Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Armario de llaves metálico abierto en el pasillo de servicio de una oficina, con dos hileras de llaves colgadas de sus ganchos
7 min read

They deleted the backups at both data centres

Joint advisory AA26-222A, published on 10 August 2026 by six agencies, records that at one Gunra victim the actors deleted backup and archived data at the primary data centre <em>and</em> at the recovery one, before and after deploying the encryptor. Another section describes how they got the key cabinet: SSH to an access control server and a symmetric key that decrypted the passwords for enterprise server accounts across the company. Our reading: two sites that accept the same credential are one site with two postal addresses. What falls outside a retention lock, and six checks for this week — two of which have to be actually run.

Rack abierto en una sala de servidores con dos bandejas de disco a medio sacar
8 min read

10% of the VMDK is enough: the arithmetic that changes your recovery plan

The ESXi encryptor Rapid7 took apart carries a percentage parameter, and the value observed was 10: on a large VMDK it touches only a tenth of the file, and that is enough to stop it booting. Partial encryption is not new — LockFile was doing it in 2021 — but the numbers are. What it does to your response clock, why no EDR agent belongs on the hypervisor (Broadcom says in so many words that it is not supported), what the same actor does to backup services, and why swapping hypervisors is not a security control.

Archivadores metálicos grises de oficina, con un cajón entreabierto y unos papeles asomando
6 min read

Ransom Busters: the rescuer offering to save you is the one who encrypted you

On 18 August GuidePoint (GRIT) reported that a supposed third party calling itself "Ransom Busters" emails ransomware victims offering to delete their data for between $20,000 and $60,000. When questioned, it confirmed access to the same stolen dataset the affiliate behind the intrusion held, and the same forensic fingerprints repeated across the incidents GuidePoint worked. What really changes everything is the date: the email arrived before the incident was public. What to do with it on the first morning.

Puesto de trabajo de una oficina vacío al amanecer, con la silla apartada, una taza fría y la persiana entreabierta
8 min read

They switched the EDR off with a reboot, and the encryption failed for lack of memory

On 4 August an Akira affiliate walked in through an MFA-less SSL VPN in roughly seven minutes and, rather than fight the EDR, rebooted the compromised host into <code>Safe Mode with Networking</code>: the agent and Defender real-time protection stopped starting. We counted the blind window against the timestamps in the Huntress report and it comes to 1 h 41 min, not the 10 minutes that circulated. The encryption did fail, but on virtual memory, not on defences.

Servidor de almacenamiento de 4U extraído sobre sus guías en una sala de servidores, con la tapa quitada y las filas de discos a la vista
9 min read

Proxmox's "protected" flag is not a lock, it's a latch

The Pay2Key ransomware shuts down the guests on a Proxmox cluster and deletes the backups using Proxmox's own API: first a <code>--protected 0</code>, then the delete. We read the pve-storage source to see why it works, and the answer is uncomfortable: clearing the latch never costs one privilege more than deleting the backup. What does raise a real boundary, and why it costs nothing.

Cuadro eléctrico con filas de interruptores automáticos: apagar cosas una a una antes de que pase lo importante
8 min read

DeadLock does not break your antivirus: it stops it like any other service

On 10 August Microsoft published its breakdown of the DeadLock encryptor. The interesting part is not the cryptography: it is the list of things it switches off before encrypting anything. Defender stopped like a service, shadow copies gone, domain controller services halted and — this is the one almost nobody looks at — event log channels not cleared but disabled in the registry.

Panel de salidas de una estación con horarios anunciados: el papel promete tiempos y el hierro tarda lo que tarda

Warning: Undefined array key "read_time" in /var/www/html/public/blog.php on line 3122
min read

RTO and RPO without the fluff: two numbers signed but never calculated

Almost every continuity plan carries an RPO and an RTO written with great confidence and calculated with none. What those two numbers actually promise, why your real RPO is the one of your last verified backup, the four clocks inside an RTO, and the arithmetic that dismantles a "four hours" sitting on a 1 Gbps link.

Escalera de evacuación atornillada a la fachada del edificio del que tiene que sacarte: la copia que depende de lo que protege
8 min read

Your backup server sits inside the domain it has to restore

In June, Veeam fixed a 9.4-out-of-10 flaw that let "an authenticated domain user" run code on the backup server. According to third-party technical analysis, on a workgroup server that flaw never came into existence. The difference is not in the code: it is in who your backup server asks whether you can be trusted. What it actually checks, why this is the sixth flaw with the same description in little over a year, the circular dependency nobody draws in the recovery plan, what taking the server out of the domain really costs, and the cases where we would not do it.

Informe de ransomware 2026: 1,7 millones de dólares de coste medio de recuperación por incidente
7 min read

Restoring is not recovering: two in three recover from backup and nearly half still pay

Sophos's annual ransomware report (2,158 IT leaders across 17 countries, Spain included) brings the biggest backup rebound in the series: 66% of victims whose data was encrypted recovered from backup, twelve points above the 54% of 2025. At the same time 48% paid, and the average cost of recovering rose 11% to $1.7 million with the ransom excluded. Why the two numbers do not contradict each other, the note on method about the two medians almost nobody is reading correctly, what is inside that bill, and the five things worth timing before the bad day.

Cl0p extorsiona sin cifrar: campaña contra PTC Windchill y FlexPLM
7 min read

Cl0p didn't encrypt a single file: extortion walks in through the app nobody watches

Cl0p is exploiting a critical vulnerability in PTC Windchill and FlexPLM (CVE-2026-12569, CVSS 9.3) to steal engineering data and extort without encrypting anything. The patch had existed since June 17; the wave of extortion emails arrived a month later. Why your backups can't undo a theft, what the Accellion→MOVEit→Oracle EBS pattern teaches (2,700+ organizations in a single campaign), and the five things we would do this week.

Romania's land registry
Wiped; saved by the out-of-reach copy
8 min read

Romania's land registry was wiped, backups included. It was saved by the copy the attacker couldn't touch

On July 14 an attacker got into Romania's ANCPI with valid credentials, failed to extort the agency, and wiped the land registry database plus every backup within reach. A week with no property sales or mortgages nationwide. The difference between incident and catastrophe was one copy beyond his reach.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN