Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Filas de puestos con ordenadores en una sala vacía; solo una pantalla encendida
8 min read

Four EDRs and no alerts: what are you left with

On 6 July, two SensePost researchers published a code injection technique and tested it against four market-leading EDRs configured to detect, block and remediate: it worked on all four and no alerts were created. On 22 September, Flashpoint reproduced it. The technique does not write into another process's memory —the path every EDR has watched for a decade— but instead places the payload into the parameters a new process starts with. We read both publications in full, including the part the headlines skipped: in Flashpoint's lab the XDR component DID block, and only stopped once two further evasions were stacked on top; and the authors themselves warn the technique "has multiple opportunities for detection". Also: why this is post-exploitation and not a way in, why the same primitive had already been described publicly before (with no known date), the four checks you can ask your console for this week —and the catch that none of them is a button, but a query over telemetry someone has to have kept and someone has to write—.

Pasillo entre armarios de servidores en penumbra, con centenares de indicadores luminosos encendidos a la vez
7 min read

Retry storms: the second outage is the one you cause

On 12 June 2025 Google Cloud went down hard. 40 minutes in, the mitigation had been rolled out and regions started to recover, the smaller ones first; us-central1 was not fully resolved until 2 h 40 min after the incident began. What stretched that region was not the bug: it was the retries. The public incident report says it plainly —"Service Control did not have the appropriate randomized exponential backoff implemented to avoid this"— and describes a herd effect on the Spanner table everything depended on. Here we cover where that same mechanism lives in an ordinary company (the cron job that takes longer than its interval, the overlapping backup, the sixty desktops booting at once when the power comes back, the monitoring that pushes hardest when it hurts), why three retries across three layers mean 64 attempts against your database, the four numbers you need written down, and when NOT to touch anything.

Pasillo de un archivo con estanterías compactas llenas de cajas de archivo numeradas
9 min read

The first AI-agent breach is on file. The hard part was being able to describe it

On 14 September the Spanish data protection authority published that it had received the first notification of a personal data breach that "would have been executed by means of an artificial intelligence agent" — its own conditional. The whole attack fits in one sentence, and the authority warns the information comes from the affected organisation and is still pending analysis. We read those four phases as what they will eventually be for somebody else: a regulator's form with a 72-hour clock on it. Which record you need to write each sentence, why "autonomously" is inferred rather than logged, what the authority now expects in writing in your risk assessment, and why three of the four phases are stopped by boring things that involve no AI at all.

Puesto de monitorización vacío de noche, con los dos monitores apagados, unos auriculares sobre la mesa y la silla apartada
9 min read

The agent says SECURE and your console has received nothing for days

At DEF CON 34, Akamai showed how to turn a commercial EDR into the attacker's hiding place. The least-reported part is the ending: one line in the hosts file cuts off all telemetry while the agent still shows "SECURE". The signal you watch is controlled by the endpoint; the only one an attacker cannot fabricate is silence in your console. And almost nobody alerts on it.

Cartel de «se busca» con el alias CyberLeek sobre una ciudad nocturna y las etiquetas de los datos reclamados: IP, identificador de dispositivo, cuenta de Microsoft, OneDrive y Discord
5 min read

GTA 6, CyberLeek and MachineGuid: the digital trail your company leaves too

To find whoever is leaking GTA 6 material, on 20 August 2026 Take-Two filed two DMCA subpoenas asking Microsoft and Discord for the MachineGuid, MSA device identifiers, IP addresses, phone numbers, linked connections and OneDrive contents of every account in three servers. What MachineGuid is, why it identifies the device rather than the account, and why your company generates exactly the same trail every working day.

Plan de continuidad sin ensayar: un servidor sacado a medias del rack con los cables de alimentación desenchufados
9 min read

A continuity plan nobody has rehearsed is a document, not a plan

Uptime Institute's May 2026 annual outage analysis says the leading driver of outages with human error behind them is still failing to follow procedures that were already established. Established: the document existed. And 87% of those who suffered an impactful outage believe it could have been prevented with better management, processes or configuration — seven points more than in 2024. What is missing, what a drill that works looks like, and when you should NOT run one.

Cuadro eléctrico general abierto en un cuarto de instalaciones, con filas de magnetotérmicos colgando todos de un mismo interruptor principal
5 min read

Six Microsoft 365 services went down together. For your continuity plan they are one

On Monday 31 August, incident EX1464935 on Exchange Online ended up as MO1465074, with OneDrive, SharePoint Online, Teams, Purview and Defender XDR inside it. Six names, one shared authentication configuration underneath. We go through the hours —including the ones BleepingComputer and Computerworld disagree on, which we say rather than picking one—, why nobody has confirmed the expired-certificate story, and the dependency almost nobody will look at: the security console and the audit layer were inside the thing that had gone down.

Cajón abierto de un fichero de tarjetas de archivo de madera en una sala de oficina, con las fichas de papel apretadas y vistas de canto
5 min read

Some people have not been able to search in Microsoft 365 since Monday. For the SLA, that is not downtime

Incident MO1456424 has been open since Monday 17 August: some Microsoft 365 users get nothing back when they search in SharePoint Online, OneDrive and Outlook. Files still open, mail still flows, and that is why the availability counter does not move. What Microsoft's advisory says word for word, why its SLA definitions of downtime leave exactly this out, and which check you need so that you find out before your users do.

Sala de reuniones vacía con las sillas recogidas: en agosto la alerta salta igual, pero la sala donde se decide está cerrada
5 min read

Three days to patch, and the third one lands on a Saturday

Since CISA changed its deadlines on 10 June, 42 of the 48 vulnerabilities it has added come with three days to fix them. We counted the weekdays over the catalog file itself: not a single 2026 entry was published on a Saturday or Sunday, and thirteen of those three-day deadlines expire exactly there. In August, with half the staff away, the bottleneck is who signs off that a server can be isolated at three in the morning.

CVE-2026-34486 en Apache Tomcat: el EncryptInterceptor procesaba los mensajes del clúster aunque fallara el descifrado, un control de seguridad que falla abriendo
5 min read

If decryption fails, the message goes through anyway

The fix for the Apache Tomcat vulnerability CISA flagged as exploited on 4 August fits in a single line of code moved somewhere else. For two weeks, if decryption of a cluster message failed, Tomcat logged the error and processed the message anyway. And only 11.0.20, 10.1.53 and 9.0.116 were affected: precisely the versions carrying the patch for the previous flaw. What it means for a control to "fail open", why the log was the only signal, and what we check.

Nueve entradas del catálogo KEV de CISA en 2026 apuntan al plano de gestión de una red SD-WAN
5 min read

Your SD-WAN doesn't go down: it gets reconfigured

Of the 172 vulnerabilities CISA has flagged as exploited so far in 2026, nine point at the same place: the management plane of an SD-WAN. And the attacker Mandiant documented inside a Catalyst SD-WAN Manager took nothing down: they registered as a peer, copied the fabric's configuration templates through the product's own API and wiped their tracks. The numbers are our own count over the KEV catalogue, including the only two entries all year with a 48-hour deadline. What to look at when the attack looks like a legitimate configuration change and your monitoring stays green.

Zabbix 8.0: análisis de qué cambia de verdad en la próxima LTS de monitorización
5 min read

Zabbix 8.0 release date, LTS and roadmap: what is real vs still a slide

Zabbix 8.0 is the next LTS and half the industry already writes about it as if it were installed. As of 30 July 2026 the latest published artefact is beta 2, dated 9 July, and in the official container registry 8.0 is called trunk. Which features are really in the official release notes (native JSON up to 128 MiB, ClickHouse as a history backend, c-ares with DNS caching), what is still only roadmap (OpenTelemetry, complex event processing, mobile app, proxy permissions) and where the real bill for the upgrade sits: the database minimums and the removed macros living inside your alerts.

Fatiga de alertas: cómo montar una monitorización que avisa de lo que importa
5 min read

Your monitoring is not broken: it is shouting

An organisation receives an average of 2,992 security alerts a day and 63% of them go unaddressed, according to Vectra AI's 2026 count. The interesting part is that the volume has been falling for three years and the unaddressed share has not moved. Filtering harder does not fix it, because the problem was never how many alerts arrive: it is how many arrived with an owner and an action written next to them. How we prune monitoring that shouts, what wakes us at three in the morning, and what waits for the morning report.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN