Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Armario rack de pared en un cuarto de instalaciones de oficina, con un servidor encendido, polvo en la bandeja, una escalera plegada y un cubo de fregona al lado
7 min read

The Exchange you left running: 21,899 unpatched servers, and yours could be one

On 31 August 2026, Shadowserver scans counted 21,899 IP addresses running an Exchange Server without the CVE-2026-62911 patch released on 11 August. Many of those servers do not belong to companies that never migrated: they are the one left running after the move to Microsoft 365, published on the internet and owned by nobody. What Microsoft's advisory says and does not say next to Germany's BSI, why since April 2022 that server can be switched off, which route Microsoft recommends in 2026 to remove it for good, and the three cases where you should not touch it.

Cartel de «se busca» con el alias CyberLeek sobre una ciudad nocturna y las etiquetas de los datos reclamados: IP, identificador de dispositivo, cuenta de Microsoft, OneDrive y Discord
8 min read

GTA 6, CyberLeek and MachineGuid: the digital trail your company leaves too

To find whoever is leaking GTA 6 material, on 20 August 2026 Take-Two filed two DMCA subpoenas asking Microsoft and Discord for the MachineGuid, MSA device identifiers, IP addresses, phone numbers, linked connections and OneDrive contents of every account in three servers. What MachineGuid is, why it identifies the device rather than the account, and why your company generates exactly the same trail every working day.

Proxmox VE 7 y CVE-2023-54391: dos servidores viejos todavía encendidos en la estantería de un cuarto trastero
7 min read

Proxmox VE 7: the patch had been out for three years and nobody knew it was a patch

On 1 September 2026 Proxmox published advisory PSA-2026-00043-1: on Proxmox VE 7, sending any tfa-challenge value is enough to log in as root@pam with no password. The code that fixed it shipped on 20 July 2023 inside a refactor nobody classified as security, which is why it was never backported. What the flaw does, why a second factor saved you, what to check on your node today, and what all of this says about your inventory.

Custom controls de Acceso Condicional: el MFA de terceros que Entra no cuenta como MFA
9 min read

Custom controls: the third-party MFA that Entra does not count as MFA

The Microsoft Learn page on Conditional Access custom controls lists eight things that control cannot do, and the third is satisfying the MFA claim requirement. It is no good for PIM role elevation, device enrollment, SSPR, sign-in frequency or cross-tenant trusts either. From September 2026 they can no longer be created or edited, and "editing" means deleting and creating again. With the Graph query to find out whether you have one.

Diez CVE en el proceso iked de un cortafuegos: leer el campo de impacto antes que el titular
8 min read

Ten CVEs in one process: the headline is not enough to decide

On 27 August, ten security advisories landed in iked, the process that negotiates a firewall's IPsec tunnels. We read them one by one, and in several of them the headline and the body do not say the same thing: one titled "unauthenticated" needs a VPN user with valid credentials; another the vendor could not reproduce; and one of the lowest-scoring is the only one that mentions reading key material. How to read a bulletin like that in forty minutes.

Armario metálico de llaves abierto en la pared de un cuarto de instalaciones, con decenas de llaves colgadas juntas
11 min read

136 keys in one object: the defaults that opened the cluster

Hugging Face published the forensic timeline of the July intrusion and OpenAI closed its report on 26 August: 17,600 reconstructed actions between the 9th and the 13th. Between the first compromised container and the object holding 136 keys there was not one further vulnerability — there were defaults. The token every pod mounts, the metadata endpoint that answers from inside, secrets concentrated in one object, and a connector credential shared across clusters. We walk the chain with the timestamps in front of us, the two CVEs CISA added to its catalogue on 27 August, and the five questions we ask a cluster.

