Monday , September 14 2026

First Half Of 2024 Report
Bangladeshi 32.4% government websites face cyber attack: NAS report

National Attack Surface (NAS) report for the first half of 2024 reveals that 56.6% of cyberattacks in Bangladesh targeted educational institutions, indicating a serious lack of maintenance and updates for school websites, making them highly vulnerable.

During this period, 32.4% of attacks targeted government websites, revealing significant security flaws. The remaining 11% affected private and business websites, highlighting the broad reach of cyber threats in the country.

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Palo Alto Networks has revealed a serious flaw in PAN-OS. It may let a remote attacker without a password run...
Read More
Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Critical Check Point VPN flaws allow remote code execution attacks

Check Point Software has revealed and fixed two major VPN flaws, CVE-2026-85102 and CVE-2026-85103. Both have a top CVSS score...
Read More
Critical Check Point VPN flaws allow remote code execution attacks

Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Cisco has said that a serious security flaw CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being used...
Read More
Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

A Russian-speaking hacker has used artificial intelligence like never before. They sent out hundreds of AI agents to find and...
Read More
Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Six Chinese AI companies ran large-scale attacks on American AI models since late 2024, according to U.S. cybersecurity and intelligence...
Read More
CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

An unknown security expert called Nightmare Eclipse has drops a new Microsoft Defender flaw called "ShieldCrash" right after Microsoft released...
Read More
Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

cPanel has shared CVE-2026-67401, a serious SQL injection flaw in EmailTrack. This flaw could allow attackers with permission to take...
Read More
cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

An ongoing attack is focused on FortiGate firewalls. Hackers use a serious flaw to install a special Node.js remote access...
Read More
FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

Attack Patterns:

The NAS report, prepared by BCSI, also outlined the primary patterns of attacks across Bangladeshi websites:

Pie chart
        Image created by Canva, information source BCSI

* Attackers damaged the public image and functionality of 51.6% of websites by defacing them.
* 27.85% experienced DDoS attacks, disrupting services and access to important resources.
* 13.24% experienced significant data breaches, risking the exposure of sensitive information to unauthorized individuals.
* 7.31% of websites remained vulnerable because attackers still had access to their admin panels.

The National Attack Surface (NAS) report for the first half of 2024 reveals a concerning trend: 56.6% of cyberattacks in Bangladesh targeted educational institutions. This suggests a significant failure to maintain and update school websites, making them vulnerable to these attacks.

Meanwhile, The ransomware group “KillSec” has attacked “বঙ্গবন্ধু সরকারি কলেজ, তারাকান্দা, ময়মনসিংহ,” stealing sensitive data. They announced the breach on their Dark Web site on October 4th, revealing control over student records, academic data, and the college’s application systems. A countdown for the full data release is set for 7 days, 2 hours, and 59 minutes, but KillSec has not revealed their ransom demands.

According to KillSec’s description, the data they have taken includes:

File system structure, directory names, and file names
Application framework structure and database information
Error logs and configuration files
Student records, including academic data and course information
Student names, exam dates, subject names, grade levels, student IDs, and marks/scores
Institutional details like academic years, class sections, and curriculum details

This isn’t KillSec’s first attack on a Bangladeshi institution. Earlier this year, they breached a financial organization, raising concerns about the nation’s cybersecurity. Their recent attack on Bangabandhu Government College further establishes them as one of the most dangerous cyber threats to Bangladesh’s digital infrastructure.

Cyberattacks are becoming more common and advanced, so all sectors must focus on cybersecurity by updating systems regularly and training staff to handle threats effectively.

Related article:

Check Also

PaperCut

Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

A Russian-speaking hacker has used artificial intelligence like never before. They sent out hundreds of …