Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Armario de red mural abierto en el pasillo de una oficina, con anillas pasahilos y cables recogidos, y un extintor apoyado en la pared al fondo
7 min read

July's patch is September's vulnerable build

SonicWall closed the SMA 1000 zero-day pair in build 12.4.3-03453 on 14 July. The 1 September advisory lists 12.4.3-03453 and earlier as affected: anyone who met the three-day KEV deadline landed on exactly the build that is back in the catalog 49 days later, with the same shape of flaw. When an appliance repeats the shape of the flaw, the question stops being whether it is patched and becomes how far that box reaches.

Cuarto de interconexión con paneles de parcheo, latiguillos de fibra naranja y amarilla recogidos en peines horizontales y una bobina de fibra colgada en la pared
8 min read

The route hijack RPKI called valid: the ROA allowed all the way down to /24

Between 28 and 30 August 2026, a BGP hijack diverted traffic for 162.55.80.0/24 across some 22 active hours and served a malicious update from behind a valid TLS certificate. We went and checked the ROA on RIPEstat: until 1 September it carried maxLength 24, so while the hijack lasted the route was RPKI valid. What origin validation checks and what it does not, why that same maxLength was also the cure, and the six verifications you can run today.

Diez CVE en el proceso iked de un cortafuegos: leer el campo de impacto antes que el titular
8 min read

Ten CVEs in one process: the headline is not enough to decide

On 27 August, ten security advisories landed in iked, the process that negotiates a firewall's IPsec tunnels. We read them one by one, and in several of them the headline and the body do not say the same thing: one titled "unauthenticated" needs a VPN user with valid credentials; another the vendor could not reproduce; and one of the lowest-scoring is the only one that mentions reading key material. How to read a bulletin like that in forty minutes.

Parte trasera de un rack abierto con servidores apilados y cables de red recogidos con bridas
11 min read

Migrating to Proxmox: the network is not held by the cluster, it is held by each node

In a VMware to Proxmox migration everybody watches the disks. Disks are the easy part: they either arrive or they do not, and you find out straight away. What gets left out of the luggage is the network configuration: in Proxmox VE it lives in a file on each node, outside the filesystem the cluster replicates. We go through the documentation sentence that says so, why the bridge is missing from the official list of live migration requirements, what the MAC change drags with it, the 10.0.2.x symptom that wastes hours, and how far SDN really takes you.

Sala de espera de oficina en penumbra con tres sillas grises alineadas contra la pared
8 min read

Guest Wi-Fi is a database of people (and it is not in your inventory)

Manchester Airports Group confirmed on 27 August that an unauthorised third party took customer data: email addresses, phone numbers, vehicle registrations and postcodes, from car park, lounge and Fast Track bookings and from in-airport Wi-Fi sign-ups. The company has not published how many people are affected; reporting puts it at around 8.7 million. Operations were unaffected, and that is precisely the problem: the system holding the most people is almost never at the top of your criticality list. Why the number plate is the field to watch, and the six questions worth one afternoon of inventory at your own front desk.

Puerta de acero de una sala de servidores sujeta abierta con una cuña, con un rack visible al fondo
8 min read

The bulletin said "denial of service". The exploit gives root: NetScaler CVE-2026-8452

Citrix shipped the patch on 30 June and described it as a denial of service; the CVSS vector on that same entry already showed high confidentiality impact and no privileges required. On 14 August, 45 days later, the exploit that gives unauthenticated root went public, and attacks followed within days: CISA set a 29 August deadline. How to check whether you are patched without knocking the box over (513 bytes, error 43549) and why the patch does not evict whoever already got in.

Dos routers de operador montados en un rack con latiguillos de fibra de dos colores llegando desde bandejas distintas
8 min read

Two ISPs are not redundancy if the ISP owns the IP

A second line saves what leaves the office, not what comes in: when the main one drops, the IP address changes, and with it DNS, open sessions, tunnels and third-party allow lists. The three real ways to have two paths, with 2026 figures: EUR 1,800 a year in RIPE fees, EUR 50 for the ASN, roughly 7,700 to 10,200 dollars for the /24 itself, and the ninety-second default of the BGP hold timer.

Aparato de red de 1U extraído sobre sus guías en un rack de sala técnica, con cable de consola conectado y un carro de servicio al lado
6 min read

NetScaler CVE-2026-19490: your version doesn't tell you whether you're exposed

On 19 August Citrix published an authentication bypass scoring 9.3 out of 10 in NetScaler ADC and Gateway. Being affected does not depend on your version alone: it depends on what you have configured, and older builds need fewer conditions. How to actually answer the question, why a pre-authentication flaw leaves your MFA out of the path, and what we do in the window before the first exploit lands.

Armario de red mural abierto en una oficina, con panel de parcheo, dos conmutadores de rack y un mazo de latiguillos peinado sobre el raíl lateral
9 min read

A CVE is no longer one bug: Cisco has changed the unit of measurement

On 19 August Cisco published two advisories carrying five CVEs scored 10.0 between them. They are not five bugs: each identifier groups an entire class of bugs and carries the score of the worst one in the bag. Across the four hardening advisories we reviewed the mitigation line says the same thing, "none." This is not a complaint about Cisco: it is that the unit you count vulnerabilities in has changed size, and your inventory has not noticed.

Armario de comunicaciones de pared en una sala técnica, con un servidor de rack, un pequeño cortafuegos y un panel de parcheo con latiguillos naranjas y grises
7 min read

"Exploitation Less Likely": 126 days in the queue for CVE-2026-33824

Microsoft patched the Windows IPsec VPN flaw on 14 April with the label "Exploitation Less Likely". CISA added it to its exploited catalogue on 18 August. Between those dates sit 126 days, a Unit 42 report, and a vendor page that still has not been corrected. Our own count across Microsoft's 24 KEV entries this year, and which mitigation you cannot apply if your VPN carries remote workers.

