Search Results for: cloud

Cloud Security Solutions: the new paradigm

Just as green shoots flood our fields after a cool spring night, waking us up with the promise of stalks determined to germinate, so we wake up one day to the emergence of a new paradigm: the dawn of Cloud Security.

If for a moment we decide to do some research on this subject, we will discover a painful tendency to use four acronyms to designate new concerns whose existence was absolutely unknown a few years ago. In this infinite universe we will find the CISPA or Cloud Infrastructure Security Posture Assessment, but also the CWPPS, or Cloud Workload Protection Platform, without forgetting the CASBs or Cloud Access Security Brokers or the CNAPP or Cloud-Native Application Protection Platform.

If at this point you have survived this string of names, I will understand your sincere interest in this new science, so allow me to take a step back and comment on the reason for this curious amalgam of new security solutions.

[Read more…]

Cloud: building from security

Continuing this series of posts related to the cloud, it’s time to talk about how to face the world of possibilities that the cloud offers. This article aims to shed some light on such a huge task and to show different aspects to be taken into account. It is an interesting path, with multiple options, which can bring enormous value both to the business and to our quality of life, as long as it is approached from an objective, realistic and critical point of view. We should not be reticent to change, but neither should we apply change for change’s sake.

La imagen tiene un atributo ALT vacío; su nombre de archivo es image-35.png

Leaving philosophical mantras aside, saying that the cloud is the panacea makes as little sense as saying that the cloud does not bring value to the business.

As always, and sorry for the insistence, it will depend on each organization and its needs. What is fundamental, within the analysis of the business case and in calculating the return on investment of the implementation of these new technological paradigms, is that the consequences, needs and capabilities of security are considered. Both in the process of migration to the cloud, as well as in the face of any technological change.

Having said this, and getting to the point, there is no doubt that migrating to the cloud has a significant cost. Whether this cost is greater or lesser will depend on how you compare, but it can be said that it is not a “cheap” decision. If we do the simple exercise of comparing a physical server to a cloud server, the difference is fairly clear. However, putting everything into context, and above all, emphasizing security, there are many other costs to be assessed.

[Read more…]

Cloud meets business continuity

Following the introductory cloud post a few days ago, and to avoid losing momentum, we are going to keep talking about the cloud, in an area where it seems particularly useful: business continuity. Along with other measures, it is clear that the existence of globally distributed datacenters (did someone say GDPR?), flexible system scaling and almost instantaneous deployment make a cloud infrastructure (on equal terms) more resilient to outages than an on-premise infrastructure. Of course, availability is not the only factor to consider, but we’ll talk about that another day.

However, to speak of the benefits of the cloud, the providers do themselves a pretty good job. What I want to talk about is some of the issues that must be considered before migrating an infrastructure to the cloud (although some of these points are also applicable to PaaS and SaaS). That is: the problems.

[Read more…]

There’s no cloud, it’s just…

By now, everyone knows what the cloud is. Many of our readers probably have hosted services in the cloud or projects underway to migrate to it. That is because, while it has changed significantly since Salesforce started with its SaaS in 1999, it’s a model that, as we know it today, has been around for well over a decade.

It is true that the number of players has grown significantly, processes have been consolidated and the number of services has increased (and continues to do so), and new standards, organizations and certifications have appeared (and continue to do so) linked to this new paradigm, but with more or less detail, we are now understanding what this “cloud” thing is all about.

And perhaps the problem is that “we are now understanding” or “with more or less detail”, because it is clear that, always generalizing, there is still a long way to go in the adoption and integration of purely cloud practices, and of course, in the implementation of the secure cloud. And that is precisely the idea of this series: to start from that “more or less detail” to gradually increase the degree of depth.

[Read more…]

Real Cloud Security

(Please note this post was originally published in the Spanish version of Security Art Work last 2nd Oct 2012)

Act I: The cloud

(In a small room we find the Chief Executive Officer (CEO), the Chief Security Officer (CSO) and the Chief Marketing Officer (CMO). The latter comes with a PC World magazine under his arm)

CMO: Blablablabla Cloud blablabla costs blablabla availability blablablabla Google.
CSO: Blablabla SLA blablabla, blablabla privacy, blablabla blablabla outsourcing, blablabla.
CEO: Blablablabla dollars, blablabla staff, IT blablabla servers. ¿Security? Blablablabla.
CSO: Blablabla, blablabla SOX, penalties, blablabla data theft blablabla, blablabla press. Blablabla impact and risk.
CMO: Insecure? Hahahaha, blablabla, blablabla and blablabla. CSO blablabla, distrust. Blabla, blabla, Gartner, blablabla?? Blablablabla. That does not happen.
CEO: blablablabla CIO, blablabla blablabla IT budget.
CSO: Alea jacta est.

Act II: Hunky-dory

(While the Chief Executive Officer looks at the Chief Marketing Officer tablet, they see the Chief Security Officer, who quickens the pace but is intercepted in the aisle)

CMO: Blablabla access, blablabla iPad, iPhone. Blablabla? CSO? Blablabla, this security guys blablabla. Access, blablabla, password blablabla, blablabla SSL.
CEO: Blablabla friendly, blabla, blablabla success. Blablablabla reason blabla costs, blablabla enterprise 2.0.
CSO: Pater Noster qui es in caelis, sanctificétur nomen Tuum

Act III: A small problem

(There is a problem in the Marshall Islands that has disabled the connection to the cloud provider, and althought it is not known yet, may have caused data loss)

CEO: Blablabla connection, blabla deletion, blablabla access. Blablablabla data, blablabla cloud!!
CMO: Blablablabla probability blabla blablablabla Gartner CIO, blabla CSO .
CSO: Blablabla risk, blablabla impact, blabla quality of service, blablabla Google.
CEO: Blablabla reputation, blablabla bussiness, blablabla Google!
CMO: …
CSO: …

Act IV: Choose Your Own Adventure

(Do you remember these books? ;)

Option #1

CSO: Blablabla backup, blabla fireproof, blablablabla recovery blablabla system.
CEO: Muacs.

Option #2

10 CEO: …
20 CMO: …
30 CSO: …
goto 10

Option #3

CSO: Blablablabla ¿CIO?
CIO: Blablabla, Terms of Service, blablablabla complaint, blablabla compensation, blablablabla.
CEO: Blablabla data, blablabla available blablabla #@!*& blablabla ten dollars.

Well, how did finished the adventure in the cloud?

If you’ve been able to continue this conversation, you might like this video that our colleague Adrian has found:

The Role of Iran’s IRGC and MOIS before and during the conflict with the United States and Israel

This article focuses on analyzing the most active threat actors in the context of the conflict involving Iran, United States, and Israel, as well as the U.S. operation known as Operation Epic Fury. The goal is to gain a deeper understanding of their operations, modus operandi, victimology, and other key aspects of their activity. In this installment, the focus is on cyber operations linked to the Islamic Revolutionary Guard Corps (IRGC) and the Ministry of Intelligence and Security of Iran (MOIS).

On February 28, 2026, the United States and Israel launched a large-scale joint offensive known as Operation Epic Fury (U.S.) and Operation Roaring Lion (Israel). Following the initial strikes, Iran responded with a multi-front retaliatory campaign that gradually escalated over the following days, evolving into a large-scale transregional conflict.

[Read more…]

Alignment in cyber tradecraft and Resilient Detection

For years, I have been focused on finding the optimal way to detect threats. However, this is a highly complex task, as there is no absolute method to definitively determine whether an activity is malicious, unless you only rely on low-level indicators. It is true that certain behaviors can be considered malicious in most cases, such as a process loaded from AppData using a TrustedInstaller token, but this is not something that occurs frequently. In other scenarios, such as the use of anti-debugging techniques in BOF (Beacon Object File) through NtDelayExecution, identifying the optimal detection point can range from simply searching for the sleep import in an executable to inspecting thread call stacks. While both approaches are effective, thread stack analysis is significantly more precise, though at a higher cost than analyzing an executable’s import table. This reality highlights the need to establish a strategy that enables defensive teams to do more with less, which is why I will discuss the concept of Resilient Detection, not only from a technical standpoint but also from a broader, strategic perspective.

First and foremost, it is necessary to understand the current ecosystem. Today, and particularly in this part of the hemisphere, the digital ecosystem is composed of Windows and Unix systems, major public cloud environments (Azure, GCP, and AWS), the global supply chain, Artificial Intelligence and essential services such as email, identity, and application platforms. The dynamic nature of this ecosystem introduces new needs, opportunities, and challenges for adversaries and, in parallel, new detection strategies.

Read the article

ATT&CK: The game of squares

The world of cybersecurity is becoming increasingly complex and challenging. With each new threat, from harmful capabilities such as malware or 0 days, to changes in infrastructure, having moved from on-premise to hybrid or full-cloud environments, there is an urgent need for schemes and methodologies to help address these adversities. We not only seek to minimize the impact of any threat, but also to achieve a level of detection and neutralization with which we feel confident, although this can often give a false sense of security.

Today we find various schemes that help us understand and contextualize the modus operandi of hostile actors. From the widely recognized MITRE to the Malware Behavior Catalogue (MBC), through Microsoft Attack Kill Chain and Lockheed Cyber Kill Chain, these tools offer us a guide to understand and confront the tactics, techniques and procedures (TTPs) used by adversaries. Within this scenario MITRE ATT&CK is the most recognized scheme. Its matrix breaks down the different techniques, tactics and procedures (TTPs) used by hostile actors.

Imagen 1: Ejemplo de Mitre ATT&CK
[Read more…]

Android Pentesting (I): Environment Configuration

In this article we will try to explain step by step in the simplest possible way how to create a working environment to perform an ethical hacking on an Android device application, so that it can be done by anyone regardless of the knowledge they have.

The first step is to create a working environment to start an audit of mobile applications on Android. To do this, we will look at several mobile device emulators and choose one in which to mount our environment.

Some emulators on the market

First, let’s explain what an emulator is. This word comes from the Latin word aemulātor (emulates), which means something that imitates the operation of something else. Wikipedia defines it as follows: “In computing, an emulator is software that allows programs or video games to run on a platform (either a hardware architecture or an operating system) different from the one for which they were originally written. Unlike a simulator, which merely attempts to reproduce the behavior of the program, an emulator attempts to accurately model the device so that the program works as if it were being used on the original device”.

[Read more…]

Health 4.0: the importance of cybersecurity in the healthcare area

The concept of Health 4.0 emerges as a specific derivation of Industry 4.0. But what is Industry 4.0? This concept arises in Germany in 2011, as a project to improve the industry but without a clear definition (see reference at the end of the article).

From this moment on, Industry 4.0 has been appearing with different interpretations, although there is a unified definition. Industry 4.0 is an umbrella that encompasses nine technologies that help in the transformation of industrial production and process automation.

These technologies are:

  • Big Data and Data Analysis
  • Simulation
  • Internet of Things (IoT)
  • Augmented Reality
  • Cloud Computing
  • Additive Manufacturing
  • Autonomous robotics
  • Cybersecurity
  • Integration systems
read more