This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.
Cybersecurity
CERT.LV Recommendations for Improving Infrastructure Cybersecurity Resilience Against Cyberattacks
Below is a table with indicators of the cyber attacker infrastructure involved in the cybersecurity incident at AS "Latvijas valsts meži." We recommend monitoring these indicators, especially for infrastructure holders who have not implemented CERT.LV SOC and ABS services. Generally, any communication allowed from/to anonymization services like TOR or publicly/anonimously accessible tunneling services such as Cloudflare Tunnel, Microsoft Dev Tunnels, ngrok tunnels, etc., should be considered suspicious. Communication between state agency networks and VPN service provider networks or data center networks should also be viewed as potentially suspicious. CERT.LV (Cyber Incident Prevention Institution) has compiled recommendations to enhance infrastructure cybersecurity resilience against cyberattacks: For testing vulnerabilities of externally exposed resources, we encourage establishing and managing your organization's program in CERT.LV's Coordinated Vulnerability Disclosure (CVD) platform: https://cvd.cert.lv/. To learn about the full range of CERT.LV services and their applicability to your resources, visit: https://cert.lv/lv/pakalpojumi