Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Estanterías de un depósito de archivo con legajos y cajas de documentos etiquetados
9 min read

"Read-only" does not exist: GitLab scores 10.0 on a flaw that can only read

CVE-2026-85706 lets a stranger read files off a self-hosted GitLab server. It writes nothing, and it still carries the maximum score. The explanation is not in the headline: it is in the vector the vendor itself signed off, with a changed scope and high integrity impact. We go through what the vector says, why CISA gave it three days and a forensic triage flag, and how to answer the one question the patch does not: were we read?

Rack de una pequeña oficina con panel de parcheo, latiguillos y equipos de red apilados
9 min read

The AI agent will not show up in your log: whoever lent it the token will

Connecting an assistant to SharePoint or the ERP is not an integration decision, it is a delegation decision. The Model Context Protocol specification, revision 2026-07-28, forbids forwarding somebody else's token in capital letters, and spells out why: the destination system's logs will show a different identity from the one that made the request. We go through the spec, the permission fallback that asks for everything on offer, the CVE in the official SDK, and the seven questions we ask before connecting anything.

Ordenador abierto sobre el banco de trabajo de un servicio de reparación informática
10 min read

Remote support: the file runs on the technician's machine

On 11 September, CISA added a ConnectWise ScreenConnect advisory to its catalogue of exploited vulnerabilities. The detail almost nobody highlights comes from the vendor itself: "ScreenConnect servers are not impacted". The machine that ends up running the file is the one support is given from. Three days earlier, N-able N-central had entered the same list with a 10.0. We counted the whole catalogue: fifteen entries in 2026 for software whose job is governing other people's computers. Windows, thirteen.

Reloj de pared de esfera oscura en una pared gris de oficina
11 min read

Cyber Resilience Act: 24 hours to report, and the clock does not start with the CVE

Article 14 of the Cyber Resilience Act starts to apply today: 24 hours for the first warning about an actively exploited vulnerability. Two details almost nobody is covering: it is the only article the regulation stretches backwards, reaching what you have already sold, and the deadline runs not from the CVE being published but from the moment you "become aware". That turns a legal obligation into an instrumentation problem: telemetry, a watched mailbox and who declares the time.

Panel de parcheo a oscuras con cuatro conectores RJ45 desconectados
10 min read

Cisco FMC: patching closes the door, but nobody gives you back your network blueprint

On 9 September, Cisco Talos confirmed active exploitation of two flaws in Secure Firewall Management Center, and counted three separate attacker clusters inside the same box. One of them dropped two scripts to harvest the configurations of the managed firewalls. That is the part almost nobody is discussing: credentials rotate, a domain gets restored, and your perimeter configuration does not rotate. It is a description of your network, and it stays valid after the patch.

Armario de comunicaciones de pared con switch y cables de red
10 min read

Windows DNS, an unauthenticated 9.8: what turns a bug into a worm is not the bug, it's your network

On 8 September Microsoft shipped the largest batch of patches in its history. Dustin Childs, of the Zero Day Initiative, counts twenty that could be classified as wormable, spread across thirteen components. Those thirteen are not one list: they are two. Seven of those CVEs sit in services your domain requires every machine to reach — DNS, Netlogon, Active Directory, DHCP — and eleven sit in roles Windows does not install on its own. The first half is managed with patching order; the second, by uninstalling. And hardly anyone knows which of the two they have switched on.

Sala de control con un muro de pantallas de monitorización y varias personas mirándolo de pie
10 min read

AI now finds zero-days on its own. Your problem is the 43 days that come after

On 4 September OpenAI launched GPT-6 Astra and declared it the first model it deploys reaching the "Critical" cybersecurity capability level of its preparedness framework. Almost all the coverage went after that half. The two numbers that decide what happens to you predate Astra and neither is about finding flaws: mean time to exploit is minus seven days according to M-Trends 2026, and the median to fully remediate a KEV-listed vulnerability is 43 days according to Verizon's DBIR. The bottleneck was never finding.

Armario de red mural abierto en el pasillo de una oficina, con anillas pasahilos y cables recogidos, y un extintor apoyado en la pared al fondo
7 min read

July's patch is September's vulnerable build

SonicWall closed the SMA 1000 zero-day pair in build 12.4.3-03453 on 14 July. The 1 September advisory lists 12.4.3-03453 and earlier as affected: anyone who met the three-day KEV deadline landed on exactly the build that is back in the catalog 49 days later, with the same shape of flaw. When an appliance repeats the shape of the flaw, the question stops being whether it is patched and becomes how far that box reaches.

Servidor de dos alturas con la tapa quitada sobre una estantería metálica, en el trastero de una oficina, con cartones apoyados en la pared
8 min read

Artifactory's "medium" CVE hit the catalog before the critical one

CISA confirmed exploitation of a 5.3 JFrog Artifactory flaw on 27 August; of the 9.8 that lets anyone forge admin tokens, on 2 September. Six days apart, and in the opposite order to the scores. Look at the full vector of the "medium" one and you see why: two of the three impact dimensions are zero and the one left at maximum is integrity. In an artifact repository, integrity is exactly what you are buying.

Puesto de monitorización vacío de noche, con los dos monitores apagados, unos auriculares sobre la mesa y la silla apartada
9 min read

The agent says SECURE and your console has received nothing for days

At DEF CON 34, Akamai showed how to turn a commercial EDR into the attacker's hiding place. The least-reported part is the ending: one line in the hosts file cuts off all telemetry while the agent still shows "SECURE". The signal you watch is controlled by the endpoint; the only one an attacker cannot fabricate is silence in your console. And almost nobody alerts on it.

Mesa de soporte de una oficina con un teléfono fijo de sobremesa, una libreta de anillas, un cordón con llaves y un teclado apartado a un lado
9 min read

The phone number on the record was a credential: Entra ID stops accepting it

Microsoft's own documentation has said it plainly for years: if you fill in a user's mobile phone or alternate email, that user can reset their password immediately "even if they haven't registered for the service". Which means a field written by a sync or by an admin worked as proof of identity. Entra ID is about to stop accepting it. What changes, why the 86% everyone quotes does not mean what it looks like, and the four different dates Microsoft gives for the same cutoff.

Cuarto de instalaciones de una oficina con un ordenador de sobremesa y un conmutador de red pequeño en una estantería metálica, junto a una caja de cables y material de limpieza
9 min read

Kestra, 10 out of 10: the flaw that does not need to face the internet

On 2 September 2026 CISA added seven exploited flaws to the KEV catalog. Three were perimeter appliances; another three are services your own team stood up (JFrog Artifactory, Kestra and LiteLLM), and the seventh, Starlette, nobody installed at all. The Kestra one scores 10.0 and opens because an authentication filter uses endsWith instead of an exact comparison. And the advisory says internet exposure is not required: reaching the port from inside is enough. What that changes in your patching queue.

Cuarto de interconexión con paneles de parcheo, latiguillos de fibra naranja y amarilla recogidos en peines horizontales y una bobina de fibra colgada en la pared
8 min read

The route hijack RPKI called valid: the ROA allowed all the way down to /24

Between 28 and 30 August 2026, a BGP hijack diverted traffic for 162.55.80.0/24 across some 22 active hours and served a malicious update from behind a valid TLS certificate. We went and checked the ROA on RIPEstat: until 1 September it carried maxLength 24, so while the hijack lasted the route was RPKI valid. What origin validation checks and what it does not, why that same maxLength was also the cure, and the six verifications you can run today.

Armario rack de pared en un cuarto de instalaciones de oficina, con un servidor encendido, polvo en la bandeja, una escalera plegada y un cubo de fregona al lado
7 min read

The Exchange you left running: 21,899 unpatched servers, and yours could be one

On 31 August 2026, Shadowserver scans counted 21,899 IP addresses running an Exchange Server without the CVE-2026-62911 patch released on 11 August. Many of those servers do not belong to companies that never migrated: they are the one left running after the move to Microsoft 365, published on the internet and owned by nobody. What Microsoft's advisory says and does not say next to Germany's BSI, why since April 2022 that server can be switched off, which route Microsoft recommends in 2026 to remove it for good, and the three cases where you should not touch it.

Cartel de «se busca» con el alias CyberLeek sobre una ciudad nocturna y las etiquetas de los datos reclamados: IP, identificador de dispositivo, cuenta de Microsoft, OneDrive y Discord
8 min read

GTA 6, CyberLeek and MachineGuid: the digital trail your company leaves too

To find whoever is leaking GTA 6 material, on 20 August 2026 Take-Two filed two DMCA subpoenas asking Microsoft and Discord for the MachineGuid, MSA device identifiers, IP addresses, phone numbers, linked connections and OneDrive contents of every account in three servers. What MachineGuid is, why it identifies the device rather than the account, and why your company generates exactly the same trail every working day.

Proxmox VE 7 y CVE-2023-54391: dos servidores viejos todavía encendidos en la estantería de un cuarto trastero
7 min read

Proxmox VE 7: the patch had been out for three years and nobody knew it was a patch

On 1 September 2026 Proxmox published advisory PSA-2026-00043-1: on Proxmox VE 7, sending any tfa-challenge value is enough to log in as root@pam with no password. The code that fixed it shipped on 20 July 2023 inside a refactor nobody classified as security, which is why it was never backported. What the flaw does, why a second factor saved you, what to check on your node today, and what all of this says about your inventory.

Custom controls de Acceso Condicional: el MFA de terceros que Entra no cuenta como MFA
9 min read

Custom controls: the third-party MFA that Entra does not count as MFA

The Microsoft Learn page on Conditional Access custom controls lists eight things that control cannot do, and the third is satisfying the MFA claim requirement. It is no good for PIM role elevation, device enrollment, SSPR, sign-in frequency or cross-tenant trusts either. From September 2026 they can no longer be created or edited, and "editing" means deleting and creating again. With the Graph query to find out whether you have one.

Diez CVE en el proceso iked de un cortafuegos: leer el campo de impacto antes que el titular
8 min read

Ten CVEs in one process: the headline is not enough to decide

On 27 August, ten security advisories landed in iked, the process that negotiates a firewall's IPsec tunnels. We read them one by one, and in several of them the headline and the body do not say the same thing: one titled "unauthenticated" needs a VPN user with valid credentials; another the vendor could not reproduce; and one of the lowest-scoring is the only one that mentions reading key material. How to read a bulletin like that in forty minutes.

Armario metálico de llaves abierto en la pared de un cuarto de instalaciones, con decenas de llaves colgadas juntas
11 min read

136 keys in one object: the defaults that opened the cluster

Hugging Face published the forensic timeline of the July intrusion and OpenAI closed its report on 26 August: 17,600 reconstructed actions between the 9th and the 13th. Between the first compromised container and the object holding 136 keys there was not one further vulnerability — there were defaults. The token every pod mounts, the metadata endpoint that answers from inside, secrets concentrated in one object, and a connector credential shared across clusters. We walk the chain with the timestamps in front of us, the two CVEs CISA added to its catalogue on 27 August, and the five questions we ask a cluster.

Sala de reuniones vacía con seis portátiles cerrados sobre la mesa y cargadores enredados
8 min read

The warning came from Anthropic, not from your antivirus

On 30 August it emerged that Anthropic was warning Claude users that an infostealer had taken their browser session. Coverage treated it as an AI story. If somebody at your company got that email, it is something else: it is an infection report for a machine in your estate, signed by a supplier that is not yours and spotted through billing. We go through why MFA never even enters the picture, the five critical events that do cut a session in Microsoft Entra and the one missing from that list, the real arithmetic of revocation (1 hour, 28 hours, up to 15 minutes of latency, up to a day for a group change) and where the purpose-built defence against token theft stands today: in preview precisely in the browser, which is where this happened.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN