Advisories by BGD e-GOV CIRT

Post Image
Global “Error524” Smishing Campaign Targeting Multiple Sectors Including Bangladesh
The campaign uses phishing-as-a-service (PhaaS) infrastructure to distribute SMS messages containing malicious links that redirect victims to phishing....
13-Apr-2026 15:00:00
Read Details
Post Image
Axios NPM Package Compromise Deploying RAT Affecting Node.js Environments
In this incident, attackers gained unauthorized access to the npm maintainer account and published malicious versions of the Axios package containing ....
01-Apr-2026 16:00:00
Read Details
Post Image
Nymaim or Avalanche-Nymaim Loader Malware Activity Detected in Bangladesh
Nymaim is a multi-stage malware loader historically used to distribute banking trojans, ransomware, and credential-stealing malware. It was closely as....
01-Apr-2026 11:25:00
Read Details
Post Image
Exposure of End-of-Life Microsoft IIS Servers in Bangladesh
BGD e-GOV CIRT strongly recommends that every organization in Bangladesh using Microsoft IIS immediately inventory their systems, isolate exposed serv....
24-Mar-2026 14:00:00
Read Details
Post Image
Critical Vulnerability in n8n (CVE-2026-21858) affects Hosts in Bangladesh
A critical unauthenticated remote code execution (RCE) vulnerability, tracked as CVE-2026- 21858 and dubbed "Ni8mare," has been identified in n8n, an ....
11-Jan-2026 16:00:00
Read Details
Post Image
MongoBleed Vulnerability (CVE-2025-14847) Exposes MongoDB Instances in Bangladesh
A nationwide assessment identified 80 internet-exposed MongoDB database instances in Bangladesh that are improperly secured or misconfigured and runni....
01-Jan-2026 16:00:00
Read Details