Thursday , June 5 2025
data

Bangladeshi online marketplace faced massive data leak

Bangladeshi online market place Travela.xyz for homestays and experiences, suffered a major data breach on June 9, 2024. The leaked information, found on a dark web hacking forum, exposed the personal data of the company’s hosts.

The leaked data, which includes user information such as Host ID, First Name, Last Name, Phone Number, Email Address, Birthdate Refer Code, Total Booking, Average Response Time, Status, OS Platform, bkash MSISDN (Mobile Number), Image, and Host Status.

CVSS 9.6: IBM QRadar & Cloud Pak Security Flaws Exposed

IBM has issued a security advisory for vulnerabilities in its QRadar Suite Software and Cloud Pak for Security platforms. These...
Read More
CVSS 9.6: IBM QRadar & Cloud Pak Security Flaws Exposed

ALERT
Thousands of IP addresses compromised nationwide: CIRT warn

As Bangladesh prepares for the extended Eid-ul-Adha holidays, the BGD e-GOV Computer Incident Response Team (CIRT) has issued an urgent...
Read More
ALERT  Thousands of IP addresses compromised nationwide: CIRT warn

New Android Malware ‘Crocodilus’ Targets Banks in 8 Countries

In March 2025, the Threatfabric mobile Threat Intelligence team identified Crocodilus, a new Android banking Trojan designed for device takeover....
Read More
New Android Malware ‘Crocodilus’ Targets Banks in 8 Countries

Qualcomm Patches 3 Zero-Days Used in Targeted Android Attacks

Qualcomm has issued security patches for three zero-day vulnerabilities in the Adreno GPU driver, affecting many chipsets that are being...
Read More
Qualcomm Patches 3 Zero-Days Used in Targeted Android Attacks

Critical RCE Flaw Patched in Roundcube Webmail

Roundcube Webmail has fixed a critical security flaw that could enable remote code execution after authentication. Disclosed by security researcher...
Read More
Critical RCE Flaw Patched in Roundcube Webmail

Hacker claim Leak of Deloitte Source Code & GitHub Credentials

A hacker known as "303" claim to breach the company's systems and leaked sensitive internal data on a dark web...
Read More
Hacker claim Leak of Deloitte Source Code & GitHub Credentials

CISA Issued Guidance for SIEM and SOAR Implementation

CISA and ACSC issued new guidance this week on how to procure, implement, and maintain SIEM and SOAR platforms. SIEM...
Read More
CISA Issued Guidance for SIEM and SOAR Implementation

Linux flaws enable password hash theft via core dumps in Ubuntu, RHEL, Fedora

The Qualys Threat Research Unit (TRU) found two local information-disclosure vulnerabilities in Apport and systemd-coredump. Both issues are race-condition vulnerabilities....
Read More
Linux flaws enable password hash theft via core dumps in Ubuntu, RHEL, Fedora

Australia enacts mandatory ransomware payment reporting

New ransomware payment reporting rules take effect in Australia yesterday (May 30) for all organisations with an annual turnover of...
Read More
Australia enacts mandatory ransomware payment reporting

Why Govt Demands Foreign CCTV Firms to Submit Source Code?

Global makers of surveillance gear have clashed with Indian regulators in recent weeks over contentious new security rules that require...
Read More
Why Govt Demands Foreign CCTV Firms to Submit Source Code?

The Travela.xyz data breach serves as a powerful reminder that even emerging companies are susceptible to the ever-present dangers of the digital world.

BCSI reported, As the investigation unfolds, it becomes evident that it is crucial for both companies and users to acknowledge these risks and proactively shield their personal information. This incident serves as a wake-up call, emphasizing the dire need for steadfast cybersecurity measures. Companies must wholeheartedly prioritize the security of their users’ information by implementing rigorous protective measures, conducting regular security audits, and remaining perpetually vigilant in the face of emerging threats.

Travela was founded in 2020 to make tourism more accessible and beneficial for local economies. it’s vision is to create a world where travel is simple, safe, and enjoyable.

Travela was incorporated as a Private Limited Company at Dhanmondi in Dhaka, Bangladesh in 2020. One from travela said, they are now working Dhaka based.

As travela worked like bnb, its app must contain sensitive information. So, if the bad actor claim is legit, victimas may suffer seriously as bad actor may use or modify the info for illegal purposes. Personal information like phone numbers, email addresses, and birthdates can be used for identity theft, phishing attacks, and other harmful activities. The leak of financial details like the bkash MSISDN increases the risk, potentially resulting in financial fraud.

In recent times, hacker target many Bangladeshi gov.t and private institutions.

Check Also

Evaly

Evaly E-commerce Platform Allegedly Hacked

Evaly, a Bangladeshi e-commerce platform, is reportedly facing a major data breach that may have …

Leave a Reply

Your email address will not be published. Required fields are marked *