Saturday , September 12 2026
NVDP

BCSI officially announce National Vulnerability Disclosure Program (NVDP)

Bangladesh Cyber Security Intelligence (BCSI) officially launch the National Vulnerability Disclosure Program (NVDP) to enhance the country’s cybersecurity. This initiative aims to create a secure platform for ethical hackers, researchers, and organizations to work together in identifying and addressing vulnerabilities that threaten government systems, critical infrastructure, and private sector entities.

NVDP aims to leverage the skills of top cybersecurity professionals in the country. It promotes responsible vulnerability disclosure to address potential threats proactively and effectively.

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Palo Alto Networks has revealed a serious flaw in PAN-OS. It may let a remote attacker without a password run...
Read More
Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Critical Check Point VPN flaws allow remote code execution attacks

Check Point Software has revealed and fixed two major VPN flaws, CVE-2026-85102 and CVE-2026-85103. Both have a top CVSS score...
Read More
Critical Check Point VPN flaws allow remote code execution attacks

Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Cisco has said that a serious security flaw CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being used...
Read More
Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

A Russian-speaking hacker has used artificial intelligence like never before. They sent out hundreds of AI agents to find and...
Read More
Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Six Chinese AI companies ran large-scale attacks on American AI models since late 2024, according to U.S. cybersecurity and intelligence...
Read More
CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

An unknown security expert called Nightmare Eclipse has drops a new Microsoft Defender flaw called "ShieldCrash" right after Microsoft released...
Read More
Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

cPanel has shared CVE-2026-67401, a serious SQL injection flaw in EmailTrack. This flaw could allow attackers with permission to take...
Read More
cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

An ongoing attack is focused on FortiGate firewalls. Hackers use a serious flaw to install a special Node.js remote access...
Read More
FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

Microsoft Patch Tuesday September 2026 Fixed 973 Flaws Fixed, 2 Zero-Days

Microsoft shared its September 2026 security updates on September 8. These updates fix 973 flaws, including two serious issues that...
Read More
Microsoft Patch Tuesday September 2026  Fixed 973 Flaws Fixed, 2 Zero-Days

Key objectives of the program include:

Strengthening National Cybersecurity: Creating a clear way to find and fix weaknesses in critical systems before they can be used.

Empowering Ethical Hackers: Providing a platform for Bangladesh’s best cybersecurity experts to help protect the nation while receiving acknowledgment and rewards for their work.

Protecting Critical Sectors: Working with financial institutions, critical infrastructure organizations, and government agencies to protect them from new threats.

Fostering Public-Private Collaboration: Working together with government and private sectors to improve cybersecurity in Bangladesh.

Key Features of NVDP:

The NVDP is built on the principles of transparency, integrity, and security, and is guided by the following core features:

Verified Researcher Participation: Only verified cybersecurity researchers will have access to the NVDP platform, ensuring all participants uphold high standards of professionalism and ethics.

Confidentiality and Safe Harbor: Researchers’ identities and vulnerability reports are kept private, and the program offers protection for researchers to report vulnerabilities without fear of punishment.

Structured Agreements: Organizations sign detailed agreements that explain the program’s purpose, safety rules, and behavior guidelines, promoting a collaborative and legally secure environment.

Controlled Access to Programs: NVDP invites only qualified researchers to participate in specific programs based on their expertise and the sensitivity of the target scope.

Empowering Cybersecurity Talent:

NVDP enhances vulnerability disclosure by emphasizing talent development and capacity building. It identifies and empowers leading cybersecurity professionals in Bangladesh, providing them with valuable opportunities.

Secure National Assets: Protect government and private systems, like banks and essential services.

Earn Recognition and Rewards: Earn financial rewards, recognition, and career growth for contributions.

Build Expertise: Access exclusive programs and challenges to improve cybersecurity skills and knowledge.

By fostering a community of skilled professionals, NVDP aims to establish Bangladesh as a global leader in cybersecurity talent and innovation.

How to Get Involved:

For Researchers:

Ethical hackers and cybersecurity researchers are encouraged to join NVDP as verified participants. The onboarding process includes:

Submitting proof of competency, such as bug hunting experience, certifications, or CTF participation.
Completing identity verification to become an officially recognized NVDP researcher.
Gaining access to private programs tailored to your expertise and interests.

For Organizations:

Government and private sector organizations can collaborate with NVDP to safeguard their systems and infrastructure. By participating in the program, organizations will:

Gain access to a pool of top cybersecurity talent.
Receive detailed vulnerability reports and mitigation strategies.
Enhance their overall cybersecurity posture through proactive measures.

The NVDP welcomes cybersecurity professionals, ethical hackers, and organizations to join the National Vulnerability Disclosure Program (NVDP) for a safer Bangladesh.

Check Also

Incident Reporting

Bangladesh Launches (CIRS) and National ICT & Cyber Security Rating System (NRS)

In an important move to boost the country’s cybersecurity, Bangladesh started the Cyber Incident Reporting …