// TEAM
Patrik Žák leads red team operations and infrastructure tests
Patrik Žák is an ethical hacker, co-founder, and Red Team Lead at SYSNETSHIELD. On engagements he leads red team operations (simulations of a real attacker against a company’s live defenses) and infrastructure penetration tests. He has been in the IT business since 2015 and has done offensive security under the SYSNETSHIELD name since October 2023, when he co-founded the company. Who tests alongside him and how engagements run is summed up on the page about who makes up SYSNETSHIELD.

// 01
What Patrik Žák works on
A red team operation tests a company against the way a real attacker works: with a goal agreed in advance and without warning the defenders, so it also measures what detection caught. The service page walks through how a red team operation runs, phase by phase.
The second part of his work is infrastructure tests from the internet and from inside the network: the perimeter, servers, and the Active Directory domain environment.
// 02
Patrik Žák’s six certifications
Patrik Žák holds six certifications from three issuers:
- CRTO: Red Team Operator (Zero-Point Security)
- CRTL: Red Team Lead (Zero-Point Security)
- CPTS: HTB Certified Penetration Testing Specialist (Hack The Box)
- CCPenX-AWS: Certified Cloud Pentesting eXpert-AWS (The SecOps Group)
- CNPen: Certified Network Pentester (The SecOps Group)
- C-AI/MLPen: Certified AI/ML Pentester (The SecOps Group)
CRTO and CRTL cover red teaming, CPTS and CNPen penetration testing. CCPenX-AWS is the cloud one and is aimed at testing in AWS. What a test in AWS covers is summed up on a separate page.
// 03
CVE-2026-39042: a finding in MikroTik RouterOS
CVE-2026-39042 is an integer overflow in the unflatten() function of the libumsg.so library in MikroTik RouterOS: through it, an unauthenticated attacker crashes the service, causing a denial of service. The National Vulnerability Database (NVD) lists the finding at CVSS 7.5 (High) and CWE-190, published July 13, 2026, and cites the author’s technical write-up among its references.
Patrik Žák is the author of the finding. The full record is in the CVE-2026-39042 entry in the NVD.
// 04
Where have the media quoted Patrik Žák?
Seven editorial articles in five outlets between December 2025 and July 2026: Forbes twice, Seznam Zprávy twice, and FinMag, Echo24, and Computertrends once each. He is not the author of any of them. In every one, he is the expert source being quoted.
- Forbes quoted him twice: on February 26, 2026, about the misuse of the Claude chatbot, and on July 7, 2026, in an article on sensitive company data in AI tools.
- Seznam Zprávy twice: on February 20, 2026, on the Czech National Bank’s purchase of graphics cards, and on April 30, 2026, in an article on people secretly using AI at work.
- FinMag quoted him on May 27, 2026, in a piece on the risks of uncontrolled AI use in companies.
- Echo24 quoted him on December 20, 2025, about scam messages in the Christmas season.
- Computertrends quoted him as an ethical hacker on December 11, 2025, about smart toys and vacuum cleaners on the network.
He has also appeared on ČT24 and CNN Prima News and was quoted in Hospodářské noviny’s July print supplement on cybersecurity. These three are a different category from the articles above: there is no link to them, because a television broadcast or a print supplement has nothing on the web to link to.
// 05
Patrik Žák teaches and publishes Security Sunday
As an ethical hacker, he teaches the course “Penetrační testování prakticky” (Penetration Testing in Practice) for robot_dreams. Every Sunday he publishes the Security Sunday newsletter and videos on YouTube, and his articles are on the blog.
// 06
Patrik Žák’s articles on the blog
He is the named author of pieces on how attacks work technically and what holds up against them: from five paths to Domain Admin in Active Directory, through QR phishing, to choosing a penetration testing vendor.
- Red teaming vs. penetration testing: when to choose which
- QR phishing and OAuth abuse: what we see in campaigns right now
- Five paths to Domain Admin that still work
- Preparing for a penetration test: what to get ready and what to hand the tester
- How often to run a penetration test: by risk, not just by law
- DORA and TLPT: what the financial sector has to test
- A ransomware attack on a company: how it runs and how to spot it earlier
- BEC and CEO fraud: how companies lose money to a fraudulent invoice
- How to choose a penetration testing vendor and what to ask
- How to secure corporate Wi-Fi and what fails most often on tests
- How we set remediation priority by risk, not by score
Updated .
// WORK WITH US
Tell us what you want tested
Tell us what you want tested. We’ll get back to you and schedule a call to pin down scope, timing, and price.