Skip to content

// responsible disclosure

Security disclosures

Vulnerabilities I have reported through coordinated disclosure. Details are only published after the affected organization has been given the opportunity to remediate.

CERT#2026052777000311 Critical Open

Multiple Security Vulnerabilities in Mijn Simyo App / API

Simyo / KPN

Identified and responsibly disclosed multiple critical and high severity security vulnerabilities in the Android app and API of Simyo, a KPN subsidiary. Reported via KPN-CERT responsible disclosure. Findings acknowledged and remediation in progress. Recognized on the KPN-CERT Hall of Fame.

Reported:
2026-05-27

Plus 2 more reports still under embargo, not shown here yet.