The official website SK

The gov.sk domain is official

This is the official website of the public authority of the Slovak Republic. Official websites mainly use the gov.sk domain. Links to individual websites of public authorities can be found at this link.

This page is secured

Be careful and always make sure that you share information only through the secure website of the Slovak public administration. A secure page always starts with https:// before the domain name of the website.

About Us Old

Backdoor in SSH Server Caused by XZ/LZMA Compression Library – Update Immediately!

Update on 3 April 2024 (in blue and italics): added vulnerable Linux distributions, more specific malicious library behaviour, recommendations. A software developer discovered a backdoor in the lzma library, which is used for compression and is part of the xz-utils package. This library is used worldwide in software for archiving, multimedia handling and may be…

Warning of Vulnerability in Palo Alto Networks Firewall

Update on 19 April 2024: Added affected versions and recommendations The National Cyber Security Center (NCSC) warns of a critical security vulnerability with a CVSS score of 10.0 in Palo Alto devices. Palo Alto has warned its customers that a critical flaw impacting PAN-OS software with GlobalProtect enabled is being actively exploited. The vulnerability has…

VMware Released Security Patches for Critical Vulnerabilities in ESXi

The National Cyber Security Centre warns of two critical vulnerabilities in VMware products (ESXi, Workstation, Fusion, and Cloud Foundation). The company documented a total of four vulnerabilities, warning that the most serious of them could allow a malicious actor with local administrative privileges on virtual machines to execute code as the virtual machine’s VMX process running…

WARNING: The National Cyber Security Centre SK-CERT does Not Distribute Malicious Code

UPDATE: Issue has been fixed. If you have such problem with our products, please contact us. In recent days, the National Cyber Security Centre SK-CERT has discovered that the Security Warnings and Security Bulletins that it produces and distributes in .pdf form are being identified by some systems as potentially harmful. It means that our…

Warning of Vulnerability in Android devices

The National Cyber Security Centre SK-CERT warns of a vulnerability in devices running Android versions 13 and 14. The vulnerability lies in the insufficient device security even when the screen is locked. A threat actor needs physical access to the device to exploit this particular vulnerability, and then can access sensitive data such as photos,…

Warning of Critical Randstorm Vulnerability in Crypto Wallets

A recent report by a blockchain security company Unciphered has revelead a critical vulnerability dubbed “Randstorm” affecting cryptocurrency wallets created between 2011 and 2015. It makes it possible to recover passwords and gain unauthorized access to a multitude of wallets spanning blockchain platforms. The report disclosed that Randstorm could affect several blockchain projects in the…

Warning to Parents about a Dangerous Group on WhatsApp

The National Cyber Security Centre SK-CERT (hereinafter referred to as “SK-CERT”) warns parents about the group “Add as many people as possible” (Přidej co nejvíc lidí) on the social media platform Whatsapp, which is currently spreading among primary school pupils in the Czech Republic and Slovakia. According to reports from the Czech Republic, the group…

Warning of Actively Exploited Zero-Day Vulnerability in Cisco IOS XE

UPDATE on 24 October 2023 at 1.00 p.m.: Identification of additional vulnerability CVE-2023-2073, update of procedure for identifying compromised devices, addition of reference to firmware updates. The National Cyber Security Centre SK-CERT (hereinafter referred to as “SK-CERT”) warns of an actively exploited vulnerability in the Cisco IOS XE software interface. Cisco has identified the active…

Critical Actively Exploited Vulnerability in Web Browsers and Applications

UPDATE on 27 September 2023 at 11:40 p.m.: Completing the list of vulnerable applications The National Cyber Security Centre SK-CERT warns of a critical security vulnerability in the popular libwebp library that allows remote execution of arbitrary code. The vulnerability has reached a maximum CVSS score of 10.0. The library can be found in thousands…

Warning of Vulnerability in Adobe Reader and Acrobat

The National Cyber Security Centre SK-CERT warns of a security update released for Adobe Reader and Acrobat for Windows and macOS systems. This update fixes a serious vulnerability that allows an attacker to execute arbitrary code. Adobe products are the world’s favourite tools for everyday use of computers and other devices. Adobe Reader and Acrobat…