Varios miniordenadores en una bandeja de rack conectados a un panel de parcheo: máquinas pequeñas alojadas y accesibles desde la red
8 min read

They came in on port 5900 and left with root: the miner was the least of it

In mid-August the Dutch cyber security centre warned that the macOS Screen Sharing flaw is being exploited on Macs with port 5900 open to the internet, and that in every reported case the attacker got root and left a Monero miner behind. Apple had already shipped the patch on 6 August. What exactly breaks in CVE-2026-65400, why classic hardening did not cover this hole, and the list almost no company has: what listens from outside.

Muro de ladrillo con la publicidad pintada de un comercio que ya no existe: el nombre sigue ahí mucho después de que el negocio cerrara
8 min read

An expired .es is released in ten days. A .com can give you eighty

Infoblox published on 13 August that around 65,000 expired domains were re-registered every day during the first half of 2026: nearly 20% of all the registrations they observe. A .com calendar gives you room —up to 45 days of auto-renew grace and 30 of redemption. A .es one does not: ten days after expiry it is cancelled and available again, with no redemption, and only the administrative or billing contact can request the renewal. What the catcher is buying, what still points at that name once it is no longer yours, and when there is nothing to renew.

Pasillo de un centro de datos: cuando el concentrador de VPN se reinicia, el acceso remoto de toda la empresa se queda fuera
6 min read

The Cisco flaw that steals nothing: it just reboots the door your people come in through

On 11 August Cisco published an advisory for ASA and Secure Firewall Threat Defense: an HTTP request against the remote access SSL VPN service makes the device reload. The CVSS vector reads C:N/I:N/A:H —nothing is leaked, nothing is altered— and two hours and twenty minutes later it was already in CISA's KEV catalog with a 14 August due date. Three days. What to check on the device, why the patch costs exactly what the attack costs, and when this does not concern you.

Torres de telecomunicaciones entre la niebla: la red móvil privada que comparten empresas que no se conocen
9 min read

They crossed from a wind farm to a power plant turbine through the grid operator's private APN

On 8 August CERT Polska published its analysis of the 29 December 2025 attack on a Polish combined heat and power plant. The attacker got in through a FortiGate with no multi-factor authentication, hopped to a cellular router, crossed the distribution operator's private APN and put three families of Siemens PLCs into STOP mode. The report does not cite a single CVE in the whole chain: what it describes is a mobile network we all call private in which any device could talk to any other.

Pasillo frío de un centro de datos entre dos filas de racks cerrados: los aparatos que están delante de todo y casi nunca aparecen en el inventario de parcheo

Warning: Undefined array key "read_time" in /var/www/html/public/blog.php on line 3212
min read

By the time CISA flagged LoadMaster, the patch had been out for 64 days

CISA added CVE-2026-8037 to its Known Exploited Vulnerabilities catalog on 7 August and set the deadline for the 10th. Progress had shipped the patch on 4 June. In between: a public PoC on 29 June and forty days of exploitation attempts. If your patch queue is ordered by the KEV catalog, you are late by design — here is the clock you should actually be watching.

Vista aérea de un enlace de autopistas con múltiples caminos posibles: el tráfico puede desviarse sin que ningún enlace se caiga
8 min read

RPKI won't stop your route being hijacked: signing the origin doesn't secure the path

70.31% of internet routes now carry a valid RPKI signature, yet only 12.3% of the autonomous systems measured achieve full protection on their routes. And the hijack that actually gets used — copying your ASN into the origin and putting yourself in front of it — passes validation with a green light. What a ROA signs and what it leaves out, the four families of attack left outside, today's event counter with its small print, and the two questions worth all the others for your provider if you do not run your own AS.

Panel de parcheo de fibra con latiguillos etiquetados a mano: la documentación de red que deja de coincidir con la realidad
7 min read

Your network spreadsheet lies: how we build a source of truth with NetBox

Documenting a network is not scanning it. NetBox's own documentation says so plainly: it represents the desired state of a network rather than its operational state, and it discourages automated import of live network state. That is the criterion almost nobody applies. What NetBox is and is not, the three-question test for whether your inventory is worth anything, what we document and what we deliberately do not, and when you do not need any of this.

WireGuard o IPsec: comparativa honesta entre los dos protocolos de túnel, con el criterio de everyWAN sobre cuál usar en cada caso y el calendario post-cuántico europeo
8 min read

WireGuard or IPsec: what we deploy where

WireGuard is about 4,000 lines of code, it landed in the Linux kernel in 2020 and it fits on one page of config. IPsec drags along thirty years of RFCs and proposals that never quite match. And we still deploy IPsec in a good share of the places we work, for three reasons that show up in no comparison table: who is on the other end of the tunnel, who authenticates the people, and what happens when the cryptography has to change. An honest comparison, no fanboyism, with Europe's post-quantum calendar on the table.

Nueve entradas del catálogo KEV de CISA en 2026 apuntan al plano de gestión de una red SD-WAN
8 min read

Your SD-WAN doesn't go down: it gets reconfigured

Of the 172 vulnerabilities CISA has flagged as exploited so far in 2026, nine point at the same place: the management plane of an SD-WAN. And the attacker Mandiant documented inside a Catalyst SD-WAN Manager took nothing down: they registered as a peer, copied the fabric's configuration templates through the product's own API and wiped their tracks. The numbers are our own count over the KEV catalogue, including the only two entries all year with a 48-hour deadline. What to look at when the attack looks like a legitimate configuration change and your monitoring stays green.

  • 1
  • 2

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN