CSIRT-CAN – Centro de Respuesta a Incidentes de Seguridad de Canarias

Blog Lists

Cyberattacks | VIRUSES

What Is a Computer Virus and How Can You Protect Yourself?Computer Viruses Remain One of the Most Common Threats in the Digital WorldA computer virus is a type of malware (malicious software) designed to disrupt the normal operation of a device, damage files, or steal information without the user's knowledge. To become active, it requires the victim to run an infected file or program, after which it can spread rapidly throughout the system.What Can a Computer Virus Affect?When a device becomes infected, the consequences can be significant:Files: They may be modified, deleted, or corrupted.Device Performance: Your computer or device may become slower or experience system failures.Personal Data: Passwords, banking information, and other sensitive data may be stolen.Network: The virus can spread to other connected devices.Security: Cybercriminals may gain unauthorized access to your system.How Does a Computer Virus Work?A computer virus typically follows these stages:Infection: It enters the device through downloaded files, malicious links, or email attachments.Installation: It installs itself without the user's knowledge.Activation: It becomes active and begins executing malicious actions.Impact: It damages files, steals information, or compromises the system.Propagation: It spreads to other files, devices, or networked systems.Persistence: In some cases, it remains active even after the device is restarted.How Can You Protect Yourself?Prevention remains the most effective defense against computer viruses. Here are some essential cybersecurity practices:Keep your antivirus software up to date.Regularly update your operating system and applications.Avoid opening links or attachments from unknown senders.Download software only from official and trusted sources.Use strong, unique passwords.Back up your important data regularly.Enable your device's firewall.Secure your Wi-Fi network with a strong password.Protect your devices with a PIN, password, or biometric authentication.Review the permissions you grant to applications.Stay informed about the latest cybersecurity threats and best practices.Some of the Most Notorious Computer Viruses in HistoryOver the years, several viruses have demonstrated the devastating impact cyberattacks can have:Brain (1986): Widely recognized as the first virus for IBM-compatible PCs.ILOVEYOU (2000): Spread worldwide through email, infecting millions of computers and causing extensive damage.WannaCry (2017): A ransomware attack that encrypted the files of thousands of organizations worldwide, demanding payment for their release.Prevention Is Your Best ProtectionMost infections begin with what appears to be a harmless action, such as opening a phishing email, clicking on a suspicious link, or downloading a file from an untrusted source. By following good cybersecurity practices and staying vigilant, you can significantly reduce the risk of becoming a victim of a computer virus.

Enjoy the summer, but stay protected from cyber scams

Summer is synonymous with vacations, travel, and relaxation. However, while millions of people are planning their getaways, cybercriminals take advantage of this period to launch increasingly sophisticated fraud campaigns.During the summer months, scams involving accommodation bookings, transportation, online payments, and fake communications increase significantly. These scams are designed to trick users into revealing their personal or financial information.Understanding the most common threats is the first step toward avoiding them.1. Smishing: SMS-Based FraudSmishing is a form of phishing carried out through text messages (SMS). Cybercriminals send messages pretending to be courier companies, banks, government agencies, or travel providers.Some of the most common messages include:"Your package could not be delivered.""Please confirm your reservation before it is canceled.""Suspicious activity has been detected on your account.""A small payment is required to complete your delivery."These messages contain a link that redirects users to a fake website designed to steal login credentials, banking information, or install malware on their device.How to protect yourselfDon't click on links received via SMS if you weren't expecting the message.Always verify the sender.Visit the company's official website by typing the address directly into your browser.If in doubt, contact the company through its official channels.2. Quishing: The Danger of Fake QR CodesQR codes have become part of our daily lives. We use them to view restaurant menus, pay for parking, access tourist information, and make payments.Because of their popularity, cybercriminals have started using them as a tool for fraud. This technique is known as Quishing (QR + Phishing).In many cases, attackers replace legitimate QR codes with fake ones that redirect users to fraudulent websites.Victims believe they are making a legitimate payment or accessing an official service when, in reality, they are handing over their personal or financial information to criminals.How to avoid this scamCheck that the QR code hasn't been placed over another one.Look carefully at the website address before entering any information.Never download apps from unknown QR codes.Before making a payment, ensure the website begins with https:// and genuinely belongs to the company.3. Fake Holiday Rental ScamsVacation bookings are also one of scammers' favorite targets.Fraudsters create highly attractive listings using real photos copied from other websites, offer prices well below market value, and present deals that seem too good to pass up.Once the victim sends a bank transfer or makes an advance payment, they discover that the accommodation never existed or that the supposed property owner was fake.Warning signsPrices that are significantly lower than comparable listings.Requests for payment by bank transfer or other direct payment methods outside the booking platform.Pressure to book immediately because "many other people are interested."Refusal to arrange a video call or provide proof of ownership.Photos that look unusually perfect or have been copied from other listings.How to book safelyUse reputable booking platforms.Read reviews from previous guests.Verify the property's location using Google Maps.Be cautious of deals that seem too good to be true.Never make payments outside the official booking platform.General Tips to Avoid Cyber Scams During the SummerMost of these scams share the same objective: getting you to act quickly without thinking.To reduce your risk:Keep the operating system on all your devices up to date.Enable Two-Factor Authentication (2FA) whenever possible.Use strong, unique passwords for every account.Never reuse passwords across different services.Only install apps from official app stores.Regularly monitor your bank accounts for suspicious transactions.Be suspicious of any message that creates a sense of urgency or fear.Prevention Is Still Your Best DefenseCybercriminals seize every opportunity to deceive users, and summer is one of the busiest seasons for online fraud campaigns.Taking just a few seconds to verify a link, confirm a booking, or inspect a QR code can help prevent financial losses, protect your personal information, and even stop identity theft.When it comes to cybersecurity, prevention remains the most effective defense.

What is the Cyber Resilience Act (CRA)?

The Cyber Resilience Act (CRA), established under Regulation (EU) 2024/2847, is a European Union regulation that introduces mandatory cybersecurity requirements for products with digital elements, including software, applications, Internet of Things (IoT) devices, connected equipment, and other digital products placed on the European market.Its main objective is to ensure that digital products are secure by design and remain secure throughout their entire lifecycle, reducing vulnerabilities and strengthening the protection of consumers, businesses, and public administrations against cyber threats.Why is it important?Digital products have become an essential part of everyday life. However, many devices and applications contain vulnerabilities that can be exploited by cybercriminals to compromise information, disrupt services, or endanger users' privacy.The CRA addresses these challenges by establishing a common cybersecurity framework across the European Union, increasing trust in digital products and promoting a safer digital ecosystem.Key requirements of the CRAAmong the main obligations introduced by the Regulation are:Integrating cybersecurity by design and by default throughout the product development process.Managing and remediating vulnerabilities throughout the entire product lifecycle.Providing security updates in a timely manner.Performing risk assessments before certain products are placed on the market.Complying with mandatory reporting requirements for actively exploited vulnerabilities and severe cybersecurity incidents to the relevant authorities.Providing users with clear information regarding product support and available security updates.Implementation timelineThe Regulation establishes a phased implementation schedule:10 December 2024: Regulation (EU) 2024/2847 entered into force.11 September 2026: Obligations related to the reporting of actively exploited vulnerabilities and severe cybersecurity incidents become applicable.11 December 2027: The main obligations of the Cyber Resilience Act become fully applicable.Who is affected?The Cyber Resilience Act primarily applies to:Manufacturers of products with digital elements.Software developers.Importers and distributors of digital products.Organizations placing technological products on the European Union market.CSIRT-CAN RecommendationCSIRT-CAN encourages organizations to stay informed about the implementation of this Regulation and begin assessing its potential impact. Adopting cybersecurity best practices, implementing continuous vulnerability management, and developing secure products will help strengthen digital resilience and reduce cyber risks.Further informationEuropean Commission – Cyber Resilience Acthttps://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-actRegulation (EU) 2024/2847https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R2847

Mobile Device Security: Protect Your Pocket Office

Nowadays, mobile devices have become an indispensable extension of our personal and professional lives. Through them, we manage corporate emails, access bank accounts, share work documents, and store personal memories. However, this portability and convenience come with significant risks: a mobile phone stores information just as sensitive and valuable as a personal or business computer.At the Canary Islands Cybersecurity Incident Response Centre (CSIRT-CAN), we remind you of the importance of not underestimating the security of our smartphones and tablets. Cybercriminals are increasingly targeting these environments with attacks such as smishing or mobile malware distribution, precisely due to a lack of awareness and protective measures by users.🛡️ Three Basic Pillars of Mobile SecurityImplementing a culture of prevention in mobile technology use does not require complex configurations. By following these three fundamental steps, you will drastically reduce your exposure to potential threats:1. Establish Secure Unlock MethodsThe first risk vector is physical access to the device due to loss or theft.Avoid simple patterns or predictable PIN codes (such as "1234" or your year of birth).Prioritize biometrics: Facial recognition or fingerprint scanning adds a robust and agile layer of security.Remember to enable automatic screen lock after a brief period of inactivity.2. Keep the Operating System and Applications UpdatedSoftware updates are not just a visual formality; they are the most effective defensive barrier you have.Updates patch vulnerabilities and security "loopholes" that attackers exploit to compromise devices.Configure your device to download and install updates automatically, preferably when connected to a trusted Wi-Fi network.3. Download Applications Only from Official StoresMalicious software often disguises itself within seemingly harmless applications.Exclusively use authorized manufacturer stores (Google Play Store for Android and App Store for iOS).Before installing any application, review the permissions it requests (for example, be suspicious if a simple game asks for access to your contacts or microphone) and check reviews from other users.💡 Additional Best Practices for Professional EnvironmentsIf you use your mobile device to access Government of the Canary Islands or corporate resources, please keep the following recommendations from the CSIRT-CAN technical team in mind:Beware of public Wi-Fi networks: Avoid making bank transactions or accessing corporate systems through open networks (airports, cafes, etc.). If strictly necessary, always use a Virtual Private Network (VPN).Device Encryption: Ensure your phone’s storage is encrypted (an option enabled by default on most modern smartphones when a secure PIN is configured).Regular Backups: Back up your information frequently to ensure that, in the event of loss or damage, you can recover your data safely.

🌐 Is your web browser up to date?

There are many web browsers available, but this post highlights some of the most widely used. To ensure the information is accurate and reliable, the versions shown correspond to the stable release channel and have been verified using each vendor's official sources.Keeping your browser up to date is one of the easiest ways to improve your browsing experience. Every new release includes security fixes, performance and stability improvements, as well as better compatibility with the latest websites and web applications.Check your browser version by entering the following in the address bar:     - Google Chrome: Stable version: 150 / Check your version: chrome://settings/help     - Microsoft Edge: Stable version: 150 / Check your version: edge://settings/help     - Mozilla Firefox: Stable version: 152.0.5 / Check your version: about:support     - Opera: Stable version: 133 / Check your version: opera://about     - Brave: Stable version: 1.92.134 / Check your version: brave://settings/help     - Safari: Stable version: 26.5 / Check your version: Safari → Acerca de Safari     - Vivaldi: Stable version: 8.0.10 / Check your version: vivaldi://aboutWhy is it important to keep your browser up to date?🔒 Improved security: Fixes vulnerabilities and protects against the latest threats.⚡ Better performance: Enhances speed, resource usage, and overall stability.🌐 Greater compatibility: Ensures websites and modern web applications work correctly.✨ New features: Includes enhancements and new capabilities introduced by each browser vendor.Official sources consultedGoogle Chrome: https://chromereleases.googleblog.com/Microsoft Edge: https://learn.microsoft.com/deployedge/microsoft-edge-relnote-stable-channelMozilla Firefox: https://www.mozilla.org/firefox/releases/Opera: https://blogs.opera.com/desktop/Brave: https://brave.com/latest/Safari (Apple): https://developer.apple.com/documentation/safari-release-notesVivaldi: https://vivaldi.com/blog/desktop/📅 Information collected in July 2026. The versions listed correspond to the stable release channel available at the time of publication and may change as vendors release new updates.💬 Have you checked whether your browser is up to date?

What do we do for you?

CSIRT-CAN offers various services for the prevention and prompt resolution of cybersecurity-related incidents.

Tarjeta de Links

Happening Now

Services by Profiles

What is CSIRT-CAN?

The CSIRT-CAN (Canary Islands Security Incident Response Center) is an entity dedicated to the protection and resilience of digital infrastructures in the Canary Islands. Our center specializes in the detection, analysis, and mitigation of cybersecurity incidents, providing technical and strategic support to public and private organizations.

Report an incident
CAPTCHA
Enter the characters shown in the image.
This question is for testing whether or not you are a human visitor and to prevent automated spam submissions.