Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Pasillo de un depósito de archivo con estanterías móviles cerradas y cajas de documentación
11 min read

Project Online shuts down on 30 September: no licence, no export

Microsoft switches Project Online off on 30 September and PWA sites stop being available. But what decides whether you make it in time is not in the announcement: it is in the service description, which requires a live Plan 3 or Plan 5 subscription in the tenant for ANY interaction. Which means the licence you were going to drop to save money during the migration is the one you need in order to export. There is also a second 120-day clock written somewhere else, the PWA is a SharePoint site and not a calendar, and the destination's published limits explicitly exclude your plan.

Rack de una pequeña oficina con panel de parcheo, latiguillos y equipos de red apilados
9 min read

The AI agent will not show up in your log: whoever lent it the token will

Connecting an assistant to SharePoint or the ERP is not an integration decision, it is a delegation decision. The Model Context Protocol specification, revision 2026-07-28, forbids forwarding somebody else's token in capital letters, and spells out why: the destination system's logs will show a different identity from the one that made the request. We go through the spec, the permission fallback that asks for everything on offer, the CVE in the official SDK, and the seven questions we ask before connecting anything.

Técnico agachado con un portátil trabajando en la parte trasera de un rack de servidores
5 min read

REPLICATION was never a read-only privilege: PostgreSQL closed a twelve-year dlopen()

On 13 August PostgreSQL shipped 18.6, 17.11, 16.15, 15.19 and 14.24. Among the CVEs they close there is one that is not about buffer overflows: any account holding the REPLICATION attribute could name as its logical decoding plugin any file visible to the system, and the server would load it and run its code as the operating system user. The patch adds a whitelist with two entries by default: if your change data capture uses decoderbufs or wal2json, it stops your replication until somebody edits postgresql.conf.

Servidor de dos alturas con la tapa quitada sobre una estantería metálica, en el trastero de una oficina, con cartones apoyados en la pared
5 min read

Artifactory's "medium" CVE hit the catalog before the critical one

CISA confirmed exploitation of a 5.3 JFrog Artifactory flaw on 27 August; of the 9.8 that lets anyone forge admin tokens, on 2 September. Six days apart, and in the opposite order to the scores. Look at the full vector of the "medium" one and you see why: two of the three impact dimensions are zero and the one left at maximum is integrity. In an artifact repository, integrity is exactly what you are buying.

Cartel de «se busca» con el alias CyberLeek sobre una ciudad nocturna y las etiquetas de los datos reclamados: IP, identificador de dispositivo, cuenta de Microsoft, OneDrive y Discord
5 min read

GTA 6, CyberLeek and MachineGuid: the digital trail your company leaves too

To find whoever is leaking GTA 6 material, on 20 August 2026 Take-Two filed two DMCA subpoenas asking Microsoft and Discord for the MachineGuid, MSA device identifiers, IP addresses, phone numbers, linked connections and OneDrive contents of every account in three servers. What MachineGuid is, why it identifies the device rather than the account, and why your company generates exactly the same trail every working day.

Priority Cleanup de Microsoft Purview: borrar por encima de la retención en Microsoft 365
9 min read

Deleting above retention: three approvals in Exchange, one in SharePoint

Microsoft Purview Priority Cleanup deletes Microsoft 365 content by overriding retention policies, labels and eDiscovery holds, and the documentation says what it deletes cannot be restored by users, by admins, or by Microsoft. Mailboxes always demand three approvals; SharePoint and OneDrive, one — and none from the retention owner. What stops it, what to switch off beforehand, and what it asks of your backup.

Sala de archivo de una oficina con estanterías metálicas llenas de cajas de cartón y carpetas, y una caja abierta sobre una mesa de trabajo
7 min read

"The column was encrypted": pgcrypto was storing cleartext and nobody noticed

On 13 August PostgreSQL closed 28 CVEs in one go. One of them is not a buffer overflow: when OpenSSL rejected the requested cipher, pgcrypto never checked the answer and wrote the value into your "encrypted" column with a trivial XOR. Neither the INSERT nor the SELECT failed. What triggers it, why the day it broke was not the day the code was written, and which version you are really running if you install from Debian rather than PGDG.

Mesa de una oficina administrativa a última hora: archivadores de anillas, una calculadora de sobremesa y un archivador metálico con un cajón abierto
5 min read

5% more for paying monthly: what changes on 1 October, and when not to switch

From 1 October 2026 Microsoft will add a 5% uplift to CSP software subscriptions on annual terms billed monthly: it names Windows Server, SQL Server, CALs and System Center, and leaves the list open. The product does not change; the price of money does. The full arithmetic — that 5% works out at borrowing at roughly 11% a year — why your date is not 1 October but each line's renewal date, and the cases where moving is not worth it.

Paso fronterizo vacío con la barrera levantada: la frontera de datos europea sigue dibujada y el tráfico pasa igual
5 min read

Three settings decide whether Claude processes your documents in Copilot, and one was decided by your tenant's creation date

Microsoft turned Anthropic models on by default in Microsoft 365 Copilot, but not in the EU. There are three separate settings with three different defaults, one of them depends on whether the tenant was created before or after 25 March 2026, and Microsoft's own documentation sends you to the Message Center to find out yours. What each source says, what cannot be inferred from them, and the twenty-minute review.

Sala de control con una pared de pantallas mostrando paneles y mapas mientras varias personas los observan: el panel que todo el mundo mira y nadie mantiene
5 min read

Metabase: the data dashboard that was also the keyring

On 3 August, attackers walked into Metabase instances through the "forgot my password" endpoint, unauthenticated, with a CVSS of 10.0. Framework and Tally have already told their users. What an attacker takes from a compromised BI dashboard is not the charts: it is the credentials for every connected database, stored unencrypted unless somebody turned encryption on by hand. Which versions are in range, why this hole never shows up in your CVE feed, and why patching is the easy half of the job.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN