Blurtek

Blog

Practical insights on cybersecurity, AI, digital transformation and software development.

Development

Incomplete Next.js App Router Patch: What to Check in 2026

Incomplete Next.js patch: why upgrading alone isn't enough and what your company must audit in production right now.

Read article
Cybersecurity

AI Browser Extensions With Gmail Access: What to Review

AI browser extensions with Gmail and Calendar access: the OAuth and extension permissions your company must audit before approving them.

Read article
Cybersecurity

ClickFix: Why You Should Never Paste a Command to "Fix" Your Browser

ClickFix tricks employees into pasting the exact command that installs malware themselves. How the technique works and how to stop it at your SME.

Read article
Cybersecurity

Next.js Launches Formal Security Advisories: What Changes

Next.js launches a formal security advisory program with its own CVEs: what it means for companies running Next.js in production.

Read article
AI

Agentic Misalignment: What to Watch Before Giving AI Agents Autonomy

Agentic misalignment: the misaligned behavior patterns every company should watch before granting real autonomy to an AI agent.

Read article
Cybersecurity

RCE in Cursor on Repo Clone: What Your Company Must Check

RCE in Cursor from cloning a repo: a malicious tasks.json or MCP config runs code with zero clicks. Checklist for companies rolling out AI IDEs.

Read article
Cybersecurity

What a Basic Pentest Won't Cover: A Checklist Before You Hire One

What a basic pentest won't cover for your SME: social engineering, source code, third parties. An honest checklist before hiring an audit.

Read article
Cybersecurity

MemGhost: One Email Can Poison Your AI's Memory Forever

Memory poisoning: a single email with hidden instructions can corrupt your AI agent's memory forever. How it works and how SMEs can prevent it.

Read article
Cybersecurity

XRING: What We Actually Know About the Unpatched HTTP/3 0-Day

XRING, the alleged unpatched HTTP/3 0-day exploiting QPACK, is spreading without a CVE or official advisory. Here's the real mechanism and how to verify it.

Read article
Cybersecurity

Free Android VPNs Leak Traffic and Put BYOD at Risk

Free Android VPNs: research found apps leaking traffic and intercepting TLS. What your company must require in its BYOD policy.

Read article
AI

AI code review: instructions beat the tool every time

AI code review: switching models barely improves reviews. A well-written instructions file does. Why this happens and how to apply it in your team.

Read article
Cybersecurity

Zero Trust for AI Agents: Why Static API Keys Are the Real Risk

Zero Trust for AI agents explained: why a static API key becomes the biggest risk when you connect an autonomous agent to company systems.

Read article
Cybersecurity

Third-Party MCP Servers: A 30-Minute Audit Before Connecting

Third-party MCP server audit: what to check in 30 minutes before connecting it to your coding agent to avoid leaking credentials.

Read article
Cybersecurity

AI Agents With Terminal Access and No Approval: The Real Risk

AI agents with terminal access and no human approval are the real cause of 2026's coding-agent incidents, not the model itself.

Read article
Cybersecurity

HalluSquatting: When Your AI Coding Agent Installs Malware

HalluSquatting: your AI coding agent hallucinates packages and an attacker registers them first. How to secure your SME's pipeline affordably.

Read article
Cybersecurity

Why Claude Code and Cursor Trigger Your EDR (And What To Do)

Claude Code, Cursor and Codex trigger EDR alerts on monitored machines: what your antivirus really detects and how your security team should respond.

Read article
Cybersecurity

GitHub's Green 'Verified' Badge Can Be Faked: What It Means

GitHub's Verified badge can be spoofed due to identity gaps and hash chain malleability. What it means for your software supply chain trust.

Read article
Cybersecurity

Friendly Fire and GhostApproval: How Attackers Hijack Your AI Coding Agent

Friendly Fire and GhostApproval: how hidden prompt injection hijacks AI coding agents like Claude Code or Cursor during PR review.

Read article
Digital transformation

EU Chat Control 2026: What Private Message Scanning Means

EU Chat Control 2026: the sixth proposal would scan encrypted private messages. What it means for your SME's GDPR compliance.

Read article
AI

Human Approval for Risky Writes: The AI Agent Safety Pattern

Human approval for risky writes: the safety pattern every autonomous AI agent needs, without killing its productivity.

Read article
Cybersecurity

Scoped Access for AI Agents: What SMEs Must Require

Scoped access for AI agents: what SMEs must require before granting an autonomous agent access to core business systems like ERP, email or CRM.

Read article
Development

CVE-2025-29927: The Next.js Authorization Bypass Still Unpatched

CVE-2025-29927 lets attackers bypass Next.js authentication via one HTTP header. Here's the mechanism, and why self-hosted apps stay exposed.

Read article
AI

AI Interpretability: How Anthropic Detects Hidden Goals

AI interpretability: Anthropic's research reads hidden goals inside Claude — why it matters before granting autonomy to AI agents.

Read article
Cybersecurity

Least Privilege for AI Agents: How to Scope API Tokens

Least privilege for AI agents: a full-write token can let an agent delete repos or data by mistake. How to scope fine-grained API tokens.

Read article
Cybersecurity

Custom Agents in GitHub Copilot CLI for Security Audits

Custom GitHub Copilot CLI agents: how to define roles, tools and guardrails to automate security audits without exposing credentials.

Read article
Cybersecurity

PII Filtering Before AI APIs: Rampart and GLiNER2 for GDPR Compliance

Filter PII before AI APIs with Rampart and GLiNER2: technical GDPR compliance guide for Spanish SMBs integrating ChatGPT, Azure OpenAI, or custom models.

Read article
Cybersecurity

CVE-2026-46242 Bad Epoll: Linux 6.4 Privilege Escalation via Chrome and Android

CVE-2026-46242 Bad Epoll: Linux 6.4-6.9 kernel race condition lets attackers escalate to root from Chrome or Android. Practical guide for Spanish SMBs.

Read article
AI

Vercel eve: Sandboxing and Approvals for AI Agents

Vercel eve sandboxes AI agents and requires human approval before risky actions. What SMEs should apply to internal AI automation without copying the framework.

Read article
Cybersecurity

FortiBleed 2026: 354 Confirmed FortiGate Attacks — What to Do Now

FortiBleed 2026: 354 active FortiGate attack chains, 73% hitting already-patched firms. Diagnosis, IOCs and 72-hour remediation plan if you run Fortinet in production.

Read article
Cybersecurity

Fake Airdrop 2026: Detect the Crypto Scam Before Connecting

Fraudulent airdrop in 2026: how to detect if an unsolicited token in your wallet is a crypto scam before connecting and losing all your assets.

Read article
Development

Next.js 16.3 and Turbopack: What Really Changes in Production

Next.js 16.3 and Turbopack in production: what benchmarks don't tell you about persistent cache, plugin compatibility, and when migration isn't worth it.

Read article
Cybersecurity

Computer Use 2026: Security Risks of Autonomous AI Agents

Computer use 2026: AI agents controlling screens and terminals open unprecedented attack vectors. Discover the real risks and how to protect your business.

Read article
Cybersecurity

ArgoCD RCE: How Unauthenticated gRPC Enables Full Kubernetes Cluster Takeover

Active ArgoCD RCE: unauthenticated gRPC enables full Kubernetes cluster takeover. Real mechanism, detection commands, and step-by-step remediation for IT teams.

Read article
Cybersecurity

BioShocking: How a Web Page Can Steal Your SSH Credentials Through AI Agents

BioShocking steals SSH credentials through AI agents with browser access—no CVE, no browser exploit needed. Learn the hidden mechanism and how to protect your org.

Read article
AI

Autonomous AI Agents with Browser and Terminal: Real Automation for SMEs in 2026

Autonomous AI agents with browser and terminal: what they already automate in Spanish SMEs, real costs, and when it makes sense to implement them in 2026.

Read article
Cybersecurity

MCP Tool Poisoning: How AI Agents Can Exfiltrate Your Corporate Data

MCP tool poisoning lets attackers manipulate AI agents to exfiltrate corporate data with no malware and no EDR alerts. Learn the mechanism and how to protect your company.

Read article
Cybersecurity

Silent Swap: How Fake Chrome Extensions Steal Your API Keys in 2026

Fake Chrome extensions use Silent Swap to silently steal API keys and dev secrets. Real attack mechanism, Spanish business vectors, and an actionable protection checklist.

Read article
Cybersecurity

SMB Backups in 2026: A No-Nonsense Guide to Protecting Your Business Data

SMB backups in 2026: what architecture you actually need, the real cost of data loss in Spain, and why 70% of backups fail when they matter most.

Read article
Cybersecurity

Mustang Panda Cloud C2: Why Your Antivirus Cannot Detect It

Mustang Panda uses OneDrive as a C2 channel. Your antivirus misses this traffic because it is technically legitimate. We explain the real mechanism.

Read article
Cybersecurity

Why 78% of Companies Take Over 3 Weeks to Detect a Supply Chain Attack

78% of companies take over 3 weeks to detect supply chain attacks because they arrive through trusted channels. Learn why detection fails and how to fix it.

Read article
Cybersecurity

Harvest Now, Decrypt Later: Which Credentials SMEs Should Migrate First to PQC

Harvest now decrypt later threatens your keys today: which SSH, VPN and PKI credentials your SME must migrate first to post-quantum cryptography before 2030.

Read article
Cybersecurity

Zero Trust vs VPN for Spanish SMEs: Which Model to Choose in 2026

Zero Trust vs VPN for Spanish SMEs: real cost comparison, risks and complexity to choose the right remote access model in 2026.

Read article
Cybersecurity

Signal Under Attack: How the Backup Recovery Key Can Cost You Your Entire Account

Signal Backup Recovery Key: the account takeover vector few businesses know about. If someone gets that key, your Signal account is gone in under ten minutes.

Read article
Cybersecurity

Fileless Rootkit on Linux: Why CVE-2026-46331 Bypasses Your Antivirus

Fileless rootkit CVE-2026-46331 on Linux bypasses corporate antivirus. Learn the exact technical mechanism and what your business needs to detect it.

Read article
Cybersecurity

Gaslight Malware 2026: How Rust Implants via Telegram C2 Poison Your AI Security Tools

Gaslight Malware 2026 uses Rust implants with Telegram C2 to poison your AI-powered SIEM. Learn the exact mechanism and how to detect it before the damage is done.

Read article
AI

AI Agent Harness vs Model: Real Data from 1,781 Companies

AI agent harness drives 77% of production outcomes, not the model. Real data from 1,781 enterprise deployments analyzed by LangChain and Gartner 2025.

Read article
Cybersecurity

npm Dependency Attacks: How They Steal CI/CD Secrets in SMEs

npm dependency attacks steal CI/CD tokens via postinstall scripts before any alert fires. Real mechanism, SME field patterns, and a zero-cost hardening checklist.

Read article
Cybersecurity

Phishing in Spanish SMBs: the attack vectors failing most in 2026

Phishing and social engineering in Spanish SMBs in 2026: which attack vectors keep working, why current controls fail, and how to reduce real risk.

Read article
AI

AI Sales Automation for Spanish SMBs: Real Costs and ROI

AI sales automation for Spanish SMBs: real implementation costs, time saved, and where it actually fails. Data-driven, no vendor hype.

Read article
AI

Why Most AI Projects in SMEs Never Reach Production

AI projects in SMEs: 70% never reach production. Discover the real causes consultants don't tell you and how to avoid failure from the start.

Read article
Cybersecurity

Why Your SMB Backups Are Failing Silently (And How to Find Out)

SMB backups failing silently: why the job shows OK but data isn't recoverable, and what to check right now before an incident exposes the gap.

Read article
Cybersecurity

SME Cybersecurity: The Real Risk of Exposed Admin Panels

Exposed admin panels are the most exploited entry point in Spanish SMEs. Discover the real attack mechanism, field cases, and actionable protection steps.

Read article
Cybersecurity

FortiBleed 2026: What to Do If Your FortiGate Is Compromised

FortiBleed 2026 has compromised thousands of FortiGate devices in Spain. If yours was exposed, follow these exact incident response steps before it's too late.

Read article
AI

AI Agents for Spanish Businesses: What Actually Works in 2026

AI agents for Spanish SMBs in 2026: proven ROI use cases, real implementation costs, and what to avoid based on field projects.

