The official website SK

The gov.sk domain is official

This is the official website of the public authority of the Slovak Republic. Official websites mainly use the gov.sk domain. Links to individual websites of public authorities can be found at this link.

This page is secured

Be careful and always make sure that you share information only through the secure website of the Slovak public administration. A secure page always starts with https:// before the domain name of the website.

About Us Old

Threats Associated with Artificial Intelligence Technologies

Applied artificial intelligence is becoming one of the greatest technological advances of our time. With its great potential, however, there come significant concerns about potential misuse, as well as unintended consequences in its deployment. Therefore, it is necessary to focus on the risks that arise from the use of artificial intelligence. What is artificial intelligence?…

Warning of Vulnerabilities in AMI MegaRAC

The National Cyber Security Centre SK-CERT warns of two vulnerabilities in the MegaRAC Baseboard Management Controller (BMC) that enable bypassing authentication and injecting arbitrary code. Regarding the nature of the vulnerable systems, physical damage to vulnerable servers is also possible. The MegaRAC Baseboard Management Controller is a component that is used for server management, independent…

Warning of Increased Risk of Ransomware Attacks on Educational Institutions

The National Cyber Security Centre SK-CERT (hereinafter referred to as “NCKB SK-CERT”) warns of an increased risk of ransomware attacks by the Medusa group, which are particularly targeted on educational institutions. A successful attack will cause a total unavailability of systems and services and a leak of sensitive information. What is the Medusa group? According…

Warning of Spearphishing Activities by North Korean Hacking Groups

The National Security Authority warns of potential cyberattack threats in connection with the increase in the use of social engineering techniques by DPRK-sponsored hacking groups. The most prominent of these groups is Kimsuky (APT 43). Their activities focus on spearphishing campaigns in which cyber actors impersonate journalists or academic scholars to collect information and documents…

Warning of Zero-Day Vulnerability in VMware ESXi System

The National Cyber Security Centre SK-CERT warns of a zero-day vulnerability in VMware ESXi system, which can be exploited using valid ESXi credentials. The vulnerability allows code execution in virtual servers under a privileged user without knowledge of credentials to virtual servers. In order to exploit the vulnerability, access to the ESXi administrative interface is…

Warning of Critical Vulnerability in Fortinet Products

The National Cyber Security Centre SK-CERT warns of a new critical vulnerability in the FortiOS operating system included in various Fortinet products. Fortinet products are widely used by organizations in the Slovak cyberspace, including operators of essential services. The warning is issued by the National Security Authority pursuant to Article 27(1) a) of the ….

Warning of GIGABYTE Motherboard Vulnerability

The National Cyber Security Centre SK-CERT warns of a vulnerability in motherboards from the manufacturer GIGABYTE, which are popular and often used in the Slovak market as well. GIGABYTE motherboards have a built-in motherboard firmware update mechanism that contains security vulnerabilities. Each time the computer reboots, the firmware initiates an update programme, and thus downloading…

TL;DR: Open VPN Database (21st Week)

A VPN service claiming that it does not log communications had again logs leaked. An illegal IPTV service was taken down in the Netherlands; and a large amount of medical and financial information was leaked in the US. An 18 year old hacker was discovered and charged with serious crimes by security forces; the founder…

Warning about an actively exploited vulnerability in a WordPress plugin

The National Cyber Security Center SK-CERT warns about an actively exploited vulnerability in the Beautiful Cookie Consent Banner plugin of the WordPress content management system. The mentioned plugin is used to create a graphical notification about the use of cookies. The plugin has over 40,000 active installations. The vulnerability allows for a XSS attack, where…