MEASURES: TIMELINE OF SELECT NÚKIB WARNINGS AND ALERTS IN 2022 JANUARY FEBRUARY MAY Alert Regarding an Increased Risk of Cyberespionage and Ransomware Attacks Against the Czech Republic In January, an alert was issued about the increased risk of cyber espionage or ransomware attacks against Czech entities due to the growing tensions in Eastern Europe. Government institutions, media, and CII were considered high-risk, and the alert included an overview of specific threats and mitigation or detection measures. Warning Against the Threat of Cyberattacks on Strategic Organizations in the Czech Republic At the end of February, the NÚKIB issued a warning about the increased threat of cyberattacks on strategic organizations in the Czech Republic following the launch of the Russian invasion to Ukraine. The warning recommended increased vigilance against the most common attack techniques in cyberspace, urged making updates to information systems and their components, and provided a set of recommendations in the context of impending DDoS attacks. Warning Against Using Smart Meters from Countries With Untrustworthy Legal Environments The next warning highlighted the supply chain security threat associated with the installation of smart meters in domestic energy distribution systems. The threat lies in the use of smart metering technology from countries with untrustworthy legal environments, which may eventually cause major disruptions to the operations of the transmission system, even with possible cross-border spillover effect. AUGUST Alert Regarding Vmware Software Vulnerabilities In August, the NÚKIB issued an alert following the discovery of a VMware software vulnerability that allows attackers to gain administrative access to a victim‘s systems without requiring authentication. The alert included a recommendation to immediately update the affected components, along with their list. SEPTEMBER Alert About the Microsoft Exchange Server Vulnerability In September, two vulnerabilities (CVE-2022-41040 and CVE-2022-41082) were discovered in the widely used Microsoft Exchange Server software. Therefore, the NÚKIB issued an alert along with mitigation measures and indicators of compromise. NOVEMBER Alert Regarding the Increased Risk of DDoS Attacks At the end of the year, the NÚKIB issued a warning about the increased risk of DDoS attacks, following an increase in frequency during this period, probably (55-70%) due to the joint meeting of the governments of the Czech Republic and Ukraine. The registered DDoS attacks during 2022 had only marginal impacts. Nevertheless, generally speaking, they can cause outages of critical services, such as public administration portals. Russian-language hacktivist groups were behind a significant part of these attacks. 30

Select target paragraph3