Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Sala de control con un muro de pantallas de monitorización y varias personas mirándolo de pie
10 min read

AI now finds zero-days on its own. Your problem is the 43 days that come after

On 4 September OpenAI launched GPT-6 Astra and declared it the first model it deploys reaching the "Critical" cybersecurity capability level of its preparedness framework. Almost all the coverage went after that half. The two numbers that decide what happens to you predate Astra and neither is about finding flaws: mean time to exploit is minus seven days according to M-Trends 2026, and the median to fully remediate a KEV-listed vulnerability is 43 days according to Verizon's DBIR. The bottleneck was never finding.

Puesto de monitorización vacío de noche, con los dos monitores apagados, unos auriculares sobre la mesa y la silla apartada
9 min read

The agent says SECURE and your console has received nothing for days

At DEF CON 34, Akamai showed how to turn a commercial EDR into the attacker's hiding place. The least-reported part is the ending: one line in the hosts file cuts off all telemetry while the agent still shows "SECURE". The signal you watch is controlled by the endpoint; the only one an attacker cannot fabricate is silence in your console. And almost nobody alerts on it.

Mesa de soporte de una oficina con un teléfono fijo de sobremesa, una libreta de anillas, un cordón con llaves y un teclado apartado a un lado
9 min read

The phone number on the record was a credential: Entra ID stops accepting it

Microsoft's own documentation has said it plainly for years: if you fill in a user's mobile phone or alternate email, that user can reset their password immediately "even if they haven't registered for the service". Which means a field written by a sync or by an admin worked as proof of identity. Entra ID is about to stop accepting it. What changes, why the 86% everyone quotes does not mean what it looks like, and the four different dates Microsoft gives for the same cutoff.

Sala de servidores de empresa de noche, con las luces apagadas, la puerta entreabierta a un pasillo iluminado, un taburete vacío junto al rack y un carro de servicio aparcado en el pasillo
8 min read

Proxmox goes 24/7 on 19 October: what those two hours actually buy you

On 2 September 2026 Proxmox announced that its enterprise support goes 24/7 on 19 October, and opened a North American subsidiary. Until now it ran Monday to Friday, 07:00–17:00 CET/CEST, on Austrian business days. What each plan includes, what it really costs per CPU socket, the three asymmetries sitting inside the announcement itself —response is not resolution, local support stays office hours, and the scope is three products rather than your system— and the six questions for reading any 24/7 support contract, your provider's included.

Cuadro eléctrico general abierto en un cuarto de instalaciones, con filas de magnetotérmicos colgando todos de un mismo interruptor principal
8 min read

Six Microsoft 365 services went down together. For your continuity plan they are one

On Monday 31 August, incident EX1464935 on Exchange Online ended up as MO1465074, with OneDrive, SharePoint Online, Teams, Purview and Defender XDR inside it. Six names, one shared authentication configuration underneath. We go through the hours —including the ones BleepingComputer and Computerworld disagree on, which we say rather than picking one—, why nobody has confirmed the expired-certificate story, and the dependency almost nobody will look at: the security console and the audit layer were inside the thing that had gone down.

Archivadores metálicos grises de oficina, con un cajón entreabierto y unos papeles asomando
6 min read

Ransom Busters: the rescuer offering to save you is the one who encrypted you

On 18 August GuidePoint (GRIT) reported that a supposed third party calling itself "Ransom Busters" emails ransomware victims offering to delete their data for between $20,000 and $60,000. When questioned, it confirmed access to the same stolen dataset the affiliate behind the intrusion held, and the same forensic fingerprints repeated across the incidents GuidePoint worked. What really changes everything is the date: the email arrived before the incident was public. What to do with it on the first morning.

Sala de reuniones vacía con las sillas recogidas: en agosto la alerta salta igual, pero la sala donde se decide está cerrada
8 min read

Three days to patch, and the third one lands on a Saturday

Since CISA changed its deadlines on 10 June, 42 of the 48 vulnerabilities it has added come with three days to fix them. We counted the weekdays over the catalog file itself: not a single 2026 entry was published on a Saturday or Sunday, and thirteen of those three-day deadlines expire exactly there. In August, with half the staff away, the bottleneck is who signs off that a server can be isolated at three in the morning.

Muro de ladrillo con la publicidad pintada de un comercio que ya no existe: el nombre sigue ahí mucho después de que el negocio cerrara
8 min read

An expired .es is released in ten days. A .com can give you eighty

Infoblox published on 13 August that around 65,000 expired domains were re-registered every day during the first half of 2026: nearly 20% of all the registrations they observe. A .com calendar gives you room —up to 45 days of auto-renew grace and 30 of redemption. A .es one does not: ten days after expiry it is cancelled and available again, with no redemption, and only the administrative or billing contact can request the renewal. What the catcher is buying, what still points at that name once it is no longer yours, and when there is nothing to renew.

Operadoras de centralita telefónica atendiendo llamadas: quien decide si reseteas una contraseña sigue siendo una persona al otro lado del teléfono
8 min read

Nobody exploited anything: who verifies it is you before resetting your MFA

Sounding convincing is not proof of identity, and in many organisations it is the only thing asked for. On 7 August Levi Strauss told the SEC that corporate information was taken from three company computers through social engineering: the work we use to measure security — patch, update, reboot — would have changed nothing. The joint CISA and FBI advisory on Scattered Spider says the targets are large companies and their contracted IT help desks, and that includes us. Why 65% of initial access now arrives through identity, why passkeys will not save you if the desk can enrol a new factor, and the eight things we ask of a reset procedure.

Fatiga de alertas: cómo montar una monitorización que avisa de lo que importa
8 min read

Your monitoring is not broken: it is shouting

An organisation receives an average of 2,992 security alerts a day and 63% of them go unaddressed, according to Vectra AI's 2026 count. The interesting part is that the volume has been falling for three years and the unaddressed share has not moved. Filtering harder does not fix it, because the problem was never how many alerts arrive: it is how many arrived with an owner and an action written next to them. How we prune monitoring that shouts, what wakes us at three in the morning, and what waits for the morning report.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN