Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Armario metálico de llaves abierto en la pared de un cuarto de instalaciones, con decenas de llaves colgadas juntas
11 min read

136 keys in one object: the defaults that opened the cluster

Hugging Face published the forensic timeline of the July intrusion and OpenAI closed its report on 26 August: 17,600 reconstructed actions between the 9th and the 13th. Between the first compromised container and the object holding 136 keys there was not one further vulnerability — there were defaults. The token every pod mounts, the metadata endpoint that answers from inside, secrets concentrated in one object, and a connector credential shared across clusters. We walk the chain with the timestamps in front of us, the two CVEs CISA added to its catalogue on 27 August, and the five questions we ask a cluster.

Armario de red mural con la puerta abierta en el cuarto trastero de una oficina, con cajas de cartón, una fregona y estanterías
7 min read

Gitea's flaw "requires write access". The signup form hands it to you

The CVE-2026-60004 write-up says you need write access to a repository. The official vector in the same advisory says <code>PR:N</code>, privileges required: none. Both are true, because Gitea installs with <code>DISABLE_REGISTRATION=false</code>. What that means for how you prioritise patching everything you self-host, what happened in the eleven seconds of the only public case, and the list of what to check today.

Caja fuerte pequeña de oficina abierta sobre una repisa, con dos sobres, un juego de llaves y una memoria USB dentro
8 min read

Cloning the repository is not a GitLab backup

On 17 August GitLab shipped four out-of-band releases for a flaw that lets an unauthenticated user modify or delete public projects. The usual answer — "we have the code cloned everywhere" — is true, and it is the part you are least likely to lose. What a clone actually carries, what lives only on the server, why the secrets file is not inside the backup, and why the June fix, the one with no CVE, explains the problem better.

Sala de servidores en penumbra con un armario de red abierto y una etiqueta de inventario despegada colgando de un cable
7 min read

Your documentation is lying to you. And so are your validations

A document does not age: it expires, and it does so silently. Markdown cannot tell the difference between what you checked, what can be checked, and what you assumed, so six months later all three read the same. We tell the real case that led us to build validated-memory: evidence states, supersession without deletion, and freshness probes with three answers instead of two. Released as open source under Apache-2.0.

Puesto de trabajo vacío de noche en una oficina pequeña: portátil cerrado, teclado mecánico, taza fría y flexo encendido
8 min read

Five days, an issue title and a Jira token

On 17 August Wiz described how it pulled a Jira token out of Snowflake by opening an issue on a public repository: the issue title was the exploit. The line that allowed it had gone in five days earlier, in a change meant to tidy the code up, and it replaced the safe pattern that GitHub's own documentation recommends in writing. What failed in the review chain, why the "if" that looked like a filter filtered nothing, and what we look at in a pipeline.

CVE-2026-63077, un fallo de CVSS 9,8 sin autenticación en todas las versiones de JetBrains TeamCity On-Premises, pone el foco en el servidor de CI/CD como sistema crítico
11 min read

Your CI/CD holds the keys to production. And you treat it as a developer tool

On 27 July 2026 JetBrains published CVE-2026-63077: an unauthenticated 9.8 affecting EVERY version of TeamCity On-Premises and allowing operating system commands to be run on the build server. There is no known exploitation. The two previous times TeamCity had a flaw like this ended with Russia's SVR inside technology companies and with BianLian operators creating users on build servers. The underlying problem is not TeamCity: it is that the machine which deploys to production is in almost nobody's critical systems inventory.

Despliegues reproducibles con Docker Swarm y GitOps: latest no es una versión
7 min read

"latest" is not a version: three lessons from deploying our own website with Docker Swarm

The pipeline went green, the webhook returned 200, and the site kept serving the old content. Three real lessons from our GitOps CI/CD on Docker Swarm: why the orchestrator does not chase your tag and what it takes for a redeploy to actually redeploy, why a linter is not a test (and the smoke test that saved our blog index), and the "zero downtime" our own file claimed but never delivered with a single replica.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN