CiberAfterWork: ciberseguridad en Capital Radio

CiberAfterWork: ciberseguridad en Capital Radio

By psanemeTechnology
Download on the App Store

CiberAfterWork: ciberseguridad en Capital Radio episodes

  • Episode 324: A Digital Shield for Spain: From the STIC Conferences to DNS Security
    In this new installment of Cyber Afterwork on Capital Radio, we dive into the heart of national cybersecurity with the start of the XIX STIC Conferences and the RootedCon congress in Madrid, where professionals and administrations unite under the motto of creating a digital shield for an interconnected Spain. During the program, we analyze the implications of the recent security breach at an Iberia provider, which highlights the supply chain risk by exposing personal data, and we discuss a WhatsApp vulnerability that allowed for the identification of billions of active accounts through automated requests lacking security limits. Additionally, we clarify the controversy regarding the privacy of the V16 beacons mandatory for 2026, confirming that they do not track movements or collect private data according to the Data Protection Agency. In the technical segment, we explore tools like Radar E2 for reverse engineering and the potential of N8N for automating defensive processes, while adding practical tips for a secure Black Friday, such as using virtual cards and encrypted connections. Finally, we feature insights from Francesco Colini of FlashStart, who emphasizes the critical importance of the DNS protocol as a pillar of internet resilience and a fundamental tool for preventively blocking fraud and phishing attacks. The episode concludes with a reflection on the need to educate young people in networking fundamentals to build a solid digital security culture from the ground up.
    Twitter:
    @ciberafterwork
    Instagram:
    @ciberafterwork
    Panda Security:
    https://www.pandasecurity.com/es/
    +info:
    https://psaneme.com/
    https://bitlifemedia.com/
    https://www.vapasec.com/
    VAPASEC
    https://www.vapasec.com/
    https://www.vapasec.com/webprotection/
    16 min
  • Episodio 324:Un Escudo Digital para España: De las Jornadas STIC a la Seguridad del DNS
    El programa Cyber Afterwork destaca el inicio de las XIX Jornadas STIC y el congreso RootedCon en Madrid, eventos clave para la ciberseguridad nacional bajo el lema de crear un escudo digital. Durante la emisión, se analiza una brecha de seguridad en un proveedor de Iberia que expuso datos personales como nombres y correos electrónicos, facilitando potenciales estafas de ingeniería social. Asimismo, se informa sobre una vulnerabilidad en WhatsApp que permitió identificar miles de millones de cuentas activas debido a la falta de límites en las peticiones de búsqueda automatizadas. Respecto a las balizas V16 obligatorias para 2026, la Agencia de Protección de Datos aclaró que estos dispositivos no recopilan datos personales ni rastrean movimientos, limitándose a enviar la ubicación en emergencias.
    En el bloque técnico, se detallan talleres sobre ingeniería inversa con la herramienta Radar E2 y la automatización de tareas de ciberseguridad mediante la plataforma N8N. Para las compras del Black Friday, los expertos recomiendan verificar la oficialidad de los sitios, usar tarjetas virtuales y evitar conexiones a redes wifi abiertas. Por su parte, Francesco Colini, de FlashStart, resalta que el protocolo DNS es fundamental para la resiliencia de internet y funciona como una barrera preventiva contra el malware y el phishing. El audio concluye subrayando la necesidad de educar a los jóvenes en conceptos básicos de redes para fomentar una cultura de seguridad digital desde la base.
    Twitter:
    @ciberafterwork
    Instagram:
    @ciberafterwork
    Panda Security:
    https://www.pandasecurity.com/es/
    +info:
    https://psaneme.com/
    https://bitlifemedia.com/
    https://www.vapasec.com/
    VAPASEC
    https://www.vapasec.com/
    https://www.vapasec.com/webprotection/
    53 min
  • Episode 324: Strategies and challenges in cybersecurity incident response
    The program emphasizes that since cyberattacks are now considered inevitable, an agile and well-prepared incident response is crucial to control economic and operational damage. Experts analyzed a technical DNS failure at Amazon Web Services that caused a 16-hour global outage, affecting payment systems and multiple dependent services. Cybercriminals quickly exploited this chaos by launching opportunistic smishing campaigns, tricking users into making "secure" transfers while they were unable to pay with cards. Additionally, a massive attack on Jaguar Land Rover highlighted the vulnerability of supply chains and the difficulty of recovering specialized industrial (OT) environments. Antonio Sanz advocates for "21st-century backups" that are immutable and resilient against intentional destruction by modern ransomware groups. Sanz also introduces the "1/9/90 theory," noting that 90% of organizations lack proper cybersecurity investment and awareness until they suffer a major crisis. Effective response requires "forensic readiness," ensuring that logs and telemetry are preserved beforehand to allow for a successful investigation. Finally, specialists must act as "psychologists" for companies, providing calm, technical agility, and clear strategic guidance to management during a crisis.
    Twitter:
    @ciberafterwork
    Instagram:
    @ciberafterwork
    Panda Security:
    https://www.pandasecurity.com/es/
    +info:
    https://psaneme.com/
    https://bitlifemedia.com/
    https://www.vapasec.com/
    VAPASEC
    https://www.vapasec.com/
    https://www.vapasec.com/webprotection/
    19 min
  • Episodio 324: Estrategias y desafíos en la respuesta ante incidentes de ciberseguridad
    Este episodio analiza la inevitable naturaleza de los ciberataques y la importancia crítica de una gestión ágil en la respuesta ante incidentes para controlar daños económicos. Se destaca el caso de Amazon Web Services, donde un fallo técnico en el DNS fue aprovechado por criminales para lanzar campañas de smishing oportunista. Asimismo, el ataque a Jaguar Land Rover evidenció el impacto devastador en la cadena de suministro y los riesgos en entornos industriales (OT). El experto Antonio Sanz subraya la necesidad de evolucionar hacia copias de seguridad del siglo XXI, que sean inmutables y resilientes ante ataques intencionados. La preparación forense (forensic readiness) es fundamental para disponer de las evidencias necesarias, como logs y telemetría, tras un incidente. Sanz describe la realidad empresarial mediante la teoría del 1/9/90, señalando que muchas organizaciones aún carecen de inversión y concienciación adecuadas. En momentos de crisis, es vital combinar la rapidez técnica con un acompañamiento casi psicológico y una comunicación clara con la dirección de la empresa. Se concluye que la seguridad no es cuestión de suerte, sino de estrategia y prevención activa ante delincuentes cada vez más sofisticados.
    Twitter:
    @ciberafterwork
    Instagram:
    @ciberafterwork
    Panda Security:
    https://www.pandasecurity.com/es/
    +info:
    https://psaneme.com/
    https://bitlifemedia.com/
    https://www.vapasec.com/
    VAPASEC
    https://www.vapasec.com/
    https://www.vapasec.com/webprotection/
    55 min
  • Interview Román Ramírez y Ofelia Tejerina- RootedCON y Association of Internauts
    IP blocking aimed at stopping illegal football broadcasts causes significant collateral damage to innocent and lawful websites. By targeting shared IPs on platforms like Cloudflare, authorities inadvertently shut down thousands of legitimate small business operations. Experts describe this strategy as "killing flies with cannons" because pirates easily bypass blocks using VPNs or TOR. Legitimate companies suffer economic losses and reputational harm when their e-commerce sites or internal tools go offline. These blocks often extend past match times because operators forget to lift them, leaving sites down for several days. Legal experts argue these measures violate fundamental rights, including the freedom of enterprise and the right to information. Román Ramírez and Ofelia Tejerina have filed a constitutional appeal to challenge these disproportionate and harmful digital restrictions. Victims are urged to formally report every incident online to expose the true socio-economic impact of these actions.
    Twitter:
    @ciberafterwork
    Instagram:
    @ciberafterwork
    Panda Security:
    https://www.pandasecurity.com/es/
    +info:
    https://psaneme.com/
    https://bitlifemedia.com/
    https://www.vapasec.com/
    VAPASEC
    https://www.vapasec.com/
    https://www.vapasec.com/webprotection/
    20 min
  • Entrevista Román Ramírez y Ofelia Tejerina- RootedCON y ASOCIACIÓN DE INTERNAUTAS
    Los bloqueos de direcciones IP para combatir la piratería en el fútbol causan graves daños colaterales a sitios web lícitos. Al afectar IPs compartidas en plataformas como Cloudflare, se cierran injustamente negocios y herramientas de gestión de pequeñas empresas. Expertos califican esta estrategia como "matar moscas a cañonazos", pues impacta a miles de usuarios para intentar frenar a pocos. Jurídicamente, esto supone una lesión a la libertad de empresa y al derecho fundamental de recibir información,. Las medidas resultan ineficaces, ya que los infractores las evaden fácilmente usando VPN o el navegador TOR,. En ocasiones, el bloqueo se extiende más allá del horario del partido, dejando a comercios sin servicio hasta el lunes. Ante esta situación, se ha presentado un recurso de amparo ante el Tribunal Constitucional para defender los derechos digitales. Se recomienda a los afectados denunciar formalmente cada incidencia para visibilizar el impacto socioeconómico de estas restricciones desproporcionadas.
    Twitter:
    @ciberafterwork
    Instagram:
    @ciberafterwork
    Panda Security:
    https://www.pandasecurity.com/es/
    +info:
    https://psaneme.com/
    https://bitlifemedia.com/
    https://www.vapasec.com/
    VAPASEC
    https://www.vapasec.com/
    https://www.vapasec.com/webprotection/
    34 min
  • Episode 323: The Impact of La Liga’s IP Blocks and Global Cybersecurity Trends
    This episode of Cyber Afterwork examines the controversy surrounding IP address blocks ordered by La Liga to combat piracy, a measure that collaterally affects thousands of legitimate websites. Experts Román Ramírez and Ofelia Tejerina criticize this "broad-brush" technical approach for harming fundamental rights, such as the freedom of enterprise and the right to information. They highlight that these blocks are easily bypassed using VPNs or browsers like Tor, making them largely ineffective. In response, RootedCON has filed a constitutional appeal to protect the secrecy of communications. The program also discusses the surge in European telephone fraud (ID spoofing) and Russian cyberattacks targeting Japanese supply chains, including major household brands and breweries. Additionally, Bizum was fined €80,000 for a data scraping breach involving personal information. Finally, affected users are urged to report unjustified blocks to telecom authorities as the show reflects on the need for business models to evolve alongside technology.
    Twitter:
    @ciberafterwork
    Instagram:
    @ciberafterwork
    Panda Security:
    https://www.pandasecurity.com/es/
    +info:
    https://psaneme.com/
    https://bitlifemedia.com/
    https://www.vapasec.com/
    VAPASEC
    https://www.vapasec.com/
    https://www.vapasec.com/webprotection/
    15 min
  • Episodio 323: El impacto de los bloqueos de La Liga y la actualidad ciber
    Este episodio de Cyber Afterwork analiza la polémica sobre los bloqueos de direcciones IP ordenados por La Liga para frenar la piratería, una medida que afecta colateralmente a miles de sitios web legítimos. Los expertos invitados critican que se utilicen soluciones técnicas que "matan moscas a cañonazos", perjudicando el derecho a la información y la libertad de empresa. Se destaca que estos bloqueos son ineficaces, pues los infractores los eluden fácilmente mediante el uso de VPN o navegadores como Tor. Ante esta situación, la organización RootedCON ha presentado un recurso de amparo ante el Tribunal Constitucional para defender el secreto de las comunicaciones y los derechos fundamentales. El programa también aborda el preocupante incremento del fraude telefónico en Europa y el impacto de ciberataques rusos en la cadena de suministro de empresas en Japón. Asimismo, se comenta la multa de 80.000 euros impuesta a Bizum por una brecha de seguridad vinculada al scraping de datos personales. Finalmente, se insta a los usuarios y empresas afectados a denunciar los bloqueos injustificados ante las autoridades de telecomunicaciones. El episodio concluye reflexionando sobre la necesidad de que los modelos de negocio se adapten a la realidad tecnológica en lugar de vulnerar derechos ciudadanos.
    Twitter:
    @ciberafterwork
    Instagram:
    @ciberafterwork
    Panda Security:
    https://www.pandasecurity.com/es/
    +info:
    https://psaneme.com/
    https://bitlifemedia.com/
    https://www.vapasec.com/
    VAPASEC
    https://www.vapasec.com/
    https://www.vapasec.com/webprotection/
    53 min
  • Interview Antonio Sanz- S2 GRUPO
    Antonio Sanz, an expert from S2 Grupo, highlights that modern cyberattacks like the one on Jaguar Land Rover now target both IT and OT environments, causing massive operational disruptions. He describes current cybercrime as opportunistic, where attackers utilize advanced ransomware to pressure organizations by compromising their data and backups. To counter this, Sanz emphasizes the need for "21st-century backups"—resilient, immutable systems that protect against intentional deletion. He also introduces the concept of "forensic readiness," urging companies to preserve telemetry and logs to enable effective investigations after a breach. While Artificial Intelligence serves as a helpful tool for interpreting evidence, Sanz warns it still requires human supervision to ensure accuracy. Furthermore, he notes that incident response involves a psychological component, helping executives manage stress and make critical financial decisions during a crisis. Ultimately, a company's survival depends on speed of action and having clear, pre-defined procedures to minimize million-dollar daily losses. This shift in strategy reflects a growing maturity in the sector, prioritizing how an organization recovers and learns from an inevitable attack.
    Twitter:
    @ciberafterwork
    Instagram:
    @ciberafterwork
    Panda Security:
    https://www.pandasecurity.com/es/
    +info:
    https://psaneme.com/
    https://bitlifemedia.com/
    https://www.vapasec.com/
    VAPASEC
    https://www.vapasec.com/
    https://www.vapasec.com/webprotection/
    14 min
  • Entrevista Antonio Sanz- S2 GRUPO
    En esta entrevista, el experto Antonio Sanz analiza la importancia crítica de la respuesta ante incidentes tras el ataque a Jaguar Land Rover, el cual afectó tanto a entornos IT como OT. Explica que el cibercrimen actual es oportunista y utiliza ransomware de última generación para comprometer incluso las copias de seguridad, buscando maximizar el beneficio económico. Por ello, Sanz subraya la necesidad de implementar "backups del siglo XXI" que sean inmutables y resilientes ante ataques intencionados. Destaca además la evolución del sector en España, donde ha crecido la madurez técnica y el uso de herramientas de telemetría para la investigación forense. Sobre la Inteligencia Artificial, la considera un apoyo útil para interpretar evidencias, aunque advierte que aún requiere supervisión humana constante. El experto también resalta la faceta psicológica del trabajo, ayudando a las directivas a gestionar el estrés y tomar decisiones financieras bajo presión. Finalmente, enfatiza el concepto de "forensic readiness", instando a las empresas a preparar sus sistemas para conservar evidencias esenciales antes de que ocurra un desastre. La clave de una gestión exitosa reside en la rapidez de actuación y en disponer de procedimientos claros para minimizar las pérdidas millonarias.
    Twitter:
    @ciberafterwork
    Instagram:
    @ciberafterwork
    Panda Security:
    https://www.pandasecurity.com/es/
    +info:
    https://psaneme.com/
    https://bitlifemedia.com/
    https://www.vapasec.com/
    VAPASEC
    https://www.vapasec.com/
    https://www.vapasec.com/webprotection/
    31 min

About CiberAfterWork: ciberseguridad en Capital Radio

From the publisher's feed

Pablo San Emeterio y Mónica Valle acompañan a Eduardo Castillo en After Work para hablar sobre ciberseguridad con invitados y profesionales destacados del sector.

More shows like CiberAfterWork: ciberseguridad en Capital Radio

Nadie Sabe Nada by SER Podcast

Nadie Sabe Nada

402 Listeners