
More than 500,000 cyber vulnerabilities were detected across Namibia between April and June 2026, as cyber events surged by 56.7%, highlighting growing cybersecurity risks facing businesses, government institutions and critical digital infrastructure.
The Namibia Cyber Security Incident Response Team (NAM-CSIRT) recorded 513,921 cyber vulnerabilities and 161,547 cyber events during the second quarter, with the sharp increase prompting renewed calls for organisations to strengthen their cyber defences against increasingly sophisticated digital threats.
Communications Regulatory Authority of Namibia (CRAN) Chief Executive Officer and Head of NAM-CSIRT, Emilia Nghikembua, said the figures underscored the persistent and evolving nature of cyber threats.
“The increase in cyber vulnerabilities and events during the second quarter is a reminder that cybersecurity threats remain persistent and continue to evolve,” Nghikembua said.
She urged organisations to proactively secure exposed internet-facing services, protect digital identities, install software updates promptly and report cyber incidents early.
The increase in vulnerabilities was largely attributed to continued exposure of remote management and legacy network services.
Open CPE WAN Management Protocol (CWMP) accounted for 320,778 vulnerability detections, followed by Network Time Protocol (NTP) Version Report vulnerabilities at 52,420 and Accessible Telnet at 42,941.
Other commonly detected weaknesses included exposed Simple Network Management Protocol (SNMP), Domain Name System (DNS) servers, File Transfer Protocol (FTP) services, vulnerable Remote Desktop Protocol (RDP) connections and systems susceptible to SSL Padding Oracle on Downgraded Legacy Encryption (POODLE) attacks.
Cyber events were dominated by 109,593 Sinkhole HyperText Transfer Protocol (HTTP) detections, followed by 39,593 Sinkhole non-HTTP events.
Meanwhile, Distributed Denial-of-Service (DDoS) participant events rose to 10,327, suggesting that compromised systems within Namibia may have been recruited into botnets and used to launch denial-of-service attacks.
The quarter also saw the emergence of new ransomware and cyber-extortion threats, including BAVACAI ransomware, which uses a double-extortion model involving data theft and encryption, and the Black X cybercriminal group, which targets organisations holding sensitive and high-value information.
Nghikembua said the launch of the National Cybersecurity Incident Management Guidelines 2026 marked an important step towards strengthening Namibia’s cyber resilience by improving the detection, reporting, response and coordination of cyber incidents across sectors.
“Cybersecurity is a shared responsibility and through collaboration, information sharing and coordinated response, we can build a more secure and resilient digital ecosystem for Namibia,” she said.
The guidelines, launched on 29 April 2026, promote a risk-based approach to cybersecurity and align with international standards, including ISO/IEC 27001 and the National Institute of Standards and Technology (NIST) Cybersecurity Framework.
NAM-CSIRT called on organisations and individuals to strengthen their cyber resilience by using strong and unique passwords, enabling multi-factor authentication, promptly applying software updates, securely configuring internet-facing systems and remaining vigilant against phishing and other social engineering attacks.







