Developer docs
API playgroundTry for free, no card

Search company profiles

CERT

Full company profile

uuid003w7ux

Namestring
CERT
Legal namestring
Carnegie Mellon University
Websiteurl
cert.org
Company typeenum
Private
Founded yearint
1988
Descriptiontext

CERT (the CERT Division of Carnegie Mellon University's Software Engineering Institute) is a federally funded research and development center (FFRDC) that studies cybersecurity problems with widespread implications and develops methods, tools, and training to counter large-scale threats. Founded in 1988, the organization pioneered computer incident response and has expanded into network situational awareness, malware analysis, secure coding, insider threat mitigation, vulnerability discovery, digital investigations, and workforce development. Its core technology assets include the VINCE (Vulnerability Information and Coordination Environment) platform for coordinated vulnerability disclosure, the public CERT/CC Vulnerability Notes Database covering over 3,500 vulnerabilities across 2,300+ vendors, and a JSON API plus CSAF-formatted documents for programmatic access. CERT/CC also operates as a CVE Numbering Authority (CNA), assigning CVE IDs and managing disclosure workflows for multiple vendors and critical infrastructure sectors.

CERT's customer base spans U.S. federal government agencies (with primary sponsorship from the U.S. Department of War and coordination with DHS/CISA), industry partners, law enforcement, and academia, with documented engagements including the U.S. Postal Service on cybersecurity workforce development and joint training exercises with Air National Guard and Air Force Reserve units. Its business model is non-commercial: as an FFRDC, CERT is funded through federal contracts and grants, and services such as vulnerability coordination are provided free to vendors and the public. The organization does not sell commercial products and does not publicly disclose revenue. Go-to-market is direct engagement with government sponsors and partners rather than a traditional sales motion. Strategic emphasis is currently expanding into Autonomy Security and Resilience, addressing assurance of machine learning systems, supported by active hiring for AI security and data science roles.

Short descriptiontext

CERT Division, part of Carnegie Mellon University's Software Engineering Institute, is a federally funded R&D center that conducts cybersecurity research, operates the VINCE vulnerability coordination platform and Vulnerability Notes Database, and serves U.S. federal agencies, industry, and academia as a trusted CVE Numbering Authority.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
501–1,000
akta.pro rankint
HeadquartersPittsburgh, United States
HQ citystring
Pittsburgh
HQ countrystring
United States
HQ regionstring
North America
Markets served

Serves global market

Offices1 record

Each record includes

City, Country, Type, Description, Source

Keyword5 values
cybersecurity research services, vulnerability coordination platform, incident response coordination, secure software development, insider threat detection
Industry6 codes
1Vulnerability Management & Penetration Testing Services
CodeBPAEADADPrimaryYes
2Cybersecurity Technical Skills (Security Engineering, SOC, Pen Testing)
CodeEDABAFAFPrimaryNo
3Cybersecurity (General)
CodeEDAOAIABPrimaryNo
4Information Technology (IT) & Cybersecurity Certifications
CodeEDAAANAAPrimaryNo
5Penetration Testing, Red Team & Ethical Hacking
CodeEDAOAIAHPrimaryNo
6Cybersecurity Awareness & Digital Safety Training for Security Personnel
CodeBPAKAOAOPrimaryNo
NAICS code1 code
  • Security Systems Services56162
Product category
Cybersecurity Research and Vulnerability Coordination Services
GTM motion1 record

Each record includes

Type, Description, Source

Revenue model1 record
1Federal Government Funding
TypeManaged Services
Description

As a federally funded research and development center (FFRDC) operated by Carnegie Mellon University and sponsored by the Department of War, CERT Division's primary funding comes from federal government sources to conduct cybersecurity research and provide services to government agencies.

sei.cmu.edu
Marketing channels5 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels3 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components4 values
Personnel, Technology or R&D, Operations, Infrastructure
GTM typeB2B
B2B
Offering typeServices
Services
Core offering1 text field

CERT Division conducts cybersecurity research and provides coordinated vulnerability disclosure, incident response coordination, and advanced cybersecurity methods and tools to government, industry, law enforcement, and academia. The division operates the VINCE platform for vulnerability coordination, maintains the publicly accessible Vulnerability Notes Database (3,500+ notes across 2,300+ vendors), and serves as a CVE Numbering Authority. Core funded activities include 11 practice areas such as insider threat detection, malware reverse engineering, situational awareness, secure development, ML/autonomy security, and cyber workforce development.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 2 values shown
  • Over 3,500 vulnerability notes published in the database
+1 more record
Product overview1 text field

CERT (CERT Division of the Carnegie Mellon University Software Engineering Institute) operates as a federally funded research and development center specializing in cybersecurity. The organization offers a unified platform combining the VINCE coordination platform for vulnerability disclosure management and a publicly accessible Vulnerability Notes Database. Services include coordinated vulnerability disclosure, CVE ID assignment as a CNA, technical analysis, and cybersecurity research spanning incident response, malware analysis, insider threats, and secure development practices. The organization has operated for over 35 years, expanding from computer incident response to comprehensive cybersecurity research and workforce development.

Product and service4 records
1VINCE (Vulnerability Information and Coordination Environment)
CategoryPlatform
Description

A secure platform for coordinated vulnerability disclosure that enables vendors and reporters to communicate about vulnerabilities, track remediation progress, and manage the coordination process through a web-based interface with user accounts and case management.

2Vulnerability Notes Database
CategoryDatabase
Description

A searchable database containing vulnerability notes with technical details, impact assessments, affected vendor information, and remediation guidance for over 3,500 vulnerabilities affecting 2,300+ vendors.

3Vulnerability Coordination Services
CategoryService
Description

Coordinated vulnerability disclosure services that bring together reporters, vendors, and stakeholders to analyze vulnerabilities, develop remediation guidance, and ensure correct information reaches the public.

4CVE Numbering Authority (CNA) Services
CategoryService
Description

As a CVE Numbering Authority, CERT/CC assigns CVE IDs to vulnerabilities and manages the vulnerability disclosure process for multiple vendors and critical infrastructure sectors.

Scale indicator3 records

Each record includes

Type, Value, Description, Source

Partnership3 partners
Strategic tierCoreTypeStrategic or Co-development Partner
Description

CERT Division is a division of the Software Engineering Institute at Carnegie Mellon University. This relationship creates multidisciplinary collaboration opportunities and amplifies research abilities through access to university expertise across computer science, engineering, and related fields.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

CERT/CC operates under DHS/CISA coordination, publishing vulnerability advisories and providing cybersecurity coordination services. The organization issues advisories that are sponsored by CISA.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

CERT Division explicitly states it partners with government, industry, law enforcement, and academia to advance cybersecurity and improve the security and resilience of computer systems and networks.

Recent move6 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight6 records

Each record includes

Type, Description

Peers10 records
TypeBroad incumbent
Description

Federal civilian cybersecurity agency that coordinates vulnerability disclosure, publishes advisories, and partners with CERT/CC on coordinated response. Directly comparable in coordination mission and explicitly cited as a CERT sponsor and partner.

TypeDirect peer
Description

Federally funded research and development center that operates CVE Numbering Authority functions, ATT&CK framework, and CWE/MITRE security research programs. Direct peer to CERT in mission, funding model, and cybersecurity research scope, serving as the most structurally comparable FFRDC peer.

TypeDirect peer
Description

Leading cybersecurity training and certification organization that develops cyber workforce capabilities, GIAC certifications, and security research. Comparable to CERT's Cyber Workforce Development practice and serves overlapping federal and enterprise training demand.

TypeEmerging player
Description

Commercial incident response and threat intelligence firm, now part of Google Cloud, offering vulnerability research and coordinated disclosure services at commercial scale. Comparable to CERT's incident response and vulnerability coordination work but operating under a commercial, for-profit model.

TypeBroad incumbent
Description

Commercial cybersecurity leader providing threat intelligence, vulnerability research, and coordinated disclosure services through its services and intelligence businesses. Comparable to CERT in vulnerability research scope but operates at global commercial scale.

TypeRegional player
Description

EU agency coordinating cybersecurity capability development, vulnerability disclosure, and CSIRT support across member states. Comparable to CERT in mission of coordinating vulnerability disclosure and CSIRT capability development, but operates in the European regulatory context.

TypeDirect peer
Description

Nonprofit, university-affiliated research institution conducting policy and technology research for federal sponsors. Comparable to CERT/SEI as an FFRDC-style research organization with federal sponsorship and academic affiliation.

TypeDirect peer
Description

University-affiliated FFRDC conducting sponsored cybersecurity research for federal sponsors. Comparable to CERT in operating model, sponsor relationships, and cybersecurity research depth.

TypeBroad incumbent
Description

Federal agency responsible for cybersecurity frameworks including the NIST Cybersecurity Framework, SP 800 series, and NVD vulnerability program. Comparable to CERT as a government-sponsored authority shaping cybersecurity standards and vulnerability disclosure practice.

TypeDirect peer
Description

Federally funded research and development center operated by MIT that conducts cybersecurity, autonomous systems, and resilience research. Direct structural peer as an academic-affiliated FFRDC with comparable cybersecurity research mandate.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses5 records

Each record includes

Headline, Details, Source

Competitive moat5 records

Each record includes

Type, Details

Key risks5 records

Each record includes

Headline, Details, Source

Key highlights6 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers2 records

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment4 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile3 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
Yes

Docs URL, Description

AI maturity
App detail

Has app

Feature6 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles3 records

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

No data
No data
Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

CERT

Cybersecurity Research and Vulnerability Coordination Servicescert.org

CERT Division, part of Carnegie Mellon University's Software Engineering Institute, is a federally funded R&D center that conducts cybersecurity research, operates the VINCE vulnerability coordination platform and Vulnerability Notes Database, and serves U.S. federal agencies, industry, and academia as a trusted CVE Numbering Authority.

What CERT does

CERT (the CERT Division of Carnegie Mellon University's Software Engineering Institute) is a federally funded research and development center (FFRDC) that studies cybersecurity problems with widespread implications and develops methods, tools, and training to counter large-scale threats. Founded in 1988, the organization pioneered computer incident response and has expanded into network situational awareness, malware analysis, secure coding, insider threat mitigation, vulnerability discovery, digital investigations, and workforce development. Its core technology assets include the VINCE (Vulnerability Information and Coordination Environment) platform for coordinated vulnerability disclosure, the public CERT/CC Vulnerability Notes Database covering over 3,500 vulnerabilities across 2,300+ vendors, and a JSON API plus CSAF-formatted documents for programmatic access. CERT/CC also operates as a CVE Numbering Authority (CNA), assigning CVE IDs and managing disclosure workflows for multiple vendors and critical infrastructure sectors.

CERT's customer base spans U.S. federal government agencies (with primary sponsorship from the U.S. Department of War and coordination with DHS/CISA), industry partners, law enforcement, and academia, with documented engagements including the U.S. Postal Service on cybersecurity workforce development and joint training exercises with Air National Guard and Air Force Reserve units. Its business model is non-commercial: as an FFRDC, CERT is funded through federal contracts and grants, and services such as vulnerability coordination are provided free to vendors and the public. The organization does not sell commercial products and does not publicly disclose revenue. Go-to-market is direct engagement with government sponsors and partners rather than a traditional sales motion. Strategic emphasis is currently expanding into Autonomy Security and Resilience, addressing assurance of machine learning systems, supported by active hiring for AI security and data science roles.

CERT firmographics

Firmographics
Name
CERT
Legal name
Carnegie Mellon University
Website
https://cert.org
Company type
Private
Founded year
1988
Operating status
Operating
Headcount range
501–1,000 employees
Short description
CERT Division, part of Carnegie Mellon University's Software Engineering Institute, is a federally funded R&D center that conducts cybersecurity research, operates the VINCE vulnerability coordination platform and Vulnerability Notes Database, and serves U.S. federal agencies, industry, and academia as a trusted CVE Numbering Authority.
Ownership category
akta.pro rank

CERT industry classification

Industry
Product category
Cybersecurity Research and Vulnerability Coordination Services
NAICS
Security Systems Services (56162)
akta.pro primary industry
Vulnerability Management & Penetration Testing Services (BPAEADAD)
akta.pro secondary industries
Cybersecurity Technical Skills (Security Engineering, SOC, Pen Testing) (EDABAFAF), Cybersecurity (General) (EDAOAIAB), Information Technology (IT) & Cybersecurity Certifications (EDAAANAA), Penetration Testing, Red Team & Ethical Hacking (EDAOAIAH), Cybersecurity Awareness & Digital Safety Training for Security Personnel (BPAKAOAO)

Keywords

  • Cybersecurity research services
  • Vulnerability coordination platform
  • Incident response coordination
  • Secure software development
  • Insider threat detection

Where CERT is headquartered

Location

Headquarters

HQ city
Pittsburgh
HQ country
United States
HQ region
North America

Offices1 record

Markets served

CERT business model

Business model
GTM type
B2B
Offering type
Services
Cost components
Personnel, Technology or R&D, Operations, Infrastructure

Revenue model

  1. Federal Government Funding: As a federally funded research and development center (FFRDC) operated by Carnegie Mellon University and sponsored by the Department of War, CERT Division's primary funding comes from federal government sources to conduct cybersecurity research and provide services to government agencies.

Go-to-market motion1 record

Distribution channels3 records

Marketing channels5 records

CERT product offering

Product offering

Core offering

CERT Division conducts cybersecurity research and provides coordinated vulnerability disclosure, incident response coordination, and advanced cybersecurity methods and tools to government, industry, law enforcement, and academia. The division operates the VINCE platform for vulnerability coordination, maintains the publicly accessible Vulnerability Notes Database (3,500+ notes across 2,300+ vendors), and serves as a CVE Numbering Authority. Core funded activities include 11 practice areas such as insider threat detection, malware reverse engineering, situational awareness, secure development, ML/autonomy security, and cyber workforce development.

Product overview

CERT (CERT Division of the Carnegie Mellon University Software Engineering Institute) operates as a federally funded research and development center specializing in cybersecurity. The organization offers a unified platform combining the VINCE coordination platform for vulnerability disclosure management and a publicly accessible Vulnerability Notes Database. Services include coordinated vulnerability disclosure, CVE ID assignment as a CNA, technical analysis, and cybersecurity research spanning incident response, malware analysis, insider threats, and secure development practices. The organization has operated for over 35 years, expanding from computer incident response to comprehensive cybersecurity research and workforce development.

Differentiator

Problem solved

Functional benefit

Products and services

  • VINCE (Vulnerability Information and Coordination Environment) A secure platform for coordinated vulnerability disclosure that enables vendors and reporters to communicate about vulnerabilities, track remediation progress, and manage the coordination process through a web-based interface with user accounts and case management.
  • Vulnerability Notes Database A searchable database containing vulnerability notes with technical details, impact assessments, affected vendor information, and remediation guidance for over 3,500 vulnerabilities affecting 2,300+ vendors.
  • Vulnerability Coordination Services Coordinated vulnerability disclosure services that bring together reporters, vendors, and stakeholders to analyze vulnerabilities, develop remediation guidance, and ensure correct information reaches the public.
  • CVE Numbering Authority (CNA) Services As a CVE Numbering Authority, CERT/CC assigns CVE IDs to vulnerabilities and manages the vulnerability disclosure process for multiple vendors and critical infrastructure sectors.

Quantifiable outcome

  • Over 3,500 vulnerability notes published in the database
  • +1 more outcomes

Companies that use CERT

Customer profile

Named customers2 records

Segments4 records

Ideal customer profiles3 records

CERT technology and API

Technology

Technology focussed Yes

API detail

Has API
Yes
API docs
API detail

Core technology

AI maturity

App detail

Feature6 records

CERT partnerships and signals

Strategic signal

Partnerships

Three partnerships are on record, tiered core.

  • Carnegie Mellon UniversitycoreStrategic or Co-development PartnerCERT Division is a division of the Software Engineering Institute at Carnegie Mellon University. This relationship creates multidisciplinary collaboration opportunities and amplifies research abilities through access to university expertise across computer science, engineering, and related fields.
  • DHS/CISAcoreStrategic or Co-development PartnerCERT/CC operates under DHS/CISA coordination, publishing vulnerability advisories and providing cybersecurity coordination services. The organization issues advisories that are sponsored by CISA.
  • Government, Industry, Law Enforcement, and Academia PartnerscoreStrategic or Co-development PartnerCERT Division explicitly states it partners with government, industry, law enforcement, and academia to advance cybersecurity and improve the security and resilience of computer systems and networks.

Scale indicators3 records

Recent moves6 records

Expansion highlights6 records

CERT competitors and assessment

Company assessment

Broad incumbents

  • CISA (Cybersecurity and Infrastructure Security Agency): Federal civilian cybersecurity agency that coordinates vulnerability disclosure, publishes advisories, and partners with CERT/CC on coordinated response. Directly comparable in coordination mission and explicitly cited as a CERT sponsor and partner.
  • CrowdStrike: Commercial cybersecurity leader providing threat intelligence, vulnerability research, and coordinated disclosure services through its services and intelligence businesses. Comparable to CERT in vulnerability research scope but operates at global commercial scale.
  • NIST (National Institute of Standards and Technology): Federal agency responsible for cybersecurity frameworks including the NIST Cybersecurity Framework, SP 800 series, and NVD vulnerability program. Comparable to CERT as a government-sponsored authority shaping cybersecurity standards and vulnerability disclosure practice.

Direct peers

  • MITRE Corporation: Federally funded research and development center that operates CVE Numbering Authority functions, ATT&CK framework, and CWE/MITRE security research programs. Direct peer to CERT in mission, funding model, and cybersecurity research scope, serving as the most structurally comparable FFRDC peer.
  • SANS Institute: Leading cybersecurity training and certification organization that develops cyber workforce capabilities, GIAC certifications, and security research. Comparable to CERT's Cyber Workforce Development practice and serves overlapping federal and enterprise training demand.
  • RAND Corporation: Nonprofit, university-affiliated research institution conducting policy and technology research for federal sponsors. Comparable to CERT/SEI as an FFRDC-style research organization with federal sponsorship and academic affiliation.
  • Johns Hopkins Applied Physics Laboratory (APL): University-affiliated FFRDC conducting sponsored cybersecurity research for federal sponsors. Comparable to CERT in operating model, sponsor relationships, and cybersecurity research depth.
  • MIT Lincoln Laboratory: Federally funded research and development center operated by MIT that conducts cybersecurity, autonomous systems, and resilience research. Direct structural peer as an academic-affiliated FFRDC with comparable cybersecurity research mandate.

Emerging players

  • Mandiant (Google Cloud): Commercial incident response and threat intelligence firm, now part of Google Cloud, offering vulnerability research and coordinated disclosure services at commercial scale. Comparable to CERT's incident response and vulnerability coordination work but operating under a commercial, for-profit model.

Regional players

  • ENISA (European Union Agency for Cybersecurity): EU agency coordinating cybersecurity capability development, vulnerability disclosure, and CSIRT support across member states. Comparable to CERT in mission of coordinating vulnerability disclosure and CSIRT capability development, but operates in the European regulatory context.

Market position

Strengths5 records

Weaknesses5 records

Competitive moat5 records

Key risks5 records

Key highlights6 records

Customer concentration

CERT social profiles

Digital presence

CERT financial estimates

Financial estimate

Revenue estimate

Valuation estimate

CERT leadership team

Management profile

Number of profiles

Profiles3 records

CERT funding detail

Funding detail

Funding overview

Funding rounds

Investors

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

CERT M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about CERT

What does CERT do?

CERT Division conducts cybersecurity research and provides coordinated vulnerability disclosure, incident response coordination, and advanced cybersecurity methods and tools to government, industry, law enforcement, and academia. The division operates the VINCE platform for vulnerability coordination, maintains the publicly accessible Vulnerability Notes Database (3,500+ notes across 2,300+ vendors), and serves as a CVE Numbering Authority. Core funded activities include 11 practice areas such as insider threat detection, malware reverse engineering, situational awareness, secure development, ML/autonomy security, and cyber workforce development.

Is CERT a public or private company?

CERT is a private company. It is classified as nonprofit foundation owned and is currently operating.

When was CERT founded?

CERT was founded in 1988. It employs 501 to 1,000 people.

Where is CERT based?

CERT is headquartered in Pittsburgh, United States, in the North America region.

How does CERT make money?

One revenue line is on record: federal Government Funding.

Who are CERT's main competitors?

Broad incumbents on record are CISA (Cybersecurity and Infrastructure Security Agency), CrowdStrike and NIST (National Institute of Standards and Technology). Direct peers are MITRE Corporation, SANS Institute, RAND Corporation, Johns Hopkins Applied Physics Laboratory (APL) and MIT Lincoln Laboratory. Mandiant (Google Cloud) is listed as an emerging player. ENISA (European Union Agency for Cybersecurity) is listed as a regional player.

Does CERT have an API?

Yes. CERT provides a JSON API for accessing vulnerability notes data. The API endpoints return structured vulnerability information including CVE IDs, affected vendors, technical descriptions, and CSAF (Common Security Advisory Framework) formatted documents. The VINCE (Vulnerability Information and Coordination Environment) platform also provides API access for vulnerability coordination workflow. Developer documentation is at kb.cert.org/vuls/api.

What industry is CERT in?

CERT's product category is Cybersecurity Research and Vulnerability Coordination Services. Its primary akta.pro industry code is BPAEADAD, Vulnerability Management & Penetration Testing Services, with a secondary code of EDABAFAF, Cybersecurity Technical Skills (Security Engineering, SOC, Pen Testing). Its NAICS code is 56162.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
HotHardwareMillions Of Tenda Wi-Fi Routers Exposed By Hidden Backdoor Security FlawResearchers from CERT at Carnegie Mellon University discovered a hidden authentication backdoor in Tenda Wi-Fi routers that grants full administrative access using the password 'rzadmin' regardless of username. The vulnerability affects millions of Tenda routers, including AC10, AC5, and AC6 models, and can be exploited remotely unless users disable remote web management. CERT was unable to contact Tenda to notify the company of the flaw, raising concerns that the undocumented backdoor may have been intentionally placed.Simplilearn.comHow to Create an IT Security Incident Response PlanThe article provides a comprehensive guide on creating an IT Security Incident Response Plan, outlining steps such as defining scope, assigning roles, and establishing severity levels. It references industry frameworks like NIST, CERT, and CIS to help organizations structure their response procedures effectively. The text also includes promotional content for cybersecurity educational programs.SecurityWeekPoland Faced a Surge in Cyberattacks in 2025, Including a Major Assault on the Energy SectorPoland experienced 2½ times more cyberattacks in 2025 compared to the previous year, totaling 270,000 attacks, with a coordinated destructive assault on the country's energy system on December 29 targeting a combined heat and power plant serving nearly 500,000 customers and multiple wind and solar farms. Cybersecurity researchers at ESET analyzed the malware and attributed the attack to Russian threat actors, while CERT Polska confirmed the attack's destructive nature marked a significant escalation from typical ransomware incidents. The incident is believed to be unprecedented among NATO and EU members in terms of targeting critical energy infrastructure with purely destructive intent.UsnewsPoland Faced a Surge in Cyberattacks in 2025, Including a Major Assault on the Energy SectorPoland experienced 2½ times more cyberattacks in 2025 compared to the previous year, with 270,000 total attacks, and in December faced a destructive attack on its energy system targeting a combined heat and power plant supplying heat to almost 500,000 customers alongside multiple wind and solar farms. The attack, described as unprecedented among NATO and EU members, showed no financial motivation and was aimed purely at destruction, marking a significant escalation from typical ransomware incidents. Cybersecurity firms CERT Polska and ESET attributed the attack to Russian-linked threat actors Dragonfly and Sandworm respectively, with Western intelligence services previously linking both groups to Russian state entities.GlobeNewswireBirchtech Commences Enforcement of $78 Million Judgment PaymentBirchtech formally requested payment of its $78 million judgment against CERT entities on February 2, 2026, after the Delaware court's 30-day stay lapsed. CERT filed an appeal on January 28, 2026, and may seek a bonded stay; interest continues to accrue. The company plans to pursue enforcement options including asset discovery and seizures.IndustrialcyberCERT Polska details cyberattacks on Polish manufacturer, energy sites; fails to disrupt power and heat supplyOn December 29, 2025, coordinated cyberattacks targeted at least 30 wind and photovoltaic farms, a private manufacturing company, and a combined heat and power plant serving nearly half a million customers in Poland, using wiper malware designed to destroy industrial control systems. Although the attacks disrupted communication between renewable energy facilities and distribution operators and caused damage to RTU controllers, they failed to affect electricity production or heat supply as intended. Security researchers have attributed the attacks to the threat cluster known as 'Static Tundra'/'Berserk Bear'/'Ghost Blizzard'/'Dragonfly', marking the first publicly documented destructive activity by this group targeting critical energy infrastructure.WwwRATEL hosts regional meeting of CIRT teams from Montenegro, Albania and CyprusThe National CERT of Serbia hosted a two-day regional meeting on April 10-11, 2025, with representatives from Montenegro, Albania, and Cyprus to exchange knowledge and strengthen cybersecurity cooperation.CmuStrengthening Network Traffic AnalysisThe article outlines the evolution of the Department of Homeland Security's Einstein program, which became mandatory for federal civilian agencies in 2007. Originally deployed in 2004 following collaboration between SEI staff and the U.S. Department of Defense, the program utilizes tools from the SEI's CERT Division to analyze network traffic and identify threats. It has expanded from providing high-level views of connections to automating the collection and sharing of security information across the federal government.CmuFostering Growth in Professional Cyber Incident ManagementThe CERT Coordination Center (CERT/CC) was established by the Software Engineering Institute (SEI) following the 1988 Morris Worm attack to serve as a neutral third party for reporting and mitigating cybersecurity vulnerabilities. The organization facilitates vulnerability mitigation through its Vulnerability Notes and has built a network of over 50 national computer security incident response teams (CSIRTs).SecurityBrief New ZealandCyber Smart Week 2024: Kiwis urged to secure their digital footprintCert NZ has launched its annual Cyber Smart Week 2024 campaign to boost New Zealand's cyber resilience amid rising cybercrime, with around half of all New Zealanders experiencing some form of cybercrime within a six-month period. The campaign focuses on encouraging individuals, small businesses, and medium-sized organizations to adopt two-factor authentication and maintain strong password hygiene as essential security measures. CERT NZ remains hopeful that increased participation will lead to tangible improvements in the country's overall cyber resilience.