
…as cyber events surge 56.7%
Cyber vulnerabilities detected across Namibia increased by 39.8% during the second quarter of 2026, while recorded cyber events surged by 56.7%, raising concerns over the country’s growing exposure to digital threats.
The Namibia Cyber Security Incident Response Team (NAM-CSIRT) recorded 513,921 cyber vulnerabilities and 161,547 cyber events between April and June 2026.
Communications Regulatory Authority of Namibia (CRAN) Chief Executive Officer and Head of NAM-CSIRT, Emilia Nghikembua, said the increase demonstrated that cyber threats remain persistent and continue to evolve.
“While these figures highlight areas that require urgent attention, they also provide valuable insight into where organisations can strengthen their security posture,” Nghikembua said.
She urged organisations to address exposed services, protect digital identities, apply security updates promptly and report cyber incidents at an early stage.
The rise in vulnerabilities was largely driven by continued exposure to remote management and legacy network services.
Open CPE WAN Management Protocol (CWMP) accounted for 320,778 vulnerability detections, followed by Network Time Protocol (NTP) Version Report vulnerabilities at 52,420 and Accessible Telnet at 42,941.
Other commonly detected vulnerabilities included exposed Simple Network Management Protocol (SNMP), Domain Name System (DNS) servers, File Transfer Protocol (FTP), Remote Desktop Protocol (RDP) and systems vulnerable to SSL Padding Oracle on Downgraded Legacy Encryption (POODLE) attacks.
Cyber events were dominated by Sinkhole HyperText Transfer Protocol (HTTP) detections, which reached 109,593, followed by 39,593 Sinkhole non-HTTP events.
Distributed Denial-of-Service (DDoS) participant events increased to 10,327, indicating that some systems may have been exposed or compromised and used to facilitate denial-of-service attacks.
The quarter also saw the emergence of new ransomware and extortion threats, including BAVACAI ransomware, which uses a double-extortion model involving data theft and encryption, and the Black X cybercriminal group, which targets organisations holding sensitive and high-value information.
Nghikembua said the National Cybersecurity Incident Management Guidelines 2026, launched on 29 April, provide a framework for improving the detection, reporting, response and coordination of cyber incidents across sectors.
“Cybersecurity is a shared responsibility and, through collaboration, information sharing and coordinated response, we can build a more secure and resilient digital ecosystem for Namibia,” she said.
The guidelines promote a risk-based approach to cybersecurity and align with international standards, including ISO/IEC 27001 and the National Institute of Standards and Technology (NIST) Cybersecurity Framework.
NAM-CSIRT urged organisations and individuals to strengthen their cyber resilience by using strong, unique passwords, enabling multi-factor authentication, installing software updates promptly, securely configuring internet-facing systems, and remaining vigilant against phishing and other social engineering attacks.








