Timeline of key warnings and alerts
issued by NÚKIB in National
cybersecurity level
February
Vulnerability in OneNote used to activate malware
NÚKIB warns against an active phishing campaign that exploits a vulnerability in Microsoft OneNote, allowing
a script to be executed when a file is opened. When activated, the script downloads malware to create a backdoor for an attacker to remotely access the user’s system.
March
TikTok threat warning
NÚKIB issues a warning concerning the threat of installing and using TikTok, citing its own analysis and findings
and information from partners about possible security threats stemming from the app’s user data collection and
processing practices and function in the context of the legal and political environment of the People’s Republic
of China.
June
Heightened risk of ransomware attacks
NÚKIB issues an alert highlighting increased cybercriminal activity involving ransomware. The alert includes
details of vulnerabilities exploited by attackers and descriptions of the usual compromise vectors. NÚKIB also
updates its document Ransomware: recommendations on mitigation, prevention and response, which provides
comprehensive information and recommendations for this type of threat.
July
Vulnerability in MikroTik RouterOS
A critical vulnerability (CVE-2023-30799) identified in MikroTik RouterOS routers allows attackers to potentially escalate privileges through a brute-force attack on login and password combinations. NÚKIB posts an alert
and recommended mitigation measures for this threat.
October
Vulnerabilities in Cisco IOS XE
Two critical vulnerabilities in the Cisco IOS XE operating system interface are discovered. The first (CVE-202320198) reaches the highest possible severity score of 10, the second (CVE-2023-20273) scores 7.2. NÚKIB
issues alerts for each.
November
WeChat application threat
NÚKIB issues an alert about the cybersecurity risks associated with using the WeChat mobile app and its Chinese
version Weixin, offered by Tencent. Justified concerns point to a possible misuse of data collection practices, with
the potential for accurately targeted cyberattacks, and the app’s function in the context of the legal environment of
China, similar to the concerns with TikTok.
38