Read article
Cybersecurity

Real Cost of a Ransomware Attack on 50–200 Employee Companies

Ransomware on mid-size companies: the real cost exceeds €180,000 and it's not the ransom. Discover the hidden expenses no insurance policy covers.

Read article
Cybersecurity

The 5 security holes almost every SME website leaves open (and how to close them this week)

90% of the SME websites we audit share the same five flaws. None requires a sophisticated attacker: just that nobody has looked. We show you how to check for them and close them.

Read article
AI

AI for SMEs in 2026: 5 automations that pay for themselves in under 90 days

AI is no longer just for big corporations. These five automations deliver measurable returns in under a quarter and can start small, without blowing up your budget or your team.

Read article
Development

SaaS vs Custom Software: A 5-Year Perspective for Spanish SMEs

Explore the detailed analysis of SaaS and custom software in the Spanish context. Compare costs, benefits, and scalability over 5 years to make informed decisions.

Read article
Maintenance

The Uncomfortable Truth About Cheap IT Maintenance Contracts: Are They Really Worth It?

Discover the hidden risks of cheap IT maintenance contracts that could end up costing your SME dearly. Learn to evaluate correctly to avoid surprises.

Read article
Maintenance

Why Backup Systems Often Fail Silently (The Mechanism No One Explains)

Discover the hidden causes of silent failures in backup systems and how to prevent them with specific tactics and appropriate security standards.

Read article
Digital transformation

The Uncomfortable Truth About Automation: Does It Really Save Time in SMEs?

Discover why automation doesn't always save time in Spanish SMEs and the real challenges your company faces when implementing it.

Read article
Cybersecurity

The Five Invisibles Affecting Your Cybersecurity Decisions: Hidden Patterns in SMEs

Discover the hidden patterns that may be compromising your SME's cybersecurity. Learn to identify them and improve your data protection strategy effectively.

Read article
Digital transformation

The Cloud Software Trap: Why 70% of SMEs Fall into the Same Mistake

Discover the mistakes 70% of SMEs make when migrating to the cloud and how to avoid them to improve ROI and operational efficiency.

Read article
Development

SaaS vs Custom Software: The Cost Analysis Providers Don't Want You to See

Uncover the hidden costs and uncomfortable truths behind SaaS and custom software in Spanish SMEs. With unique data and analysis others omit.

Read article
Maintenance

The Pitfall of Cheap IT Maintenance Contracts: What You Aren't Told

Find out why cheap IT maintenance contracts can be costly in the long run. We analyze hidden costs, service quality, and more.

Read article
Maintenance

Why Your Backups Fail Even if the Log Says They're OK: The Hidden Mechanism No One Knows

Discover the hidden mechanisms that can cause your backups to fail. Learn how to prevent unexpected failures and protect your data integrity.

Read article
Cybersecurity

The Cyber Insurance Myth: Does It Really Protect or Is It an Illusion?

Discover the uncomfortable truth behind cyber insurance: does it really protect SMEs or just offer a false sense of security? We analyze its limitations and alternatives.

Read article
Development

The Secrets of Custom Software Your Provider Will Never Tell You

Uncover the hidden costs and risks of custom software your provider won't mention. Learn to negotiate and ensure a successful project for your SME.

Read article
Maintenance

Why the Backup You Trust Never Executes: The Hidden Mechanism Behind the Failure

Discover the hidden errors causing your backups to fail and how proactive monitoring can save your data.

Read article
Development

SaaS vs Custom Development: The Cost Analysis No One Tells You

Discover the hidden cost analysis between SaaS and custom development for Spanish SMEs, revealing data and mechanisms you won't find anywhere else.

Read article
AI

The Uncomfortable Truth About AI: Does It Really Help SMEs or Is It Just Another Trend?

Find out if artificial intelligence truly benefits SMEs or is just a passing trend. We analyze myths and realities in the Spanish context with unique data.

Read article
Cybersecurity

Why Your Backups Are Failing Mechanically and How to Fix It

Uncover the hidden causes behind mechanical backup failures and specific solutions for SMEs. Protect your data with effective strategies you won't find elsewhere.

Read article
Digital transformation

The Cloud Debate: Is It Really Safer for Your SME?

We explore whether the cloud is truly safe for Spanish SMEs, debunking myths and providing specific data you won't find elsewhere.

Read article
Cybersecurity

The Illusion of Digital Audits: Unmasking Empty Promises

Digital audits promise security but often disappoint. Find out why these evaluations can be misleading and how to avoid their traps.

Read article
Maintenance

The Silent Error Condemning Your Backups: A Detailed Autopsy

Discover why your backups are doomed to fail and how to avoid common mistakes not mentioned in standard reports.

Read article
Digital transformation

The 6-Month Pattern: The Critical Moment in SME Digital Transformations

Discover why digital transformations in SMEs often hit a crisis at 180 days and how to avoid it with specific strategies and data from the Spanish market.

Read article
Development

We analyzed 30 custom software contracts: 73% had this overlooked clause

Discover the hidden clause found in 73% of custom software contracts that few read. Learn how to identify it and understand its implications for your SME.

Read article
Maintenance

IT Maintenance: The Invisible Errors That Sabotage Your Infrastructure Efficiency

Discover the hidden errors in IT maintenance that affect the efficiency of your technological infrastructure and how to avoid them with innovative solutions.

Read article
Maintenance

IT Maintenance: What Your Provider Will Never Tell You About Their Service

Discover the hidden truths of IT maintenance, from costs to customization. Learn to identify what your provider doesn't tell you.

Read article
Development

Custom Software Development: The Hidden Cost No One Tells You About

Discover the hidden costs of custom software that can impact SMEs beyond design and programming. Learn about financial risks and long-term benefits.

Read article
Development

Demystifying Custom Software: A Luxury or a Necessity for Your SME?

Discover why custom software might be the key to your SME's efficiency and competitiveness, beyond common myths.

Read article
Development

The Questions No One Tells You Before Hiring Custom Software

Discover the key questions to ask before hiring custom software and make informed decisions for your SME.

Read article
Digital transformation

Checklist: 7 Critical Steps for an Effective Digital Transformation in Spanish SMEs

Discover the essential steps for your Spanish SME to achieve a successful digital transformation, with a unique focus on cybersecurity and digital culture.

Read article
Digital transformation

Digital Transformation: Mistakes That Destroy Half of Your Investments

Uncover hidden mistakes in the digital transformation of Spanish SMEs and how to avoid them to optimize your tech investments.

Read article
Maintenance

Cloud Security: The Myth of Fortress and Its Hidden Vulnerabilities

Discover why the cloud isn't as secure as it seems. From regulations to hidden risks that could jeopardize Spanish SMEs.

Read article
Digital transformation

Digital Transformation in Logistics: Real Impact on Spanish SMEs

Discover how digital transformation is revolutionizing logistics in Spanish SMEs, with real examples and unique strategies.

Read article
AI

Artificial Intelligence: Does It Truly Solve the IT Talent Shortage?

Explore how AI might be the key to mitigating IT talent shortages, but also uncover the uncomfortable truths few mention.

Read article
AI

AI in 2026: How Automation Will Transform SMEs

Discover how artificial intelligence in 2026 will change the future of SMEs through automation, optimizing processes and improving operational efficiency.

Read article
Cybersecurity

Cybersecurity: How Much Data Could You Lose in an Hour of Downtime?

Discover the real economic impact of downtime on SMEs and how to protect against data loss.

Read article
AI

The Best-Kept Secrets of Artificial Intelligence in SMEs

Discover the hidden challenges and real opportunities of implementing AI in SMEs, with data and strategies no one else shares.

Read article
Cybersecurity

The Myth of Total Cybersecurity: Is It Costing Us More Than We Think?

We explore how the myth of total cybersecurity is diverting resources and propose a more practical approach for SMEs. Discover hidden costs and effective strategies.

Read article
Cybersecurity

Demystifying Cybersecurity: Is It Really That Expensive?

Discover how cybersecurity can be accessible and essential for SMEs, debunking myths and analyzing the real cost-benefit.

Read article
Cybersecurity

How to prioritize cybersecurity risks without slowing operations

A simple framework to decide what to fix first, what to monitor and what to accept temporarily.

Read article
AI

Internal chatbots with controlled documentation: where they truly help

It is not about adding a chat box. It is about solving repetitive questions with context, permissions and traceability.

Read article
Digital transformation

How to integrate ERP and CRM without creating more chaos

Integration is not about connecting two tools. It is about deciding which data rules and what process each team needs.

Read article
Development

Custom development: when it is worth it and when it is not

Building custom software makes sense when it removes friction that off-the-shelf tools cannot solve well.

Read article
Maintenance

Monitoring that actually prevents outages

Alerting is not enough. You need context, useful thresholds and the ability to respond.

Read article
AI

AI governance for real companies

Using AI without access, quality and review criteria creates more risk than value.

Read article
Cybersecurity

Pentesting with business impact

A useful pentest does not end in a PDF. It ends in decisions and prioritized fixes.

Read article
Digital transformation

What an IT roadmap for leadership should include

A useful roadmap is not a project list. It is a sequence of decisions with impact, risk and dependencies.

Read article
Development

Technical SEO for B2B service websites

Organic visibility starts with clean structure, performance and pillar pages that match real intent.

Read article
Maintenance

When it makes sense to outsource server maintenance

Outsourcing is not about losing control. It is about gaining coverage, method and time for your team.

Read article
AI

Document automation with AI: where to start

Invoices, contracts and operational records often hide some of the highest-return automations.

Read article
Digital transformation

How to reduce friction with technology vendors

Complexity does not always come from the stack. Often it comes from a lack of ownership across vendors.

Read article
Maintenance

Useful observability for leadership and IT

The best dashboards do not show more data. They show the data that changes decisions.

Read article
AI

The myth that AI reduces costs from day one

AI ROI does not arrive in 30 days. Companies that understand this upfront move faster than those that buy the promise.

Read article
Cybersecurity

The real cost of a security incident (beyond the ransom)

Companies that have been attacked do not remember the ransom. They remember the weeks offline, the lost clients and the exhausted team.

Read article
Cybersecurity

What nobody tells you when you buy managed security

Buying an MSSP is not buying peace of mind. It is trading one problem for another if you do not know what to ask before signing.

Read article
Cybersecurity

We have audited over 20 companies this year: here is what we always find

Sector, size and tech stack do not matter. There are three problems that appear in practically every company we audit.

Read article
AI

Opinion: 80% of corporate chatbots should not exist

Most chatbots we see in companies are demos that made it to production. They solve nothing real and erode the team's trust in AI.

Read article
Development

The questions that separate a good development supplier from one that will make your life difficult

Commissioning custom development is one of the riskiest technology decisions. These questions help you evaluate a supplier before signing.

Read article
AI

What it really costs to automate a process with AI (with real price ranges)

Nobody gives figures because it depends on many variables. But knowing real ranges helps you evaluate proposals and plan budget.

Read article
Digital transformation

What I would do arriving today as CTO at a 150-person logistics company

A mid-sized logistics company has very predictable technology problems. Here is the plan I would apply in the first 90 days.

Read article
Digital transformation

Before and after centralising IT management at an 80-person company

It was not a technology project. It was an operational clarity project. Here is what changed.

Read article
Cybersecurity

The checklist we use before any security audit

Before conducting a technical audit, there is a preparation process that determines whether findings will be actionable or just paper.

Read article
Cybersecurity

Prediction: what will change in cybersecurity for mid-sized companies before year end

These are not abstract trends. They are concrete changes already affecting companies in Spain that will accelerate over the coming months.

Read article
AI

Generative AI for SMEs: how to use it without breaking the budget

Many mid-sized companies are paying for AI tools they use at 10% capacity. This guide explains how to get maximum value with controlled investment.

Read article
Cybersecurity

What to expect from a cybersecurity audit: what vendors rarely explain

A security audit is not a penetration test. This guide breaks down types, realistic timelines and how to interpret the final report.

Read article
Digital transformation

Cloud migration without drama: how to plan the real first year

60% of cloud migrations run over schedule. Here we explain the most common failure patterns and how to avoid them before you start.

Read article