Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Muro de ladrillo con la publicidad pintada de un comercio que ya no existe: el nombre sigue ahí mucho después de que el negocio cerrara
8 min read

An expired .es is released in ten days. A .com can give you eighty

Infoblox published on 13 August that around 65,000 expired domains were re-registered every day during the first half of 2026: nearly 20% of all the registrations they observe. A .com calendar gives you room —up to 45 days of auto-renew grace and 30 of redemption. A .es one does not: ten days after expiry it is cancelled and available again, with no redemption, and only the administrative or billing contact can request the renewal. What the catcher is buying, what still points at that name once it is no longer yours, and when there is nothing to renew.

Cuadro eléctrico con filas de interruptores automáticos: apagar cosas una a una antes de que pase lo importante
8 min read

DeadLock does not break your antivirus: it stops it like any other service

On 10 August Microsoft published its breakdown of the DeadLock encryptor. The interesting part is not the cryptography: it is the list of things it switches off before encrypting anything. Defender stopped like a service, shadow copies gone, domain controller services halted and — this is the one almost nobody looks at — event log channels not cleared but disabled in the registry.

Terminal de contenedores nevada con grúas portuarias y miles de contenedores apilados: la cadena de suministro por la que viaja el código que instalas
8 min read

ChainDrop: 444 npm packages compromised and not a single patch to apply

On 4 August, between 09:35 and 13:20 UTC, a worm spread by itself across 444 npm packages, stealing the credentials it needed to keep spreading. The first malicious version went out through the legitimate pipeline, carrying a valid provenance signature. And there is a trap that inverts the correct reflex: revoking the stolen token is exactly what fires the next payload. What to look for in your lockfiles, in what order to rotate, and why there is no fixed version to install here.

Un MacBook abierto visto desde arriba sobre un escritorio con una libreta y un lápiz: el equipo de trabajo donde alguien pega un comando dictado por una web
8 min read

The macOS malware that exploits nothing: you paste it in yourself

On 6 August, Huntress published its analysis of a Go-based credential stealer for macOS that had been sitting inside a monitored Mac for three months. There is no CVE, no exploit and nothing to patch: the chain starts with a web page dictating a command and a user pasting it into Terminal. What that command does line by line, why Gatekeeper never gets involved, what it actually takes from a company (Keychain, session cookies, browser passwords) and why the warning Apple added in macOS 26.4 is a speed bump rather than a wall.

Cl0p extorsiona sin cifrar: campaña contra PTC Windchill y FlexPLM
7 min read

Cl0p didn't encrypt a single file: extortion walks in through the app nobody watches

Cl0p is exploiting a critical vulnerability in PTC Windchill and FlexPLM (CVE-2026-12569, CVSS 9.3) to steal engineering data and extort without encrypting anything. The patch had existed since June 17; the wave of extortion emails arrived a month later. Why your backups can't undo a theft, what the Accellion→MOVEit→Oracle EBS pattern teaches (2,700+ organizations in a single campaign), and the five things we would do this week.

FakeGit
7,600 fake repos; your AI is the target
8 min read

Malware no longer fools you: it fools your AI. FakeGit and its 7,600 fake GitHub repositories

The FakeGit campaign seeded GitHub with 7,600 fake repositories; roughly 200 of them alone account for over 14 million malware downloads. The news isn't the volume: more than 800 posed as MCP servers and AI skills, and the assistants recommended them on their own. It has a name now: agentbaiting.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN