Advisories by BGD e-GOV CIRT

Post Image
SideWinder-Associated Campaign Targeting South Asian Government and Financial Infrastructure
The recovered toolkit included exploitation capability against GeoServer/GeoTools, Laravel Ignition, Apache Tomcat Manager and Redis, as well as weak-....
17-Sep-2026 15:00:00
Read Details
Post Image
Passkey-Themed Social Engineering Campaign Targeting Cloud Identities and SaaS Data
BGD e-GOV CIRT is issuing this advisory regarding an active social-engineering campaign in which threat actors use passkey, MFA, SSO and identity-veri....
14-Sep-2026 14:30:00
Read Details
Post Image
Python NodeStealer Evolves into Full- Featured Spyware: Browser, Credential, Clipboard, Keylogging and Facebook Account Intelligence Theft
NodeStealer has been tracked since 2023 as an information-stealing malware family targeting browser information and Facebook accounts. Previous versio....
06-Sep-2026 15:30:00
Read Details
Post Image
TerminalFix Campaign: ClickFix- Based Multistage Intrusion Deploying Reverse Tunneling and Active Directory Reconnaissance
This effectively turns the infected workstation into a proxy/pivot point inside the organization's trusted network. Microsoft specifically describes t....
02-Sep-2026 15:30:00
Read Details
Post Image
DoNot (APT-C-35) Cyber-Espionage Campaign Targeting Bangladesh Military and Defence Personnel
The lure itself was customized around Bangladesh’s military environment. The malicious document used the biography of a Bangladesh Air Force officer a....
17-Aug-2026 12:00:00
Read Details
Post Image
The Gentlemen Ransomware: A Rapidly Scaling RaaS Threat Targeting Bangladesh
The group operates a cross-platform, self-propagating encryptor that can independently spread across Windows, Linux, NAS, BSD, and VMware ESXi systems....
09-Aug-2026 15:00:00
Read Details