Supporting implementation of #EU #cybersecurity regulations by advancing open-source certification & assessment tools. Funded by #HorizonEU.

Joined January 2026
9 Photos and videos
Transparency builds trust 🔍✅ Our partner @tropicsquare is applying radical openness approach by publicly disclosing a physical #vulnerability in #TROPIC01, identified via independent #security audit. 🚫 No evidence of real-world exploitation, and mitigations are in place.
We built TROPIC01 to find its limits. Today we're publishing a Security Advisory on a hardware vulnerability discovered during an independent audit by the Ledger Donjon team - alongside the deeper findings our engineers made as a result. What was found: 👉️ During their audit, Ledger Donjon successfully executed a Laser Fault Injection attack bypassing firmware boot signature under lab conditions - but essential hardware security withstood it. 👉️ Building on that discovery, our team found that more complex combined attack paths can potentially breach the hardware boundary and expose all confidential data. Worth knowing: 👉️ This is not a remote exploit and there is no evidence of real-world exploitation. 👉️ Mitigation measures for this attack vector are available for deployment. True hardware security is built on transparency and auditability. So we don't just tolerate scrutiny, we invite it. This disclosure is that principle in practice. A huge thanks to @DonjonLedger team for their exceptional technical expertise, professionalism and dedication to coordinated disclosure. 📄 Read our full announcement: bit.ly/4vGfgEH 🔬 Link to technical deep-dive: bit.ly/49Cj8Ol
2
29
CCAT Project retweeted
Ready to connect with the #opensource community face-to-face? 🤝 The #DevConf_CZ booths are the place to be! Stop by to chat, network, and grab legendary swag with @grafana, @fedora, @openSUSE, @OpenSSLProject ...& many more! 🎟️Register now: devconf.info/cz/#registratio…
3
3
170
CCAT Project retweeted
As part of the Czech President’s state visit to Estonia, a business delegation meeting was held at @UniTartuCS. We exchanged ideas for the research and collaboration. Special attention was given to ongoing research projects such as @CHESS_EU, #SECURENET, @CCAT_project and #QARQ.
2
5
63
One of the application areas CCAT targets is #GovTech, where CCAT tools can help reduce the implementation gap between #cybersecurity regulations and real-world #DigitalGovernment systems 🏛️🌐
Digital government is advancing, but the World Bank’s GovTech Maturity Index shows targeted support is needed to close the digital divide. Difficulties arise where technology meets people. Read the blog for more on this: wrld.bg/iyos50Z2QNQ
26
Proud to collaborate with two partners from #Estonia 🇪🇪 — a country with the highest share of women among #ICT graduates in the #EU (36.1%) that sets a strong example for the future of digital innovation and #cybersecurity. @cybernetica and @unitartu 👏
Behind every tech innovation, there are graduates. But, in the EU, women still make up a minority of ICT graduates. → Highest share of women: 🇪🇪 Estonia: 36.1% 🇸🇪 Sweden: 36.1% 🇷🇴 Romania: 34.5% Full dataset by @Eurostat: link.europa.eu/Pm4wJM
35
🟣 @devconf_cz (18–19 June, Brno 🇨🇿) will host “Usable Cybersecurity Assessment Tools” session by @yazz_acar (#UPB) and @marybakhtina (@FI_MUNI). Join short usability sessions at the CCAT booth and try #TLSScanner, #SCRUTINY & #seccerts yourself! devconf.info/cz/schedule/
76
Recommended reading! 📚
How are organisations really using open source in 2026? The 2026 State of Open Source Report highlights trends, challenges, and opportunities for teams building with OSS. It contains some striking statistics around time spent maintaining vs. developing, vulnerability management, and shifting attitudes toward governance and digital sovereignty. Produced by Perforce Software in collaboration with the Eclipse Foundation and Open Source Initiative, this year’s report is a must-read for developers, architects, and technology leaders working in open ecosystems. Get your copy 👉 hubs.la/Q049bFD-0 #OSS #opensource #StateOfOpenSource #DigitalSovereignty
25
Transparency and verifiability of HW security components are also key topics in #CCAT project, addressed in particular through the #SCRUTINY tool, developed together with @tropicsquare 🌴 Great to see this issue in the spotlight at @BTCPrague!
Hardware wallets are only as trustworthy as the silicon inside them. Yet most secure elements are black boxes - closed, unauditable, taken on faith. That's exactly the problem Tropic Square exists to solve. 🔓 We'll be at BTC Prague 2026 (June 11–13, Booth B46) - Europe's largest Bitcoin event - showing what a genuinely transparent, open architecture secure element looks like in practice. If you're building hardware wallets, embedded devices, or anything where security can't be a gut feeling, come talk to us. We'd love to show you what TROPIC01 can do for your next project. 🎟️ Grab a discounted ticket using our promo link before you come: btcprague.com/?promo_id=4048… See you in Prague. 👋 #BTCPrague #BTCPrague2026 #HardwareWallets #FutureProofSecurity #OpenSourceHardware #TropicSquare #TrustedHardware #embedded #TROPIC01 #cybersecurity #secureelement #security #hardware #opensource #HardwareSecurity #OpenHardware
1
29
Couldn't be there in person? 🎬 Watch the #CCAT presentation about #seccerts here: youtube.com/watch?v=KOQYvHvj…
We’re excited to announce that the recordings from #OCX26 are now live on our new YouTube channel. Explore sessions from each collocated event and catch up on the talks you missed: hubs.la/Q04fPTf40 #OCX26 #opensource #conference #Brussels
1
60
Cybersecurity cooperation between South Moravia and Estonia continues to grow, driven by projects such as #CCAT, @CHESS_EU, @QARC_101225691 and #SECURENET 🛡️ 📖 Read more here [in CZ]: ris3.gov.cz/aktuality/jihomo… @mpo_tweetuje
43
CCAT Project retweeted
See you at SAHA 2026! 👋 Today, more and more systems are deployed in the field, constantly connected, and expected to remain trusted over time. For hardware design houses, drones & autonomus systems developers, and security engineers, this brings very real challenges around device identity, key protection, and secure updates. 🔐 At Tropic Square, we believe trust at the hardware level should be open, transparent, and auditable. Will you be at @SahaExpo ? If you are working on embedded systems, UAVs, communication, or sensing technologies and want to meet the future of hardware security, we will be there and would love to connect! 🚀 If you'd like to meet on-site, feel free to reach out to Simon Fic (bit.ly/4dgimsj to set up a meeting. 🤝 Looking forward to the conversations!
2
3
230
A quick note: almost 50% of #CCAT researchers, testers and support staff are women 👩💻 We must be doing something right 😉
Today is Girls in ICT Day! 👩‍💻✨ When girls have equal access to digital skills and opportunities, they don’t just join the tech sector, they transform it. Let’s keep building spaces where every girl can thrive in ICT. Discover how the EU can help: link.europa.eu/MyCpwT
42
🚀 #CCAT is heading to #OCX26! Tomorrow, Václav Matyáš (@FI_MUNI) and Jaroslav Řezník (@RedHat) will present #seccerts, an #opensource tool turning security certification data into a structured, searchable dataset 🔎 See more: lnkd.in/dyiQb8E3 @ocxconference
🎉 Welcome everyone to #OCX26! The energy is so high onsite. Pick up your badge at the reception and start the day with a coffee and snacks before we kick off our first keynote with Mike Milinkovich! We're so excited to have you here 😍 #OCX #conference
56
#Cybersecurity risks can hide behind something as simple as a #QR code 📲 In a recent @WDR feature, researchers from @unipb presented #TLSScanner, a #CCAT tool that analyses websites and checks their security configurations before users access them. 🎬 See link below 👇
1
119
Finally! 😉 Register for DevConf.CZ — a conference supported by #CCAT partner @RedHat that brings together users, developers, administrators, and contributors working with #opensource technologies ⬇️
The moment we’ve all been waiting for is here! Registration for #DevConf_CZ 2026 is OPEN! 🎉 Secure your spot today and join us for another incredible year of learning, knowledge sharing and community building. devconf.info/cz/#registratio… #DefineFuture #OpenSource #Registration
31
Four tools, one goal 🎯➡️ Making continuous cybersecurity assessment easier. Developed by #CCAT partners across Europe and designed for real-world use, the tools help organisations navigate #EU 🇪🇺 #cybersecurity requirements. Learn more in the slides 👇
36
Our project website 🌐 is now live! Find out more about our tools and follow the latest updates: 🔗 ccat.fi.muni.cz/
81