Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Plan de continuidad sin ensayar: un servidor sacado a medias del rack con los cables de alimentación desenchufados
9 min read

A continuity plan nobody has rehearsed is a document, not a plan

Uptime Institute's May 2026 annual outage analysis says the leading driver of outages with human error behind them is still failing to follow procedures that were already established. Established: the document existed. And 87% of those who suffered an impactful outage believe it could have been prevented with better management, processes or configuration — seven points more than in 2024. What is missing, what a drill that works looks like, and when you should NOT run one.

Mostrador de pedidos de un almacén con el monitor apagado apartado, una libreta con los pedidos apuntados a mano, albaranes en un pincho y un teléfono descolgado
8 min read

The backup was safe. And it had spent 47 hours inside the same outage

A hosting provider's official status page said two things on the same day: \"there is no risk of data loss\" and \"it is not possible to access backups or migrate affected services to another node\". Both were true, and together they describe the design flaw almost nobody has in their plan: a perfect RPO with an RTO that has no number. We rebuild the clock from the provider's own status page and propose the figure missing from almost every plan: the hour at which you stop waiting.

Cuadro eléctrico general abierto en un cuarto de instalaciones, con filas de magnetotérmicos colgando todos de un mismo interruptor principal
8 min read

Six Microsoft 365 services went down together. For your continuity plan they are one

On Monday 31 August, incident EX1464935 on Exchange Online ended up as MO1465074, with OneDrive, SharePoint Online, Teams, Purview and Defender XDR inside it. Six names, one shared authentication configuration underneath. We go through the hours —including the ones BleepingComputer and Computerworld disagree on, which we say rather than picking one—, why nobody has confirmed the expired-certificate story, and the dependency almost nobody will look at: the security console and the audit layer were inside the thing that had gone down.

Armario de llaves metálico abierto en el pasillo de servicio de una oficina, con dos hileras de llaves colgadas de sus ganchos
7 min read

They deleted the backups at both data centres

Joint advisory AA26-222A, published on 10 August 2026 by six agencies, records that at one Gunra victim the actors deleted backup and archived data at the primary data centre <em>and</em> at the recovery one, before and after deploying the encryptor. Another section describes how they got the key cabinet: SSH to an access control server and a symmetric key that decrypted the passwords for enterprise server accounts across the company. Our reading: two sites that accept the same credential are one site with two postal addresses. What falls outside a retention lock, and six checks for this week — two of which have to be actually run.

Rack abierto en una sala de servidores con dos bandejas de disco a medio sacar
8 min read

10% of the VMDK is enough: the arithmetic that changes your recovery plan

The ESXi encryptor Rapid7 took apart carries a percentage parameter, and the value observed was 10: on a large VMDK it touches only a tenth of the file, and that is enough to stop it booting. Partial encryption is not new — LockFile was doing it in 2021 — but the numbers are. What it does to your response clock, why no EDR agent belongs on the hypervisor (Broadcom says in so many words that it is not supported), what the same actor does to backup services, and why swapping hypervisors is not a security control.

Caja fuerte pequeña de oficina abierta sobre una repisa, con dos sobres, un juego de llaves y una memoria USB dentro
8 min read

Cloning the repository is not a GitLab backup

On 17 August GitLab shipped four out-of-band releases for a flaw that lets an unauthenticated user modify or delete public projects. The usual answer — "we have the code cloned everywhere" — is true, and it is the part you are least likely to lose. What a clone actually carries, what lives only on the server, why the secrets file is not inside the backup, and why the June fix, the one with no CVE, explains the problem better.

Una tormenta de verano avanzando sobre el desierto, origen del fallo de refrigeración que apagó 5.000 servidores
8 min read

Your servers can be switched off by someone you never signed anything with

On 13 August more than 5,000 servers were powered off in a building in Phoenix, taking down the websites, email and DNS of thousands of companies. The decision to shut down was the right one; what is interesting is the chain the order came down, because the end customer sits at the bottom of it with no contract with whoever decides. What to ask about the building your hardware lives in, and why DNS took down people who were not even there.

Panel de salidas de una estación con horarios anunciados: el papel promete tiempos y el hierro tarda lo que tarda

Warning: Undefined array key "read_time" in /var/www/html/public/blog.php on line 3122
min read

RTO and RPO without the fluff: two numbers signed but never calculated

Almost every continuity plan carries an RPO and an RTO written with great confidence and calculated with none. What those two numbers actually promise, why your real RPO is the one of your last verified backup, the four clocks inside an RTO, and the arithmetic that dismantles a "four hours" sitting on a 1 Gbps link.

Escalera de evacuación atornillada a la fachada del edificio del que tiene que sacarte: la copia que depende de lo que protege
8 min read

Your backup server sits inside the domain it has to restore

In June, Veeam fixed a 9.4-out-of-10 flaw that let "an authenticated domain user" run code on the backup server. According to third-party technical analysis, on a workgroup server that flaw never came into existence. The difference is not in the code: it is in who your backup server asks whether you can be trusted. What it actually checks, why this is the sixth flaw with the same description in little over a year, the circular dependency nobody draws in the recovery plan, what taking the server out of the domain really costs, and the cases where we would not do it.

Informe de ransomware 2026: 1,7 millones de dólares de coste medio de recuperación por incidente
7 min read

Restoring is not recovering: two in three recover from backup and nearly half still pay

Sophos's annual ransomware report (2,158 IT leaders across 17 countries, Spain included) brings the biggest backup rebound in the series: 66% of victims whose data was encrypted recovered from backup, twelve points above the 54% of 2025. At the same time 48% paid, and the average cost of recovering rose 11% to $1.7 million with the ransom excluded. Why the two numbers do not contradict each other, the note on method about the two medians almost nobody is reading correctly, what is inside that bill, and the five things worth timing before the bad day.

Caída de Google Cloud en europe-west4-a por fallo de energía y refrigeración en el datacenter
10 min read

Three milliseconds and 44 degrees: the cloud outage that had nothing to do with software

On 15 July 2026 a three-millisecond voltage dip on the utility feed took three services in a Google Cloud zone in the Netherlands out of service for almost fifteen hours. No CVE, no botched deployment, no BGP route: an electrical transient, a backup system that failed to pick up the load, a chiller controller that dropped offline, and a data hall at 44°C. What exactly failed according to the official incident report, why redundancy on paper is not always redundancy, what it means that a zone is not a building, and the seven questions worth asking any datacenter — including your own — before it happens.

Romania's land registry
Wiped; saved by the out-of-reach copy
8 min read

Romania's land registry was wiped, backups included. It was saved by the copy the attacker couldn't touch

On July 14 an attacker got into Romania's ANCPI with valid credentials, failed to extort the agency, and wiped the land registry database plus every backup within reach. A week with no property sales or mortgages nationwide. The difference between incident and catastrophe was one copy beyond his reach.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN