Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Cuarto de instalaciones de una oficina con un ordenador de sobremesa y un conmutador de red pequeño en una estantería metálica, junto a una caja de cables y material de limpieza
9 min read

Kestra, 10 out of 10: the flaw that does not need to face the internet

On 2 September 2026 CISA added seven exploited flaws to the KEV catalog. Three were perimeter appliances; another three are services your own team stood up (JFrog Artifactory, Kestra and LiteLLM), and the seventh, Starlette, nobody installed at all. The Kestra one scores 10.0 and opens because an authentication filter uses endsWith instead of an exact comparison. And the advisory says internet exposure is not required: reaching the port from inside is enough. What that changes in your patching queue.

Sala de reuniones vacía con seis portátiles cerrados sobre la mesa y cargadores enredados
10 min read

The warning came from Anthropic, not from your antivirus

On 30 August it emerged that Anthropic was warning Claude users that an infostealer had taken their browser session. Coverage treated it as an AI story. If somebody at your company got that email, it is something else: it is an infection report for a machine in your estate, signed by a supplier that is not yours and spotted through billing. We go through why MFA never even enters the picture, the five critical events that do cut a session in Microsoft Entra and the one missing from that list, the real arithmetic of revocation (1 hour, 28 hours, up to 15 minutes of latency, up to a day for a group change) and where the purpose-built defence against token theft stands today: in preview precisely in the browser, which is where this happened.

Sala de reuniones pequeña y vacía, con un altavoz de conferencia sobre la mesa, sillas desordenadas y luz natural entrando por la persiana
8 min read

Teams can now block meeting bots: it ships turned off

On 21 August Microsoft announced (MC1459141) that admins will be able to automatically block detected external bots in Teams meetings. We read the documentation for the ExternalBotAccessMode parameter: the word doing all the work is "detected", the new mode has to be assigned through policy, and it touches neither Copilot nor the assistant recording from your client's tenant. What actually decides where the transcript ends up — and when we would not switch it on.

Cuadro eléctrico industrial abierto en una sala técnica, con embarrado de cobre, magnetotérmicos en carril DIN y cableado de potencia
8 min read

Colocation is no longer negotiated in U: it is negotiated in kW

In the first half of 2026, AI cloud providers signed 420 MW of colocation capacity in Europe. In the same period a year earlier they signed 89. Powered land in the big markets costs 82% more than in 2021. None of that raises your invoice tomorrow, which is exactly why it is worth looking at today: what changes is not the price of a rack unit, it is what your contract actually measures.

Sala de servidores en penumbra con un armario de red abierto y una etiqueta de inventario despegada colgando de un cable
7 min read

Your documentation is lying to you. And so are your validations

A document does not age: it expires, and it does so silently. Markdown cannot tell the difference between what you checked, what can be checked, and what you assumed, so six months later all three read the same. We tell the real case that led us to build validated-memory: evidence states, supersession without deletion, and freshness probes with three answers instead of two. Released as open source under Apache-2.0.

Puesto de trabajo vacío de noche en una oficina pequeña: portátil cerrado, teclado mecánico, taza fría y flexo encendido
10 min read

Five days, an issue title and a Jira token

On 17 August Wiz described how it pulled a Jira token out of Snowflake by opening an issue on a public repository: the issue title was the exploit. The line that allowed it had gone in five days earlier, in a change meant to tidy the code up, and it replaced the safe pattern that GitHub's own documentation recommends in writing. What failed in the review chain, why the "if" that looked like a filter filtered nothing, and what we look at in a pipeline.

Paso fronterizo vacío con la barrera levantada: la frontera de datos europea sigue dibujada y el tráfico pasa igual
8 min read

Three settings decide whether Claude processes your documents in Copilot, and one was decided by your tenant's creation date

Microsoft turned Anthropic models on by default in Microsoft 365 Copilot, but not in the EU. There are three separate settings with three different defaults, one of them depends on whether the tenant was created before or after 25 March 2026, and Microsoft's own documentation sends you to the Message Center to find out yours. What each source says, what cannot be inferred from them, and the twenty-minute review.

