Skip to main content
CERT Polska

CERT Polska

Search complete. 7 mentions across 6 episodes found for "CERT Polska".

Oct 2, 2026

Jerry BellHOST
1:34
The other reads any file off the server.
Jerry BellHOST
1:37
Cert Polska says it couldn't reach Dayforce, so there's no word on a fix yet.
Jerry BellHOST
1:42
Payroll holds your employees' bank details, so ask Dayforce in writing whether these are fixed in your environment.
Jerry BellHOST
1:49
Five, just selecting a model in Unsloth Studio ran Python code from that model's repository before the model itself even loaded.
RichHOST
4:18
And there's another catch for anyone thinking, "Well, I'll read the command first." A short instruction can tell the computer to retrieve more instructions from elsewhere and run those too.
RichHOST
4:28
CERT Polska, and this is Poland's Computer Security Incident Response Team, documented that kind of command in its February seventeenth, twenty twenty-six investigation of another fake CAPTCHA incident.
RichHOST
4:41
The line you can see may only start the process.
RichHOST
4:45
All right.
Sean McMillanHOST
42:44
Now that was, like, left behind as an artifact, right? So how does that-- how did you discover that? How does that, like, play into, um, h-having that there, what does that allow you as someone in your role or even a, a defender? Like, what does that give them the ability to do?
Emilio GallegosGUEST
43:08
Well, in, in this particular case, I wanna say that we were blessed, uh, with, uh, tons of different indicators that, um, CERT Polska, they did a, a very good job at-
Sean McMillanHOST
43:22
Yeah
Emilio GallegosGUEST
43:22
... um, really nailing them down and sort of describing what is it that they saw.
Corey NachreinerHOST
10:18
This is them essentially adding some firmware security.
Corey NachreinerHOST
10:21
I, I will say a- al- although, uh, CERT Polska and us have a, probably have a opinion on it, the flag doesn't mean you're compromised for sure.
Corey NachreinerHOST
10:31
It means it's running in a state that's not 100% recognized.
Corey NachreinerHOST
10:36
And I think everyone would agree that if you ever have that status, you gotta assume [chuckles] you're compromised, and that means a lot of things.
Corey NachreinerHOST
11:07
So I would say this is a, a, a good step to take when you have these sorts of issues in a router or a routing device.
Marc LaliberteHOST
11:15
Yep.
Marc LaliberteHOST
11:16
Um, CERT Polska gave a few other IoCs.
Marc LaliberteHOST
11:19
They said look for a highly privileged user named Ops on the device.
speaker_1HOST
6:38
Yeah.
speaker_1HOST
6:38
So CERT Polska discovered unknown threat actors exploiting two distinct flaws to seize control of vulnerable devices.
speaker_1HOST
6:47
And they're doing this without any authentication whatsoever.
speaker_0HOST
6:50
Zero authentication.

Unknown podcast

2026-09-13: CISA added five actively exploited flaws to the KEV catalog with patch deadlines through September

Sep 13 · 1 Mention

CarolinaHOST
2:39
MicroTik flaws.
CarolinaHOST
2:40
Enable kernel memory disclosure and privilege escalation without authentication, exploited in attacks CERT Polska calls MicroTrik.
CarolinaHOST
2:47
And five additional CVEs.
CarolinaHOST
2:49
See show notes for the full list.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.