Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Sala llena de puestos de trabajo vacíos con los monitores apagados
9 min read

The RDS failure is listed as "mitigated". The mitigation is turning the machine off and on

On 11 September Microsoft opened an issue for Remote Desktop Services hanging after the September update. Eight hours later it marked it as "Mitigated". We went and read the mitigation: stop the virtual machine and start it again. The affected-platform list on that same page is not the three Windows Server versions in the headlines either: it runs to six. And the package you want to uninstall is the one closing a 9.8 unauthenticated hole in the very same service.

Armarios de rack vacíos recién instalados en el pasillo de una oficina
9 min read

VMware to Proxmox: the disk arrives intact, Windows will not boot, and the mistake was made two weeks earlier

The Proxmox VE import wizard copies the machine off ESXi without a hitch. Then Windows will not boot, and it is not the wizard's fault: the official documentation says that to boot from VirtIO SCSI, Windows "needs to see a disk requiring the driver before". That before is the problem, because the only place you can do it is the machine you have already shut down. The official way out works, but it is a per-machine, sequential procedure that lives inside the maintenance window. The alternative is not to speed it up: it is to move it to another date.

Armario de comunicaciones de pared con switch y cables de red
10 min read

Windows DNS, an unauthenticated 9.8: what turns a bug into a worm is not the bug, it's your network

On 8 September Microsoft shipped the largest batch of patches in its history. Dustin Childs, of the Zero Day Initiative, counts twenty that could be classified as wormable, spread across thirteen components. Those thirteen are not one list: they are two. Seven of those CVEs sit in services your domain requires every machine to reach — DNS, Netlogon, Active Directory, DHCP — and eleven sit in roles Windows does not install on its own. The first half is managed with patching order; the second, by uninstalling. And hardly anyone knows which of the two they have switched on.

Fotocopiadora multifunción de oficina con la puerta de tóner abierta y la bandeja de papel a medio sacar
7 min read

August's patch broke printing in WPF apps: the three ways out, with the maths done

The 11 August .NET Framework cumulative update breaks printing and PDF export in WPF applications using Calibri, Cambria, Constantia and Corbel: <code>System.IO.FileFormatException</code> on a font Windows itself installs. Microsoft acknowledged it on the 24th, thirteen days later, and the interim workaround switches off the overflow protection that same patch had just added. We looked at what exactly it turns off, why the decision should be per application rather than per fleet, and which of the three ways out costs least in each case.

Armario de comunicaciones de pared en una sala técnica, con un servidor de rack, un pequeño cortafuegos y un panel de parcheo con latiguillos naranjas y grises
7 min read

"Exploitation Less Likely": 126 days in the queue for CVE-2026-33824

Microsoft patched the Windows IPsec VPN flaw on 14 April with the label "Exploitation Less Likely". CISA added it to its exploited catalogue on 18 August. Between those dates sit 126 days, a Unit 42 report, and a vendor page that still has not been corrected. Our own count across Microsoft's 24 KEV entries this year, and which mitigation you cannot apply if your VPN carries remote workers.

Mesa de una oficina administrativa a última hora: archivadores de anillas, una calculadora de sobremesa y un archivador metálico con un cajón abierto
8 min read

5% more for paying monthly: what changes on 1 October, and when not to switch

From 1 October 2026 Microsoft will add a 5% uplift to CSP software subscriptions on annual terms billed monthly: it names Windows Server, SQL Server, CALs and System Center, and leaves the list open. The product does not change; the price of money does. The full arithmetic — that 5% works out at borrowing at roughly 11% a year — why your date is not 1 October but each line's renewal date, and the cases where moving is not worth it.

Sala de centralita telefónica con operadoras conectando llamadas: el servicio que resuelve nombres y por el que pasa todo el mundo
8 min read

The DNS server you have to patch is your domain controller

CVE-2026-62878 scores 9.8: a stack-based buffer overflow in Windows DNS, no authentication and no user interaction. Microsoft's bulletin lists sixteen affected products and all sixteen require a reboot. In many of the networks we come across, that machine is also the one validating everybody's passwords, which is why it hasn't been rebooted in months — sometimes years. What the bulletin actually says, what goes down while it boots, and the checks we run before the window.

Cuadro eléctrico con filas de interruptores automáticos: apagar cosas una a una antes de que pase lo importante
8 min read

DeadLock does not break your antivirus: it stops it like any other service

On 10 August Microsoft published its breakdown of the DeadLock encryptor. The interesting part is not the cryptography: it is the list of things it switches off before encrypting anything. Defender stopped like a service, shadow copies gone, domain controller services halted and — this is the one almost nobody looks at — event log channels not cleared but disabled in the registry.

Sala llena de ordenadores encendidos y funcionando con normalidad: los certificados de Secure Boot caducaron en junio y ningún equipo dejó de arrancar
7 min read

Secure Boot expired in June and nothing broke. That is the problem

On 24 and 27 June, two of the certificates Microsoft has used to sign the boot chain since 2011 expired. Not a single machine went down: Microsoft states plainly that the device keeps starting and updating normally. What stops is something else — revocations, the boot manager, early-boot mitigations — and it raises no alert at all. A third date is still open: 19 October. How to check in two minutes whether your Windows estate, your Linux servers and — this is the one nobody looks at — your virtual machines already carry the 2023 certificates.

El peaje del ESU de Windows 10: el precio se duplica cada año y es acumulativo
8 min read

Windows 10 and the October toll: ESU doubles every year and you cannot skip year one

Microsoft charges $61 per device for the first year of Windows 10 extended security updates, and its own documentation says two things almost nobody puts together: the price doubles every consecutive year and ESUs are cumulative, so enrolling in year three means paying for all three. Delaying enrolment does not reduce the bill if you end up enrolling: it shifts the payment and leaves you without patches while you wait. The full math, the three blind spots that cost real money (the 2027 headline is not about your company, LTSC is not covered, and Office lives on until 2028 but you can no longer log a bug) and when paying for ESU really is the right call.

CVE-2026-14266 en 7-Zip: por qué en la mayoría de los PCs de empresa el mejor parche es desinstalarlo
6 min read

The best patch for 7-Zip is uninstalling it (on most of your PCs)

CVE-2026-14266 is a heap overflow in 7-Zip's XZ decoder: it affects version 21.07 and every release up to 26.01. With no public exploit and no known exploitation, it is not an emergency. But that is two code-execution flaws in two months, the program updates by hand, and Windows 11 has opened .7z and .rar natively since 2023. Before updating two hundred machines, it is worth checking how many actually need it.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN