Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Armario de comunicaciones de pared en una sala técnica, con un servidor de rack, un pequeño cortafuegos y un panel de parcheo con latiguillos naranjas y grises
7 min read

"Exploitation Less Likely": 126 days in the queue for CVE-2026-33824

Microsoft patched the Windows IPsec VPN flaw on 14 April with the label "Exploitation Less Likely". CISA added it to its exploited catalogue on 18 August. Between those dates sit 126 days, a Unit 42 report, and a vendor page that still has not been corrected. Our own count across Microsoft's 24 KEV entries this year, and which mitigation you cannot apply if your VPN carries remote workers.

Percha de pared en la entrada de personal de una oficina con decenas de tarjetas de acceso colgadas de cordones y varios ganchos vacíos
8 min read

The directory holds more records than the company has employees

McDonald's reports just over 150,000 employees in its annual filing. The batch of its corporate directory put up for sale this week holds 1.7 million records. We placed the leaked counts next to the declared headcounts of seven companies, and the result is not a story about carelessness: it is about what a Microsoft Entra ID directory actually contains, who can read all of it with any ordinary password, and why the switch that closes it is one the vendor itself advises against touching.

Mesa de una oficina administrativa a última hora: archivadores de anillas, una calculadora de sobremesa y un archivador metálico con un cajón abierto
8 min read

5% more for paying monthly: what changes on 1 October, and when not to switch

From 1 October 2026 Microsoft will add a 5% uplift to CSP software subscriptions on annual terms billed monthly: it names Windows Server, SQL Server, CALs and System Center, and leaves the list open. The product does not change; the price of money does. The full arithmetic — that 5% works out at borrowing at roughly 11% a year — why your date is not 1 October but each line's renewal date, and the cases where moving is not worth it.

Centralita telefónica manual con hileras de interruptores etiquetados a mano: apagar uno era rápido; saber qué línea dejaba muda, no
9 min read

The report says "zero impacts", and that does not mean nobody uses it

Baseline Security Mode puts twenty-one settings in the Microsoft 365 admin center that used to live only in PowerShell: switching off basic authentication, EWS, ActiveX, IDCRL, Publisher. Microsoft's guidance says to turn each one on when its impact report comes back at zero. The detail that changes the reading: the Office app settings are delivered through Cloud Policy, and Windows clients below version 2510 do not send the simulation mode telemetry that feeds that report. What each switch turns off, what actually breaks when you close EWS, and the order we do it in.

Pasillo de un archivo lleno de cajas y carpetas: el SharePoint local de una empresa guarda sus documentos igual, y desde el 14 de julio ya no recibe arreglos
8 min read

Your SharePoint 2016 got its last patch on 14 July

CVE-2026-55040 lets an attacker with no credentials impersonate any user or administrator of an on-premises SharePoint. Microsoft fixed it on 14 July 2026: exactly the day SharePoint Server 2016 and 2019 went out of support. The proof of concept went public on 12 August and was seen in use the same day, but KEVintel's sensors date the first attempt to 19 July, twenty-four days earlier. Why asking whether it should have been published is the wrong argument, and what to check today on a server that will not receive any more fixes.

Sala de centralita telefónica con operadoras conectando llamadas: el servicio que resuelve nombres y por el que pasa todo el mundo
8 min read

The DNS server you have to patch is your domain controller

CVE-2026-62878 scores 9.8: a stack-based buffer overflow in Windows DNS, no authentication and no user interaction. Microsoft's bulletin lists sixteen affected products and all sixteen require a reboot. In many of the networks we come across, that machine is also the one validating everybody's passwords, which is why it hasn't been rebooted in months — sometimes years. What the bulletin actually says, what goes down while it boots, and the checks we run before the window.

Paso fronterizo vacío con la barrera levantada: la frontera de datos europea sigue dibujada y el tráfico pasa igual
8 min read

Three settings decide whether Claude processes your documents in Copilot, and one was decided by your tenant's creation date

Microsoft turned Anthropic models on by default in Microsoft 365 Copilot, but not in the EU. There are three separate settings with three different defaults, one of them depends on whether the tenant was created before or after 25 March 2026, and Microsoft's own documentation sends you to the Message Center to find out yours. What each source says, what cannot be inferred from them, and the twenty-minute review.

Fichero de archivo de madera con un cajón abierto lleno de tarjetas catalogadas: dónde vive de verdad cada documento y quién puede abrir el cajón

Warning: Undefined array key "read_time" in /var/www/html/public/blog.php on line 3212
min read

That recording lives in the OneDrive of someone who no longer works here

At the end of September, Microsoft moves whiteboards created in Teams channels out of the creator's OneDrive and into the channel's SharePoint site. It is a small change that concedes a large problem: much of a company's collective work lives inside one individual's personal account. Where each recording actually lands, why the deletion clock starts the day you delete the account rather than the day the person leaves, and why leaving the account blocked "just in case" is not the plan you think it is.

Cajones de un fichero de biblioteca con sus portaetiquetas vacíos: el directorio sigue estando en el sitio de siempre y la fuente de autoridad se está moviendo a la nube

Warning: Undefined array key "read_time" in /var/www/html/public/blog.php on line 3212
min read

Entra Connect: the date that stops your sync, and the date that just emails you

On 30 September 2026, any Entra Connect synchronisation running below version 2.5.79.0 stops working. This is not the Cloud Sync migration: it is a separate thing, and it is the only one of the two with a fixed date. The migration runs in waves, allows exceptions and has no announced retirement date. What exactly breaks when sync stops (hint: not email — the offboarding that never reaches the cloud), why auto-upgrade fails to save precisely the servers that need it, and the eight rows in Microsoft's own comparison table that decide whether you can move to Cloud Sync yet.

Primer plano de papel triturado con restos de texto: el recall en la nube borra el mensaje del buzón del destinatario, y ahora podrá ordenarlo otra empresa
8 min read

Cross-tenant recall: Exchange Online lets another company delete mail from your mailboxes

In mid-August Microsoft starts rolling out cross-tenant message recall in Exchange Online (MC1423106). It ships switched off, and you do not turn it on to recover your own emails: you turn it on so senders in another tenant can delete messages already delivered to your people's mailboxes. What cloud recall does today (hard delete, read messages included, retrying for up to 24 hours), why the allow list looks far too much like the list of domains invoice fraud uses, what actually protects you (retention, not the checkbox), and the logging gap almost nobody has read.

El AI Act ya aplica desde el 2 de agosto de 2026: qué obligaciones entraron de verdad, qué aplazó el Ómnibus digital sobre IA y el checklist de inventario de everyWAN
8 min read

The AI Act already applies to you — and not for the reason the headlines gave

On 2 August the bulk of the EU AI Act became applicable. Six days earlier, the Digital Omnibus on AI (Regulation EU 2026/1744, in force since 27 July) pushed high-risk obligations to December 2027 and August 2028. What does apply from 2 August is Article 50 — transparency — with fines of up to €15M or 3% (the lower amount for SMEs) and a date almost nobody wrote down: 2 December 2026. What actually changed, where Article 25 really bites, and the inventory checklist we run on a Microsoft 365 tenant.

La nueva retención por último acceso de Microsoft Purview borra ficheros de SharePoint y OneDrive y deja 93 días de papelera como único margen
7 min read

What nobody opens gets deleted: Purview, last accessed, and the 93 days to notice

By mid-August 2026 Microsoft finishes rolling out a Purview retention rule that deletes SharePoint and OneDrive files nobody has opened for a given period, justified on the grounds that Copilot will answer better. It deletes nothing on its own: somebody has to configure it. But it is the first deletion trigger that measures not a property of the document but the absence of human activity, and the file nobody opens in three years may well be the one you need in year four. What is actually shipping, the 93 recycle-bin days that are your only margin, why version history will not save you, and what we would do before touching that button.

Más de 700 organizaciones afectadas por el robo de tokens OAuth de una aplicación conectada, sin ninguna contraseña robada
8 min read

The token that never asks for MFA: connected apps in your Microsoft 365

More than 700 organisations were potentially exposed in August 2025 without a single password being stolen: the attacker took the OAuth tokens of an application they had connected themselves. On 13 July 2026 Microsoft published the map of a full year of that technique: two attack chains and not one suspicious sign-in. The part that fails is not the login, it is consent: how to inventory the applications connected to your tenant with two Graph queries, what each button actually switches off, and why changing the consent setting revokes nothing already granted.

EWS en Exchange Online: la fecha límite real para escribir la lista de aplicaciones permitidas es el 31 de agosto de 2026
8 min read

EWS shuts down in October, but your deadline is 31 August

On 1 October Exchange Online starts disabling EWS, and on 1 April 2027 it disables it for good, with no re-enablement. But one detail turns the calendar on its head: from October, leaving EWSEnabled set to True with an empty allowed-application list starts to mean "block everything", and if you do not write that list before the end of August, in September Microsoft writes it for you based on whatever it saw running. What to look at in the usage report, the exact commands, why that automatic list fails both by omission and by excess, and the gaps Graph still does not cover according to Microsoft's own roadmap.

El peaje del ESU de Windows 10: el precio se duplica cada año y es acumulativo
8 min read

Windows 10 and the October toll: ESU doubles every year and you cannot skip year one

Microsoft charges $61 per device for the first year of Windows 10 extended security updates, and its own documentation says two things almost nobody puts together: the price doubles every consecutive year and ESUs are cumulative, so enrolling in year three means paying for all three. Delaying enrolment does not reduce the bill if you end up enrolling: it shifts the payment and leaves you without patches while you wait. The full math, the three blind spots that cost real money (the 2027 headline is not about your company, LTSC is not covered, and Office lives on until 2028 but you can no longer log a bug) and when paying for ESU really is the right call.

La subida de precios de Microsoft 365 del 1 de julio de 2026, con la cuenta real por usuario
8 min read

Microsoft 365 has already gone up: the percentage that scares you is not the one that costs you money

On 1 July the price increase for Microsoft 365 commercial suites came into force. Through June everyone repeated the same advice —renew before the 1st and you freeze your price— and that advice expired four weeks ago. The official before-and-after price table, the math that actually matters (per-user increase multiplied by headcount and by twelve), why the price that does NOT change is the most informative figure in the announcement, which capabilities land in each suite, and the five things we would do before your renewal.

CVE-2026-14266 en 7-Zip: por qué en la mayoría de los PCs de empresa el mejor parche es desinstalarlo
6 min read

The best patch for 7-Zip is uninstalling it (on most of your PCs)

CVE-2026-14266 is a heap overflow in 7-Zip's XZ decoder: it affects version 21.07 and every release up to 26.01. With no public exploit and no known exploitation, it is not an emergency. But that is two code-execution flaws in two months, the program updates by hand, and Windows 11 has opened .7z and .rar natively since 2023. Before updating two hundred machines, it is worth checking how many actually need it.

Secuestro de DNS en Wi-Fi de hoteles para robar cuentas de Microsoft 365
7 min read

The hotel Wi-Fi works for someone else: DNS hijacked to steal Microsoft 365 accounts

Since June 2026 an active campaign has been compromising captive portals at hotels and conference centers, changing their DNS and redirecting guests to fake Microsoft 365 pages. The refined part: by abusing the device code flow they take your account without stealing your password, with MFA "satisfied". What is happening, why the padlock won't save you, and what we would do: from full-tunnel VPN to blocking the device code flow.

Certighost (CVE-2026-54121): impersonar un Domain Controller vía AD CS
8 min read

Certighost: any user could become your Domain Controller. The question isn't whether you patched, it's whether you've audited your AD CS

Certighost (CVE-2026-54121) let an unprivileged domain user impersonate a Domain Controller via Active Directory Certificate Services and take over the entire domain. Microsoft patched it on July 14; a working PoC has been public since July 24. The mechanism in one sentence, why AD CS is the escalation surface almost nobody audits, and the plan for today: patch, inventory your CAs, machine account quota to zero, and audit templates.

Microsoft retira el SMS como MFA en Entra ID: passkeys por defecto
7 min read

Microsoft SMS MFA end of life: Entra ID stops sending texts in February 2027

On July 13 Microsoft announced that Entra ID will stop providing SMS and voice calls as an authentication method: passkeys by default from September 1 and full retirement on February 1, 2027, with no opt-out. Anyone insisting on SMS will have to contract and pay their own telecom provider. The full timeline, why SMS was never a serious second factor, and the plan we would apply to any tenant.

  • 1
  • 2

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN