● OVERVIEW OF 2024 Record number of VULNERABILITIES Last year, over 40,000 security vulnerabilities were reported. These affected popular content management systems, network devices, and e-commerce platforms, among others. Much to the advantage of attackers, users of vulnerable software were often slow to update it. T he second week of August started with an alarming incident at the Estonian Transport Administration. After a security system flagged suspicious activity on the organisation’s network, a closer investigation soon revealed an unpleasant truth: an attacker had compromised the system used to manage the agency’s computers and devices and gained administrator-level access. Although initial concerns arose that data might have been stolen, a subsequent investigation ruled this out. The solution used for the agency’s remote device management was Fortinet’s FortiClient EMS. This software had a critical vulnerability (CVE-2023-48788), disclosed by Fortinet on How to protect yourself against the exploitation of vulnerabilities - Keep the operating systems, firmware, applications and other software on all your systems up to date. - Replace outdated devices that are no longer supported with security updates from the manufacturer. - Protect your network and administrative interfaces. Utilise VPNs and limit access to devices, particularly system management interfaces, to specified IP addresses only. 34 12 March, along with a new version addressing the issue. Unfortunately, the Transport Administration had not installed this essential update. Attackers found the vulnerable system, exploited the weakness, and breached the network. ONE OF MANY Unfortunately, there are many such stories involving both public- and private-sector organisations. In early February, a government agency reported that its VPN servers had been compromised. The attack, which began in January, exploited vulnerabilities in Ivanti software that had been publicly disclosed just 12 days earlier. In August, CERT-EE alerted the administrator of an online store about a critical vulnerability in their Magento platform. Unfortunately, the store owner did not act on the warning, and in November, the online store was compromised using that same vulnerability. CERT-EE actively scans Estonia’s cyberspace for systems with critical vulnerabilities. When such websites or devices are identified, their owners are notified and advised on how to fix the issues. In 2023, CERT-EE issued 2,427 notifications; last year, this number more than tripled to 7,955. Of these, the largest share – 2,462 – were warnings about vulnerabilities in WordPress and its plugins, while 263 related to vulnerabilities in CYBER SECURITY IN ESTONIA 2025

Select target paragraph3