Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Terminal de contenedores nevada con grúas portuarias y miles de contenedores apilados: la cadena de suministro por la que viaja el código que instalas
10 min read

ChainDrop: 444 npm packages compromised and not a single patch to apply

On 4 August, between 09:35 and 13:20 UTC, a worm spread by itself across 444 npm packages, stealing the credentials it needed to keep spreading. The first malicious version went out through the legitimate pipeline, carrying a valid provenance signature. And there is a trap that inverts the correct reflex: revoking the stolen token is exactly what fires the next payload. What to look for in your lockfiles, in what order to rotate, and why there is no fixed version to install here.

Sala de control con una pared de pantallas mostrando paneles y mapas mientras varias personas los observan: el panel que todo el mundo mira y nadie mantiene
10 min read

Metabase: the data dashboard that was also the keyring

On 3 August, attackers walked into Metabase instances through the "forgot my password" endpoint, unauthenticated, with a CVSS of 10.0. Framework and Tally have already told their users. What an attacker takes from a compromised BI dashboard is not the charts: it is the credentials for every connected database, stored unencrypted unless somebody turned encryption on by hand. Which versions are in range, why this hole never shows up in your CVE feed, and why patching is the easy half of the job.

Sección de un tronco con sus anillos de crecimiento: capas acumuladas durante años, como el código del kernel donde se escondían Zapscape y SCTPhantom
8 min read

Zapscape and SCTPhantom: your Proxmox does not run Debian's kernel

Two Linux kernel flaws published this week break the two boundaries we take for granted: the virtual machine (Zapscape, CVE-2026-64561) and the container (SCTPhantom, CVE-2026-64564). Understanding them is the easy part. The hard part is answering whether the kernel your node actually boots already carries the fixes, because the versions in the advisory — 6.12.101, 7.1.6 — do not exist on your server: Proxmox does not use Debian's kernel. The exact proxmox-kernel versions that do close them (and why 7.0.14-9 is not enough), how to check in four commands, and who genuinely needs to hurry.

Parte trasera de un rack de nodos de almacenamiento: la mejora de Fast EC se enciende pool por pool, no con la actualización
7 min read

Fast EC ships switched off: the Ceph Tentacle flag that only turns once

Ceph Tentacle ships Fast EC, the erasure coding performance work people had been waiting years for. And it arrives switched off: you enable it pool by pool, with one command, and the monitor then refuses to clear it — rolling back means draining and recreating the pool. On top of that, the "at least double" in the headline was measured with a 16K stripe unit, which is precisely what an existing pool cannot have. The conditions the monitor enforces, the half of the improvement frozen on the day you created the pool, what happens to the cluster when you flip it, and why three-way replication is still faster.

Panel de parcheo de fibra con latiguillos etiquetados a mano: la documentación de red que deja de coincidir con la realidad
7 min read

Your network spreadsheet lies: how we build a source of truth with NetBox

Documenting a network is not scanning it. NetBox's own documentation says so plainly: it represents the desired state of a network rather than its operational state, and it discourages automated import of live network state. That is the criterion almost nobody applies. What NetBox is and is not, the three-question test for whether your inventory is worth anything, what we document and what we deliberately do not, and when you do not need any of this.

CVE-2026-34486 en Apache Tomcat: el EncryptInterceptor procesaba los mensajes del clúster aunque fallara el descifrado, un control de seguridad que falla abriendo
8 min read

If decryption fails, the message goes through anyway

The fix for the Apache Tomcat vulnerability CISA flagged as exploited on 4 August fits in a single line of code moved somewhere else. For two weeks, if decryption of a cluster message failed, Tomcat logged the error and processed the message anyway. And only 11.0.20, 10.1.53 and 9.0.116 were affected: precisely the versions carrying the patch for the previous flaw. What it means for a control to "fail open", why the log was the only signal, and what we check.

CVE-2026-9198 en Langflow entra en el catálogo KEV de CISA el 4 de agosto de 2026: la capa de IA y automatización autoalojada (Langflow, n8n, Open WebUI) tratada como producción
8 min read

The AI pilot nobody switched off is already production

On 4 August, CISA added a 9.8 in Langflow to its exploited-vulnerabilities catalogue: one endpoint that hands superuser tokens to anyone who reaches the port, chained with another that runs whatever code you send it. The patch had been out for six weeks. It is not an isolated case: in Open WebUI the ENABLE_CODE_EXECUTION=false switch turned nothing off, and in n8n anyone who could edit a workflow could run commands on the host. Three products, the same starting assumption. What we do with the AI and automation layer, and when we recommend not self-hosting it at all.

CVE-2026-66066, un fallo de CVSS 9,5 en Active Storage de Ruby on Rails, permite leer ficheros del servidor subiendo una imagen cuando la aplicación procesa variantes con libvips
10 min read

A 9.5 in Rails: the flaw is not in your application, it is in the library nobody chose

On 29 July 2026 Rails published CVE-2026-66066: a 9.5 in Active Storage letting an unauthenticated attacker read files from the server — including the process environment with secret_key_base and the database credentials — by uploading an image. The flaw is not in the code you commissioned, nor exactly in Rails: it is in which formats libvips considers safe to read, a C library nobody at your company chose. And libvips has published since 2022 which of its operations it has not verified, with a switch to block them. The label was there; what was missing was flipping it.

Ceph Squid 19.2 llega a su fin de vida estimado el 19 de septiembre de 2026
8 min read

Your Ceph has a date: Squid runs out of patches on 19 September

Ceph's lifecycle table puts the estimated end of life of Squid (19.2) on 19 September 2026: fifty days from today. Its replacement, Tentacle (20.2), has been stable since November and Proxmox has marked it stable since 9.2. The problem is not the jump, it is that it is not a jump: it is a sequence of three maintenance windows whose order you do not get to choose, with two details almost nobody has looked at — the mgr/zabbix module is gone, and erasure coding optimisations do not switch themselves on.

Zabbix 8.0: análisis de qué cambia de verdad en la próxima LTS de monitorización
8 min read

Zabbix 8.0: what actually changes and what is still a slide

Zabbix 8.0 is the next LTS and half the industry already writes about it as if it were installed. As of 30 July 2026 the latest published artefact is beta 2, dated 9 July, and in the official container registry 8.0 is called trunk. Which features are really in the official release notes (native JSON up to 128 MiB, ClickHouse as a history backend, c-ares with DNS caching), what is still only roadmap (OpenTelemetry, complex event processing, mobile app, proxy permissions) and where the real bill for the upgrade sits: the database minimums and the removed macros living inside your alerts.

Despliegues reproducibles con Docker Swarm y GitOps: latest no es una versión
7 min read

"latest" is not a version: three lessons from deploying our own website with Docker Swarm

The pipeline went green, the webhook returned 200, and the site kept serving the old content. Three real lessons from our GitOps CI/CD on Docker Swarm: why the orchestrator does not chase your tag and what it takes for a redeploy to actually redeploy, why a linter is not a test (and the smoke test that saved our blog index), and the "zero downtime" our own file claimed but never delivered with a single replica.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN