Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Armario de red mural abierto en el pasillo de una oficina, con anillas pasahilos y cables recogidos, y un extintor apoyado en la pared al fondo
7 min read

July's patch is September's vulnerable build

SonicWall closed the SMA 1000 zero-day pair in build 12.4.3-03453 on 14 July. The 1 September advisory lists 12.4.3-03453 and earlier as affected: anyone who met the three-day KEV deadline landed on exactly the build that is back in the catalog 49 days later, with the same shape of flaw. When an appliance repeats the shape of the flaw, the question stops being whether it is patched and becomes how far that box reaches.

Dos routers de operador montados en un rack con latiguillos de fibra de dos colores llegando desde bandejas distintas
8 min read

Two ISPs are not redundancy if the ISP owns the IP

A second line saves what leaves the office, not what comes in: when the main one drops, the IP address changes, and with it DNS, open sessions, tunnels and third-party allow lists. The three real ways to have two paths, with 2026 figures: EUR 1,800 a year in RIPE fees, EUR 50 for the ASN, roughly 7,700 to 10,200 dollars for the /24 itself, and the ninety-second default of the BGP hold timer.

Armario de red mural abierto en una oficina, con panel de parcheo, dos conmutadores de rack y un mazo de latiguillos peinado sobre el raíl lateral
9 min read

A CVE is no longer one bug: Cisco has changed the unit of measurement

On 19 August Cisco published two advisories carrying five CVEs scored 10.0 between them. They are not five bugs: each identifier groups an entire class of bugs and carries the score of the worst one in the bag. Across the four hardening advisories we reviewed the mitigation line says the same thing, "none." This is not a complaint about Cisco: it is that the unit you count vulnerabilities in has changed size, and your inventory has not noticed.

Torres de telecomunicaciones entre la niebla: la red móvil privada que comparten empresas que no se conocen
9 min read

They crossed from a wind farm to a power plant turbine through the grid operator's private APN

On 8 August CERT Polska published its analysis of the 29 December 2025 attack on a Polish combined heat and power plant. The attacker got in through a FortiGate with no multi-factor authentication, hopped to a cellular router, crossed the distribution operator's private APN and put three families of Siemens PLCs into STOP mode. The report does not cite a single CVE in the whole chain: what it describes is a mobile network we all call private in which any device could talk to any other.

Nueve entradas del catálogo KEV de CISA en 2026 apuntan al plano de gestión de una red SD-WAN
8 min read

Your SD-WAN doesn't go down: it gets reconfigured

Of the 172 vulnerabilities CISA has flagged as exploited so far in 2026, nine point at the same place: the management plane of an SD-WAN. And the attacker Mandiant documented inside a Catalyst SD-WAN Manager took nothing down: they registered as a peer, copied the fabric's configuration templates through the product's own API and wiped their tracks. The numbers are our own count over the KEV catalogue, including the only two entries all year with a 48-hour deadline. What to look at when the attack looks like a legitimate configuration change and your monitoring stays green.

CVE-2026-16812 en el VeloCloud Orchestrator: el orquestador SD-WAN expuesto por diseño
7 min read

Your WAN orchestrator is on the internet by design: VeloCloud's 10.0

CVE-2026-16812 is an unauthenticated command injection in the on-premises VeloCloud Orchestrator: CVSS 10.0, exploited before a patch existed, and in CISA's KEV catalogue the same day with three days to fix it. Arista's advisory says the console is exposed by default and that no configuration prevents that exposure; a few lines further down it recommends restricting access to the web interface to trusted administrative networks. Both are true, and the bad day is decided in the distance between them.

SD-WAN multi-sede: cuándo compensa y cuándo sobra
5 min read

SD-WAN yes, but not everywhere: when it pays off and when it's overkill

Gartner predicted that by 2026, 70% of enterprises would have SD-WAN. We deploy it — and even so, more than once we have recommended against it. What problem it actually solves, when it pays off (changing sites, two transports, suffering applications), when two lines and WireGuard do the job, and the costs that never show up in the demo: the forever license, the orchestrator as a dependency and the complexity that doesn't disappear — it relocates.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN