Ciberseguridad, Derecho e IA: Análisis del Phishing. Teoría y análisis de un ataque típico. (IA)

Ciberseguridad, Derecho e IA: Análisis del Phishing. Teoría y análisis de un ataque típico. (IA)

🎙 Ricardo de la Puente Moreno 👥 2K 📅 May 31, 2026 ⏱ 102 min 👁 209 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

phishingcybersecurityAIsocial engineeringMax Phishing

Summary

The presentation, part of a seminar on cybersecurity, digital law, and AI, is delivered by Ricardo de la Puente Moreno, a cybersecurity master’s student with 32 years of IT experience. It begins with an introduction to phishing, defining it as a cyberattack where criminals impersonate legitimate entities to steal confidential information. The speaker outlines various phishing types, including email phishing, spear phishing, smishing, vishing, pharming, and clone phishing, explaining each with examples. He then describes the typical four-phase attack process: bait, hook, trap, and theft, emphasizing the use of urgency and social engineering. The presentation highlights warning signs such as suspicious URLs, unfamiliar senders, incredible offers, urgency, spelling errors, and suspicious attachments. Statistical data from APWG is cited, noting billions of phishing emails daily and high rates of user failure to identify attacks. The core of the talk is a live demonstration using the open-source tool Max Phishing, which creates fake login pages to capture credentials. The speaker explains how the tool works, including its use of Python, tunneling, and integration with Telegram or WhatsApp for exfiltration. He discusses the role of AI in lowering the barrier for creating sophisticated attacks, mentioning AI tools like Hacker GPT and Exploit GPT. The presentation concludes with a discussion on ethical hacking and the importance of awareness and protection.

216 words

Critical Evaluation

Value of the Information & Strength of the Argument

The presentation provides valuable practical insights into phishing mechanisms and demonstrates a real tool, which is educational for understanding attack vectors. The argumentation is based on the speaker’s extensive experience and a live demonstration, making it concrete. However, the lack of formal citations and reliance on personal anecdotes weakens the scientific rigor. The discussion on AI’s role in cyberattacks is relevant but not deeply explored, and the ethical considerations are only briefly touched upon.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate; the speaker cites APWG statistics but does not provide specific references or URLs. The demonstration is clear but lacks a systematic methodology. The title accurately reflects the content, which is a mix of theory and practical analysis. No comments were provided for analysis.

137 words

Title / Content Match

The title accurately reflects the content, which covers phishing theory, a practical demonstration, and the role of AI in cyberattacks.

Quality & Reliability

6/10

The speaker demonstrates practical knowledge of phishing techniques and tools, but the presentation lacks formal citations and relies heavily on anecdotal evidence and personal experience. The demonstration is educational but not peer-reviewed.

Key Moments

Cited Sources

Concurring Sources

  • Phishing - Wikipedia — Provides general information on phishing that aligns with the presentation.

Contribution & Novelties

The presentation offers a practical, hands-on demonstration of a phishing attack using a modern open-source tool, which is valuable for educational purposes. It highlights how AI has lowered the barrier for creating sophisticated attacks, a relevant contemporary issue. The discussion on ethical hacking and AI tools like Hacker GPT adds a forward-looking perspective.

Pour aller plus loin :

91 words

Radar Profile

The radar profile shows moderate scores across all dimensions, indicating a balanced but not exceptional presentation. The highest score is in quantity of information, reflecting the comprehensive coverage of phishing types and techniques, while the lowest is in technical level, suggesting the content is accessible to a general audience.

Reliability 5/10