Sala de reuniones vacía con seis portátiles cerrados sobre la mesa y cargadores enredados
10 min read

The warning came from Anthropic, not from your antivirus

On 30 August it emerged that Anthropic was warning Claude users that an infostealer had taken their browser session. Coverage treated it as an AI story. If somebody at your company got that email, it is something else: it is an infection report for a machine in your estate, signed by a supplier that is not yours and spotted through billing. We go through why MFA never even enters the picture, the five critical events that do cut a session in Microsoft Entra and the one missing from that list, the real arithmetic of revocation (1 hour, 28 hours, up to 15 minutes of latency, up to a day for a group change) and where the purpose-built defence against token theft stands today: in preview precisely in the browser, which is where this happened.

Puesto de trabajo vacío en una oficina técnica de noche, con dos monitores apagados y un rack al fondo
10 min read

Defender switches off the investigate button: AIR can no longer be triggered by hand

Tomorrow, 1 September 2026, Microsoft Defender's automated investigation and response stops running as a separate experience and can no longer be triggered by hand. The official documentation says so in a two-paragraph box, and message MC1411577 went up on 2 July: sixty-one days of notice. We go through what actually breaks (the scripts calling startInvestigation), why "run a full scan" does not answer the same question, who this does not affect at all, and the seven-day clock in the Action center you should look at today.

Mesa de oficina con un portátil cerrado, una llave de seguridad USB en un llavero y un teléfono móvil boca abajo
10 min read

Passkeys on 1 September: the cases that do not fit

In July we went through the timeline for the retirement of SMS and voice in Microsoft Entra ID. Five days after that post Microsoft published a FAQ, and there are now forty-eight hours to go until the first date. This is the run-through of what is still unanswered: the FAQ's "No" to the lockout question and what it says three lines further down, the self-service password reset that goes with the same move, the declared gap for B2B guests, the break-glass accounts the documentation never mentions, and why the temporary opt-out switch, which lives on the Graph beta endpoint, is not the answer we would give.

Archivo de oficina con cajas y carpetas apiladas en estanterías metálicas bajo luz natural
10 min read

They are not old bugs: they are old classes of bug. We ran the numbers on CISA's catalogue

We downloaded CISA's Known Exploited Vulnerabilities catalogue and counted its 1,685 entries. Of the 201 added in 2026, 123 carry an identifier from this same year and the median gap is zero: what is old is not the individual bug but the class. We measured that too, using the file's own cwes field: CWE-20, improper input validation, tops the catalogue with 118 entries, followed by command injection and out-of-bounds write. And something turned up that we were not looking for: on 10 June directive BOD 26-04 revoked BOD 22-01, and since then 81% of what goes in arrives with a three-day deadline instead of the previous 23%.

Cuarto de impresión de una oficina con una multifunción, cajas de papel y un servidor en una estantería metálica
9 min read

PaperCut: the print server runs as SYSTEM, and nearly half the measured estate has no patch

On 27 August PaperCut confirmed active exploitation of PaperCut NG and MF. The identifiers landed the next day: CVE-2026-81578 (CVSS 8.8) and CVE-2026-82078 (CVSS 9.4), chained into unauthenticated remote code execution. Huntress watched one intrusion last under two minutes, and in their proof of concept the code executes as SYSTEM. The figure that orders everything else: 47% of the 2,500 installations Huntress tracks are on version 23 or older, for which no patch exists. What happened hour by hour, why Thursday's patch did not hold on Friday, and today's notice that turns one of the indicators into a false positive.

Sala de espera de oficina en penumbra con tres sillas grises alineadas contra la pared
8 min read

Guest Wi-Fi is a database of people (and it is not in your inventory)

Manchester Airports Group confirmed on 27 August that an unauthorised third party took customer data: email addresses, phone numbers, vehicle registrations and postcodes, from car park, lounge and Fast Track bookings and from in-airport Wi-Fi sign-ups. The company has not published how many people are affected; reporting puts it at around 8.7 million. Operations were unaffected, and that is precisely the problem: the system holding the most people is almost never at the top of your criticality list. Why the number plate is the field to watch, and the six questions worth one afternoon of inventory at your own front desk.

