Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Disco duro externo conectado a un portátil sobre una mesa de despacho
7 min read

The clone doesn't carry the .git/config. The ZIP does

Four CVEs published in August and September 2026 describe the same sequence: you open a folder with an AI coding agent, the agent calls git to work out where it is, and that folder's local configuration runs a program with your credentials before anybody asks whether you trust it. Inside: what git's documentation says about core.fsmonitor, why an ordinary clone does not work as a delivery route, why the ownership check git does have is disarmed by the most ordinary gesture there is, and the trick that hides the key from your own grep.

Sala de reuniones vacía con dos pizarras blancas y sillas alrededor de una mesa larga
9 min read

Your patching policy has no entry for "there is no patch"

On 21 September someone broke into the Dutch Institute for Vulnerability Disclosure, the people whose job is telling everyone else to patch. Eleven days later, the second of the two chained flaws still has no published fix. Inside: the timeline the victim published under its own name; why the headline —"an AI agent did it"— is not what decides the outcome, and what the logs actually say ("loud and very messy"); the advisory field reading "Patch status: Available" two sections above the paragraph saying the vendor "are working on a fix", and why your vulnerability process reads the field and not the paragraph; the two public documents that do not agree and are both true; what is left when the patch does not exist —break the chain at the other link, remove exposure, cut the blast radius, raise detection—; and the paragraph missing from your security policy, written out in full so you can copy it, with the two clauses that make it work: it expires by itself, and it carries a name and a job title.

Filas de puestos con ordenadores en una sala vacía; solo una pantalla encendida
8 min read

Four EDRs and no alerts: what are you left with

On 6 July, two SensePost researchers published a code injection technique and tested it against four market-leading EDRs configured to detect, block and remediate: it worked on all four and no alerts were created. On 22 September, Flashpoint reproduced it. The technique does not write into another process's memory —the path every EDR has watched for a decade— but instead places the payload into the parameters a new process starts with. We read both publications in full, including the part the headlines skipped: in Flashpoint's lab the XDR component DID block, and only stopped once two further evasions were stacked on top; and the authors themselves warn the technique "has multiple opportunities for detection". Also: why this is post-exploitation and not a way in, why the same primitive had already been described publicly before (with no known date), the four checks you can ask your console for this week —and the catch that none of them is a button, but a query over telemetry someone has to have kept and someone has to write—.

Sala con filas de puestos de trabajo y ordenadores bajo luz fluorescente
8 min read

CVE-2026-32996: the backup agent left the administrator ticket written in a log file

The exploit overflows no stack and corrupts no memory: it opens a text file any user on the machine can read, finds a session identifier inside, presents it over a named pipe and runs whatever you want as SYSTEM. With the vendor advisory in front of us, three things being reported wrong about CVE-2026-32996 in Veeam Agent for Windows: the version the headlines quote (13.0.1.2067) is the server build, not the agent one —the number to check is 13.0.3.1220—; the patch for two hundred laptops hangs off the change window of the backup server, the machine nobody wants to touch; and the phrase "active exploitation" was only ever in the headline of a bulletin whose body said something else, and which was then pulled. Why AT:P in the vector changes which machines you look at first, and the four things we would do this week.

Armario de comunicaciones de pared en una sede pequeña, con router, módem y switch conectados con cables de red
9 min read

Your site-to-site tunnel doesn't ask for MFA because there's nobody to ask

CVE-2026-85102 entered the CISA catalog on September 22 with a three-day deadline, and almost all the coverage stopped at "patch your remote access VPN". The official description says "Site to Site VPN or Remote Access VPN": the tunnel between your own offices too, where there is no user to ask for a second factor, the trust was configured once and never expires, and the flaw happens during certificate negotiation — before your MFA and conditional access ever get to run. With the caveat almost nobody mentions (that path only applies if the tunnel authenticates with certificates, not a pre-shared key), the cross-reading of both advisories — the branch that saves you from one is the one listed in the scope of the other — and the four things we would check this week.

Armario de comunicaciones montado en la pared de una pequeña empresa, con un router, un módem y un switch, y los cables recogidos sin orden dentro
8 min read

The flaw is WordPress's; your php.ini decides the exposure

CVE-2026-87902 entered CISA's Known Exploited Vulnerabilities catalogue on 25 September, three days after the advisory and a proof of concept went public. It is a 9.2 and it is WordPress core, patched across 25 branches down to 4.7.37 (December 2016). But 9.2 measures the damage, not your exposure: the CVSS 4.0 vector itself carries AT:P — "conditions are required" — and none of the deciding conditions belong to WordPress. A PHP directive, a PEAR file and a directory inside your active theme. What each one checks, why the obvious command for looking at it from a shell returns a false answer — we measured it on a box running PHP 8.3.6 — and what NOT to do if you suspect it already happened.

Vista aérea de un enlace de autopista en trébol, con varias rutas posibles entre los mismos dos puntos
8 min read

Your SD-WAN orchestrator is the key to every one of your sites

On 22 September CISA added CVE-2026-93952 to the known exploited vulnerabilities catalogue: a 10.0 out of 10 in VeloCloud Orchestrator, the system that configures every site in an SD-WAN network. The second exploited 10.0 in that same orchestrator in eight weeks. And the exploitation condition the vendor itself publishes is an uncomfortable line: it requires access to the PUBLIC portion of the certificate the branch device authenticates with. Why that points at the trust model and not just at an input validation bug, what to do if your version train has no patch yet, the three traces to look for in the filesystem today, and the question we ask before centralising a control plane.

Pasillo frío de un centro de datos con una silla vacía y un carro de consola aparcado junto a un armario abierto
7 min read

The Proxmox CVE your scanner cannot evaluate

CVE-2023-54391 is a 9.8: you get in as root@pam with no password. We queried its record through the NVD API and the GitHub Advisories API, and here is what comes back: NVD publishes no CPE configuration at all and flags the record as Deferred; GitHub returns an empty list of affected packages; and the only range that exists stops at "7.4" while your nodes call themselves 7.4-17. A scanner that decides by version matching has nothing to decide with. Meanwhile a provider published its post mortem: twelve hypervisors mining from 31 August to 17 September, logs wiped and the sentence "we cannot prove it".

Armario de comunicaciones con paneles de parcheo y una maraña de cables de red azules
5 min read

The patch for your switch had been out for 97 days

On 21 September CISA added a single CVE to its catalogue of exploited vulnerabilities: a stack-based buffer overflow in the CGI program of Zyxel GS1900 switch firmware, unauthenticated and with command execution. Zyxel published the advisory and the ten fixed firmware builds on 16 June: 97 days earlier. We counted the 30 entries the catalogue has taken in so far this month and the median is 5 days, so the list mixes two different populations. Why "LAN-based" is not a mitigating factor but the attack's requirement, what the small print does not say about models out of support, and why the entry asks for forensic triage before you reflash.

Dos portátiles abiertos sobre una mesa de oficina y una mano escribiendo sobre unos papeles
7 min read

The agent pinned the plugin's commit. Git handed it the attacker's branch

Plugin4Shell affects the four most widely used AI coding agents: they clone the plugin repository, check out the pinned commit and never verify they landed on it. We reproduced in the lab, with git 2.43, the git behaviour it rests on: exit code 0, a warning nobody reads, and the attacker's content in the working tree. The same 40-character string gives a different answer depending on which git command reads it, so auditing with git log is no help. And today's defence today depends above all on where the plugin repository is hosted.

Interior de un servidor de dos zócalos abierto, con los procesadores y dos bancos de módulos de memoria a la vista
8 min read

Patching the kernel means rebooting, and the reboot erases the evidence

CISA added two Linux kernel flaws to its exploited catalogue today, due by Monday. One has sat in your scanner for eleven months rated 3.3 out of 10; the kernel project scores it 7.8 on the very same record. Both entries carry the forensic-triage flag CISA now attaches to two out of every three new additions, and its guidance says not to remediate before collecting evidence. In the kernel, remediating means rebooting. And rebooting erases a good part of what you are asked to keep.

Cerro con torres de comunicaciones, antenas parabólicas y radioenlaces contra el cielo
9 min read

MikroTik shipped that port closed: the flaw is theirs, the exception is yours

On 5 September CERT Polska published six RouterOS vulnerabilities; two of them chained give full control of a MikroTik with no authentication, and Shadowserver counted 122,500 devices with SSH reachable from the internet. The vendor's own advisory says its default configuration blocks that port. So the thing to look at is not the CVE: it is who opened the exception, when, and why nobody gave it an expiry date.

Interior de un armario de comunicaciones de planta con switch, panel de conexiones y cableado de cobre y fibra
12 min read

Cisco ISE, a perfect 10 with no workaround: your network already decided what to do without it

On 16 September Cisco published a CVSS 10.0 in Identity Services Engine: an authentication bypass in an API, no workaround available, active exploitation and command execution as root. Before arguing about the maintenance window there are two things to look at: ISE's own access.log, because the advisory ships indicators and the recommendation to re-image the node if anything shows up, and the show run on a floor switch, because that is where what your network will do when the policy engine stops answering is already written. The default value of radius-server deadtime is 0.

Parte trasera de un chasis de servidor con módulos de ventilador y cables de alimentación
10 min read

Acronis Backup: "requires local access" — and that access is what you sell your customers

On 15 September Acronis published a one-sentence advisory: local privilege escalation through insecure file permissions in its backup plugin for cPanel and Plesk, CVSS 7.8, exploited in targeted attacks. A "local" 7.8 is exactly the CVE almost every patching queue pushes to next week. On a machine with a single administrator, that call is defensible. On a server where every customer gets their own system user, the requirement for "local access with low privileges" is not describing a barrier: it is describing your business model.

Estanterías de un depósito de archivo con legajos y cajas de documentos etiquetados
9 min read

"Read-only" does not exist: GitLab scores 10.0 on a flaw that can only read

CVE-2026-85706 lets a stranger read files off a self-hosted GitLab server. It writes nothing, and it still carries the maximum score. The explanation is not in the headline: it is in the vector the vendor itself signed off, with a changed scope and high integrity impact. We go through what the vector says, why CISA gave it three days and a forensic triage flag, and how to answer the one question the patch does not: were we read?

Sala llena de puestos de trabajo vacíos con los monitores apagados
9 min read

The RDS failure is listed as "mitigated". The mitigation is turning the machine off and on

On 11 September Microsoft opened an issue for Remote Desktop Services hanging after the September update. Eight hours later it marked it as "Mitigated". We went and read the mitigation: stop the virtual machine and start it again. The affected-platform list on that same page is not the three Windows Server versions in the headlines either: it runs to six. And the package you want to uninstall is the one closing a 9.8 unauthenticated hole in the very same service.

Ordenador abierto sobre el banco de trabajo de un servicio de reparación informática
10 min read

Remote support: the file runs on the technician's machine

On 11 September, CISA added a ConnectWise ScreenConnect advisory to its catalogue of exploited vulnerabilities. The detail almost nobody highlights comes from the vendor itself: "ScreenConnect servers are not impacted". The machine that ends up running the file is the one support is given from. Three days earlier, N-able N-central had entered the same list with a 10.0. We counted the whole catalogue: fifteen entries in 2026 for software whose job is governing other people's computers. Windows, thirteen.

Reloj de pared de esfera oscura en una pared gris de oficina
8 min read

Cyber Resilience Act: 24 hours to report, and the clock does not start with the CVE

Article 14 of the Cyber Resilience Act starts to apply today: 24 hours for the first warning about an actively exploited vulnerability. Two details almost nobody is covering: it is the only article the regulation stretches backwards, reaching what you have already sold, and the deadline runs not from the CVE being published but from the moment you "become aware". That turns a legal obligation into an instrumentation problem: telemetry, a watched mailbox and who declares the time.

Panel de parcheo a oscuras con cuatro conectores RJ45 desconectados
10 min read

Cisco FMC: patching closes the door, but nobody gives you back your network blueprint

On 9 September, Cisco Talos confirmed active exploitation of two flaws in Secure Firewall Management Center, and counted three separate attacker clusters inside the same box. One of them dropped two scripts to harvest the configurations of the managed firewalls. That is the part almost nobody is discussing: credentials rotate, a domain gets restored, and your perimeter configuration does not rotate. It is a description of your network, and it stays valid after the patch.

Armario de comunicaciones de pared con switch y cables de red
10 min read

Windows DNS, an unauthenticated 9.8: what turns a bug into a worm is not the bug, it's your network

On 8 September Microsoft shipped the largest batch of patches in its history. Dustin Childs, of the Zero Day Initiative, counts twenty that could be classified as wormable, spread across thirteen components. Those thirteen are not one list: they are two. Seven of those CVEs sit in services your domain requires every machine to reach — DNS, Netlogon, Active Directory, DHCP — and eleven sit in roles Windows does not install on its own. The first half is managed with patching order; the second, by uninstalling. And hardly anyone knows which of the two they have switched on.

  • 1
  • 2

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN