As cybersecurity is our passion, we are constantly involved in various research projects related to the field. We work on defense and detection methods as well as we participate in bug bounty programs, perform vulnerability research and other offensive type of research.
Clients choose REDTEAM.PL primarily because of our recognizable consultants and their documented track record. We have worked in cybersecurity since the late 1990s – over 25 years. We hold dozens of acknowledgements for responsibly disclosed vulnerabilities in widely used software and over 50 written client references. Adam Ziaja of REDTEAM.PL co-authored handbooks for the European Union Agency for Cybersecurity (ENISA) and wrote a book published by Polish Scientific Publishers PWN, while our research has been cited by the SANS Institute, Forbes magazine, CERT Polska and CERT Orange. All services are performed exclusively by experienced consultants – we never staff engagements with people lacking years of hands-on practice. We have also held Polish court-appointed expert witness status for well over a decade.
Security vulnerabilities
We found and responsibly disclosed multiple vulnerabilities:
CVE-2025-43368 – Use-After-Free in WebKit Process Model affecting Safari on macOS and iOS
CVE-2023-47114 – Ethyca Fides HTML Injection Vulnerability in HTML-Formatted DSR Packages
CVE-2023-46125 – Ethyca Fides Information Disclosure Vulnerability in Config API Endpoint
“Cybersecurity researchers at Warsaw-based RED TEAMdiscovered a flaw in the way Safari handles sharing actions. Click in Safari to share a cute kitten picture with a friend and you could unknowingly pass critical information about your system to an attacker”
A Bug In Apple’s Safari Browser Could Let Hackers Steal Your Files — Forbes Magazine
“DNS based threat hunting and DoH (DNS over HTTPS) by Adam Ziaja – As someone who has been advocating the detection of malicious activities via DNS for many years, I was dismayed when I found out about malicious use of DNS over HTTPS (DoH). This is a great technical primer for blue teamers to learn the ins and outs of DoH and how red teamers/adversaries can use it to bypass just about every single defense we have.”
A book devoted to the technical aspects of computer forensics and post-breach analysis, “Praktyczna analiza powłamaniowa” (Practical post-breach analysis), Wydawnictwo Naukowe PWN (2017).
Techblog
On our techblog, located at blog.redteam.pl we share knowledge about various aspects of cybersecurity and demonstrate our competencies in the field.
Our team identified and responsibly disclosed multiple critical and high rated vulnerabilities in widely used global products. Acknowledgements for reported vulnerabilities have come from Adobe, Apple, BlackBerry, Deutsche Telekom, eBay, GitLab, Google, Harvard University, LastPass, Microsoft, Netflix, Nokia, Oracle, SoundCloud, VMware, Yahoo, Yandex and Zynga, among others:
REDTEAM.PL client references
REDTEAM.PL performed penetration testing of an online store. The work was completed on time, with due diligence and was of high quality. — GO Sport
REDTEAM.PL performed penetration testing of a web application. Tests were carried out within the agreed timeframe and with due diligence. Results of the work provided in the report were understandable. — Allianz
REDTEAM.PL has performed penetration tests of a mobile application. The entrusted work has been carried out on time and with due diligence, which resulted in a high quality evaluation of the services provided. — Carefleet (Crédit Agricole Group)
REDTEAM.PL carried out internal and external network penetration tests and personnel awareness tests (red teaming). The team showed great commitment as well as a proactive attitude and flexibility during testing. We recommend cooperation with REDTEAM.PL. — Orbis (Accor Group)
We recommend REDTEAM.PL, the config review and penetration testing services requested by us were provided with the highest quality. The audit team demonstrated great commitment, professionalism and extensive knowledge. — Institute of National Remembrance (IPN)
REDTEAM.PL carried out penetration tests of software produced by TELDAT. The work was performed professionally, on time and with due diligence. The conclusions in the form of a report were precise and related to all areas of interest to the contracting party. — TELDAT
REDTEAM.PL performed penetration testing of a web application. The work was carried out in a timely manner, with due diligence and professional ethics. — PKO Życie TU (PKO Banking Group)
CERT.LV would like to thank REDTEAM.PL for the valuable information, which has helped us to improve security of IT resources of the Republic of Latvia. — Latvian National and Governmental CSIRT
REDTEAM.PL has performed logs and disk images analysis. Computer forensics service was performed on time and with due diligence. The delivered results in the form of a report were comprehensible.
REDTEAM.PL performs tasks in the field of security testing. The assignments are carried out on time and of high quality. — Center for Informatics Technology (Ministry of Digital Affairs)
We recommend cooperation with REDTEAM.PL for professionalism and full commitment in the provision of services related to the security of websites. — EFL Leasing (Crédit Agricole Group)
REDTEAM.PL has performed penetration tests of the integration module with the payment operator of the Reserved online store. The work was completed on time and with due diligence, and the service provided was high quality. — Reserved (LPP)
CERT.EE would like to thank REDTEAM.PL for the valuable information, which has helped us to improve security of IT resources of the Republic of Estonia. — Estonian National and Governmental CSIRT