Securing the .pl TLD.

Warsaw, Poland
⚠️ Fake ads & malicious apps: toll fraud operation Cybercriminals used malware to enroll victims in paid subscriptions without their consent. They promoted malicious Google Play apps through fake Meta ads, targeting Polish Android users. Read➡️cert.pl/en/posts/2026/09/tol…
4
4
858
We've just published a behind-the-scenes look at the process of finding, analysing and disclosing the MikroTrick vulnerability. With the rapid development of AI agents in the field, we expext to see more of such cases every month. Details on our website: cert.pl/en/posts/2026/09/mik…
10
19
2,080
A new entry vector used in a destructive attack against one of Poland's energy plants. A configuration that allowed it is widely used in the infrastructure around the world. How had the attackers managed to achieve this? All the answers inside our report: cert.pl/en/posts/2026/08/inc…
2
43
135
27,441
📢 Marcin Dudek at @defcon presenting a never-before-seen entry vector used in a destructive attack against one of Poland's energy plants. The Head of CERT Polska speaks about the details and challenges of analysing such an incident. A link to the full report in the thread 👇
3
11
49
4,826
‼️ A twist in UNC1151/Ghostwriter activity In the previous months, we've noticed a change in the behaviour of the aforementioned cluster of activity. 🔗 More information, including examples, shared on our website: cert.pl/en/posts/2026/06/UNC…
8
10
1,593
Fuzzing has long been one of the most effective methods for finding vulnerabilities. But what happens when an LLM takes the wheel? Our latest research explores autonomous, AI-driven fuzzing and what it means for the future of security testing. 👇 cert.pl/en/posts/2026/05/aut…
1
51
204
50,702
CERT Polska sheds light on a new FvncBot campaign targeting Polish users. The fake bank app acts as a loader for hidden additional modules, while abusing accessibility features enables device takeover and remote control. Read the full analysis: cert.pl/posts/2026/03/analiz…
2
6
1,446
🚨 2 weeks left to apply as a speaker for the SECURE conference! 🚨 🗓️ You have up until the 15th of February to submit the form at cfp.secure.edu.pl Give us a short description of your speech and wait for the response. 💡 See you in Warsaw on the 8th of April!
1
1,621
‼️At the end of last year, there was a series of coordinated attacks in Polish cyberspace. 📌Today, our team is publishing a report describing the technical analysis of these events. We show the scheme of operation and the tools used by the attackers. ➡️cert.pl/uploads/docs/CERT_Po…
12
146
300
75,424
Over 0.5M domains appeared on the Warning List since March 2020! Used by all the major polish ISPs, the List enables redirecting users trying to access pages classified as malicious. It's also compatible with browser extensions and free to use. More: cert.pl/en/warning-list/
1
1
4,281
🔍 Have you tried monitoring certificate transparency logs lately and found existing tools or libraries disappointing? ✅ Fear not! We're releasing a better one, with tiled format support, async operations, state persistence and an easy-to-use API. 🔗 github.com/CERT-Polska/ct-mo…
10
40
4,996
We've recently spotted a phishing campaign distributing a malware app used for NFC relay scams. Our analysts prepared a case study, both for general users and those more technical, check it out: cert.pl/en/posts/2025/11/ana…
4
12
3,621
Today we released a new stable version of DRAKVUF Sandbox v0.19.0 🎉– a project that leverages the DRAKVUF system for agentless malware analysis. Detailed release notes can be found on our Github: github.com/CERT-Polska/drakv…
1
47
120
10,576
🇵🇱🇪🇺 The main cyber goal of Polish presidency of the Council of the European Union achieved! 🟦 Cyber Blueprint, a project for which CERT Polska provided substantial insight, has been accepted as an emergency plan for a cyber crisis. 🔗 Read more: consilium.europa.eu/en/press…
3
7
5,432