
Press archive
Press archive
Over two decades of press, radio and television appearances on cybersecurity, hacking and artificial intelligence.
143 entries
2026

2025

Videoblog de "Pasión por el Despacho"

Granjas de Bots

They reveal to the CNI their chats with hacktivists
Summary
Rafa, the Cibercapitan, and I took to the CCN-CERT's STIC conference, the centre under Spain's CNI, a talk on hacktivism and psychological operations in cyberspace. We showed the real conversations we held with four pro-Russian groups, among them NoName057(16), which I link to this year's attacks on Vitrasa and the councils of Vigo and Lugo. I stress an uncomfortable idea: these aren't four kids at home, they're highly organised, resilient people who live for this out of conviction, and they attack Spain for its support of NATO.

AI is here to stay
Summary
Artificial intelligence is here to stay and will make a great deal of work easier, but with the speed at which it has entered our lives many people haven't gauged the risks. I'm an advocate of using it while being aware of the dangers of its misuse, starting with watching who we hand our data to. And I warn that cybercriminals already use it to automate attacks, sharpen scams in any language and build deepfakes that impersonate identities.

The 'Holy League': the alliance between jihadists and pro-Russians
Summary
Groups that on paper detest each other, pro-Russian hacktivists, jihadists and those aligned with China or Iran, set aside their differences and coordinate under a single banner to strike the West. In this report, tied to the National Cryptologic Centre's conference, I explain why that alliance works: each one believes it's doing the right thing and they're all united by a common goal. They range from denial-of-service attacks to the theft and sale of company and industrial data to the highest bidder.
Ethics and freedom as pillars of digital security
Summary
In this interview I go over what drives me after more than two decades in this field: as I often say, some people simply don't want to watch the world burn. I argue that cybersecurity is an inherent part of the business, that sooner or later we'll all be vulnerable to an attack and that there's no longer any separation between digital life and physical life. And I stand up for hacker culture, community and privacy, because privacy is essential to being free.

Cybersecurity is an investment
Summary
In this interview at the CTV Forum in A Coruna I make a point I never tire of repeating: security is not an expense, it is part of the design of any project from day one. I also warn that Spain has let the artificial intelligence and cybersecurity train pass, and risks missing the quantum one too. And I recall a figure that still stings, the British company that lost twenty-four million euros to a fraud using synthetic voice and image.
TV
Robo de Datos Médicos

Artificial Intelligence and Cybersecurity
Summary
AI plays on both sides: it drives up the sophistication of attacks, but it also lets us defend ourselves better. I show it with a real case, the fake video in which Marta Ortega offered a supposed miracle investment opportunity, and I explain that today it's enough to run the link through a detector to see it's almost certainly fake. On the defensive side, a computer receives thousands of attacks a day and without AI it would be impossible to review them one by one; with it we extract patterns and tell the real from the false positive.

Ciberseguridad en Crossover

Mi vida contada para ANFAIA

Dark Web en The Wild Project

Working with the City of Malaga
Summary
I was part of a commission of twenty experts that reviewed and strengthened the City of Malaga's Cybersecurity Strategy, alongside people from Madrid's Cybersecurity Centre, the State Digital Administration Agency and the Bank of Spain. What I liked most is that Malaga doesn't stop at the technical, it also works on the social and awareness side. I hope more cities take on this kind of initiative and don't limit themselves to following the national and regional ones.

25 años del Malware "I Love You"

Ciberseguridad en Infraestructuras críticas

Opinion on attacks against the power grid
Summary
On the great blackout of 28 April I stayed cautious: I lean more towards a technical fault than a cyberattack, among other reasons because industrial networks have no direct internet access. I rule out that groups like Dark Storm or NoName, which claimed it on social media, had that capability, because their thing is denial of service, not bringing down a power grid. And I add a thought: if a government wanted to destabilise a country with a blackout, it wouldn't do it on a Monday, but on a weekend, when the technicians are off.

Fault or cyberattack?
Summary
When half the peninsula went dark, many rushed to talk of a cyberattack. In this piece I put the brakes on: if it really had been an attack, we'd know where it came from, with the diplomatic consequences that drags along. I go over the real precedents, like the blackouts caused in Ukraine with malware such as BlackEnergy or Industroyer, but I remind everyone that a technical fault is still the most common explanation.

