En esta sección se ofrecen contenidos de interés para los profesionales que manejan en su actividad diferentes lenguajes de programación, entornos de desarrollo, herramientas para garantizar la seguridad, analistas y auditores de código, criptógrafos, o especialistas en ingeniería inversa y malware.

Preventing the leaking of information in ICS

Posted on 28/05/2020, by
INCIBE (INCIBE)
Preventing the leaking of information in ICS
Exfiltration of data, or information leakage, poses a threat to all companies throughout the world. It is important to know the possible ways information can get out to control them and avoid a loss of information in our organisation. Since in industry the most important factor is availability, this threat has to be put into perspective.

Cyber-resilience: the key to overcoming incidents

Posted on 14/05/2020, by
INCIBE (INCIBE)
Cyber-resilience
The goal of cyber-resilience for an organization, whether or not it belongs to a strategic sector, whether or not it provides one of these digital services, is to maintain its primary purpose and integrity in the face of a cybersecurity threat or attack to an ideal level. Continuous detection processes must be established given that total prevention will never be guaranteed.

Sodinokibi: prevention, identification and response

Posted on 30/04/2020, by
INCIBE (INCIBE)
Sodinokibi
Sodinokibi uses the RaaS (Ramsonware as a Service) model, which favours its rapid spread. In this article we present some lines of action that should be followed in the case of having been a victim of this sophisticated malware or if it is suspected that it could have infected our systems.

NetWalker ransomware: analysis and preventative measures

Posted on 08/04/2020, by
INCIBE (INCIBE)
Decorative imagen
In the last few days there have been various reports, both nationally and internationally, of a ransomware campaign called NetWalker, also known as Mailto or Koko, which appears to target healthcare centers, taking advantage of the current state of alarm declared as a result of the COVID-19 pandemic.

Evolving towards secure Modbus

Posted on 20/02/2020, by
INCIBE (INCIBE)
Modbus decorative image
The Modbus protocol, in its TCP version, was not developed with cybersecurity capabilities in its communications. For this reason, many researchers have studied the different possibilities that could be undertaken at the technical level to incorporate a security layer in it, giving rise to a new version of Modbus/TCP called secure Modbus/TCP, which will gradually begin to be implemented in industrial communications.
Etiquetas

Safety recommendations for electric vehicle charging stations

Posted on 06/02/2020, by
INCIBE (INCIBE)
station
Over the last few years we have seen how electric vehicles have experienced a boom in terms of their development and retail and, along with them, the deployment of their charging points. In this article we will discuss a series of requirements, in terms of security, that should be implemented in these charging stations in order to ensure their security.

Secure use of communications and protocols at charging stations

Posted on 09/01/2020, by
INCIBE (INCIBE)
communications and protocols
Electric charging stations are increasingly used in urban furniture in cities. Electric cars and their need to be charged are a reality. Because of this, there is an increase in supply points that depend on specific protocols and communications for these stations.

Attacking a BusyBox, the small Gaulish village

Posted on 05/09/2019, by
INCIBE (INCIBE)
Busybox
A BusyBox is software or a program that combines several functionalities in a small executable. This small tool was created for use in integrated operating systems with very limited resources, and they are usually used in control systems. But, as in all tools, you have to know what security level they have and if it can be improved.

Measuring the severity of vulnerabilities: changes in CVSS 3.1

Posted on 01/08/2019, by
Hugo Rodríguez Santos (INCIBE)
CVSS3.1
The open and most-widely-used framework for communication and vulnerability scoring, the CVSS (Common Vulnerability Scoring System), has been updated, incorporating improvements in its new version 3.1 with respect to the previous one. This standard assesses the severity of computer systems vulnerabilities and assigns them a score of 0 to 10.

Protect your DNS requests with DNS over TLS

Posted on 04/07/2019, by
Ignacio Porro Sáez (INCIBE)
Protect
Security breaches that put our privacy at risk, leaks of our data, passwords... are incidents that happen more and more often. Protecting ourselves from these information leaks is often beyond our reach, but this does not mean that we should not try to take measures to protect our data. DNS-over-TLS can be very helpful in encrypting our communications, making them much more secure.