The RIA yearbook: 2021 was a year of security vulnerabilities

16.02.2022 | 17:24

Last year, several critical security vulnerabilities were discovered which caused serious problems both in Estonia and elsewhere in the world. In many cases, the slow response to security vulnerabilities made it easy to attack Estonian companies and authorities.

IT systems around the world are being attacked all the time, and the security vulnerabilities that have been discovered can be of great benefit to those who are trying to use such vulnerabilities to get rich or gain influence. Every year, the Information System Authority (RIA) registers more than 20,000 inquiries and more than 2,300 serious cyber incidents that have a real impact on the system or its operation.

According to Andres Sutt, Minister of Entrepreneurship and Information Technology, the situation of the cyberspace has become significantly more complicated in recent years, and the current security situation is exacerbating it.

‘The threat of war in Ukraine may also lead to an increase in cyber attacks in our region. The Estonian digital society depends on the security of communication and information systems, which is why the state and the e-state are synonymous – if the e-state does not work, then our state will not work either. As a result, every authority and company, especially a company providing a vital service, must pay special attention to cybersecurity,’

Sutt emphasised.

According to Gert Auväärt, Director of Cyber Security of RIA, cybercriminals use the disclosed security vulnerabilities – the paths already trodden. ‘If a security vulnerability is discovered, they will try to take advantage of it immediately. There are several such examples in the new yearbook,’ said Auväärt.

‘If the vulnerability allows giving commands to the systems remotely, it is not hard to bypass the protection and gain access to the digital solutions. The most critical or zero-day vulnerabilities must be eliminated as soon as possible. Alternatively, the victim can isolate the systems and devices affected by the security vulnerability from the web,’ said the Director of Cyber Security of RIA. To prevent such situations, RIA actively shares information with cybersecurity managers to patch such vulnerabilities as soon as possible. ‘Every one of our warnings or threat assessments is important, and by responding to them in a timely manner, it is possible to avoid a lot of problems.’

In March, Microsoft disclosed four zero-day vulnerabilities in its mail server software that allowed attackers access to the entire server, including emails and passwords. According to Microsoft, the attackers quickly built tools that looked for Exchange servers that had not yet been updated to infect them with malware. The day after the vulnerability was revealed, RIA discovered 80 mail servers with security vulnerabilities in Estonia. Five days later, Microsoft announced that there are more than 60,000 such servers worldwide.

‘We told companies and authorities if they had any of these vulnerabilities. A week later, we analysed again how many are still affected, and it turned out that two-thirds had not taken the necessary steps to protect the mail server,’ Auväärt gave an unfortunate example. ‘As a rule, unpatched systems result in criminals finding them and installing malware to them.’

According to Sutt, companies and authorities are often passive and their awareness of cyber threats is too low. ‘In cooperation with RIA, we have provided information and recommendations to the heads of state agencies and companies providing vital services on how to increase their preparedness to deal with cyber incidents and what to keep in mind in these situations. Company managers need to understand that their decisions affect whether or not timely attention is paid to cyber hygiene and the security of IT systems in their organisation,’ said Sutt.

In August, Atlassian, a well-known software company, announced that their Confluence software contained a critical vulnerability that could allow remote code execution. The security vulnerability allowed an unauthenticated user to compromise the Confluence server of a company or authority and edit, add, and/or copy data there. This also allowed them to install malicious code for subsequent attacks. Three state agencies were attacked in Estonia in this way. As the criminals were discovered quickly, there was no major damage. However, a timely software update would have helped avoid such a situation altogether.

The exact effect of the Log4j zero-day vulnerability, which became apparent in December, is still not clear, but malware which mined cryptocurrencies was installed in computers located in Estonia. There were also reports abroad that vulnerabilities were being exploited to prepare for ransomware attacks.

Last year, RIA received information about 2,237 cyber incidents with an impact. Phishing pages (775), malicious redirects to websites (262), and disruptions of service (254) were the most frequently identified and reported. Account takeovers were reported 170 times and account compromises 168 times. RIA was notified of 47 denial-of-service attacks and 30 ransomware attacks.

In addition to security vulnerabilities, the yearbook covers financial fraud, denial-of-service attacks, the summer cyber incidents of RIA, ransomware attacks, incidents with a happy ending, legacy, elections, the biggest cyber attacks in the world, and more.

SEIKO KUIK

Press officer

open graph imagesearch block image