Bruno Salvatella (CyberSources): “AI is lowering the barrier to entry for cybercriminals” | #cybercrime | #infosec


At just 19, Bruno Salvatella combines his cybersecurity studies with his role as founder and CEO of CyberSources, a project born out of a very specific need: to organise and simplify access to the many tools used every day by professionals and students in the field.

What began as a personal collection has evolved into a platform featuring more than 600 verified penetration testing, OSINT and digital forensics tools, backed by a community of over 22,000 members.

CyberSources has also established itself within Spain’s startup ecosystem after becoming a finalist in Startup School 26, an initiative run by Spain’s National Cybersecurity Institute (INCIBE) and Tetuan Valley, and securing the backing of companies including NordVPN and Hudson Rock. In this interview, Salvatella discusses the cybersecurity challenges posed by artificial intelligence, the need to verify open-source tools, the difficult balance between open knowledge and potential misuse, shortcomings in the training of new professionals, and threats such as phishing and ransomware.

QUESTION (Q). CyberSources has become a go-to repository for cybersecurity professionals. What problem did you identify in the sector that led you to create a platform of this kind?

ANSWER (A). I began studying cybersecurity and realised that I needed to keep all the tools and resources I was using organised in one place, so I started compiling them for myself. When I shared the collection, I saw that other people had exactly the same problem: cybersecurity has a huge number of tools and resources, but finding the good ones –the ones that are genuinely worthwhile or right for a particular task– takes a great deal of time. CyberSources grew out of that personal need, which turned out to be a problem shared across the community.

Q. At a time when thousands of penetration testing, OSINT and digital forensics tools are available, what criteria do you use to verify, classify and keep your catalogue of more than 600 solutions up to date?

A. Every tool added to the catalogue is reviewed by me and by a team of trusted moderators before it is published. This two-stage verification helps us avoid two things: low-quality tools that offer no real value, and potentially malicious tools that could be used to cause harm. The process is deliberately neither automated nor geared towards volume: we would rather grow more slowly while maintaining the level of trust our community expects from us.

Tasks that once took hours can now be completed in minutes

Q. Artificial intelligence is transforming both cyber defence and cybercrime. How is it changing the use of open-source tools, and what trends are you seeing at CyberSources?

A. We are seeing it from both sides. On the defensive side, a growing number of open-source tools are integrating AI to automate reconnaissance, log correlation and vulnerability triage.

Tasks that once took hours can now be completed in minutes. On the offensive side, AI is lowering the barrier to entry: generating convincing phishing messages, automating OSINT reconnaissance and even assisting with exploit writing no longer require the same level of technical expertise as before.

At CyberSources, we try to ensure that defenders have access to those same capabilities, so that the balance does not shift entirely in the attacker’s favour.

Q. The community is one of the project’s greatest assets. With more than 22,000 members across different platforms, how do you maintain the quality of contributions and prevent potentially dangerous or malicious tools from being shared?

A. We have a team of volunteers and moderators on both Discord and Reddit who review the community’s content and contributions, and I personally monitor what is posted every day.

We also go beyond moderation: we organise cybersecurity talks and events within the community because our aim is not merely to control what is shared, but to make cybersecurity accessible to everyone through high-quality content that delivers real value.

Q. You were a finalist in Startup School 26, organised by INCIBE and Tetuan Valley. How did the mentors assess the project, and which aspects did they highlight during the programme?

A. I am extremely grateful for everything they have given me. My background is purely technical, in cybersecurity studies. Everything involved in building a startup –legal issues, marketing and how to value a company– was new territory for me.

The Tetuan Valley mentors helped me enormously with all of that, and I do not think CyberSources would be where it is today without their support. I would recommend the programme without hesitation to anyone starting a project in this sector.

Defenders need the same tools used by attackers in order to understand how to protect themselves

Q. Many cybersecurity tools can be used both to protect systems and to attack them. Where do you think the balance should lie between open access to knowledge and preventing unlawful use?

A. I firmly believe that cybersecurity knowledge cannot be closed off: defenders need the same tools used by attackers in order to understand how to protect themselves.

What we do at CyberSources is draw a clear line between “a tool intended for education or legitimate auditing” and “a tool designed exclusively to cause harm”: the former has a place on the platform; the latter does not. Ultimate responsibility always lies with the person using the tool, but we will not make things easier for anyone who is clearly seeking to cause harm.

Q. Companies such as NordVPN and Hudson Rock already support CyberSources. What does this kind of sponsorship mean for an open-source project, and does it affect your independence in any way?

A. They help us enormously, particularly by enabling us to keep the project active and maintain our enthusiasm for growing it. Hudson Rock is especially important to me because they were the first to believe in me and support me in all of this, when CyberSources was still a much smaller project. As for our independence, the criteria determining which tools are included on the platform have never been influenced by our sponsors. That is something I feel very strongly about, and it will not change.

People talk a great deal about young cyber talent when it goes down the wrong path, but invest little in giving those who want to build something legitimate a way forward from the age of 16 or 17

Q. Spain is placing increasing emphasis on strengthening its cybersecurity capabilities. Based on your experience, what shortcomings do you currently see in training, access to resources and talent recruitment?

A. I see two clear shortcomings. The first concerns training: there is a great deal of scattered technical content, but no clear pathway for someone starting from scratch, particularly outside major cities.

The second concerns early talent development: people talk a great deal about young cyber talent when it goes down the wrong path, but invest little in giving those who want to build something legitimate a way forward from the age of 16 or 17. Programmes such as the one run by INCIBE and Tetuan Valley are moving in the right direction, but we need many more of them.

Q. New vulnerabilities, ransomware campaigns and attack techniques emerge every week. Which threats should businesses and public authorities be most concerned about today?

A. For me, phishing remains the number-one threat, and it is becoming increasingly difficult to detect because AI can generate messages that are far more credible and personalised than they were a few years ago. I am also particularly concerned about ransomware targeting SMEs: these companies often lack the budget or a dedicated cybersecurity team, and a single attack can force them out of business. Finally, there is data exposure caused by cloud misconfigurations, which remains a basic and very common failure even at large organisations.

Q. Looking ahead, what is the roadmap for CyberSources? Is your ambition simply to turn it into the largest open-source repository of cybersecurity tools, or will the project expand into new services or solutions for the sector?

A. The plan is to keep growing and become more international, rather than remaining focused solely on the Spanish market. And yes, we are going beyond the repository: we are working on launching a section offering very affordable courses, because cybersecurity training is often expensive and I believe it should be accessible to everyone.

The underlying idea is to become a leading name in the sector and continue growing, while always preserving the principle that everything should be accessible to anyone, regardless of their budget.



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW