Nicolás Acosta, CISO at Corona

Sensible about cybersecurity

An interview with Nicolás A. CISO at Corona. Part II.

In this post, we share the second part of our conversation with Nicolás Acosta, Chief Information Security Officer (CISO) of Corona. We spoke about risks, setbacks, and truths and falsehood in cybersecurity. If you have not read the first part click here to read it. Risk Management Thinking about risks …

New York City Skyline

Querier Writeup

How to solve HTB Querier

In my opinion, Querier is a great box. We can learn a bit about Windows pentesting, a widely used operating system. The challenge begins with a public SMB where we will pass our first level. Next we will work with SQL Server and we will need to use a special …

Nicolás Acosta, CISO at Corona

Innovation more understandable

"We make innovation more understandable, more worldly."

Our guest Nicolás is the Chief Information Security Officer (CISO) of Corona; a Colombian Multinational company dedicated to manufacturing ceramics for home improvement, construction, industry, agriculture, and energy markets. Corona has 20 production plants in Colombia, 3 in the US, 3 in México and 3 in Central...

People manipulation

Attacking the weakest link

Attacking without borders.

Companies invest millions of dollars on IT infrastructure and cybersecurity to keep their information protected. But when it comes to training their employees the investment is barely enough. Employees that daily manipulate, organize, create or update a company’s main data are the main link between IT...

Choices. Photo by Nathan Dumlao on Unsplash:

Risk indicator roundup

A matter of taste

What is the best risk indicator? Bottom line: there is no "best", only different approaches to the same thing. Ultimately, it’s up to you. Here we will show the pros and cons of each so you can make an informed decision (about that which will guide your informed decisions …

Yellow police line tape on Unsplash:

Preventing Hacks at CERN

A chat with Andrés Gómez.

Have you heard about God’s particle? In 2012, the Large Hadron Collider (LHC) found the Higgs Boson; a particle predicted to exist in the 1960s thanks to the work of Peter Higgs and other physicists. The LHC consists of a 27-kilometer ring of superconducting magnets with several accelerating structures …

Parsing code. Photo by Markus Spiske on Unsplash:

Parse and Conquer

Why Asserts uses Parser combinators

As you might have noticed, at Fluid Attacks we like parser combinators, functional programming, and, of course, Python. In the parser article, I showed you the essentials of Pyparsing and we also showed how to leverage its power to find SQL injections in a PHP application. Here we will extend …

multicolor abstract paint on Unsplash:

Seek for chaos and dive into it

The Antifragile philosophy

Imagine a medium-sized sealed carton box, with two or three glasses inside. If you kick the box (like kicking a soccer ball), the glasses will surely break. The glasses are fragile. Now, think of the same box, but with two or three standard steel hammers. Nothing will happen to those …

Chess strategy. Photo by Inactive. on Unsplash:

Great Expectations

What to expect when you're at risk

Thus far, the situations we have modeled have been either over-simplifications or fabrications in order to illustrate a concept. This article will try to improve on that a bit by considering more variables and closer to reality, too. We will do so by presenting the subject matter needed to understand …

Born into cloud

Secure Cloud as Code

The weakest link in security is not the technology.

Amazon Web Services (AWS) is one of the biggest cloud services used by thousands of companies around the world, and with a centralized and strong security, it is one of the best on the market. Services like Terraform or AWS CloudFormation allow us to write our infrastructure definitions as code …

Broken blue ceramic plate on Unsplash:

The F*CK strategy

The pratfall effect application on business

Do you like fried chicken? A year ago or so, KFC -the chicken fast-food chain- was featured in almost every news outlet in the UK: they ran out of chicken for an entire weekend. A horror story for a food-chain with 900 restaurants in the country. People were mad at …

Yellow police line tape on Unsplash:

Do not read this post

What if this post were a malicious link?

Why the f*ck did you click to this post? Seriously, why? Chances are, you were attracted to the title, paradoxically, suggesting not to do something. But, here you are. We are glad you did not follow that direction but we deliberately crafted that title to attract your attention, to …