Puerta de acero de una sala de servidores sujeta abierta con una cuña, con un rack visible al fondo
8 min read

The bulletin said "denial of service". The exploit gives root: NetScaler CVE-2026-8452

Citrix shipped the patch on 30 June and described it as a denial of service; the CVSS vector on that same entry already showed high confidentiality impact and no privileges required. On 14 August, 45 days later, the exploit that gives unauthenticated root went public, and attacks followed within days: CISA set a 29 August deadline. How to check whether you are patched without knocking the box over (513 bytes, error 43549) and why the patch does not evict whoever already got in.

Armario de red mural con la puerta abierta en el cuarto trastero de una oficina, con cajas de cartón, una fregona y estanterías
7 min read

Gitea's flaw "requires write access". The signup form hands it to you

The CVE-2026-60004 write-up says you need write access to a repository. The official vector in the same advisory says <code>PR:N</code>, privileges required: none. Both are true, because Gitea installs with <code>DISABLE_REGISTRATION=false</code>. What that means for how you prioritise patching everything you self-host, what happened in the eleven seconds of the only public case, and the list of what to check today.

Armario de llaves metálico abierto en el pasillo de servicio de una oficina, con dos hileras de llaves colgadas de sus ganchos
7 min read

They deleted the backups at both data centres

Joint advisory AA26-222A, published on 10 August 2026 by six agencies, records that at one Gunra victim the actors deleted backup and archived data at the primary data centre <em>and</em> at the recovery one, before and after deploying the encryptor. Another section describes how they got the key cabinet: SSH to an access control server and a symmetric key that decrypted the passwords for enterprise server accounts across the company. Our reading: two sites that accept the same credential are one site with two postal addresses. What falls outside a retention lock, and six checks for this week — two of which have to be actually run.

Archivadores metálicos grises de oficina, con un cajón entreabierto y unos papeles asomando
6 min read

Ransom Busters: the rescuer offering to save you is the one who encrypted you

On 18 August GuidePoint (GRIT) reported that a supposed third party calling itself "Ransom Busters" emails ransomware victims offering to delete their data for between $20,000 and $60,000. When questioned, it confirmed access to the same stolen dataset the affiliate behind the intrusion held, and the same forensic fingerprints repeated across the incidents GuidePoint worked. What really changes everything is the date: the email arrived before the incident was public. What to do with it on the first morning.

Puesto de trabajo de una oficina vacío al amanecer, con la silla apartada, una taza fría y la persiana entreabierta
8 min read

They switched the EDR off with a reboot, and the encryption failed for lack of memory

On 4 August an Akira affiliate walked in through an MFA-less SSL VPN in roughly seven minutes and, rather than fight the EDR, rebooted the compromised host into <code>Safe Mode with Networking</code>: the agent and Defender real-time protection stopped starting. We counted the blind window against the timestamps in the Huntress report and it comes to 1 h 41 min, not the 10 minutes that circulated. The encryption did fail, but on virtual memory, not on defences.

Servidor de almacenamiento de 4U extraído sobre sus guías en una sala de servidores, con la tapa quitada y las filas de discos a la vista
9 min read

Proxmox's "protected" flag is not a lock, it's a latch

The Pay2Key ransomware shuts down the guests on a Proxmox cluster and deletes the backups using Proxmox's own API: first a <code>--protected 0</code>, then the delete. We read the pve-storage source to see why it works, and the answer is uncomfortable: clearing the latch never costs one privilege more than deleting the backup. What does raise a real boundary, and why it costs nothing.

Aparato de red de 1U extraído sobre sus guías en un rack de sala técnica, con cable de consola conectado y un carro de servicio al lado
6 min read

NetScaler CVE-2026-19490: your version doesn't tell you whether you're exposed

On 19 August Citrix published an authentication bypass scoring 9.3 out of 10 in NetScaler ADC and Gateway. Being affected does not depend on your version alone: it depends on what you have configured, and older builds need fewer conditions. How to actually answer the question, why a pre-authentication flaw leaves your MFA out of the path, and what we do in the window before the first exploit lands.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN