Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Sala llena de puestos de trabajo vacíos con los monitores apagados
9 min read

The RDS failure is listed as "mitigated". The mitigation is turning the machine off and on

On 11 September Microsoft opened an issue for Remote Desktop Services hanging after the September update. Eight hours later it marked it as "Mitigated". We went and read the mitigation: stop the virtual machine and start it again. The affected-platform list on that same page is not the three Windows Server versions in the headlines either: it runs to six. And the package you want to uninstall is the one closing a 9.8 unauthenticated hole in the very same service.

Fila de puestos de trabajo vacíos en una oficina
10 min read

Entra ID retires memberOf on 3 November: after that date, membership stops being recalculated

Message centre post MC1448379, published on 5 August, has been read as a deadline. Read it the other way round: if you run a memberOf rule in production, you already have the problem it describes, and the preview documentation says so in a paragraph almost nobody reads. What happens on 3 November is not an outage or an error: memberships stay "in their last known state". That is where licences, Conditional Access and Teams membership hang from.

Mesa de soporte de una oficina con un teléfono fijo de sobremesa, una libreta de anillas, un cordón con llaves y un teclado apartado a un lado
9 min read

The phone number on the record was a credential: Entra ID stops accepting it

Microsoft's own documentation has said it plainly for years: if you fill in a user's mobile phone or alternate email, that user can reset their password immediately "even if they haven't registered for the service". Which means a field written by a sync or by an admin worked as proof of identity. Entra ID is about to stop accepting it. What changes, why the 86% everyone quotes does not mean what it looks like, and the four different dates Microsoft gives for the same cutoff.

Omnissa Horizon certificado en Proxmox VE: dos puestos de oficina vacíos con los monitores apagados y un cliente ligero detrás de la pantalla
6 min read

Proxmox VE is now Horizon Ready, but in manual mode: you create and power off the desktops yourself

On 4 September 2026 Proxmox announced that Proxmox VE has achieved Omnissa Horizon Ready Hypervisor certification. It is real and it removes a requirement, but it lands in "Manual Provisioning Mode": the program page states that provisioning and power policy are not supported. Meanwhile, Horizon has been integrating over the API with another non-vSphere hypervisor since December. Two different regimes, what Horizon stops doing for you, the RAM and GPU arithmetic nobody runs, and which estates this is a way out for today.

Sala de reuniones pequeña y vacía, con un altavoz de conferencia sobre la mesa, sillas desordenadas y luz natural entrando por la persiana
8 min read

Teams can now block meeting bots: it ships turned off

On 21 August Microsoft announced (MC1459141) that admins will be able to automatically block detected external bots in Teams meetings. We read the documentation for the ExternalBotAccessMode parameter: the word doing all the work is "detected", the new mode has to be assigned through policy, and it touches neither Copilot nor the assistant recording from your client's tenant. What actually decides where the transcript ends up — and when we would not switch it on.

Fichero de archivo de madera con un cajón abierto lleno de tarjetas catalogadas: dónde vive de verdad cada documento y quién puede abrir el cajón

Warning: Undefined array key "read_time" in /var/www/html/public/blog.php on line 3484
min read

That recording lives in the OneDrive of someone who no longer works here

At the end of September, Microsoft moves whiteboards created in Teams channels out of the creator's OneDrive and into the channel's SharePoint site. It is a small change that concedes a large problem: much of a company's collective work lives inside one individual's personal account. Where each recording actually lands, why the deletion clock starts the day you delete the account rather than the day the person leaves, and why leaving the account blocked "just in case" is not the plan you think it is.

Un MacBook abierto visto desde arriba sobre un escritorio con una libreta y un lápiz: el equipo de trabajo donde alguien pega un comando dictado por una web
8 min read

The macOS malware that exploits nothing: you paste it in yourself

On 6 August, Huntress published its analysis of a Go-based credential stealer for macOS that had been sitting inside a monitored Mac for three months. There is no CVE, no exploit and nothing to patch: the chain starts with a web page dictating a command and a user pasting it into Terminal. What that command does line by line, why Gatekeeper never gets involved, what it actually takes from a company (Keychain, session cookies, browser passwords) and why the warning Apple added in macOS 26.4 is a speed bump rather than a wall.

Cajones de un fichero de biblioteca con sus portaetiquetas vacíos: el directorio sigue estando en el sitio de siempre y la fuente de autoridad se está moviendo a la nube

Warning: Undefined array key "read_time" in /var/www/html/public/blog.php on line 3484
min read

Entra Connect: the date that stops your sync, and the date that just emails you

On 30 September 2026, any Entra Connect synchronisation running below version 2.5.79.0 stops working. This is not the Cloud Sync migration: it is a separate thing, and it is the only one of the two with a fixed date. The migration runs in waves, allows exceptions and has no announced retirement date. What exactly breaks when sync stops (hint: not email — the offboarding that never reaches the cloud), why auto-upgrade fails to save precisely the servers that need it, and the eight rows in Microsoft's own comparison table that decide whether you can move to Cloud Sync yet.

Sala llena de ordenadores encendidos y funcionando con normalidad: los certificados de Secure Boot caducaron en junio y ningún equipo dejó de arrancar
7 min read

Secure Boot expired in June and nothing broke. That is the problem

On 24 and 27 June, two of the certificates Microsoft has used to sign the boot chain since 2011 expired. Not a single machine went down: Microsoft states plainly that the device keeps starting and updating normally. What stops is something else — revocations, the boot manager, early-boot mitigations — and it raises no alert at all. A third date is still open: 19 October. How to check in two minutes whether your Windows estate, your Linux servers and — this is the one nobody looks at — your virtual machines already carry the 2023 certificates.

El peaje del ESU de Windows 10: el precio se duplica cada año y es acumulativo
8 min read

Windows 10 and the October toll: ESU doubles every year and you cannot skip year one

Microsoft charges $61 per device for the first year of Windows 10 extended security updates, and its own documentation says two things almost nobody puts together: the price doubles every consecutive year and ESUs are cumulative, so enrolling in year three means paying for all three. Delaying enrolment does not reduce the bill if you end up enrolling: it shifts the payment and leaves you without patches while you wait. The full math, the three blind spots that cost real money (the 2027 headline is not about your company, LTSC is not covered, and Office lives on until 2028 but you can no longer log a bug) and when paying for ESU really is the right call.

La subida de precios de Microsoft 365 del 1 de julio de 2026, con la cuenta real por usuario
8 min read

Microsoft 365 has already gone up: the percentage that scares you is not the one that costs you money

On 1 July the price increase for Microsoft 365 commercial suites came into force. Through June everyone repeated the same advice —renew before the 1st and you freeze your price— and that advice expired four weeks ago. The official before-and-after price table, the math that actually matters (per-user increase multiplied by headcount and by twelve), why the price that does NOT change is the most informative figure in the announcement, which capabilities land in each suite, and the five things we would do before your renewal.

CVE-2026-14266 en 7-Zip: por qué en la mayoría de los PCs de empresa el mejor parche es desinstalarlo
6 min read

The best patch for 7-Zip is uninstalling it (on most of your PCs)

CVE-2026-14266 is a heap overflow in 7-Zip's XZ decoder: it affects version 21.07 and every release up to 26.01. With no public exploit and no known exploitation, it is not an emergency. But that is two code-execution flaws in two months, the program updates by hand, and Windows 11 has opened .7z and .rar natively since 2023. Before updating two hundred machines, it is worth checking how many actually need it.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN