Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Batería de torniquetes de acceso vacíos en el vestíbulo de una estación de metro
9 min read

Ingress NGINX: half of Kubernetes was maintained by two people

The kubernetes/ingress-nginx repository is archived read-only and its last release is dated 19 March: 187 days without a new release. This is not neglect, it is a deliberate retirement, and the reason signed by the Kubernetes Steering Committee and Security Response Committee was not a CVE: the component that publishes half of all cloud native environments to the internet was maintained by "one or two people working in their free time". What to check today with one command, why migrating to Gateway API is not translating YAML, and the five behaviours your routing has that nobody chose.

Técnico agachado con un portátil trabajando en la parte trasera de un rack de servidores
5 min read

REPLICATION was never a read-only privilege: PostgreSQL closed a twelve-year dlopen()

On 13 August PostgreSQL shipped 18.6, 17.11, 16.15, 15.19 and 14.24. Among the CVEs they close there is one that is not about buffer overflows: any account holding the REPLICATION attribute could name as its logical decoding plugin any file visible to the system, and the server would load it and run its code as the operating system user. The patch adds a whitelist with two entries by default: if your change data capture uses decoderbufs or wal2json, it stops your replication until somebody edits postgresql.conf.

Sala de archivo de una oficina con estanterías metálicas llenas de cajas de cartón y carpetas, y una caja abierta sobre una mesa de trabajo
7 min read

"The column was encrypted": pgcrypto was storing cleartext and nobody noticed

On 13 August PostgreSQL closed 28 CVEs in one go. One of them is not a buffer overflow: when OpenSSL rejected the requested cipher, pgcrypto never checked the answer and wrote the value into your "encrypted" column with a trivial XOR. Neither the INSERT nor the SELECT failed. What triggers it, why the day it broke was not the day the code was written, and which version you are really running if you install from Debian rather than PGDG.

Chasis de servidor de almacenamiento extraído sobre sus guías en un pasillo de datacenter, con dos filas de discos de 3,5 pulgadas en bandejas metálicas y un destornillador apoyado en el borde
7 min read

Ceph patches four CVEs: the package closes three, the fourth is on you

On 19 August Ceph shipped Squid 19.2.6 and Tentacle 20.2.4 tagged [URGENT]. One of the four flaws is not fixed by installing anything: it forces you to rotate every CephX key in the cluster, ten manual steps, and it leaves the cluster in HEALTH_ERR in the meantime. What is inside each CVE, why anyone holding a "mon allow r" key could read your OSD LUKS passphrases, and what we found today in Proxmox's Ceph repository.

Sala de servidores en penumbra con un armario de red abierto y una etiqueta de inventario despegada colgando de un cable
7 min read

Your documentation is lying to you. And so are your validations

A document does not age: it expires, and it does so silently. Markdown cannot tell the difference between what you checked, what can be checked, and what you assumed, so six months later all three read the same. We tell the real case that led us to build validated-memory: evidence states, supersession without deletion, and freshness probes with three answers instead of two. Released as open source under Apache-2.0.

Terminal de contenedores nevada con grúas portuarias y miles de contenedores apilados: la cadena de suministro por la que viaja el código que instalas
5 min read

ChainDrop: 444 npm packages compromised and not a single patch to apply

On 4 August, between 09:35 and 13:20 UTC, a worm spread by itself across 444 npm packages, stealing the credentials it needed to keep spreading. The first malicious version went out through the legitimate pipeline, carrying a valid provenance signature. And there is a trap that inverts the correct reflex: revoking the stolen token is exactly what fires the next payload. What to look for in your lockfiles, in what order to rotate, and why there is no fixed version to install here.

Sala de control con una pared de pantallas mostrando paneles y mapas mientras varias personas los observan: el panel que todo el mundo mira y nadie mantiene
5 min read

Metabase: the data dashboard that was also the keyring

On 3 August, attackers walked into Metabase instances through the "forgot my password" endpoint, unauthenticated, with a CVSS of 10.0. Framework and Tally have already told their users. What an attacker takes from a compromised BI dashboard is not the charts: it is the credentials for every connected database, stored unencrypted unless somebody turned encryption on by hand. Which versions are in range, why this hole never shows up in your CVE feed, and why patching is the easy half of the job.

Sección de un tronco con sus anillos de crecimiento: capas acumuladas durante años, como el código del kernel donde se escondían Zapscape y SCTPhantom
5 min read

Zapscape and SCTPhantom: your Proxmox does not run Debian's kernel

Two Linux kernel flaws published this week break the two boundaries we take for granted: the virtual machine (Zapscape, CVE-2026-64561) and the container (SCTPhantom, CVE-2026-64564). Understanding them is the easy part. The hard part is answering whether the kernel your node actually boots already carries the fixes, because the versions in the advisory — 6.12.101, 7.1.6 — do not exist on your server: Proxmox does not use Debian's kernel. The exact proxmox-kernel versions that do close them (and why 7.0.14-9 is not enough), how to check in four commands, and who genuinely needs to hurry.

Parte trasera de un rack de nodos de almacenamiento: la mejora de Fast EC se enciende pool por pool, no con la actualización
7 min read

Fast EC ships switched off: the Ceph Tentacle flag that only turns once

Ceph Tentacle ships Fast EC, the erasure coding performance work people had been waiting years for. And it arrives switched off: you enable it pool by pool, with one command, and the monitor then refuses to clear it — rolling back means draining and recreating the pool. On top of that, the "at least double" in the headline was measured with a 16K stripe unit, which is precisely what an existing pool cannot have. The conditions the monitor enforces, the half of the improvement frozen on the day you created the pool, what happens to the cluster when you flip it, and why three-way replication is still faster.

Panel de parcheo de fibra con latiguillos etiquetados a mano: la documentación de red que deja de coincidir con la realidad
7 min read

Your network spreadsheet lies: how we build a source of truth with NetBox

Documenting a network is not scanning it. NetBox's own documentation says so plainly: it represents the desired state of a network rather than its operational state, and it discourages automated import of live network state. That is the criterion almost nobody applies. What NetBox is and is not, the three-question test for whether your inventory is worth anything, what we document and what we deliberately do not, and when you do not need any of this.

CVE-2026-34486 en Apache Tomcat: el EncryptInterceptor procesaba los mensajes del clúster aunque fallara el descifrado, un control de seguridad que falla abriendo
5 min read

If decryption fails, the message goes through anyway

The fix for the Apache Tomcat vulnerability CISA flagged as exploited on 4 August fits in a single line of code moved somewhere else. For two weeks, if decryption of a cluster message failed, Tomcat logged the error and processed the message anyway. And only 11.0.20, 10.1.53 and 9.0.116 were affected: precisely the versions carrying the patch for the previous flaw. What it means for a control to "fail open", why the log was the only signal, and what we check.

CVE-2026-9198 en Langflow entra en el catálogo KEV de CISA el 4 de agosto de 2026: la capa de IA y automatización autoalojada (Langflow, n8n, Open WebUI) tratada como producción
5 min read

The AI pilot nobody switched off is already production

On 4 August, CISA added a 9.8 in Langflow to its exploited-vulnerabilities catalogue: one endpoint that hands superuser tokens to anyone who reaches the port, chained with another that runs whatever code you send it. The patch had been out for six weeks. It is not an isolated case: in Open WebUI the ENABLE_CODE_EXECUTION=false switch turned nothing off, and in n8n anyone who could edit a workflow could run commands on the host. Three products, the same starting assumption. What we do with the AI and automation layer, and when we recommend not self-hosting it at all.

CVE-2026-66066, un fallo de CVSS 9,5 en Active Storage de Ruby on Rails, permite leer ficheros del servidor subiendo una imagen cuando la aplicación procesa variantes con libvips
5 min read

A 9.5 in Rails: the flaw is not in your application, it is in the library nobody chose

On 29 July 2026 Rails published CVE-2026-66066: a 9.5 in Active Storage letting an unauthenticated attacker read files from the server — including the process environment with secret_key_base and the database credentials — by uploading an image. The flaw is not in the code you commissioned, nor exactly in Rails: it is in which formats libvips considers safe to read, a C library nobody at your company chose. And libvips has published since 2022 which of its operations it has not verified, with a switch to block them. The label was there; what was missing was flipping it.

Ceph Squid 19.2 llega a su fin de vida estimado el 19 de septiembre de 2026
7 min read

Your Ceph has a date: Squid runs out of patches on 19 September

Ceph's lifecycle table puts the estimated end of life of Squid (19.2) on 19 September 2026: fifty days from today. Its replacement, Tentacle (20.2), has been stable since November and Proxmox has marked it stable since 9.2. The problem is not the jump, it is that it is not a jump: it is a sequence of three maintenance windows whose order you do not get to choose, with two details almost nobody has looked at — the mgr/zabbix module is gone, and erasure coding optimisations do not switch themselves on.

Zabbix 8.0: análisis de qué cambia de verdad en la próxima LTS de monitorización
5 min read

Zabbix 8.0 release date, LTS and roadmap: what is real vs still a slide

Zabbix 8.0 is the next LTS and half the industry already writes about it as if it were installed. As of 30 July 2026 the latest published artefact is beta 2, dated 9 July, and in the official container registry 8.0 is called trunk. Which features are really in the official release notes (native JSON up to 128 MiB, ClickHouse as a history backend, c-ares with DNS caching), what is still only roadmap (OpenTelemetry, complex event processing, mobile app, proxy permissions) and where the real bill for the upgrade sits: the database minimums and the removed macros living inside your alerts.

Despliegues reproducibles con Docker Swarm y GitOps: latest no es una versión
7 min read

"latest" is not a version: three lessons from deploying our own website with Docker Swarm

The pipeline went green, the webhook returned 200, and the site kept serving the old content. Three real lessons from our GitOps CI/CD on Docker Swarm: why the orchestrator does not chase your tag and what it takes for a redeploy to actually redeploy, why a linter is not a test (and the smoke test that saved our blog index), and the "zero downtime" our own file claimed but never delivered with a single replica.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN