Main Page

National Cyber and Information Security Agency

Logo NÚKIB


Relevant and clear information on the new NIS2 Directive can be found at nis2.nukib.gov.cz/en.

For information on the National Coordination Centre (NCC) in the Czech Republic, visit nkc.nukib.gov.cz/en.

 

Selected News

NÚKIB Joins International Advisory on Russian Cyber Campaign Targeting Zimbra Collaboration Suite

The National Cyber and Information Security Agency of the Czech Republic (NÚKIB) has joined partners from several countries in issuing a Joint Cybersecurity Advisory concerning an ongoing cyber campaign by the threat group LAUNDRY BEAR, which has been targeting users of the Zimbra Collaboration Suite (ZCS) email platform since at least July 2025. 

According to the advisory, actors linked to the Russian Federation are primarily seeking access to e-mail communications and other sensitive information from government institutions, the defence sector, energy organisations, media outlets, educational institutions, non-governmental organisations, and technology companies. The campaign exploits a vulnerability in the Zimbra webmail interface that allows malicious code to be executed simply by viewing a specially crafted e-mail in a vulnerable version of the system. 

After successfully exploiting the vulnerability, attackers attempt to obtain e-mail contents, contact lists, authentication credentials, multi-factor authentication back-up codes, and other data that may subsequently be used for espionage activities. The campaign also includes efforts to maintain long-term access to compromised accounts. 

NÚKIB recommends that organisations using Zimbra Collaboration Suite immediately verify that they are running updated versions of the platform containing the fix for vulnerability CVE‑2025‑66376. Organisations should also review available indicators of compromise, monitor suspicious activity related to email services, and pay increased attention to protecting user accounts. 

The full advisory is available here: NSA and Partners Alert Zimbra Collaboration Suite Users of a Russian State-Supported Phishing Campaign > National Security Agency/Central Security Service > Press Release View  

New frontier AI models and their implications for cybersecurity

NÚKIB has published a new analysis examining the rise of so-called frontier AI models and their implications for cybersecurity.

These next-generation AI systems represent a major leap forward in the automated discovery and validation of software vulnerabilities. Unlike previous tools, they can operate at scale and significantly compress the timeline from vulnerability identification to potential exploitation.

The analysis warns that, in the near term, these advances may disproportionately benefit attackers. While AI can dramatically accelerate the discovery of vulnerabilities, defensive measures – particularly patching and remediation – remain constrained by human, technical, and organizational resources.

NÚKIB also highlights that comparable capabilities are likely to become accessible to a much broader range of actors in the coming years, including both state-sponsored and non-state threat actors. As a result, organizations may face an increased volume of cyber incidents, including indirect impacts stemming from compromises within their supply chains.

The paper outlines the key trends shaping this rapidly evolving landscape and offers recommendations to help organizations adapt, with a particular focus on vulnerability management and the integration of AI into defensive cybersecurity operations.

The analysis can be found here: https://nukib.gov.cz/en/infoservis-en/publications-reports/

NÚKIB Director Lukáš Kintr Highlights Strategic Cybersecurity Cooperation During Estonia Visit

As part of a presidential delegation, NÚKIB Director Lukáš Kintr visited Estonia on a state visit. NÚKIB was further represented by its experts within the accompanying delegation.

During the two-day program in Tallinn and Tartu, a series of meetings were held with strategic partners from the public, private, and academic sectors. These meetings confirmed the strong and long-standing partnership between the two countries in the field of cybersecurity and opened up opportunities for further deepening this cooperation.

One of the key points of the program was a meeting with the e-Governance Academy (eGA), a long-term partner of the Czech Republic in digital transformation and cybersecurity. The discussions focused on the further development of projects in the field of building cyber capacities, including initiatives such as Cyber Balkans 2 and projects under the NATO Cyber Defence Capacity Building program. The TSI project was also highlighted, as both sides view it as an excellent opportunity to achieve the necessary changes and facilitate the implementation process of NIS2.

The program also included participation in the international CyCon conference, where the delegation accompanied the President during his speech, followed by a speech by the NÚKIB Director at a bilateral business forum focused on cybersecurity.

"Cooperation between the Czech Republic and Estonia in the field of cybersecurity is not only long-standing but increasingly strategic. It is built on shared values, mutual trust, and a common perception of security threats," said NÚKIB Director Lukáš Kintr.

Special emphasis was placed on connecting the strengths of both countries. Estonia is long considered a leader in digitalization, while the Czech Republic has a strong industrial base and a rapidly developing technological and cybersecurity ecosystem.

"The opportunity lies in connecting these strengths, combining Estonian experience and innovation with Czech technological capacity," added Kintr.

Further bilateral meetings in Tallinn were held with representatives of the Republic of Estonia Information System Authority (RIA), where national priorities, current challenges in cybersecurity, and the growing threat of online fraud were discussed.

On the second day of the visit in Tartu, the delegation attended an expert meeting of cybersecurity professionals at the University of Tartu. Discussions focused on cooperation in research and development, linking industry with the academic sector, and experiences from student exchange programs. Joint projects, such as the CHESS initiative, were also mentioned.

"Our countries are close not only in size but also in values. This closeness creates a solid foundation for further development of cooperation in the fields of security and technology," said NÚKIB Director Lukáš Kintr during the meetings.

The visit concluded with informal networking and a confirmation of both sides' interest in further deepening cooperation at the bilateral level, as well as within the EU and NATO.

The visit brought new opportunities for specific projects, strengthened existing partnerships, and confirmed that the Czech Republic and Estonia share not only similar challenges but also the ambition to jointly strengthen Europe's cyber resilience.

Deputy Director of NÚKIB Martina Ulmanová Held Talks in Tokyo on Strengthening Cooperation in Cybersecurity and Artificial Intelligence

Deputy Director of the National Office for Cyber and Information Security (NÚKIB) Martina Ulmanová, together with Cyber Attachée for the Indo-Pacific Veronika Kolek Netolická, attended the Global Cybersecurity Group meeting in Tokyo. During her official visit, she spoke at an international conference and held a series of bilateral meetings with key partners, particularly representatives of Japan’s National Cybersecurity Office (NCO) and the Ministry of Internal Affairs and Communications (MIC). The discussions confirmed mutual interest in further developing cooperation in cybersecurity, protection of critical infrastructure, and the security aspects of deploying artificial intelligence.

At the meeting, Deputy Director Ulmanová presented the Czech Republic’s approach to building cybersecurity and implementing the National Cybersecurity Strategy 2026–2030, which emphasizes strengthening national resilience, developing professional capacities, and actively engaging in international cooperation.

“Cybersecurity is an ongoing process that requires international cooperation and the sharing of best practices across countries and sectors. International partnerships are a key prerequisite for an effective response to current threats,” said Deputy Director Martina Ulmanová.

A key part of the program included bilateral talks with representatives of the Japanese NCO, led by Director Yoichi Iida. The discussions followed up on the signing of a memorandum of cooperation between the two institutions and focused on its implementation through a joint action plan for the period 2026–2028. Both sides also confirmed their interest in regular high-level dialogue and further deepening strategic cooperation.

“We highly value our long-term cooperation with Japanese partners, which, thanks to the memorandum of cooperation, is now moving to an even more practical level. It is important for us that the various areas of cooperation are reflected in concrete activities, whether it’s information sharing, joint exercises, or the involvement of experts in international projects,” added Deputy Director Martina Ulmanová.

Another significant topic of the discussions was cooperation within NATO and the IP4 format, especially in connection with the organization of the next NATO Cyber Champions Summit. The Czech Republic, as the host country for 2026, shared its experiences and declared its readiness to support Japan, which will host the summit in 2027.

Further talks were held with representatives of Japan’s MIC and focused on the security aspects of artificial intelligence and the implementation of the Hiroshima AI Process initiative. This initiative represents an international framework for the development of safe, trustworthy, and responsible AI, responding to the rapid advancement of generative and advanced systems. The Czech Republic advocates a risk-based approach in this area, building on the European AI Act, and emphasizes the need to supplement the regulatory framework with practical security measures. The discussions confirmed a shared interest in strengthening AI security cooperation, sharing practical experiences, and developing mechanisms to protect advanced systems from misuse or manipulation.

The NÚKIB delegation also participated in expert discussions focused on critical infrastructure protection, public-private partnerships, and the impact of new technologies on cybersecurity.

The working visit program was complemented by meetings with the mission of the Ministry of Industry and Trade, which attended the SPEXA Space Business Forum and related networking activities, including a reception focused on connecting delegations. In the field of cybersecurity for space systems and satellite services, NÚKIB closely cooperates with the Ministry of Industry and Trade on the implementation of European programs such as Galileo PRS and GOVSATCOM, ensuring their security aspects in the Czech Republic.

The meetings in Tokyo thus built on previous bilateral activities and confirmed the shared interest of both countries in strengthening security and stability in cyberspace.