra and the one missing from that list, the real arithmetic of revocation (1 hour, 28 hours, up to 15 minutes of latency, up to a day for a group change) and where the purpose-built defence against token theft stands today: in preview precisely in the browser, which is where this happened.

Puesto de trabajo vacío en una oficina técnica de noche, con dos monitores apagados y un rack al fondo
10 min read

Defender switches off the investigate button: AIR can no longer be triggered by hand

Tomorrow, 1 September 2026, Microsoft Defender's automated investigation and response stops running as a separate experience and can no longer be triggered by hand. The official documentation says so in a two-paragraph box, and message MC1411577 went up on 2 July: sixty-one days of notice. We go through what actually breaks (the scripts calling startInvestigation), why "run a full scan" does not answer the same question, who this does not affect at all, and the seven-day clock in the Action center you should look at today.

Panel de parcheo de fibra con latiguillos etiquetados a mano: la documentación de red que deja de coincidir con la realidad
7 min read

Your network spreadsheet lies: how we build a source of truth with NetBox

Documenting a network is not scanning it. NetBox's own documentation says so plainly: it represents the desired state of a network rather than its operational state, and it discourages automated import of live network state. That is the criterion almost nobody applies. What NetBox is and is not, the three-question test for whether your inventory is worth anything, what we document and what we deliberately do not, and when you do not need any of this.

CVE-2026-9198 en Langflow entra en el catálogo KEV de CISA el 4 de agosto de 2026: la capa de IA y automatización autoalojada (Langflow, n8n, Open WebUI) tratada como producción
8 min read

The AI pilot nobody switched off is already production

On 4 August, CISA added a 9.8 in Langflow to its exploited-vulnerabilities catalogue: one endpoint that hands superuser tokens to anyone who reaches the port, chained with another that runs whatever code you send it. The patch had been out for six weeks. It is not an isolated case: in Open WebUI the ENABLE_CODE_EXECUTION=false switch turned nothing off, and in n8n anyone who could edit a workflow could run commands on the host. Three products, the same starting assumption. What we do with the AI and automation layer, and when we recommend not self-hosting it at all.

El AI Act ya aplica desde el 2 de agosto de 2026: qué obligaciones entraron de verdad, qué aplazó el Ómnibus digital sobre IA y el checklist de inventario de everyWAN
8 min read

The AI Act already applies to you — and not for the reason the headlines gave

On 2 August the bulk of the EU AI Act became applicable. Six days earlier, the Digital Omnibus on AI (Regulation EU 2026/1744, in force since 27 July) pushed high-risk obligations to December 2027 and August 2028. What does apply from 2 August is Article 50 — transparency — with fines of up to €15M or 3% (the lower amount for SMEs) and a date almost nobody wrote down: 2 December 2026. What actually changed, where Article 25 really bites, and the inventory checklist we run on a Microsoft 365 tenant.

CVE-2026-63077, un fallo de CVSS 9,8 sin autenticación en todas las versiones de JetBrains TeamCity On-Premises, pone el foco en el servidor de CI/CD como sistema crítico
11 min read

Your CI/CD holds the keys to production. And you treat it as a developer tool

On 27 July 2026 JetBrains published CVE-2026-63077: an unauthenticated 9.8 affecting EVERY version of TeamCity On-Premises and allowing operating system commands to be run on the build server. There is no known exploitation. The two previous times TeamCity had a flaw like this ended with Russia's SVR inside technology companies and with BianLian operators creating users on build servers. The underlying problem is not TeamCity: it is that the machine which deploys to production is in almost nobody's critical systems inventory.

EWS en Exchange Online: la fecha límite real para escribir la lista de aplicaciones permitidas es el 31 de agosto de 2026
8 min read

EWS shuts down in October, but your deadline is 31 August

On 1 October Exchange Online starts disabling EWS, and on 1 April 2027 it disables it for good, with no re-enablement. But one detail turns the calendar on its head: from October, leaving EWSEnabled set to True with an empty allowed-application list starts to mean "block everything", and if you do not write that list before the end of August, in September Microsoft writes it for you based on whatever it saw running. What to look at in the usage report, the exact commands, why that automatic list fails both by omission and by excess, and the gaps Graph still does not cover according to Microsoft's own roadmap.

Antenas de radiotelescopio al anochecer: la adolescencia tecnológica de la humanidad según el ensayo de Dario Amodei
12 min read

The adolescence of technology: reading Dario Amodei's essay with our hands in the mud

In January 2026 the CEO of Anthropic published a twenty-two-thousand-word essay on the five risks of powerful AI and on whether we are ready for them. His answer is no. We read the whole thing from inside a company that deploys automation and AI on real infrastructure: the five risks laid out, an honest scorecard, the four points where we do not buy his argument — including one almost nobody has reported correctly — and what a company that does not build models should be doing today.

Una IA autónoma automatiza la post-explotación en un ataque real; la respuesta es detección 24/7
8 min read

The tireless intern now works for the other side: an autonomous AI is already automating real attacks

In an intrusion at Thailand's Ministry of Finance, the attacker left an open-source AI agent running unattended to automate the boring part of the attack: enumerate, escalate privileges, find the next step. It broke nothing new —it got in through default credentials and unpatched 2021 CVEs— but it did the dirty work faster and without rest. What actually changes is speed, and the only answer to speed is 24/7 detection and response.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN