Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Pasillo estrecho de un centro de datos, con un rack abierto de paneles de parcheo de fibra en primer plano y latiguillos aguamarina y amarillos recogidos en las guías de cable
10 min read

Redundancy does not survive the procedure

On 1 September, a scheduled capacity upgrade sequentially unplugged 100% of the fiber paths serving part of Google Cloud's us-central1-b zone, in thirteen minutes. Just before that, the report describes a correct architecture: physically separated paths, diverse power, tolerance to double and triple failures. A 2003 Berkeley study already explained why none of it helped: operator error is not more frequent than hardware failure, it is just less frequently masked.

Plan de continuidad sin ensayar: un servidor sacado a medias del rack con los cables de alimentación desenchufados
9 min read

A continuity plan nobody has rehearsed is a document, not a plan

Uptime Institute's May 2026 annual outage analysis says the leading driver of outages with human error behind them is still failing to follow procedures that were already established. Established: the document existed. And 87% of those who suffered an impactful outage believe it could have been prevented with better management, processes or configuration — seven points more than in 2024. What is missing, what a drill that works looks like, and when you should NOT run one.

Priority Cleanup de Microsoft Purview: borrar por encima de la retención en Microsoft 365
9 min read

Deleting above retention: three approvals in Exchange, one in SharePoint

Microsoft Purview Priority Cleanup deletes Microsoft 365 content by overriding retention policies, labels and eDiscovery holds, and the documentation says what it deletes cannot be restored by users, by admins, or by Microsoft. Mailboxes always demand three approvals; SharePoint and OneDrive, one — and none from the retention owner. What stops it, what to switch off beforehand, and what it asks of your backup.

Mostrador de pedidos de un almacén con el monitor apagado apartado, una libreta con los pedidos apuntados a mano, albaranes en un pincho y un teléfono descolgado
8 min read

The backup was safe. And it had spent 47 hours inside the same outage

A hosting provider's official status page said two things on the same day: \"there is no risk of data loss\" and \"it is not possible to access backups or migrate affected services to another node\". Both were true, and together they describe the design flaw almost nobody has in their plan: a perfect RPO with an RTO that has no number. We rebuild the clock from the provider's own status page and propose the figure missing from almost every plan: the hour at which you stop waiting.

Cuadro eléctrico general abierto en un cuarto de instalaciones, con filas de magnetotérmicos colgando todos de un mismo interruptor principal
8 min read

Six Microsoft 365 services went down together. For your continuity plan they are one

On Monday 31 August, incident EX1464935 on Exchange Online ended up as MO1465074, with OneDrive, SharePoint Online, Teams, Purview and Defender XDR inside it. Six names, one shared authentication configuration underneath. We go through the hours —including the ones BleepingComputer and Computerworld disagree on, which we say rather than picking one—, why nobody has confirmed the expired-certificate story, and the dependency almost nobody will look at: the security console and the audit layer were inside the thing that had gone down.

Rincón de oficina con una papelera metálica desbordada de papel y una destructora con el depósito lleno
9 min read

Recoverable Items: 14 days, 30 GB and the day the mailbox can no longer delete

The folder that saves you when someone empties the deleted items does not show up in Outlook, keeps things for 14 days by default and holds 30 GB. Put the mailbox on hold and the ceiling rises to 100 GB — in exchange for never draining again: things only go in. And on the day it hits that ceiling, per Microsoft's own documentation, the user cannot delete, versions stop being kept and audit entries stop being written. How to measure your headroom with two commands, how to open the drain that ships disconnected, and why a folder deleted with Shift+Delete does not come back even under litigation hold.

Servidores de rack idénticos apilados en un carro metálico, pendientes de montar, delante de un rack a medio poblar
8 min read

Corosync adds 650 milliseconds per node: the clock your upgraded cluster is still carrying

The time a Proxmox cluster takes to re-form membership after losing a node is not fixed: it grows by 650 ms for every node you add, and on factory values a 29-node cluster reaches 45.21 seconds — exactly where the documentation itself asks you to fix it, before the 60-second watchdog starts rebooting healthy nodes. Proxmox VE 9.2 lowered it to 125 ms, but only when the cluster is created: clusters upgraded from 8 to 9 keep the old value.

Armario de llaves metálico abierto en el pasillo de servicio de una oficina, con dos hileras de llaves colgadas de sus ganchos
7 min read

They deleted the backups at both data centres

Joint advisory AA26-222A, published on 10 August 2026 by six agencies, records that at one Gunra victim the actors deleted backup and archived data at the primary data centre <em>and</em> at the recovery one, before and after deploying the encryptor. Another section describes how they got the key cabinet: SSH to an access control server and a symmetric key that decrypted the passwords for enterprise server accounts across the company. Our reading: two sites that accept the same credential are one site with two postal addresses. What falls outside a retention lock, and six checks for this week — two of which have to be actually run.

Portal de un edificio antiguo con una única puerta acristalada, el portero automático y los buzones metálicos
8 min read

Your identity provider is not an application: it is infrastructure

On Monday 24 August, at 03:38, a denial-of-service attack began against Norway's shared government digital platform. Ten public services went down and several had nothing wrong with them: the door everyone goes through had jammed. Digdir writes on its status page that <code>eSignering</code> was unavailable "because of the limitations in ID-porten", and also that the services were "stable with the limitations that have been put in place" — part of the outage was put there by the defenders. Why single sign-on is still the right call, what changes when the door becomes infrastructure, and the three questions that reclassify it.

Archivadores metálicos grises de oficina, con un cajón entreabierto y unos papeles asomando
6 min read

Ransom Busters: the rescuer offering to save you is the one who encrypted you

On 18 August GuidePoint (GRIT) reported that a supposed third party calling itself "Ransom Busters" emails ransomware victims offering to delete their data for between $20,000 and $60,000. When questioned, it confirmed access to the same stolen dataset the affiliate behind the intrusion held, and the same forensic fingerprints repeated across the incidents GuidePoint worked. What really changes everything is the date: the email arrived before the incident was public. What to do with it on the first morning.

Cajón abierto de un fichero de tarjetas de archivo de madera en una sala de oficina, con las fichas de papel apretadas y vistas de canto
8 min read

Some people have not been able to search in Microsoft 365 since Monday. For the SLA, that is not downtime

Incident MO1456424 has been open since Monday 17 August: some Microsoft 365 users get nothing back when they search in SharePoint Online, OneDrive and Outlook. Files still open, mail still flows, and that is why the availability counter does not move. What Microsoft's advisory says word for word, why its SLA definitions of downtime leave exactly this out, and which check you need so that you find out before your users do.

Estante metálico de una sala técnica con una fila de cartuchos de cinta en sus cajas y una unidad de cinta montada en rack
9 min read

The Microsoft 365 backup that never leaves Microsoft

Microsoft 365 Backup restores a SharePoint site in under twenty minutes, costs $0.15 per protected GB per month and keeps a year of restore points. Its own documentation also says the data never crosses the Microsoft 365 trust boundary, that the storage is append-only rather than immutable, and that deleting the backups is not blocked. Which scenario that covers, which it does not, and the two new dependencies that appear the day you switch it on.

Una tormenta de verano avanzando sobre el desierto, origen del fallo de refrigeración que apagó 5.000 servidores
8 min read

Your servers can be switched off by someone you never signed anything with

On 13 August more than 5,000 servers were powered off in a building in Phoenix, taking down the websites, email and DNS of thousands of companies. The decision to shut down was the right one; what is interesting is the chain the order came down, because the end customer sits at the bottom of it with no contract with whoever decides. What to ask about the building your hardware lives in, and why DNS took down people who were not even there.

Sala de reuniones vacía con las sillas recogidas: en agosto la alerta salta igual, pero la sala donde se decide está cerrada
8 min read

Three days to patch, and the third one lands on a Saturday

Since CISA changed its deadlines on 10 June, 42 of the 48 vulnerabilities it has added come with three days to fix them. We counted the weekdays over the catalog file itself: not a single 2026 entry was published on a Saturday or Sunday, and thirteen of those three-day deadlines expire exactly there. In August, with half the staff away, the bottleneck is who signs off that a server can be isolated at three in the morning.

Pasillo de un centro de datos: cuando el concentrador de VPN se reinicia, el acceso remoto de toda la empresa se queda fuera
6 min read

The Cisco flaw that steals nothing: it just reboots the door your people come in through

On 11 August Cisco published an advisory for ASA and Secure Firewall Threat Defense: an HTTP request against the remote access SSL VPN service makes the device reload. The CVSS vector reads C:N/I:N/A:H —nothing is leaked, nothing is altered— and two hours and twenty minutes later it was already in CISA's KEV catalog with a 14 August due date. Three days. What to check on the device, why the patch costs exactly what the attack costs, and when this does not concern you.

Panel de salidas de una estación con horarios anunciados: el papel promete tiempos y el hierro tarda lo que tarda

Warning: Undefined array key "read_time" in /var/www/html/public/blog.php on line 3230
min read

RTO and RPO without the fluff: two numbers signed but never calculated

Almost every continuity plan carries an RPO and an RTO written with great confidence and calculated with none. What those two numbers actually promise, why your real RPO is the one of your last verified backup, the four clocks inside an RTO, and the arithmetic that dismantles a "four hours" sitting on a 1 Gbps link.

Informe de ransomware 2026: 1,7 millones de dólares de coste medio de recuperación por incidente
7 min read

Restoring is not recovering: two in three recover from backup and nearly half still pay

Sophos's annual ransomware report (2,158 IT leaders across 17 countries, Spain included) brings the biggest backup rebound in the series: 66% of victims whose data was encrypted recovered from backup, twelve points above the 54% of 2025. At the same time 48% paid, and the average cost of recovering rose 11% to $1.7 million with the ransom excluded. Why the two numbers do not contradict each other, the note on method about the two medians almost nobody is reading correctly, what is inside that bill, and the five things worth timing before the bad day.

NIS2 en España: la ley sin publicar y el cuestionario de proveedor que ya está en tu correo
8 min read

NIS2 in Spain: the law is not here yet, your customer's questionnaire is

As of 29 July 2026 the Spanish law transposing NIS2 still has not been published in the official gazette: the text was approved by the Council of Ministers in January 2025 at first reading and is still a draft bill, and on 8 July the European Commission decided to refer Spain to the Court of Justice of the EU asking for penalties. That does not mean NIS2 is not affecting you: it means it will not arrive via an inspector, but via your largest customer's procurement department. What already applies today with no transposition needed, what those supplier questionnaires really ask, and what we would do with ninety days ahead of us.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN