Skip to content

CERT-Cyberross

Security advisories

Published when we observe a campaign that materially affects organisations in the markets we cover. Summaries are public and always will be — if something is coming for your sector, knowing about it should not require a contract.

Severity scale

We grade by what the campaign is doing right now to organisations like yours, not by CVSS. A theoretical flaw with a 9.8 score and no observed exploitation is not a critical advisory; an unsophisticated invoice fraud actively draining accounts in your sector is.

Critical
Active campaign causing confirmed loss in a market we cover. Act today.
High
Infrastructure staged, or campaign confirmed against a comparable sector. Act this week.
Moderate
Technique observed and worth reviewing against your controls. Act this quarter.

Getting them early

Published advisories are always free. What customers get is the same intelligence before publication, with the indicators and detection rules attached — usually several days ahead, and sometimes weeks when we are tracking infrastructure that has not been used yet.

If you are in an affected sector and not a customer, ask us anyway. We would rather you were defended than billed.

Next step

See what an attacker sees

We map your external attack surface the way an adversary does — exposed assets, leaked credentials, impersonation domains. No agent, no access, no cost.

30 min

A scoping call, with an engineer rather than a sales rep.

What it costs

Nothing, and there is no sequence afterwards. If we are not the right fit we will say so and suggest who is.

Under attack now?

Do not use this form. The hotline is answered around the clock and reaches a duty analyst directly.