Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Armario de red mural abierto en el pasillo de una oficina, con anillas pasahilos y cables recogidos, y un extintor apoyado en la pared al fondo
7 min read

July's patch is September's vulnerable build

SonicWall closed the SMA 1000 zero-day pair in build 12.4.3-03453 on 14 July. The 1 September advisory lists 12.4.3-03453 and earlier as affected: anyone who met the three-day KEV deadline landed on exactly the build that is back in the catalog 49 days later, with the same shape of flaw. When an appliance repeats the shape of the flaw, the question stops being whether it is patched and becomes how far that box reaches.

Puesto de monitorización vacío de noche, con los dos monitores apagados, unos auriculares sobre la mesa y la silla apartada
9 min read

The agent says SECURE and your console has received nothing for days

At DEF CON 34, Akamai showed how to turn a commercial EDR into the attacker's hiding place. The least-reported part is the ending: one line in the hosts file cuts off all telemetry while the agent still shows "SECURE". The signal you watch is controlled by the endpoint; the only one an attacker cannot fabricate is silence in your console. And almost nobody alerts on it.

Cartel de «se busca» con el alias CyberLeek sobre una ciudad nocturna y las etiquetas de los datos reclamados: IP, identificador de dispositivo, cuenta de Microsoft, OneDrive y Discord
8 min read

GTA 6, CyberLeek and MachineGuid: the digital trail your company leaves too

To find whoever is leaking GTA 6 material, on 20 August 2026 Take-Two filed two DMCA subpoenas asking Microsoft and Discord for the MachineGuid, MSA device identifiers, IP addresses, phone numbers, linked connections and OneDrive contents of every account in three servers. What MachineGuid is, why it identifies the device rather than the account, and why your company generates exactly the same trail every working day.

Custom controls de Acceso Condicional: el MFA de terceros que Entra no cuenta como MFA
9 min read

Custom controls: the third-party MFA that Entra does not count as MFA

The Microsoft Learn page on Conditional Access custom controls lists eight things that control cannot do, and the third is satisfying the MFA claim requirement. It is no good for PIM role elevation, device enrollment, SSPR, sign-in frequency or cross-tenant trusts either. From September 2026 they can no longer be created or edited, and "editing" means deleting and creating again. With the Graph query to find out whether you have one.

Armario metálico de llaves abierto en la pared de un cuarto de instalaciones, con decenas de llaves colgadas juntas
11 min read

136 keys in one object: the defaults that opened the cluster

Hugging Face published the forensic timeline of the July intrusion and OpenAI closed its report on 26 August: 17,600 reconstructed actions between the 9th and the 13th. Between the first compromised container and the object holding 136 keys there was not one further vulnerability — there were defaults. The token every pod mounts, the metadata endpoint that answers from inside, secrets concentrated in one object, and a connector credential shared across clusters. We walk the chain with the timestamps in front of us, the two CVEs CISA added to its catalogue on 27 August, and the five questions we ask a cluster.

Sala de espera de oficina en penumbra con tres sillas grises alineadas contra la pared
8 min read

Guest Wi-Fi is a database of people (and it is not in your inventory)

Manchester Airports Group confirmed on 27 August that an unauthorised third party took customer data: email addresses, phone numbers, vehicle registrations and postcodes, from car park, lounge and Fast Track bookings and from in-airport Wi-Fi sign-ups. The company has not published how many people are affected; reporting puts it at around 8.7 million. Operations were unaffected, and that is precisely the problem: the system holding the most people is almost never at the top of your criticality list. Why the number plate is the field to watch, and the six questions worth one afternoon of inventory at your own front desk.

Portal de un edificio antiguo con una única puerta acristalada, el portero automático y los buzones metálicos
8 min read

Your identity provider is not an application: it is infrastructure

On Monday 24 August, at 03:38, a denial-of-service attack began against Norway's shared government digital platform. Ten public services went down and several had nothing wrong with them: the door everyone goes through had jammed. Digdir writes on its status page that <code>eSignering</code> was unavailable "because of the limitations in ID-porten", and also that the services were "stable with the limitations that have been put in place" — part of the outage was put there by the defenders. Why single sign-on is still the right call, what changes when the door becomes infrastructure, and the three questions that reclassify it.

Jaula de rejilla metálica cerrada con candado en una sala de datacenter compartida, con dos racks de servidores detrás
6 min read

The patch that isn't yours: what to do with Entra ID's CVE-2026-69836

On 20 August Microsoft published a critical remote code execution flaw in Entra ID, and the next day corrected the exploitation field to "No". There is nothing to install: the record says "customerActionRequired: false". What is yours is the ability to answer "were we affected?", and on an Entra ID Free licence that lasts seven days. How to read the record from Microsoft's own API, and the checklist we apply to the tenant.

Centralita telefónica manual con hileras de interruptores etiquetados a mano: apagar uno era rápido; saber qué línea dejaba muda, no
9 min read

The report says "zero impacts", and that does not mean nobody uses it

Baseline Security Mode puts twenty-one settings in the Microsoft 365 admin center that used to live only in PowerShell: switching off basic authentication, EWS, ActiveX, IDCRL, Publisher. Microsoft's guidance says to turn each one on when its impact report comes back at zero. The detail that changes the reading: the Office app settings are delivered through Cloud Policy, and Windows clients below version 2510 do not send the simulation mode telemetry that feeds that report. What each switch turns off, what actually breaks when you close EWS, and the order we do it in.

Cronómetro deportivo: los cinco días entre el aviso VMSA-2026-0006 y las primeras conexiones de vCenter comprometidos a la infraestructura del atacante
6 min read

The vCenter advisory said there was no known exploitation. It held for five days

Broadcom published VMSA-2026-0006 on 29 July with no information suggesting exploitation, and that is how we quoted it here the next day. On 3 August the first compromised vCenters started connecting to attacker infrastructure, and on 12 August QUIRSO published the count: 361 victim IP addresses across 47 countries. What those numbers mean, what they do not, and the question that decides whether this concerns you: who can open a connection to your vCenter.

Torres de telecomunicaciones entre la niebla: la red móvil privada que comparten empresas que no se conocen
9 min read

They crossed from a wind farm to a power plant turbine through the grid operator's private APN

On 8 August CERT Polska published its analysis of the 29 December 2025 attack on a Polish combined heat and power plant. The attacker got in through a FortiGate with no multi-factor authentication, hopped to a cellular router, crossed the distribution operator's private APN and put three families of Siemens PLCs into STOP mode. The report does not cite a single CVE in the whole chain: what it describes is a mobile network we all call private in which any device could talk to any other.

CVE-2026-9198 en Langflow entra en el catálogo KEV de CISA el 4 de agosto de 2026: la capa de IA y automatización autoalojada (Langflow, n8n, Open WebUI) tratada como producción
8 min read

The AI pilot nobody switched off is already production

On 4 August, CISA added a 9.8 in Langflow to its exploited-vulnerabilities catalogue: one endpoint that hands superuser tokens to anyone who reaches the port, chained with another that runs whatever code you send it. The patch had been out for six weeks. It is not an isolated case: in Open WebUI the ENABLE_CODE_EXECUTION=false switch turned nothing off, and in n8n anyone who could edit a workflow could run commands on the host. Three products, the same starting assumption. What we do with the AI and automation layer, and when we recommend not self-hosting it at all.

Más de 700 organizaciones afectadas por el robo de tokens OAuth de una aplicación conectada, sin ninguna contraseña robada
8 min read

The token that never asks for MFA: connected apps in your Microsoft 365

More than 700 organisations were potentially exposed in August 2025 without a single password being stolen: the attacker took the OAuth tokens of an application they had connected themselves. On 13 July 2026 Microsoft published the map of a full year of that technique: two attack chains and not one suspicious sign-in. The part that fails is not the login, it is consent: how to inventory the applications connected to your tenant with two Graph queries, what each button actually switches off, and why changing the consent setting revokes nothing already granted.

Secuestro de DNS en Wi-Fi de hoteles para robar cuentas de Microsoft 365
7 min read

The hotel Wi-Fi works for someone else: DNS hijacked to steal Microsoft 365 accounts

Since June 2026 an active campaign has been compromising captive portals at hotels and conference centers, changing their DNS and redirecting guests to fake Microsoft 365 pages. The refined part: by abusing the device code flow they take your account without stealing your password, with MFA "satisfied". What is happening, why the padlock won't save you, and what we would do: from full-tunnel VPN to blocking the device code flow.

Certighost (CVE-2026-54121): impersonar un Domain Controller vía AD CS
8 min read

Certighost: any user could become your Domain Controller. The question isn't whether you patched, it's whether you've audited your AD CS

Certighost (CVE-2026-54121) let an unprivileged domain user impersonate a Domain Controller via Active Directory Certificate Services and take over the entire domain. Microsoft patched it on July 14; a working PoC has been public since July 24. The mechanism in one sentence, why AD CS is the escalation surface almost nobody audits, and the plan for today: patch, inventory your CAs, machine account quota to zero, and audit templates.

Microsoft retira el SMS como MFA en Entra ID: passkeys por defecto
7 min read

Microsoft SMS MFA end of life: Entra ID stops sending texts in February 2027

On July 13 Microsoft announced that Entra ID will stop providing SMS and voice calls as an authentication method: passkeys by default from September 1 and full retirement on February 1, 2027, with no opt-out. Anyone insisting on SMS will have to contract and pay their own telecom provider. The full timeline, why SMS was never a serious second factor, and the plan we would apply to any tenant.

Check Point SmartConsole
Zero-day CVE-2026-16232 · exposed management
8 min read

The Check Point zero-day wasn't after your firewall: it was after its console

CVE-2026-16232: an authentication bypass in SmartConsole allowed logging into the server that governs all your Check Point gateways as an administrator, with no credentials. It was exploited before the patch existed and CISA gave three days to remediate. Why the management plane is a bigger prize than the firewall itself, and the checklist that applies even without Check Point.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN