Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Rack de una pequeña oficina con panel de parcheo, latiguillos y equipos de red apilados
9 min read

The AI agent will not show up in your log: whoever lent it the token will

Connecting an assistant to SharePoint or the ERP is not an integration decision, it is a delegation decision. The Model Context Protocol specification, revision 2026-07-28, forbids forwarding somebody else's token in capital letters, and spells out why: the destination system's logs will show a different identity from the one that made the request. We go through the spec, the permission fallback that asks for everything on offer, the CVE in the official SDK, and the seven questions we ask before connecting anything.

Fila de puestos de trabajo vacíos en una oficina
10 min read

Entra ID retires memberOf on 3 November: after that date, membership stops being recalculated

Message centre post MC1448379, published on 5 August, has been read as a deadline. Read it the other way round: if you run a memberOf rule in production, you already have the problem it describes, and the preview documentation says so in a paragraph almost nobody reads. What happens on 3 November is not an outage or an error: memberships stay "in their last known state". That is where licences, Conditional Access and Teams membership hang from.

Mesa de soporte de una oficina con un teléfono fijo de sobremesa, una libreta de anillas, un cordón con llaves y un teclado apartado a un lado
9 min read

The phone number on the record was a credential: Entra ID stops accepting it

Microsoft's own documentation has said it plainly for years: if you fill in a user's mobile phone or alternate email, that user can reset their password immediately "even if they haven't registered for the service". Which means a field written by a sync or by an admin worked as proof of identity. Entra ID is about to stop accepting it. What changes, why the 86% everyone quotes does not mean what it looks like, and the four different dates Microsoft gives for the same cutoff.

Cartel de «se busca» con el alias CyberLeek sobre una ciudad nocturna y las etiquetas de los datos reclamados: IP, identificador de dispositivo, cuenta de Microsoft, OneDrive y Discord
8 min read

GTA 6, CyberLeek and MachineGuid: the digital trail your company leaves too

To find whoever is leaking GTA 6 material, on 20 August 2026 Take-Two filed two DMCA subpoenas asking Microsoft and Discord for the MachineGuid, MSA device identifiers, IP addresses, phone numbers, linked connections and OneDrive contents of every account in three servers. What MachineGuid is, why it identifies the device rather than the account, and why your company generates exactly the same trail every working day.

Custom controls de Acceso Condicional: el MFA de terceros que Entra no cuenta como MFA
9 min read

Custom controls: the third-party MFA that Entra does not count as MFA

The Microsoft Learn page on Conditional Access custom controls lists eight things that control cannot do, and the third is satisfying the MFA claim requirement. It is no good for PIM role elevation, device enrollment, SSPR, sign-in frequency or cross-tenant trusts either. From September 2026 they can no longer be created or edited, and "editing" means deleting and creating again. With the Graph query to find out whether you have one.

Cuadro eléctrico general abierto en un cuarto de instalaciones, con filas de magnetotérmicos colgando todos de un mismo interruptor principal
8 min read

Six Microsoft 365 services went down together. For your continuity plan they are one

On Monday 31 August, incident EX1464935 on Exchange Online ended up as MO1465074, with OneDrive, SharePoint Online, Teams, Purview and Defender XDR inside it. Six names, one shared authentication configuration underneath. We go through the hours —including the ones BleepingComputer and Computerworld disagree on, which we say rather than picking one—, why nobody has confirmed the expired-certificate story, and the dependency almost nobody will look at: the security console and the audit layer were inside the thing that had gone down.

Armario metálico de llaves abierto en la pared de un cuarto de instalaciones, con decenas de llaves colgadas juntas
11 min read

136 keys in one object: the defaults that opened the cluster

Hugging Face published the forensic timeline of the July intrusion and OpenAI closed its report on 26 August: 17,600 reconstructed actions between the 9th and the 13th. Between the first compromised container and the object holding 136 keys there was not one further vulnerability — there were defaults. The token every pod mounts, the metadata endpoint that answers from inside, secrets concentrated in one object, and a connector credential shared across clusters. We walk the chain with the timestamps in front of us, the two CVEs CISA added to its catalogue on 27 August, and the five questions we ask a cluster.

Sala de reuniones vacía con seis portátiles cerrados sobre la mesa y cargadores enredados
8 min read

The warning came from Anthropic, not from your antivirus

On 30 August it emerged that Anthropic was warning Claude users that an infostealer had taken their browser session. Coverage treated it as an AI story. If somebody at your company got that email, it is something else: it is an infection report for a machine in your estate, signed by a supplier that is not yours and spotted through billing. We go through why MFA never even enters the picture, the five critical events that do cut a session in Microsoft Entra and the one missing from that list, the real arithmetic of revocation (1 hour, 28 hours, up to 15 minutes of latency, up to a day for a group change) and where the purpose-built defence against token theft stands today: in preview precisely in the browser, which is where this happened.

Mesa de oficina con un portátil cerrado, una llave de seguridad USB en un llavero y un teléfono móvil boca abajo
8 min read

Passkeys on 1 September: the cases that do not fit

In July we went through the timeline for the retirement of SMS and voice in Microsoft Entra ID. Five days after that post Microsoft published a FAQ, and there are now forty-eight hours to go until the first date. This is the run-through of what is still unanswered: the FAQ's "No" to the lockout question and what it says three lines further down, the self-service password reset that goes with the same move, the declared gap for B2B guests, the break-glass accounts the documentation never mentions, and why the temporary opt-out switch, which lives on the Graph beta endpoint, is not the answer we would give.

Portal de un edificio antiguo con una única puerta acristalada, el portero automático y los buzones metálicos
8 min read

Your identity provider is not an application: it is infrastructure

On Monday 24 August, at 03:38, a denial-of-service attack began against Norway's shared government digital platform. Ten public services went down and several had nothing wrong with them: the door everyone goes through had jammed. Digdir writes on its status page that <code>eSignering</code> was unavailable "because of the limitations in ID-porten", and also that the services were "stable with the limitations that have been put in place" — part of the outage was put there by the defenders. Why single sign-on is still the right call, what changes when the door becomes infrastructure, and the three questions that reclassify it.

Jaula de rejilla metálica cerrada con candado en una sala de datacenter compartida, con dos racks de servidores detrás
6 min read

The patch that isn't yours: what to do with Entra ID's CVE-2026-69836

On 20 August Microsoft published a critical remote code execution flaw in Entra ID, and the next day corrected the exploitation field to "No". There is nothing to install: the record says "customerActionRequired: false". What is yours is the ability to answer "were we affected?", and on an Entra ID Free licence that lasts seven days. How to read the record from Microsoft's own API, and the checklist we apply to the tenant.

Percha de pared en la entrada de personal de una oficina con decenas de tarjetas de acceso colgadas de cordones y varios ganchos vacíos
8 min read

The directory holds more records than the company has employees

McDonald's reports just over 150,000 employees in its annual filing. The batch of its corporate directory put up for sale this week holds 1.7 million records. We placed the leaked counts next to the declared headcounts of seven companies, and the result is not a story about carelessness: it is about what a Microsoft Entra ID directory actually contains, who can read all of it with any ordinary password, and why the switch that closes it is one the vendor itself advises against touching.

Centralita telefónica manual con hileras de interruptores etiquetados a mano: apagar uno era rápido; saber qué línea dejaba muda, no
9 min read

The report says "zero impacts", and that does not mean nobody uses it

Baseline Security Mode puts twenty-one settings in the Microsoft 365 admin center that used to live only in PowerShell: switching off basic authentication, EWS, ActiveX, IDCRL, Publisher. Microsoft's guidance says to turn each one on when its impact report comes back at zero. The detail that changes the reading: the Office app settings are delivered through Cloud Policy, and Windows clients below version 2510 do not send the simulation mode telemetry that feeds that report. What each switch turns off, what actually breaks when you close EWS, and the order we do it in.

Cajones de un fichero de biblioteca con sus portaetiquetas vacíos: el directorio sigue estando en el sitio de siempre y la fuente de autoridad se está moviendo a la nube

Warning: Undefined array key "read_time" in /var/www/html/public/blog.php on line 3576
min read

Entra Connect: the date that stops your sync, and the date that just emails you

On 30 September 2026, any Entra Connect synchronisation running below version 2.5.79.0 stops working. This is not the Cloud Sync migration: it is a separate thing, and it is the only one of the two with a fixed date. The migration runs in waves, allows exceptions and has no announced retirement date. What exactly breaks when sync stops (hint: not email — the offboarding that never reaches the cloud), why auto-upgrade fails to save precisely the servers that need it, and the eight rows in Microsoft's own comparison table that decide whether you can move to Cloud Sync yet.

Operadoras de centralita telefónica atendiendo llamadas: quien decide si reseteas una contraseña sigue siendo una persona al otro lado del teléfono
8 min read

Nobody exploited anything: who verifies it is you before resetting your MFA

Sounding convincing is not proof of identity, and in many organisations it is the only thing asked for. On 7 August Levi Strauss told the SEC that corporate information was taken from three company computers through social engineering: the work we use to measure security — patch, update, reboot — would have changed nothing. The joint CISA and FBI advisory on Scattered Spider says the targets are large companies and their contracted IT help desks, and that includes us. Why 65% of initial access now arrives through identity, why passkeys will not save you if the desk can enrol a new factor, and the eight things we ask of a reset procedure.

Pass-ta-key: tres técnicas de Unit 42 contra las passkeys sincronizadas de Google Password Manager en Chrome sobre Windows, incluida la extracción del secreto de 32 bytes que las descifra todas
8 min read

Your passkey isn't broken — the master key gets copied

On 3 August, Unit 42 published three ways into passkey-protected accounts without breaking a single line of cryptography. The worst of them lifts a 32-byte secret out of Chrome's memory that decrypts every passkey synced to the account — and in Google's current implementation that secret cannot be rotated or revoked. All three start the same way: with malware already running on a Windows machine, with no administrator rights and no privilege escalation. We still recommend passkeys, and this post explains why that is not a contradiction.

Más de 700 organizaciones afectadas por el robo de tokens OAuth de una aplicación conectada, sin ninguna contraseña robada
8 min read

The token that never asks for MFA: connected apps in your Microsoft 365

More than 700 organisations were potentially exposed in August 2025 without a single password being stolen: the attacker took the OAuth tokens of an application they had connected themselves. On 13 July 2026 Microsoft published the map of a full year of that technique: two attack chains and not one suspicious sign-in. The part that fails is not the login, it is consent: how to inventory the applications connected to your tenant with two Graph queries, what each button actually switches off, and why changing the consent setting revokes nothing already granted.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN