Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Sala de reuniones vacía con las sillas recogidas: en agosto la alerta salta igual, pero la sala donde se decide está cerrada
8 min read

Three days to patch, and the third one lands on a Saturday

Since CISA changed its deadlines on 10 June, 42 of the 48 vulnerabilities it has added come with three days to fix them. We counted the weekdays over the catalog file itself: not a single 2026 entry was published on a Saturday or Sunday, and thirteen of those three-day deadlines expire exactly there. In August, with half the staff away, the bottleneck is who signs off that a server can be isolated at three in the morning.

CVE-2026-34486 en Apache Tomcat: el EncryptInterceptor procesaba los mensajes del clúster aunque fallara el descifrado, un control de seguridad que falla abriendo
8 min read

If decryption fails, the message goes through anyway

The fix for the Apache Tomcat vulnerability CISA flagged as exploited on 4 August fits in a single line of code moved somewhere else. For two weeks, if decryption of a cluster message failed, Tomcat logged the error and processed the message anyway. And only 11.0.20, 10.1.53 and 9.0.116 were affected: precisely the versions carrying the patch for the previous flaw. What it means for a control to "fail open", why the log was the only signal, and what we check.

Nueve entradas del catálogo KEV de CISA en 2026 apuntan al plano de gestión de una red SD-WAN
8 min read

Your SD-WAN doesn't go down: it gets reconfigured

Of the 172 vulnerabilities CISA has flagged as exploited so far in 2026, nine point at the same place: the management plane of an SD-WAN. And the attacker Mandiant documented inside a Catalyst SD-WAN Manager took nothing down: they registered as a peer, copied the fabric's configuration templates through the product's own API and wiped their tracks. The numbers are our own count over the KEV catalogue, including the only two entries all year with a 48-hour deadline. What to look at when the attack looks like a legitimate configuration change and your monitoring stays green.

Zabbix 8.0: análisis de qué cambia de verdad en la próxima LTS de monitorización
8 min read

Zabbix 8.0: what actually changes and what is still a slide

Zabbix 8.0 is the next LTS and half the industry already writes about it as if it were installed. As of 30 July 2026 the latest published artefact is beta 2, dated 9 July, and in the official container registry 8.0 is called trunk. Which features are really in the official release notes (native JSON up to 128 MiB, ClickHouse as a history backend, c-ares with DNS caching), what is still only roadmap (OpenTelemetry, complex event processing, mobile app, proxy permissions) and where the real bill for the upgrade sits: the database minimums and the removed macros living inside your alerts.

Fatiga de alertas: cómo montar una monitorización que avisa de lo que importa
8 min read

Your monitoring is not broken: it is shouting

An organisation receives an average of 2,992 security alerts a day and 63% of them go unaddressed, according to Vectra AI's 2026 count. The interesting part is that the volume has been falling for three years and the unaddressed share has not moved. Filtering harder does not fix it, because the problem was never how many alerts arrive: it is how many arrived with an owner and an action written next to them. How we prune monitoring that shouts, what wakes us at three in the morning, and what waits for the morning report.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN