CiberAfterWork: ciberseguridad en Capital Radio

CiberAfterWork: ciberseguridad en Capital Radio

By psanemeTechnology
Download on the App Store

CiberAfterWork: ciberseguridad en Capital Radio episodes

  • Episode 322: Incident Response: Strategy and Survival
    This episode focuses on incident response, emphasizing that since attacks are inevitable, businesses must prioritize agile management to mitigate economic and operational damage. The experts analyze the 16-hour AWS outage caused by a DNS failure, which disrupted payment systems and was exploited by criminals to launch bank-impersonating smishing campaigns. They also discuss the Jaguar Land Rover attack, which cost nearly £2 billion, likely because the breach affected critical operational technology (OT) systems rather than just IT. Guest expert Antonio Sanz explains that ransomware has evolved into multiple extortion, where attackers steal data, contact clients, and deliberately destroy old-fashioned backups. To counter this, companies must adopt "21st-century backups" that are immutable or resilient against intentional destruction by hackers. Sanz notes that while 1% of firms have vast resources, 90% lack basic awareness, leaving them vulnerable to opportunistic attacks through credential leaks or a lack of multi-factor authentication. Forensic readiness is highlighted as a vital preparation step, ensuring that logs and evidence are preserved to allow for a proper investigation after a breach. Finally, Artificial Intelligence is viewed as a supportive tool for interpreting complex data, though it still requires human oversight to ensure accuracy.
    Twitter:
    @ciberafterwork
    Instagram:
    @ciberafterwork
    Panda Security:
    https://www.pandasecurity.com/es/
    +info:
    https://psaneme.com/
    https://bitlifemedia.com/
    https://www.vapasec.com/
    VAPASEC
    https://www.vapasec.com/
    https://www.vapasec.com/webprotection/
    19 min
  • Episodio 322: Respuesta ante incidentes: Estrategia y supervivencia
    Este programa analiza la respuesta ante incidentes enfatizando que los ataques son inevitables y la gestión posterior es crítica para minimizar daños económicos. Se explica el apagón de AWS, aclarando que fue un fallo técnico de DNS que duró 16 horas y provocó fallos masivos en pagos con tarjeta. Ciberdelincuentes aprovecharon esta interrupción para lanzar campañas rápidas de smishing, suplantando bancos para engañar a usuarios preocupados por sus transacciones. El caso de Jaguar Land Rover destaca por un impacto de casi 2.000 millones de libras, posiblemente debido a daños en sistemas de operación (OT). Los ataques de ransomware han evolucionado hacia la extorsión múltiple, incluyendo el robo de datos y la destrucción deliberada de copias de seguridad. Se subraya la necesidad de contar con backups resilientes e inmutables del "siglo XXI" para resistir ataques intencionados contra la propia recuperación. Antonio Sanz introduce la teoría del 1/9/90, señalando que la gran mayoría de organizaciones carece de una concienciación y presupuesto de seguridad básico. La prioridad durante una crisis debe ser mantener la calma y actuar con agilidad para reducir el tiempo de inactividad empresarial. La Inteligencia Artificial se valora como una herramienta de apoyo para interpretar comandos complejos, aunque aún requiere supervisión humana constante. Finalmente, se destaca el concepto de forensic readiness para asegurar que existan evidencias suficientes (logs) que permitan investigar el origen de un ataque.
    Twitter:
    @ciberafterwork
    Instagram:
    @ciberafterwork
    Panda Security:
    https://www.pandasecurity.com/es/
    +info:
    https://psaneme.com/
    https://bitlifemedia.com/
    https://www.vapasec.com/
    VAPASEC
    https://www.vapasec.com/
    https://www.vapasec.com/webprotection/
    53 min
  • Episode 321: Cybersecurity on the Web: Cloud Resilience and Digital Identity Protection
    This program features a detailed discussion on contemporary cybersecurity challenges, centered around a significant Amazon Web Services (AWS) technical outage. Experts Eduardo Castillo, Pablo San Emeterio, and Mónica Valle examine how this infrastructure failure disrupted global business availability and supply chains, emphasizing that security encompasses more than just preventing attacks. The dialogue introduces a new cyber threat intelligence report from Bapasec, which identifies trends such as automated IP scanning and the targeting of legacy systems. Additionally, the contributors highlight a data breach at Securitas Direct, illustrating the physical risks that arise when security firms are compromised. To address these vulnerabilities, the sources advocate for proactive digital hygiene, including robust password management, multifactor authentication, and the use of specialized scanners. The program concludes by promoting an upcoming national congress on digital fraud to further educate professionals on evolving cybercrime tactics.
    Twitter:
    @ciberafterwork
    Instagram:
    @ciberafterwork
    Panda Security:
    https://www.pandasecurity.com/es/
    +info:
    https://psaneme.com/
    https://bitlifemedia.com/
    https://www.vapasec.com/
    VAPASEC
    https://www.vapasec.com/
    https://www.vapasec.com/webprotection/
    23 min
  • Episodio 321: Ciberseguridad en la Red: Resiliencia Cloud y Protección de la Identidad Digital
    El episodio de Ciber Afterwork analiza un importante fallo técnico en Amazon Web Services que afectó la disponibilidad de servicios globales como Alexa y Prime Video. Pablo San Emeterio explica que el problema se debió a fallos en el protocolo DNS o en balanceadores de carga, impidiendo el acceso a bases de datos. Ante esto, se enfatiza la necesidad de estrategias multicloud para garantizar la resiliencia en la cadena de suministro tecnológica. También se aborda el incidente de Securitas Direct en Suecia, donde se comprometió información sensible, evidenciando que ninguna empresa es invulnerable. Herbé Lambert, de Panda Security, invita a reflexionar sobre la huella digital y el equipo necesario para navegar de forma segura. Lambert advierte que las consecuencias de un ciberataque varían desde el estrés por spam hasta pérdidas económicas de miles de euros y daños reputacionales. Como medidas de prevención, se sugiere realizar inventarios de dispositivos, usar autenticación multifactor y mantener copias de seguridad desconectadas. VapaSec presenta su informe de amenazas, destacando que los ataques suelen automatizarse y provenir mayoritariamente de Estados Unidos y España. Los atacantes buscan activamente paneles de inicio de sesión y archivos de configuración que puedan contener contraseñas expuestas. El programa concluye con la invitación al Congreso Nacional de Ciberseguridad en Fraude para debatir sobre cibercrimen y nuevas normativas.
    Twitter:
    @ciberafterwork
    Instagram:
    @ciberafterwork
    Panda Security:
    https://www.pandasecurity.com/es/
    +info:
    https://psaneme.com/
    https://bitlifemedia.com/
    https://www.vapasec.com/
    VAPASEC
    https://www.vapasec.com/
    https://www.vapasec.com/webprotection/
    53 min
  • Interview Josep Albor- ESET
    In this interview, ESET cybersecurity expert Josep Albors discusses the evolving landscape of digital threats within the video game industry. He explains how the shift toward online connectivity has expanded the attack surface, allowing criminals to use malicious game cracks, phishing links, and deceptive in-game chats to steal valuable account credentials or financial data. Beyond individual victims, Albors warns that gaming software can serve as a gateway into corporate networks through unpatched vulnerabilities or advanced "anti-cheat" tools that possess deep system access. The conversation highlights the rise of speculative virtual economies and the exploitation of vulnerable players, including minors and high-profile streamers. Ultimately, the expert emphasizes that while games are not inherently dangerous, users and guardians must maintain digital awareness and utilize security measures like two-factor authentication to mitigate risks.
    Twitter:
    @ciberafterwork
    Instagram:
    @ciberafterwork
    Panda Security:
    https://www.pandasecurity.com/es/
    +info:
    https://psaneme.com/
    https://bitlifemedia.com/
    https://www.vapasec.com/
    VAPASEC
    https://www.vapasec.com/
    https://www.vapasec.com/webprotection/
    16 min
  • Interview Josep Albor- ESET
    In this interview, ESET cybersecurity expert Josep Albors discusses the evolving landscape of digital threats within the video game industry. He explains how the shift toward online connectivity has expanded the attack surface, allowing criminals to use malicious game cracks, phishing links, and deceptive in-game chats to steal valuable account credentials or financial data. Beyond individual victims, Albors warns that gaming software can serve as a gateway into corporate networks through unpatched vulnerabilities or advanced "anti-cheat" tools that possess deep system access. The conversation highlights the rise of speculative virtual economies and the exploitation of vulnerable players, including minors and high-profile streamers. Ultimately, the expert emphasizes that while games are not inherently dangerous, users and guardians must maintain digital awareness and utilize security measures like two-factor authentication to mitigate risks.
    Twitter:
    @ciberafterwork
    Instagram:
    @ciberafterwork
    Panda Security:
    https://www.pandasecurity.com/es/
    +info:
    https://psaneme.com/
    https://bitlifemedia.com/
    https://www.vapasec.com/
    VAPASEC
    https://www.vapasec.com/
    https://www.vapasec.com/webprotection/
    16 min
  • Entrevista Josep Albor- ESET
    Josep Albors, especialista de ESET, analiza la evolución de los videojuegos hacia un modelo predominantemente online. Este cambio ha atraído a ciberdelincuentes que buscan beneficios económicos mediante el robo de credenciales y cuentas. Los atacantes utilizan "cracks" maliciosos que infectan dispositivos con troyanos bajo la promesa de software gratuito. Existe un mercado negro para el robo de objetos virtuales valiosos, como "skins" de alto coste monetario. Plataformas como Steam o Discord son usadas para distribuir malware o como centros de mando y control. Se menciona el peligro de usar dispositivos corporativos para jugar, abriendo puertas a redes empresariales. Los chats de juegos facilitan estafas dirigidas tanto a menores como a adultos mediante engaños emocionales. Se reportan casos graves, como el robo de donaciones a un streamer enfermo mediante un juego troyanizado. El experto advierte sobre los riesgos de seguridad de los sistemas antitrampas con permisos de nivel de kernel. La prevención técnica debe acompañarse de una mejor identificación de usuarios y gestión de vulnerabilidades. Albors subraya que es vital la concienciación y la implicación de los padres en la actividad lúdica de menores. El resumen concluye recomendando el Museo del Videojuego de Ibi para fomentar la cultura y seguridad digital.
    Twitter:
    @ciberafterwork
    Instagram:
    @ciberafterwork
    Panda Security:
    https://www.pandasecurity.com/es/
    +info:
    https://psaneme.com/
    https://bitlifemedia.com/
    https://www.vapasec.com/
    VAPASEC
    https://www.vapasec.com/
    https://www.vapasec.com/webprotection/
    30 min
  • Episode 320: The Dark Side of Video Games and Digital Identity
    This episode explores the evolving landscape of digital threats, specifically focusing on the online gaming industry and cybercrime-as-a-service. Experts discuss how video games serve as gateways for scams, credential theft, and corporate network intrusions, emphasizing that minors and adults alike are targets. The dialogue highlights a major Spanish law enforcement success against a "phishing-as-a-service" developer who sold professional-grade robbery kits to less technical criminals. Additionally, the text covers supply chain vulnerabilities through a data breach at Discord and common social engineering tactics used on WhatsApp. The overarching message stresses the importance of digital literacy, parental involvement in gaming, and robust corporate resilience to combat increasingly professionalized criminal structures.
    Twitter:
    @ciberafterwork
    Instagram:
    @ciberafterwork
    Panda Security:
    https://www.pandasecurity.com/es/
    +info:
    https://psaneme.com/
    https://bitlifemedia.com/
    https://www.vapasec.com/
    VAPASEC
    https://www.vapasec.com/
    https://www.vapasec.com/webprotection/
    13 min
  • Episodio 320: El Lado Oscuro de los Videojuegos y la Identidad Digital
    En este programa analizamos las tendencias actuales de la ciberdelincuencia, centrándose en el entorno de los videojuegos y la protección de la identidad digital. Los expertos comentan el reciente desmantelamiento de una red de phishing por la Guardia Civil que operaba bajo el modelo "Crime as a Service", facilitando herramientas para clonar páginas bancarias. En el ámbito del gaming, Josep Albors de ESET explica cómo los delincuentes utilizan chats y falsos "cracks" para infectar dispositivos y robar cuentas con activos valiosos, como los skins. Se exponen incidentes graves, como el compromiso de servidores de juegos para atacar a usuarios y el robo de criptomonedas a streamers mediante software troyanizado. El podcast también aborda el ataque a Discord a través de su proveedor Zendesk, el cual expuso documentos de identidad oficiales de miles de usuarios. En cuanto a redes sociales, se advierte contra las nuevas estafas en grupos de WhatsApp y se recomienda configurar la privacidad para evitar ser incluido en chats desconocidos. Los especialistas recalcan que la seguridad absoluta no existe y que es vital que los padres se involucren activamente en la vida digital de los menores para prevenir el ciberacoso. La charla también destaca la necesidad de la ciberresiliencia empresarial mediante modelos como "Zero Trust" para resistir y recuperarse de ataques inevitables. Se desmitifica que los videojuegos sean solo para niños, señalando que la media de edad del jugador supera los 30 años, lo que exige una mayor conciencia global. Finalmente, se invita a los oyentes a visitar el Museo del Videojuego de Ibi para fomentar la cultura y la seguridad en este sector. El episodio concluye enfatizando el uso del sentido común en entornos de ocio, donde solemos bajar la guardia ante posibles enlaces maliciosos.
    Twitter:
    @ciberafterwork
    Instagram:
    @ciberafterwork
    Panda Security:
    https://www.pandasecurity.com/es/
    +info:
    https://psaneme.com/
    https://bitlifemedia.com/
    https://www.vapasec.com/
    VAPASEC
    https://www.vapasec.com/
    https://www.vapasec.com/webprotection/
    53 min
  • Interview Juan Cobo y Pablo Vera- FERROVIAL y ZSCALER
    This discussion features Juan Cobo, the Global CISO of Ferrovial, and Pablo Vera from Zscaler as they examine the evolving landscape of corporate cybersecurity. They emphasize that risk management must be proactive, particularly as multinational companies face complex geopolitical threats and the rise of insider vulnerabilities caused by employee errors. A significant portion of the conversation focuses on Artificial Intelligence, identifying it as both a sophisticated tool for attackers and a vital defense mechanism for identifying behavioral anomalies. The experts advocate for a Zero Trust architecture to minimize attack surfaces and stress the necessity of industrializing recovery processes to ensure business resilience. Ultimately, they conclude that integrating security into the initial stages of digital transformation is essential for maintaining operational continuity in an increasingly volatile global environment.
    Twitter:
    @ciberafterwork
    Instagram:
    @ciberafterwork
    Panda Security:
    https://www.pandasecurity.com/es/
    +info:
    https://psaneme.com/
    https://bitlifemedia.com/
    https://www.vapasec.com/
    VAPASEC
    https://www.vapasec.com/
    https://www.vapasec.com/webprotection/
    18 min

About CiberAfterWork: ciberseguridad en Capital Radio

From the publisher's feed

Pablo San Emeterio y Mónica Valle acompañan a Eduardo Castillo en After Work para hablar sobre ciberseguridad con invitados y profesionales destacados del sector.

More shows like CiberAfterWork: ciberseguridad en Capital Radio

Nadie Sabe Nada by SER Podcast

Nadie Sabe Nada

403 Listeners