Thursday, 20 August 2026
Rīga TV

World and Latvian news in one place

TechnologyPublished: 20 August 2026 at 23:04

Expert: Recent Cyberattacks Expose Long-Known but Unfixed Vulnerabilities

Cybersecurity commentator Ieva Ilvesa says recent high-profile cyberattacks in Latvia reveal years of unaddressed security flaws, and recommends the state form two separate teams — one to handle fallout, one to build risk-based defenses.

Foto: Delfi

Cybersecurity commentator Ieva Ilvesa has analyzed two recent, widely discussed cyberattacks in Latvia, including an incident tied to the road traffic safety directorate CSDD involving a disclosed vulnerability and prolonged litigation, as well as a case involving Latvia's state forests. According to the author, both incidents share a common root cause: a long-known but unaddressed vulnerability, meaning the state and companies are now paying the price for years of neglected cybersecurity "homework."

Ilvesa notes that Latvia is not unique in this regard — in June, the US cybersecurity agency CISA recommended that institutions prioritize known vulnerabilities, evaluating them against four criteria, including whether a publicly accessible resource is affected and how easily the vulnerability can be exploited through automation. The author stresses that the time gap between vulnerability disclosure and remediation can be exploited by hostile actors, including Russia.

Two parallel directions

The author calls on Latvia's leading cybersecurity institutions to work along two parallel tracks with separate, dedicated resources. The first is the practical — rather than purely regulatory — remediation of already-known vulnerabilities. The second involves shifting from annual or monthly audits toward continuous, risk-based security assessment and adaptation, including ongoing coordination with suppliers and service providers.

Ilvesa points out that EU regulatory measures, such as the mandatory unified reporting platform for actively exploited vulnerabilities taking effect on September 11, are useful for oversight but do not provide real defensive capability. She argues that crisis response and long-term strategy building must not be assigned to a single team, since urgent tasks will always overshadow long-term work. Two separate teams with a shared goal — reducing the impact of both current and future attacks — are therefore needed.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category