CVE-2026-9198 en Langflow entra en el catálogo KEV de CISA el 4 de agosto de 2026: la capa de IA y automatización autoalojada (Langflow, n8n, Open WebUI) tratada como producción
8 min read

The AI pilot nobody switched off is already production

On 4 August, CISA added a 9.8 in Langflow to its exploited-vulnerabilities catalogue: one endpoint that hands superuser tokens to anyone who reaches the port, chained with another that runs whatever code you send it. The patch had been out for six weeks. It is not an isolated case: in Open WebUI the ENABLE_CODE_EXECUTION=false switch turned nothing off, and in n8n anyone who could edit a workflow could run commands on the host. Three products, the same starting assumption. What we do with the AI and automation layer, and when we recommend not self-hosting it at all.

El AI Act ya aplica desde el 2 de agosto de 2026: qué obligaciones entraron de verdad, qué aplazó el Ómnibus digital sobre IA y el checklist de inventario de everyWAN
8 min read

The AI Act already applies to you — and not for the reason the headlines gave

On 2 August the bulk of the EU AI Act became applicable. Six days earlier, the Digital Omnibus on AI (Regulation EU 2026/1744, in force since 27 July) pushed high-risk obligations to December 2027 and August 2028. What does apply from 2 August is Article 50 — transparency — with fines of up to €15M or 3% (the lower amount for SMEs) and a date almost nobody wrote down: 2 December 2026. What actually changed, where Article 25 really bites, and the inventory checklist we run on a Microsoft 365 tenant.

Google corrige 1.072 fallos de seguridad de Chrome con agentes de IA y pasa a publicar un hito cada dos semanas
8 min read

Google fixed 1,072 Chrome bugs with AI: the bottleneck is now you

Chrome 149 and 150 fixed 1,072 security bugs, more than the previous 23 releases combined, with AI agents that find, reproduce, triage and patch. But the number is not the story: Chrome is moving to a milestone every two weeks and piloting two security releases a week. What really changes in your patch cycle, why counting CVEs no longer measures anything, and which of your software will never get this treatment.

Antenas de radiotelescopio al anochecer: la adolescencia tecnológica de la humanidad según el ensayo de Dario Amodei
12 min read

The adolescence of technology: reading Dario Amodei's essay with our hands in the mud

In January 2026 the CEO of Anthropic published a twenty-two-thousand-word essay on the five risks of powerful AI and on whether we are ready for them. His answer is no. We read the whole thing from inside a company that deploys automation and AI on real infrastructure: the five risks laid out, an honest scorecard, the four points where we do not buy his argument — including one almost nobody has reported correctly — and what a company that does not build models should be doing today.

Proxmox VE entra en el ecosistema de NVIDIA Mission Control: qué cambia de verdad para tu infraestructura
7 min read

Proxmox joins NVIDIA's ecosystem: a logo will not migrate your infrastructure

Today Proxmox Server Solutions announced it is joining the NVIDIA Mission Control ecosystem: Proxmox VE as the virtualisation and high-availability layer beneath the management services of AI factories, with engineering work for the Grace and Vera CPUs. What the announcement actually says, where Proxmox sits in that picture and where it does not, and why an announcement changes the conversation in a boardroom but changes none of the things that decide your migration.

Una IA autónoma automatiza la post-explotación en un ataque real; la respuesta es detección 24/7
8 min read

The tireless intern now works for the other side: an autonomous AI is already automating real attacks

In an intrusion at Thailand's Ministry of Finance, the attacker left an open-source AI agent running unattended to automate the boring part of the attack: enumerate, escalate privileges, find the next step. It broke nothing new —it got in through default credentials and unpatched 2021 CVEs— but it did the dirty work faster and without rest. What actually changes is speed, and the only answer to speed is 24/7 detection and response.

FakeGit
7,600 fake repos; your AI is the target
8 min read

Malware no longer fools you: it fools your AI. FakeGit and its 7,600 fake GitHub repositories

The FakeGit campaign seeded GitHub with 7,600 fake repositories; roughly 200 of them alone account for over 14 million malware downloads. The news isn't the volume: more than 800 posed as MCP servers and AI skills, and the assistants recommended them on their own. It has a name now: agentbaiting.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN