We describe the technical details of the MikroTrick chain, which combines the CVE-2026-67279 and CVE-2026-86060 ...
On 14 September 2026, CERT Polska found two Facebook advertisements targeting Polish users with false warnings that their PDF application had expired. Both ads redirected users to the Google Play ...
After obtaining our new .NET extraction powers we quickly had a chance to give them another try. This time we decided to focus on a malware family called XWorm - a multi-purpose tool that is most ...
The UNC1151/Ghostwriter group remains one of the most active APT groups monitored by the CERT Polska team. For many years, it has consistently conducted phishing campaigns aimed at gaining access to ...
CERT Polska has received a report about vulnerabilities in CyberArk Endpoint Privilege Manager software and participated in coordination of their disclosure. The vulnerability CVE-2025-22271: The ...
Za nami kolejny rok działania zespołu CERT Polska. Był on wyjątkowy, ponieważ wieńczył trzecią dekadę naszej działalności – świętujemy właśnie 30. urodziny! Rok 2025 to czas pełen wyzwań, rozwoju i ...
CERT Polska has received a report about vulnerabilities in KAON PG5298A/PG5298B routers and participated in coordination of their disclosure. The vulnerability CVE-2025-63080: Firmware in KAON PG5298A ...
CERT Polska has received a report about vulnerabilities in SIMPLE.ERP software and participated in coordination of their disclosure. The vulnerability CVE-2024-8773 allows MS SQL protocol downgrade ...
CERT Polska has received a report about vulnerabilities in Logseq software and participated in coordination of their disclosure. The vulnerability CVE-2026-9279: Logseq exposes an IPC handler that ...
CERT Polska has analyzed an android malware sample distributed through infrastructure impersonating Booking.com. We refer to it as cifrat (a name derived from the the io.cifnzm.utility67pu package ...
CERT Polska has received a report about vulnerability in Code Runner MCP Server software and participated in coordination of its disclosure. We thank Eryk Winiarz for the responsible vulnerability ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results