24/7 incident response phone: 24/7 incident response · +34 902 540 891

Research and innovation

Industrial cybersecurity moves at the pace set by the threats driving it. Staying ahead requires continuous research: opening what nobody has audited, understanding new malware before it reaches a plant and testing what has not yet made it into any manual.

Why we research

We do not research for prestige, but because our services need it. When a client calls us about an incident, the malware may be new; when a manufacturer wants to sell in Europe, its product may never have been opened up; when a new attack technique appears, it must be understood before it can be defended against. Research keeps the rest of our work ahead of the adversary.

The work takes place in Ti Lab, our laboratory, which houses real control equipment, a hardware bench, radio capabilities and analysis tools. This page explains what we research and what results come from it; the Ti Lab page explains with what and how.

And we follow one rule: when we find a flaw in someone else's product, we disclose it responsibly. It is neither concealed nor sold; disclosure is coordinated with the party responsible for fixing it.

Applied research

Vulnerabilities discovered and disclosed

Ten CVE identifiers resulting from the team's research and published through coordinated disclosure with vendors, INCIBE-CERT and CISA. Each link opens the public advisory with scope, scoring and remediation information.

2023 · IoT

CVE-2023-5499

Shenzhen Reachfar GPS v28

Exposure of logs and sensitive data in a personal GPS tracker. High severity, CVSS 7.5.

INCIBE-CERT advisory

2023 · 4G/5G networks

CVE-2023-4882CVE-2023-4883CVE-2023-4884CVE-2023-4885

Open5GS

Four core-network vulnerabilities: denial of service, invalid pointer release, missing authentication and interception of VNF communications.

INCIBE-CERT advisory

2023 · IIoT

CVE-2023-4817

ICP DAS ET-7060

Unrestricted file upload in an industrial Ethernet module, with the potential to compromise the device.

INCIBE-CERT advisory

2021 · Access control

CVE-2021-3604

Primion-Digitek Secure 8

Remote blind SQL injection that could expose user and administrator information. Critical severity, CVSS 9.8.

INCIBE-CERT advisory

2020 · Industrial control

CVE-2020-25191

National Instruments CompactRIO

Incorrect permissions on an API entry point that could allow an unauthenticated remote reboot of the controller.

CISA advisory

2020 · Automation

CVE-2020-7580

Siemens industrial products

An unquoted search path in a shared component that could enable code execution with SYSTEM privileges.

CISA advisory

2020 · Industrial gateways

CVE-2020-10633

HMS Networks eWON Flexy and Cosy

Non-persistent cross-site scripting in industrial gateways that could be used to initiate a password change.

CISA advisory
Research lines

Research areas

Six active fronts. They are not isolated areas: an incident at a substation may involve an IED's firmware, its IEC 61850 protocol and the radio link used for remote control, all at once.

Embedded-device and firmware security

What lies inside a device: forgotten debugging interfaces, factory-embedded credentials and firmware that nobody has audited. We work on PLCs, RTUs, sensors and connected medical devices, including physical extraction.

View details

Vulnerability discovery (zero-day)

Finding the flaw before the attacker does. We dedicate specialist time to searching for previously unknown vulnerabilities in proprietary or third-party software using targeted fuzzing and instrumentation.

View details

Reverse engineering and industrial malware

Understanding what comes without source code: a sample from an incident or an undocumented protocol. We closely track malware designed for industry—a small but very serious catalogue.

View details

Radio communications security

The spectrum nobody watches: wireless telemetry, LPWAN, industrial Bluetooth, private 5G and remote control. With Software Defined Radio, we capture, analyse and test what an attacker would test.

View details

Artificial intelligence applied to OT defence

AI where it genuinely adds value, not because it is fashionable: anomaly detection in industrial protocols, support for malware analysis and models that run locally when data cannot leave the plant.

View details

Industrial protocols and architectures

The language of the plant: Modbus, DNP3, S7, IEC 61850 and GOOSE. We study how control systems communicate to detect anomalies and design resilient architectures.

View details
Applied AI

What we are developing with artificial intelligence

Models for detecting anomalies, explaining alerts and making risk decisions in industrial networks. We distinguish work that has already been applied or published from research still on the roadmap.

Applied and published

Applied

IIoT intrusion detection with transformers

Sequential models for analysing industrial traffic in real time and detecting behaviour that departs from the normal baseline.

View publication
Applied

Adversarially trained Bayesian autoencoder

Interpretable anomaly detection using Bayesian networks, adversarial learning and an evolutionary strategy.

View publication
Applied

Federated explainability for anomalies

Alert characterisation in distributed IoT environments without centralising the sensitive data held by each node.

View publication
Applied

Semiparametric Bayesian networks for risk estimation

Flexible probabilistic modelling to improve risk estimation when data does not follow simple distributions.

Applied

Explainable classifiers for cyberattack detection

Classification with semiparametric Bayesian networks that can justify which variables led to each decision.

Applied

Probabilistic data preprocessing

Non-parametric discretisation of probabilistically labelled data to build more stable models.

View publication

Roadmap

Roadmap

Variational inference for autoencoders and adversarial models

Quantifying model uncertainty to distinguish real anomalies from noise and legitimate operational changes.

Roadmap

Industrial traffic generation and zero-day discovery

Generative adversarial models to produce network scenarios for training, fuzzing and previously unknown vulnerability discovery.

Roadmap

Robust reinforcement learning for risk minimisation

Selecting defensive measures under uncertainty while considering operational impact, cost and attack evolution.

Roadmap

Multi-objective mitigation optimisation

Balancing risk reduction, availability, implementation effort and plant constraints at the same time.

Verifiable results

Publications

A selection of work involving Titanium researchers and collaborators. Each title links to its DOI, publisher or an external academic repository.

  1. 2026
    Sow Smarter, Not Harder: Evaluating LLM-Generated Seeds for Fuzzing Critical Infrastructure

    J. Barredo, M. Eceiza, J. L. Flores & M. Iturbe · CRITIS 2025, LNCS 16291

  2. 2025
    CARNYX: A Framework for Vulnerability Detection via Power Consumption Analysis in Embedded Systems

    J. Barredo, M. Eceiza, J. L. Flores & M. Iturbe · International Journal of Information Security 24(4)

  3. 2025
  4. 2025
  5. 2025
    Practical Approaches Towards IoT Dataset Generation for Security Experiments

    X. Sáez-de-Cámara et al. · Advanced Machine Learning for Cyber-Attack Detection in IoT Networks

  6. 2024
    Group Decision-Making Process for Cyberattack Mitigation

    A. Bregar, A. Husseis & J. L. Flores · GDN 2024

  7. 2024
    A Summary of: Federated Explainability for Network Anomaly Characterization

    X. Sáez-de-Cámara et al. · 9th Spanish National Cybersecurity Research Conference

  8. 2024
    Vulnerability Detection and Response: Current Status and New Approaches

    Á. Longueira-Romero, R. Iglesias, J. L. Flores & I. Garitano · CyberSecurity in a DevOps Environment

  9. 2023
    Anomaly-Based Intrusion Detection in IIoT Networks Using Transformer Models

    J. Casajús-Setién, C. Bielza & P. Larrañaga · IEEE CSR 2023, pp. 72–77

  10. 2023
    Enhancing Cybersecurity Proactive Decision-Making Through Attack Tree Analysis and MITRE Framework

    A. Husseis, J. L. Flores, A. Bregar, G. Mazzeo & L. Coppolino · IEEE ICCST 2023

  11. 2023
    Gotta Catch 'em All: Aggregating CVSS Scores

    Á. Longueira-Romero, J. L. Flores, R. Iglesias & I. Garitano · RECSI

  12. 2023
  13. 2023
    Federated Explainability for Network Anomaly Characterization

    X. Sáez-de-Cámara et al. · RAID 2023, pp. 346–365

  14. 2023
    A MCDM Methodology for Cyberattack Mitigation

    A. Bregar, A. Husseis & J. L. Flores · International Symposium on Operations Research

  15. 2023
  16. 2023
    Gotham Testbed: A Reproducible IoT Testbed for Security Experiments and Dataset Generation

    X. Sáez-de-Cámara et al. · IEEE Transactions on Dependable and Secure Computing

  17. 2023
  18. 2022
    Evolutive Adversarially-Trained Bayesian Network Autoencoder for Interpretable Anomaly Detection

    J. Casajús-Setién, C. Bielza & P. Larrañaga · PGM 2022, PMLR 186

  19. 2022
    Non-Parametric Discretization for Probabilistic Labeled Data

    J. L. Flores, B. Calvo & A. Pérez · Pattern Recognition Letters 161, pp. 52–58

  20. 2021
    Contextualized Filtering for Shared Cyber Threat Information

    A. Dimitriadis et al. · Sensors 21(14), 4890

  21. 2021
  22. 2021
    Towards Automatic and Portable Data Loading Template Attacks on Microcontrollers

    U. Rioja, L. Batina, J. L. Flores & I. Armendariz · ISQED 2021, pp. 437–443

  23. 2021
Responsible disclosure

Have you found a flaw in something we make?

As a security company, we publish how to report a vulnerability. If you have found an issue on this website or in any of our products, write to us: we respond, do not pursue good-faith research and credit anyone who wishes to be acknowledged.

Titanium · Legal information
Titanium · Legal information
Titanium · Legal information