The official website SK

The gov.sk domain is official

This is the official website of the public authority of the Slovak Republic. Official websites mainly use the gov.sk domain. Links to individual websites of public authorities can be found at this link.

This page is secured

Be careful and always make sure that you share information only through the secure website of the Slovak public administration. A secure page always starts with https:// before the domain name of the website.

About Us Old

Warning of Multiply Vulnerabilities in Apple Products

The National Cyber Security Centre SK-CERT warns of several vulnerabilities in Apple products that could be exploited by attackers for remote code execution, denial of service or information theft. Apple has released a patch for several vulnerabilities, including several critical ones that allow attackers to execute several malicious activities – denial of service, privilege escalation,…

TL;DR: Thieves Scream “We Robbed a Thief” (3rd Week)

Security researchers have released decryption keys for ransomware; criminals have stolen Darkweb business from other criminals; and hacktivists are freely distributing data from two forensic companies. Europol and the security forces carried out several successful international interventions against fraudsters in call centres. The success of security forces Europol, in cooperation with the law enforcement and…

Warning of Critical Vulnerabilities in Git System

The National Cyber Security Centre SK-CERT warns of critical vulnerabilities in Git system that could be exploited by attackers for remote code execution. Git is a distributed revision control tool. Git is a popular open-source tool used worldwide. Critical vulnerabilities are tracked as CVE-2022-23521 and CVE-2022-41903. The vulnerabilities allow an unauthenticated attacker to execute code…

Warning of Programmable Logic Controllers Vulnerability from Siemens

The National Cyber Security Centre SK-CERT warns of a new vulnerability in the firmware of programmable logic controllers (PLC) from Siemens. PLC devices from Siemens are also popular and widely used in Slovakia in various areas of manufacturing and industry. The vulnerability allows an attacker to bypass all protected boot features allowing him to modify…

TL;DR: Christmas SMS (1st and 2nd Week)

A corporation was fined for illegal advertising; schoolchildren in the US were given three days of cyber holiday; and a British medical centre gave its patients an unwanted gift in the form of a text message. Security researchers published decryption keys for ransomware; and cybercriminals started using artificial intelligence to write malware. Fine for advertising…

TL;DR: Attack on the Children’s Hospital and Success of the Ukrainian Police (51st Week)

Security forces in Ukraine managed to achieve another success in the fight against cybercrime. The LastPass data breach is escalating; and there is also more recent information about the sports betting company DraftKings’ data leak. Cybercriminals attacked a children’s hospital in Canada; and several charges were laid and several sentences handed down. Ransomware attack on…

Warning of a New Critical Vulnerability in FortiOS and FortiProxy

The National Cyber Security Centre SK-CERT (hereinafter referred to as “NCSC SK-CERT”) warns of a new critical vulnerability in FortiOS and FortiProxy products. FortiOS and FortiProxy are Fortinet products. FortiOS is an operating system that is used in other Fortinet products, FortiProxy is a web proxy used mainly for URL filtering, threat protection and malware…

TL;DR: LastPass and Zero Knowledge (47th and 48th Weeks)

A company focusing on secure password storage has become a victim of a data leak; two cybercriminals have been arrested with millions in profits; and a French energy company has discovered that weak password encryption does not pay off. Passwords are “safe” LastPass became a target of another cyberattack, leading to a data breach. Cybercriminals…

Upgrade Your Traffic Light Protocol – Move to TLP 2.0!

Although a new version of the TLP standard has been available for a longer time (the National Cyber Security Centre SK-CERT already published the relevant article in August), not all organizations have adopted these changes into their processes. The National Cyber Security Centre SK-CERT (hereinafter referred to as “NCSC SK-CERT”) therefore appeals to all those…

Critical vulnerability in OpenSSL – updated on 1 November 2022

The National Cyber Security Centre SK-CERT reminds that the OpenSSL developers have announced the release of a patch for a critical security vulnerability on Tuesday, 1 November 2022 at 2:00 p.m. (winter time). Please note that details will be published during our bank holiday. Operators of essential services are therefore strongly advised to place necessary…