Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Puesto de monitorización vacío de noche, con los dos monitores apagados, unos auriculares sobre la mesa y la silla apartada
9 min read

The agent says SECURE and your console has received nothing for days

At DEF CON 34, Akamai showed how to turn a commercial EDR into the attacker's hiding place. The least-reported part is the ending: one line in the hosts file cuts off all telemetry while the agent still shows "SECURE". The signal you watch is controlled by the endpoint; the only one an attacker cannot fabricate is silence in your console. And almost nobody alerts on it.

Puesto de trabajo vacío en una oficina técnica de noche, con dos monitores apagados y un rack al fondo
8 min read

Defender switches off the investigate button: AIR can no longer be triggered by hand

Tomorrow, 1 September 2026, Microsoft Defender's automated investigation and response stops running as a separate experience and can no longer be triggered by hand. The official documentation says so in a two-paragraph box, and message MC1411577 went up on 2 July: sixty-one days of notice. We go through what actually breaks (the scripts calling startInvestigation), why "run a full scan" does not answer the same question, who this does not affect at all, and the seven-day clock in the Action center you should look at today.

Puesto de trabajo de una oficina vacío al amanecer, con la silla apartada, una taza fría y la persiana entreabierta
8 min read

They switched the EDR off with a reboot, and the encryption failed for lack of memory

On 4 August an Akira affiliate walked in through an MFA-less SSL VPN in roughly seven minutes and, rather than fight the EDR, rebooted the compromised host into <code>Safe Mode with Networking</code>: the agent and Defender real-time protection stopped starting. We counted the blind window against the timestamps in the Huntress report and it comes to 1 h 41 min, not the 10 minutes that circulated. The encryption did fail, but on virtual memory, not on defences.

Varios miniordenadores en una bandeja de rack conectados a un panel de parcheo: máquinas pequeñas alojadas y accesibles desde la red
8 min read

They came in on port 5900 and left with root: the miner was the least of it

In mid-August the Dutch cyber security centre warned that the macOS Screen Sharing flaw is being exploited on Macs with port 5900 open to the internet, and that in every reported case the attacker got root and left a Monero miner behind. Apple had already shipped the patch on 6 August. What exactly breaks in CVE-2026-65400, why classic hardening did not cover this hole, and the list almost no company has: what listens from outside.

Sala de reuniones vacía con las sillas recogidas: en agosto la alerta salta igual, pero la sala donde se decide está cerrada
8 min read

Three days to patch, and the third one lands on a Saturday

Since CISA changed its deadlines on 10 June, 42 of the 48 vulnerabilities it has added come with three days to fix them. We counted the weekdays over the catalog file itself: not a single 2026 entry was published on a Saturday or Sunday, and thirteen of those three-day deadlines expire exactly there. In August, with half the staff away, the bottleneck is who signs off that a server can be isolated at three in the morning.

Cuadro eléctrico con filas de interruptores automáticos: apagar cosas una a una antes de que pase lo importante
8 min read

DeadLock does not break your antivirus: it stops it like any other service

On 10 August Microsoft published its breakdown of the DeadLock encryptor. The interesting part is not the cryptography: it is the list of things it switches off before encrypting anything. Defender stopped like a service, shadow copies gone, domain controller services halted and — this is the one almost nobody looks at — event log channels not cleared but disabled in the registry.

Un MacBook abierto visto desde arriba sobre un escritorio con una libreta y un lápiz: el equipo de trabajo donde alguien pega un comando dictado por una web
8 min read

The macOS malware that exploits nothing: you paste it in yourself

On 6 August, Huntress published its analysis of a Go-based credential stealer for macOS that had been sitting inside a monitored Mac for three months. There is no CVE, no exploit and nothing to patch: the chain starts with a web page dictating a command and a user pasting it into Terminal. What that command does line by line, why Gatekeeper never gets involved, what it actually takes from a company (Keychain, session cookies, browser passwords) and why the warning Apple added in macOS 26.4 is a speed bump rather than a wall.

Pass-ta-key: tres técnicas de Unit 42 contra las passkeys sincronizadas de Google Password Manager en Chrome sobre Windows, incluida la extracción del secreto de 32 bytes que las descifra todas
8 min read

Your passkey isn't broken — the master key gets copied

On 3 August, Unit 42 published three ways into passkey-protected accounts without breaking a single line of cryptography. The worst of them lifts a 32-byte secret out of Chrome's memory that decrypts every passkey synced to the account — and in Google's current implementation that secret cannot be rotated or revoked. All three start the same way: with malware already running on a Windows machine, with no administrator rights and no privilege escalation. We still recommend passkeys, and this post explains why that is not a contradiction.

CVE-2026-18577 en N-able N-central: un salto de autenticación en la consola desde la que los proveedores de IT gestionan los equipos de sus clientes, explotado con el control remoto del propio producto
8 min read

The agent we install on your machines is also a door

On 3 August, CISA added CVE-2026-18577 to its exploited-vulnerabilities catalogue with a deadline of the 6th. It is a flaw in the console many IT providers use to manage their customers' machines, and it arrived as the incomplete patch for another flaw published two days earlier. The vendor found out through a rise in licensing issues, not a security alert. Access was not granted by malware: the attackers used the product's own remote-control feature and left a tunnel behind so they would still be inside after the console was cut off. We are a managed services provider, and this post is about what that means for the people who hire us.

CVE-2025-68686: el parche de FortiOS que se saltaba con una barra de más
8 min read

Patching is not cleaning: FortiOS and the extra slash

On 27 July, CISA added a FortiOS flaw to its exploited-vulnerabilities catalogue with a deadline attached: 10 August. CVE-2025-68686 opens no new door: it reopens the one Fortinet believed it had closed in April 2025, and it does so with one extra slash in the path. The story of the symbolic link in the language-files folder, the patch that was a string comparison, the 7.2, 7.0 and 6.4 branches left with no fix at all, and why patching is an action while being clean is a conclusion you have to prove.

Fatiga de alertas: cómo montar una monitorización que avisa de lo que importa
8 min read

Your monitoring is not broken: it is shouting

An organisation receives an average of 2,992 security alerts a day and 63% of them go unaddressed, according to Vectra AI's 2026 count. The interesting part is that the volume has been falling for three years and the unaddressed share has not moved. Filtering harder does not fix it, because the problem was never how many alerts arrive: it is how many arrived with an owner and an action written next to them. How we prune monitoring that shouts, what wakes us at three in the morning, and what waits for the morning report.

Una IA autónoma automatiza la post-explotación en un ataque real; la respuesta es detección 24/7
8 min read

The tireless intern now works for the other side: an autonomous AI is already automating real attacks

In an intrusion at Thailand's Ministry of Finance, the attacker left an open-source AI agent running unattended to automate the boring part of the attack: enumerate, escalate privileges, find the next step. It broke nothing new —it got in through default credentials and unpatched 2021 CVEs— but it did the dirty work faster and without rest. What actually changes is speed, and the only answer to speed is 24/7 detection and response.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN