● OVERVIEW OF 2024
Record number of
VULNERABILITIES
Last year, over 40,000 security vulnerabilities were reported. These
affected popular content management systems, network devices, and
e-commerce platforms, among others. Much to the advantage of
attackers, users of vulnerable software were often slow to update it.
T
he second week of August started with
an alarming incident at the Estonian
Transport Administration. After a security system flagged suspicious activity
on the organisation’s network, a closer investigation soon revealed an unpleasant truth: an
attacker had compromised the system used to
manage the agency’s computers and devices and
gained administrator-level access. Although initial concerns arose that data might have been
stolen, a subsequent investigation ruled this out.
The solution used for the agency’s remote
device management was Fortinet’s FortiClient EMS. This software had a critical vulnerability (CVE-2023-48788), disclosed by Fortinet on
How to protect yourself
against the exploitation
of vulnerabilities
- Keep the operating systems, firmware,
applications and other software on all
your systems up to date.
- Replace outdated devices that are no
longer supported with security updates
from the manufacturer.
- Protect your network and administrative
interfaces. Utilise VPNs and limit access to
devices, particularly system management
interfaces, to specified IP addresses only.
34
12 March, along with a new version addressing
the issue. Unfortunately, the Transport Administration had not installed this essential update.
Attackers found the vulnerable system, exploited
the weakness, and breached the network.
ONE OF MANY
Unfortunately, there are many such stories
involving both public- and private-sector
organisations.
In early February, a government agency
reported that its VPN servers had been compromised. The attack, which began in January,
exploited vulnerabilities in Ivanti software that
had been publicly disclosed just 12 days earlier.
In August, CERT-EE alerted the administrator of an online store about a critical vulnerability in their Magento platform. Unfortunately, the
store owner did not act on the warning, and in
November, the online store was compromised
using that same vulnerability.
CERT-EE actively scans Estonia’s cyberspace
for systems with critical vulnerabilities. When
such websites or devices are identified, their
owners are notified and advised on how to fix the
issues.
In 2023, CERT-EE issued 2,427 notifications;
last year, this number more than tripled to 7,955.
Of these, the largest share – 2,462 – were warnings about vulnerabilities in WordPress and its
plugins, while 263 related to vulnerabilities in
CYBER SECURITY IN ESTONIA 2025