La teoría del Ciberataque

Sobre el apagón de España

Estafas DeepFake

Phishing and tabnabbing
Summary
I explain for Newtral what tabnabbing is, that phishing technique which changes the content of a tab you've left open in the background in order to impersonate a website and steal your credentials. Behind it is a piece of JavaScript that rewrites the page while you're not looking. On mobile it's less likely to happen, because of how browsers manage battery, and the best defence is to keep your software updated and always check the website where you're about to enter your data.
El origen del teclado QWERTY

Hablando de la Dark Web en Tiempo de Juego

Best practices for Artificial Intelligence
Summary
I'm collaborating with the European AI Office on drafting the first code of best practices for general-purpose AI, alongside a thousand experts, companies and member states. I take part online from Vigo in the risk and cybersecurity groups, because I want the technology being born to be secure and for no one, governments included, to be able to manipulate its results. I don't draft the text, but I contribute ideas and debate to the people in the working groups.

Deep Web, Dark Web, Dark Net y Sicarios

Entrevista en Azodose

Data breach at Telefonica
Summary
The Hellcat group, which appeared in late 2024, got into Telefonica's internal ticketing system using compromised employee credentials and made off with some 2.3 GB of data. In this analysis I offer a reading worth keeping in mind: an incident like this hits mainly on the inside, the company's own operations, more than its customers.

Can the Attorney General's messages be recovered?
Summary
Can deleted messages be recovered from a phone? In this article I explain it without the smoke. Carriers keep the metadata of calls and texts for about twelve months, but not their content; the rest is the domain of the digital forensics expert, with tools like Cellebrite and cloud backups. And I add a key nuance: within a couple of days you can tell what can be extracted from a phone, though it's often a matter of hours.

Entrevista en O Economista · Colegio Economistas A Coruña
2024

Piratería, multas y Roja Directa

Quincemil Tech Meeting
Summary
At this Quincemil Tech Meeting I drop a figure that tends to throw people: if cybercrime were a country, it would be the world's eighth-largest economy by GDP, far above the drug trade. I explain how ransomware has become an affiliate business that recruits even people with no technical knowledge, and why buying expensive tools without staff to run them is useless. The point I want to land is simple: investing in protection always works out cheaper than recovering from an attack.

Pódcast CyberMindful con Sandra Estok

DanaCon charity event for the Valencia flood victims
Summary
With Martin Vigo I helped put together DanaCON Solidario, an online cybersecurity congress to raise donations for those affected by the Valencia floods. We brought together forty-eight speakers from Spain and Latin America across two twelve-hour days, with the donations going straight to Caritas, World Central Kitchen or the Food Bank. It wasn't the first: earlier we ran CoronaCON against covid, which raised forty thousand euros. Ours is a sector that pulls together.

Geopolitics, digital sovereignty and compliance
Summary
In this debate with Marlon Molina we go over the real state of cybersecurity without mincing words, beyond the purely technical. We talk about geopolitics, digital sovereignty and why regulatory compliance has become a critical piece of the defence. An analysis meant for those who have to make decisions, not only for whoever is sitting at the console.

Cyberscams and personal data
Summary
I comment on the case of a man from Vigo investigated over a cyberscam with some three hundred victims across Spain, who opened online accounts with other people's data to move and invest the money without leaving a trace. I recall that for years now cybercrime has moved more money than the drug trade, so scams like this aren't done by people who are bored. My usual recommendations: proper passwords and a password manager, two-factor authentication and antivirus on every device, the phone included.

Podcast sobre Bug Bounty y Ciberseguridad

Ciberguerra en el Líbano

Attacks on Hezbollah's pagers
Summary
I analyse for ABC how Mossad could have sabotaged Hezbollah's pagers to make them explode all at once. It had to be a lightning-fast operation: either they were pre-modified at the factory or done in a hurry, with a tracking code, because a shipment sitting still for long would have raised suspicion. I compare it to our storm emergency alerts, a first message so everyone takes the pager out of their pocket and a second one for the detonation. It was very well planned.

Ciberseguridad y Hackers

Ciberseguridad en RNE
Dos expertos de Ciberseguridad felicitados por la NASA
TV
Fallos de seguridad en la web de NASA

NASA and Bug Bounty
Summary
A colleague and I challenged each other to see who would find a flaw on NASA's website first, and we ended up tied: we both managed it at almost the same time and the agency sent each of us a thank-you letter from its headquarters in Washington. The one I found could have allowed users' credentials to be stolen, and it wasn't easy at all, because NASA has things very well secured. That's the beauty of bounty programmes: you open the door to a thousand eyes watching over your organisation's security.

Global incident with CrowdStrike
Summary
On the same CrowdStrike incident I explain why it was so hard to fix: many machines had to be repaired by hand, and if you have five you do it, but imagine someone with two or three thousand. On top of that they broke a basic rule of the trade, never push anything to production on a Friday. It's another reminder that in Europe we depend too much on outside players and that we ought to develop some digital sovereignty, with our own services.

Opinion on CrowdStrike and digital sovereignty
Summary
The global IT outage of July 2024 wasn't Microsoft's, it was a CrowdStrike error while updating its product, and it took down almost all our clients, even Microsoft's cloud. I take the chance to insist on our technological dependence: we live at the mercy of US antivirus and US cloud, they press a button and we're left with no access even if the data is in Europe. CrowdStrike is a cutting-edge company, but the fault was theirs, not a change in Windows.

Privacy in the Digital Wallet
Summary
I reviewed the technical documentation of the Digital Wallet the government wanted to use to control minors' access to pornography, and I dismantled the claim that it was anonymous: the moment you contact its server they identify you by the public key, and there's an ID field and the device's IP. If the government wants to, it will be able to know who uses the app. Besides, it's not much use, because it only affects Spanish sites and there are ways around it; parental controls would be a better solution.

Cyberattacks and geopolitics
Summary
I link the wave of attacks on Iberdrola, Telefonica, Santander and the DGT to geopolitics: lately we've been on bad terms with some countries, and Russia and Israel are among the biggest cybersecurity powers. The Santander case was a supply-chain attack, through a third party. I insist that organisations still see cybersecurity as an expense when it's an investment, and that behind this there are no hooded kids, but mafias out for money.

Entrevista en "Con P de Podcast"

The future of cybersecurity: a map with two main streets
Summary
In this report on the future of cybersecurity I bring the ethical-hacking view: we hackers are the good guys, cybercriminals the bad. I foresee more cybercrime for money and more scams with AI and deepfakes, and I recount the RootedCon demo in which my voice sounded like a CEO's in real time. I repeat two ideas that obsess me: since 2017 cybercrime has moved more than the drug trade, and we're dangerously dependent on foreign technology, because in a global conflict one button strips us of those services.

The keys to avoiding cyberscams
Summary
Faced with the surge in cyberscams in Galicia I sum up the defence in two words: distrust and verify, or put another way, what you wouldn't do in the street don't do online. I warn that the bad guys already use AI too to clone voices and images in fake videos and fraudulent ads, and that we're working on apps to detect those forgeries, though they have all the time and money in the world. Strong passwords, different for each site, and two-factor authentication.

Artificial Intelligence project with OdiseIA and Google.org
Summary
Google.org selected three of us from OdiseIA in Vigo for its Digital Futures Project fund, and I got to lead a group exploring how AI affects companies' cybersecurity. The goal is to create an easy-to-understand best-practices guide that helps them defend themselves better against attacks. I do it out of vocation, not for money, because the bad guys are about to have far more tools at their disposal.

Las empresas deben apostar por expertos en Ciberseguridad
Hablando sobre Ciberdelincuencia en la Televisión de Galicia

Equipo de Investigación · La Estafa del Nini

Podcast Café & Pizza · Lo que hizo este hacker te sorprenderá

Copiando voz de CEO para Fraude

Technology exists thanks to hackers
Summary
In this interview I tell how I started at fourteen tinkering with Infovia and a chat room called Axis, when it was trivial to get into the PC of anyone connected by modem. I make the case that a hacker is not a criminal and that much of the technology we use, the internet included, exists thanks to hackers, and that won't change. I also recall a figure I repeat a lot: six out of ten SMEs that suffer a cyberattack end up shutting their doors.

The depths of Telegram
Summary
Telegram has become a bazaar where drugs, pirated football, pornography and even the coordination of attacks on companies and media all live side by side. In this report I sum it up bluntly: it's no exaggeration to say Telegram is the new deep web. And I point out where the real danger lies for the ordinary user, in the files you download loaded with malware.

CEO deepfake fraud at RootedCon
Summary
With Daniel Fernandez I demonstrated at RootedCon how easy it is to clone an executive's voice with AI for the CEO scam. I gave the talk while a machine swapped my voice in real time for that of a well-known CEO, with a gaming laptop worth about fourteen hundred euros and free software. I warn that generative AI multiplies fraud, from phishing in perfect Spanish to the twenty-four-million-euro con a British company suffered, and that, while regulating is good, the bad guys will stay one step ahead.

Cybersecurity posture
Summary
Here I argue that having a good cybersecurity posture isn't a luxury, it's what lets a company grow and keep fighting in the market. I recall a figure that should keep any executive up at night: six out of ten SMEs that suffer a cyberattack end up closing. And I warn against those selling magic solutions, because real security is about accompanying the company, not palming off a generic product on it.

Podcast con Lorenzo Martínez (Lawwait)

Podcast con Lucas Riggio

Reconocimiento facial en aeropuertos
2023

"Es muy fácil entrar en la deep web" · Antonio Fernandes, Hacker

De Hacker a Hacker: Entrevista de Pablo González

A fake email brings down the town council
Summary
I comment on the cyberattack against the Cangas town council, which began with a fake email to a civil servant and turned out to be ransomware, LockBit 3.0, that knocked out half the municipal staff and blocked the payroll. I suspect the same gang that shortly before had stolen data from the Galician operator R, and I point out there may be more councils in Pontevedra affected. LockBit is one of the most prolific groups in the world.

Antonio Fernandes · Hacker de la vieja escuela

Un mail hackeado le cuesta 100.000 euros a un empresario

Entrevista en Securiters
Hablamos mucho de ciberataques, pero la propaganda modifica el comportamiento

Tus datos: no solo TikTok, ni solo en Pekín

CISO y dirección IT · Entrevista a Antonio Fernandes

¿Quién está detrás del ciberataque al Clínic de Barcelona?
¿Por qué Estados Unidos quiere prohibir TikTok?
Todo es Mentira y el uso de TikTok
2022

Digital gatherings on campus
Summary
I took part as a guest in the Decembro Maker Talks digital-culture gatherings, on the Ourense campus, within the provincial council's Emprende Makers project. The programme brought together cybersecurity, the internet of things, robotics, 3D printing and video games, with speakers from the sector and the presentation of the Talento Maker awards.

The Wild Project #172 ft Antonio Fernandes (Hacker)

España, uno de los países más atacados

Aprendemos as claves para protexer unha empresa

Communicator of the Year award in Cybersecurity
Summary
I received the Pericia Tecnologica award for communicator of the year in Cybersecurity, presented by the PETEC association at the National Police Academy in Avila. It's recognition of twenty years spreading the word, training and organising events like ViCON. It happened to mark two decades since my first talk on Linux and security, so it was a path that led somewhere.

EP131: Navegadores dentro de TikTok y Facebook + Zatko

The students of the industrial cybersecurity course
Summary
I took part in the closing of the first edition of the University of Vigo's industrial cybersecurity specialist course, a one-of-a-kind programme in Galicia that sold out its places with working industry professionals. Siemens described that first cohort's job prospects as strong.
Prensa
The cyberattacks of the future
Summary
On how threats will evolve, I think there'll be a specialisation by sector to reach more customers: the malware of the future will target industries, governments and political parties, to get more return on the effort. I also expect a rise in supply-chain attacks, driven by economic interests according to what the market demands.
Que é Pegasus? Como se espía nas redes?

La otra cara de los códigos QR y el peligro que suponen

The mafias want a lot of money fast
Summary
In the middle of the panic over Russian cyberattacks following the invasion of Ukraine, I call for calm against the alarmism: many of those measures have been advised for years. I warn that not all the mafias are in Russia, there are some in Spain too, and that they range from the petty scammer to the organised super-mafia. I sum it up with an image: burglars don't go for the house with the most alarms, but the least protected one, and the mafias are after cash, so they attack the least protected system.

Companies and institutions 'shield' themselves against a surge
Summary
I explain that for some time now we've been living a cyber cold war with Russia and China at the front, and that attacks on the media have grown, because if you control the information you've won half the war. I warn that utilities and banks will suffer more attacks as essential services, and that many gangs are backed by governments. Against that, common sense: antivirus, two-factor, VirusTotal and keeping everything updated, because 100% security doesn't exist, but you can put up obstacles.

Galician civil servants, protected against Russia
Summary
On the cyberwar in Ukraine I play down the drama: there have always been cyberattacks, I don't see any special surge against ordinary citizens. In Galicia, with Amtega, civil servants are fairly secure and a lot is being done, like the Galician cybersecurity hub, though resources are short. I warn that NATO should be careful, because attributing an attack to a country is hard, with plenty of false flags and murky interests in play.

Bot attack on Ukrainian infrastructure
Summary
I comment on the cyber dimension of Russia's invasion of Ukraine, the first hybrid war between countries. I confirm that the Russians were launching denial-of-service attacks against Ukrainian entities and that this was spilling over onto its banking too. Even before the tanks arrived, dormant trojans had already been triggered in Ukrainian servers.

How to escape the 'mafia' that steals your bank details
Summary
I explain how to escape the phishing and smishing that impersonate your bank: behind it there aren't two bored guys at home, but well-organised mafias playing cat and mouse. My rule is simple, if you're not expecting any delivery, that email isn't for you; and faced with any alert, always go to the official website instead of clicking the link, checking that the domain has nothing to do with the real company. Different passwords, updated software and, when in doubt, Incibe's 017 helpline.
2021

A hacker is always a good thing
Summary
In this interview after Ciber.gal I argue that a hacker is always a good thing: a curious mind that wants to understand how things work, and whoever uses that knowledge to do harm is a cybercriminal, not a hacker. I warn that companies aren't prepared and still treat cybersecurity as an expense when it's an investment, because this isn't only about buying expensive technology, it's about processes and people. In Galicia we don't even reach a dozen people dedicated to this.
Ciber.gal y Cibercrimen
Prensa
More sophisticated malware
Summary
On the malware of the future I insist on specialisation by sector to reach more customers, with attacks aimed at industries, governments and parties to get more return on the effort. I also foresee more supply-chain attacks, geared to serving economic interests according to what the market demands.

Entrevista con Lord Draugr

EUROPOL detecta la oferta de VACUNAS FALSAS

Charla con Enrique de Vicente sobre Cyber Polygon

In cybersecurity, the bad guys are ahead
Summary
In this interview I start from an uncomfortable asymmetry: attackers are ahead because they have money, highly skilled people and do only this, while the defender has to protect every front at once and it's enough for one to fail. I give examples like Colonial, which didn't even have a head of cybersecurity, and I compare the European framework, with the NIS directive setting mandatory minimums, against a US model that leaves critical infrastructure in private hands. And I call for more investment in the state's forces to move from reacting to anticipating.
"Levamos uns cantos anos nunha especie de ciberguerra fría"

CosasDeHackers · Hablamos de Bug Bounty

The virtual world is more dangerous, you don't know how far it can go
Summary
I regret that companies aren't prepared for a cyberattack, as we saw at the SEPE or in Castellon, and that it's still seen as a purely technical problem when losing your data ends up on the bottom line. I describe cybercrime as one more arm of organised crime, which already turns over more than the drug trade and even has call centres to handle ransoms. And I warn that the virtual world is more dangerous than the real one precisely because we drop our guard; the hacking of Jeff Bezos's phone ended in the most expensive divorce in history.

Interview on FluProject
Summary
In this interview I describe myself as someone who has spent twenty years in technology entirely out of vocation. I tell of my beginnings in the BBS scene, the demoscene and Infovia, and my collaboration with the European Commission evaluating projects and in a group on the risks of consumer products with AI. Of a CISO's day-to-day I highlight the human side, guiding people towards safer practices, and I drop an idea I stand by: identity is the new perimeter.

"Progress is like a tsunami"
Summary
Progress is like a tsunami: you can stay on the sand and let it drag you under, or grab a board and try to surf it. With that metaphor I open this interview, in which I insist that a hacker is not a cybercriminal, because ethics lie in the person and not in the technology. I also criticise companies looking for a jack-of-all-trades techie when what they need is a specialist, just as with a broken arm you go to the trauma surgeon and not the GP.

How the first bug bounty of a public administration went
Summary
In December, the Catalan government became the first Spanish public administration to open a bug bounty, and I was one of the fifteen researchers invited to prod its systems. I tell how it went on the inside, with five flaws validated by Catalonia-CERT, and I call for what's fair: that these initiatives be paid as they should be and not end in a t-shirt and a certificate.

The Catalan government recruits a Galician hacker
Summary
The Catalan government asked for my help to set up the first bug bounty of a public administration in Spain: recruiting a team of fifteen bounty hunters and letting them look for flaws in its network. We found five vulnerabilities, which its technicians fixed under the supervision of Catalonia-CERT. I helped them find the people and define how to report the flaws to the agency; a pioneering project in the country.

Working reporting software flaws to the big tech firms
Summary
Reporting flaws to the big tech firms started for me as a hobby over Christmas 2019, to keep from getting rusty on the technical side. In this interview I explain how bug bounty works, from reconnaissance of domains to stumbling on a misconfigured server that left a well-known company's source code in plain view. And I make clear that, although some people pull in more than a hundred thousand euros a year, I prefer to keep it as a side pursuit so as not to end up resenting it.
2020

The Civil Guard scouts Galician talent
Summary
I was a mentor for the Civil Guard's National Cyber League, a contest in which some two thousand teams of young people defend a company under attack in a simulated environment. My job was to guide the teams that qualified for the final. There's plenty of talent in Galicia: in the first edition the Galician contestants took home scholarships, internships and prizes, no finalist left empty-handed.

"Expertos en ciberseguridad ayudan"

Police efforts to curb CEO fraud
Summary
On CEO fraud, that fake email asking you to change the account where payments are made, the solution I give is common sense: when something involves money, whoever it comes from, confirm it by another channel. If they ask you to change an account, pick up the phone number you already know for that person and ask whether it was really them. Around then we had formed the SpInquisitors bounty-hunter group and were preparing a bug bounty workshop for RootedCON.
2019

The Men in Black who protect cyberspace
Summary
In this report on those tasked with watching over cyberspace I argue that European citizens need to be given tools. The NIS Directive has pushed countries to create their strategies, but there's much still to apply for the public. I miss a mechanism for any European to report flaws in the administration, along the lines of the whistleblower directive, and I call for a citizen-facing, publicly accessible CSIRT.

Childhood and mobile phone use
Summary
On what age to give a child a phone, I'm in favour of them getting to know technology early, because we can't deny it and they need to keep up; a phone is a tool that connects to places, not the reincarnation of evil. That said, don't give a child your own phone with your personal and work data, because a child is very easy to trick into clicking where they shouldn't. I'm not one for banning, but for getting informed and giving them tools, leaning for example on Incibe's guides for parents.

We hackers are not Hollywood heroes
Summary
Being a hacker, more than a job, is a way of being: curiosity to know how and why things work and to make them do what they weren't meant to. The reality is a long way from the Hollywood stereotype. I warn that there are many more incidents and ransom payments than come to light, I champion the role of women in hacking and, on Snowden and Assange, I clarify that they are hacktivists.

Legal hurdles for scam investigations
Summary
I comment on why it's so hard to investigate online scams in Vigo: many criminals operate from peripheral countries that cooperate little, and that slows the investigations. And I warn that the bad guys will move into the world of video games, one of the highest-earning industries, posing as others or using PayPal accounts maliciously.

Two Galicians, Telefonica ambassadors
Summary
ElevenPaths, Telefonica's cybersecurity unit, chose nine of us as ambassadors to spread security awareness online. I warn of a trend that's already real: today it's easier to be harmed online than in the street. On our phones we carry data we wouldn't want getting out, so beware of apps and public Wi-Fi, because you don't know who's on the other side.

The University of Vigo signs up hackers
Summary
The University of Vigo signed several of us hackers to teach courses and the new inter-university Master's in Cybersecurity, and to debate how to shield Industry 4.0 factories. With Belen Perez, with whom I organise the Hack & Beers in Vigo, I taught a course on cybersecurity in smart factories.

The Netherlands rewards a hacker for his help
Summary
The Dutch government thanked me for reporting a vulnerability with a letter and, tongue in cheek, a black t-shirt that read "I hacked the Dutch government and all I got was this lousy t-shirt." It's not the only recognition: I appear in the US Department of Defense's HackerOne, in Philips's Hall of Honors and in the EU CERT's Hall of Fame. For me bug bounty is a hobby, a way of not getting technically rusty.
2018

Drug traffickers use encryption for their communications
Summary
In a report on how gangs use encryption apps I explain the ins and outs: handing your privacy to a third party, be it Telegram, Signal or WhatsApp, means trusting they'll handle your communications securely. I recall that with public-key cryptography, among other techniques, anyone can build their own practically unbreakable communication system. As a hacker, I stay sceptical and don't rule out weak points that allow leaks.

Hackers at Vigo's Hack&Beers
Summary
With Belen Perez we organised an edition of Vigo's Hack & Beers devoted to giving women visibility, with five Galician experts giving the talks. We wanted to showcase the talent we have to export, in a relaxed setting where people learn and connect. With the new European data protection rules I warned that big companies face fines that can hit their revenue, and that some, like Facebook, will have to up their game.

Hackers warn of the danger of petrol-station IoT
Summary
I signed the report that alerted the EU to cybersecurity flaws in a hundred and eighty-nine Spanish petrol stations with connected devices: in almost all of them an intruder could run hundreds of commands from the internet and even change the pump prices. Professionals have known about the problem since 2015, it costs next to nothing to fix and the impact of an attack could be serious, but almost no one has bothered. Awareness is needed.

Hackers and Kevin Mitnick
Summary
I recall my meeting with Kevin Mitnick, of whom I still keep the photo: he's a legend. I champion the people from the groups I grew up with, like Hispahack, Els Apostols or La Vieja Guardia, and the European pioneers of the Chaos Computer Club, who still organise some of the best events on the continent. Fifteen years after that photo, I'm still running the Hack & Beers in Vigo every quarter.
2017
Las posibilidades laborales del ámbito hacker

A hacker is not a criminal
Summary
Before the students of a telecoms Master's in Vigo I argued that a hacker is not a criminal and recommended going into the security of the Internet of Things, because right now shipping the product comes first and security waits, and this technology is going to change everything. I warned that there are already televisions that spy through microphone and camera, and even toys with flaws that let someone speak to a child through them. I'm active and ready to help: I want to give back to the community what it gave me.

Success of Vigo's Hack&Beers
Summary
The second Hack & Beers of Galicia brought together around thirty security experts in Vigo, with talks such as Dave Ryan's on pentesting. I think the audience took away some interesting tricks on discovering that there are tools online to keep an acceptable level of security without paying the prices of the big consultancies, automating penetration tests to save money.

Santiago hosts the biggest international free-technology gathering
Summary
I took part as a speaker at Santiago's Librecon, the biggest international free-technology gathering, with three hundred and fifty experts and two hundred companies, talking about the challenges of Industry 4.0 alongside names like Yaiza Rubio and Pilar Vila.

Security experts at Hack&Beers
Summary
An edition of Vigo's Hack & Beers brought together between thirty and forty ethical hackers and Galician experts, with one clear conclusion: an awareness campaign is needed so that ordinary people take more measures. The audience included business owners, teachers, students and researchers. I insist on a practical idea: if you hire an outside firm for pentesting they charge you a fortune, but with the available tools you can do it yourself and save.

The EU recruits a former hacker
Summary
The EU added me to the expert list of the Enisa agency to help devise legal strategies, assess risks and stop cyberattacks like WannaCry. I tell how as a teenager I found holes in company websites and warned them, and how I drove around Vigo with a laptop checking how vulnerable the Wi-Fi networks were. Much of the work would be remote, evaluating and collaborating depending on the group you're assigned to.

Cybercrime and the threats ahead
Summary
I foresee the classic threats continuing, ransomware and phishing, but growing more specialised with AI and Big Data exploitation, and used too by state-backed groups for cyberwar. I warn about the old software still running in critical systems: old flaws will be found and used for mass attacks. And about Industry 4.0, where we're heading towards them infecting what we produce to spread malware to customers, with connected devices as the target for a global zombie network.

A Galician leads ethical hacking
Summary
In this interview I tell how at seventeen I uncovered holes in banking websites to warn them, and that I'd just passed an online MIT course on cybersecurity. I explain ethical hacking: intrusion attempts with an attacker's mindset but with permission and at a fair price. On whether the good hacker exists, I answer that a hacker is someone with a passion, and passion is neither good nor bad, it's a matter of ethics; the era of the romantic hacker who broke barriers just for the challenge is now history.

Vigo cybersecurity experts warn industry
Summary
I recall when a friend and I drove around Vigo with a laptop to map the city's cybersecurity and found how many homes hadn't set a password on their Wi-Fi. I warn that, although almost everyone has some antivirus, very few renew their passwords, have a firewall or use an account with limited privileges. With Industry 4.0, what we've seen so far could look like child's play if a factory is suddenly paralysed by a ransom attack.
2016

The police prepare for Christmas scams
Summary
I'm back from a cryptography congress with one thousand seven hundred experts organised by the National Cryptography Centre, where advanced persistent threats and cyberespionage were discussed: 2017 promises to be lively. For online shopping I recommend methods like PayPal and always going straight to the official store. Because beyond the money they scam from you, the problem is who you hand your name, address and card to: they could steal your identity or hijack your machine. Always check the domain and the padlock of secure encrypted payment.

They lock up companies to extort them
Summary
I warn that companies in Vigo are suffering ransomware, which encrypts the office drives and demands a ransom in bitcoin to return the files. Over the past year I've noticed this kind of attack coming into fashion, and although no company wants to admit whether it paid, I know of some that had incidents. Criminals use bitcoin precisely to complicate everything and throw off the trail.
2010

The watchmen of the network of networks
Summary
An early profile of my beginnings as an entrepreneur, when a partner and I set up Fernandes Soluciones, specialising in systems security and in helping companies protect themselves from espionage and attacks while, at the same time, selling themselves better. They described us as ethical hackers, those people of healthy curiosity who try every lock to see whether it's properly shut.
In the hands of Antonio Fernandes
Summary
A personal profile of my beginnings: they tell how my first contact with a computer came around the time of my first communion and that, while others went to watch Celta, I was watching the screen. Even then we advised companies on security, though most only worried when something serious happened to them.

Web attack on the EU Presidency
Summary
I analyse the incident on the website of Spain's EU presidency, where Mr. Bean's face appeared instead of Zapatero's. I clarify that no one attacked the servers and it wasn't a montage: it was a cross-site scripting flaw, a hole that lets content from another website be shown through the search box, without getting into the server. The real risk of these things isn't the server, it's tricking the user into entering data thinking they're on the official page, as in phishing.
2009

Malware that turns computers into zombies
Summary
I explain how zombie computers are created, controlled by criminals with viruses that arrive via websites, emails or downloads: they can get in even from a USB stick and you're at their mercy without knowing it, with your data and your connection in the hands of the network's owner. I recall that in 2007 a legion of zombies attacked the thirteen DNS root servers, the heart of the internet; had they all gone down, it would have been chaos until it was fixed.
2006

The dangers of P2P sharing
Summary
In a report on the risks of sharing files over P2P I insist that security depends on the user and on what they share. I confess I don't even use eMule, revolutionary technology though it is, and I see a future for it in communication between people, voice over IP and video calls. The minimum precaution: check carefully what you're handling, because some people hide illegal content or a virus under an innocent title.

Child pornography on P2P networks
Summary
On the risks of P2P networks I hold that their security depends entirely on the user and on what they share. I predict a good future for this technology, not only for films but also for books, voice over IP and video calls, but I remind everyone that all technology depends on the use you give it. The minimum precaution is to check what you download before opening it, because some people hide a porn film or a virus under a Disney title.

Vigo's wireless networks are insecure
Summary
In this report on the cybervillains of the future I tell, already turned adviser, that sneaking into your neighbour's Wi-Fi to steal their connection is an everyday thing. If you cross Vigo on any given night you can find more than three hundred networks belonging to companies and individuals, almost all of them vulnerable. And the worst part is that the victim will only notice their connection running slower, without suspecting that someone is controlling their machine.
2005

Reaction to a cybercriminal's arrest
Summary
In the reactions to the acquittal of the hacker QuickBasic, who broke into the websites of the Tax Agency and the PP party, I made clear that to us he wasn't a hacker: he used a program within reach of any amateur. He was lucky to be let off, though no one can take away the scare of facing prison. I think he did it for notoriety, to show off how good he was and land a job and fame, not out of the drive to learn that moves a real hacker.
2004

Opinion on the leak of the Windows source code
Summary
I analyse the leak of part of the source code of Windows NT and 2000. In that code, downloaded by thousands of internet users, you can see the programming of the desktop or the network core, and I think it will cause new security flaws, though I stress it wasn't Microsoft's fault. After studying it closely, everything points to the leak coming from a US company, not a government or a university.
2003

Launch of the Tecnoatlantico Forum
Summary
I was part of the honorary committee of Tecnoatlantico, Vigo's first forum for computing and new technologies, which brought together a thousand enthusiasts over four days in Cotogrande, with professional forums, workshops and internet gurus like Albert Gabas, of the Chaos Computer Club.
2001

UNR breaks into Spain's leading websites
Summary
One of my first steps, at twenty, in the Vigo group Unluck Net Research, which ran security audits on big websites and exposed flaws others couldn't see. Ours was an intellectual challenge: when we found a flaw we reported it to the company to fix, and only if they ignored us did we alert the auditors. We never touched customer data; we did R&D, not gratuitous damage.
2000

The 'internet kid' comes to Vigo
Summary
One of my first appearances, at nineteen and still in secondary school, when I ran the Vigo branch of the Babysoft group, devoted to bespoke programming, IT security and server hosting, alongside Daniel Fernandez. It all began with a contact made online that ended in a trip to Mallorca.