Cybersecurity backed by verifiable results
These findings were responsibly disclosed, fixed in production software and credited in public vulnerability records.
- vulnerabilities in the OffSeq Radar database
- 100K+
- eID software improved
- National
- agency pentesting experience
- NATO
- recognised security researcher
- CERT.LV
6
Results
2023–2026- 01
Cross-instance configuration poisoning in X-Road
X-Road Security Server (< 7.8.2)
X-Road Security Servers wrote federated global-configuration parts to disk based on the ecosystem identifier carried inside each part, without verifying it matched the actual source. A malicious federation partner could serve a SHARED-PARAMETERS part naming a victim ecosystem — signed with the victim’s own key — and overwrite its authoritative trust configuration, gaining persistent control and the ability to impersonate any of the victim’s members and Security Servers.
Insufficient verification of data authenticity (CWE-345, CWE-346)
View advisory (opens in a new tab) How we would test your environment
CVSS 8.0 High GHSA-c5gr-pcm6-828r 2026 - 02
Pre-authentication denial of service in X-Road signature verification
X-Road Security Server (< 7.8.2)
The hash-chain verifier in X-Road’s batch-signature handling had no cycle detection, depth limit or cap on resolved steps, and the attacker-controlled chain was resolved before signature and certificate checks. A registered ecosystem member could send a small crafted request (a few KB) to trigger exponential CPU use or unbounded recursion, exhausting processing threads and disrupting the data-exchange service before authentication.
Uncontrolled resource consumption (CWE-400)
View advisory (opens in a new tab) How we would test your environment
CVSS 6.5 Medium GHSA-rc33-88jw-c5jp 2026 - 03
Command injection fixed in Estonia’s national eID software
DigiDoc4 — Estonia’s official eID signing application
DigiDoc4’s file-manager integration constructed shell commands using unsanitised filenames. A specially crafted filename could execute arbitrary code when a user selected the file for signing or encryption. The issue affected software used for legally binding electronic signatures.
OS command injection (CWE-78)
Read the write-up (opens in a new tab) How we would test your environment
Critical 2026 - 04
SWQL injection in SolarWinds Platform
SolarWinds Platform (≤ 2024.1 SR 1)
A query-language injection vulnerability allowed an attacker to manipulate back-end database queries in the SolarWinds Platform. It was identified during penetration testing for the NATO Communications and Information Agency.
SQL / SWQL injection (CWE-89)
View on NVD (opens in a new tab) How we would test your environment
CVSS 7.5 High CVE-2024-28996 2024 - 05
Cross-site scripting vulnerability in Oracle Enterprise Command Center
Oracle E-Business Suite — ECC Framework
An unauthenticated attacker could obtain unauthorised read and update access to data in the framework and connected Oracle products. Oracle fixed the issue in its October 2023 Critical Patch Update.
Cross-site scripting (CWE-79)
View on NVD (opens in a new tab) How we would test your environment
CVSS 6.1 Medium CVE-2023-22107 2023 - 06
SQL injection affecting customer data, responsibly disclosed
International company (responsibly anonymized)
An SQL injection vulnerability could have exposed customer data. It was reported through a responsible-disclosure process and fixed promptly. CERT.LV has publicly acknowledged our founder’s contributions to the security of Latvia’s internet space.
SQL injection
About CERT.LV (opens in a new tab) How we would test your environment
High 2023 - 07
threat-finder — open-source runtime CVE scanner
OffSeq open-source tools
A runtime vulnerability scanner that identifies CVEs affecting services currently running on a host and prioritises them by network exposure. It is part of the public toolset we develop and use in engagements.
Research & tooling
View on GitHub (opens in a new tab) How we would test your environment
2025
Certified to international standards
-
OSCP OffSec
-
Lead Pen Test Professional PECB -
ISO/IEC 27001 Senior Lead Auditor PECB -
Certified Information Systems Auditor ISACA -
Red Team Operations Clarified Security
-
Critical Information Infrastructure Protection NATO CCDCOE
-
Web Applications Attack & Defence NATO CCDCOE
-
IT Systems Attack & Defense CybExer
-
Cybercrime CEPOL -
Cyber Bite: Darkweb CEPOL -
OSINT – Cryptocurrencies CEPOL -
Security Awareness: Privileged Accounts SANS
Book a consultation
[email protected] +371 2256 5353