Timeline of key warnings and alerts issued by NÚKIB in National cybersecurity level February Vulnerability in OneNote used to activate malware NÚKIB warns against an active phishing campaign that exploits a vulnerability in Microsoft OneNote, allowing a script to be executed when a file is opened. When activated, the script downloads malware to create a backdoor for an attacker to remotely access the user’s system. March TikTok threat warning NÚKIB issues a warning concerning the threat of installing and using TikTok, citing its own analysis and findings and information from partners about possible security threats stemming from the app’s user data collection and processing practices and function in the context of the legal and political environment of the People’s Republic of China. June Heightened risk of ransomware attacks NÚKIB issues an alert highlighting increased cybercriminal activity involving ransomware. The alert includes details of vulnerabilities exploited by attackers and descriptions of the usual compromise vectors. NÚKIB also updates its document Ransomware: recommendations on mitigation, prevention and response, which provides comprehensive information and recommendations for this type of threat. July Vulnerability in MikroTik RouterOS A critical vulnerability (CVE-2023-30799) identified in MikroTik RouterOS routers allows attackers to potentially escalate privileges through a brute-force attack on login and password combinations. NÚKIB posts an alert and recommended mitigation measures for this threat. October Vulnerabilities in Cisco IOS XE Two critical vulnerabilities in the Cisco IOS XE operating system interface are discovered. The first (CVE-202320198) reaches the highest possible severity score of 10, the second (CVE-2023-20273) scores 7.2. NÚKIB issues alerts for each. November WeChat application threat NÚKIB issues an alert about the cybersecurity risks associated with using the WeChat mobile app and its Chinese version Weixin, offered by Tencent. Justified concerns point to a possible misuse of data collection practices, with the potential for accurately targeted cyberattacks, and the app’s function in the context of the legal environment of China, similar to the concerns with TikTok. 38

Select target paragraph3