Friday , May 9 2025

BD CIRT announce “Cyber Drill 2024”: Registration open

BGD e-GOV CIRT is excited to announce the Financial Institutions and Critical Information Infrastructure (CII) Cyber Drill 2024, designed for Bangladeshi cybersecurity professionals. This event aims to enhance participants’ skills against evolving cyber threats through realistic scenarios and challenges. Participants will analyze incidents and related artifacts to find solutions, with necessary materials and access provided.

Information those who want to participate:

Microsoft Patches Four Critical Azure and Power Apps Vulns

Microsoft has fixed critical vulnerabilities in its core cloud services, including Azure Automation, Azure Storage, Azure DevOps, and Microsoft Power...
Read More
Microsoft Patches Four Critical Azure and Power Apps Vulns

Qilin Ransomware topped April 2025 with 45+ data leak disclosures

The cyber threat landscape is rapidly changing, with a notable increase in ransomware activity in April 2025, driven by the...
Read More
Qilin Ransomware topped April 2025 with 45+ data leak disclosures

SonicWall Patches 3 Flaws in SMA 100 Devices

SonicWall has released patches for three security flaws in SMA 100 Secure Mobile Access appliances that could allow remote code...
Read More
SonicWall Patches 3 Flaws in SMA 100 Devices

Top Ransomware Actively Attacking Financial Sector: 406 Incidents Disclosed

From April 2024 to April 2025, Flashpoint analysts noted that the financial sector was a major target for threat actors,...
Read More
Top Ransomware Actively Attacking Financial Sector: 406 Incidents Disclosed

Critical (CVSS 10) Flaw in Cisco IOS XE WLCs Allows RRA

Cisco has issued a security advisory for a critical vulnerability in its IOS XE Software for Wireless LAN Controllers (WLCs)....
Read More
Critical (CVSS 10) Flaw in Cisco IOS XE WLCs Allows RRA

CVE-2025-29824
Play Ransomware Exploited Windows CVE-2025-29824 as Zero-Day

Attackers linked to the Play ransomware operation deployed a zero-day privilege escalation exploit during an attempted attack against an organization...
Read More
CVE-2025-29824  Play Ransomware Exploited Windows CVE-2025-29824 as Zero-Day

Hacker exploited Samsung MagicINFO 9 Server RCE flaw

Hackers are exploiting an unauthenticated remote code execution vulnerability in the Samsung MagicINFO 9 Server to take control of devices...
Read More
Hacker exploited Samsung MagicINFO 9 Server RCE flaw

CISA adds Langflow flaw to its KEV catalog

CISA added the Langflow vulnerability, CVE-2025-3248 (CVSS score 9.8), to its Known Exploited Vulnerabilities catalog. Langflow is a popular tool...
Read More
CISA adds Langflow flaw to its KEV catalog

Google Fixes Android Flaw (CVE-2025-27363) Exploited by Attackers

Google has released its monthly Android security updates, addressing 46 vulnerabilities, including one that has been actively exploited. CVE-2025-27363 (CVSS...
Read More
Google Fixes Android Flaw (CVE-2025-27363) Exploited by Attackers

UAP hosted “UAP Cyber Siege 2025”, A national level cybersecurity competition

The Cyber Security Club, representing the Department of Computer Science and Engineering at the University of Asia Pacific (UAP), has...
Read More
UAP hosted “UAP Cyber Siege 2025”, A national level cybersecurity competition

Each team may consist of 5 members from same institution.
Prior to registration, team must pay a registration fee – BDT 10,000 (Ten Thousand).
Participants are free to use any tool they choose.
Participants must not seek help from third-parties for solving Cyber Drill problems.
Violation of organizer’s terms will terminate the player and/or team from the competition.
Registration will close on October 20, 2024
Pre-selection event will be online on October 26, 2024
Thirty teams will take part in an on-site cyber drill on November 9, 2024.

Rules of Engagement:

1. All participants shall be registered in the registration platform, the registration guideline is available at https://www.cirt.gov.bd/cyberdrill2024

2. A team must have 3 to 5 members from the same organization, and all participants must compete as part of that team.

3. Each team must have an organization-appointed leader and an appropriate team name.

4.All members can submit flags, but each challenge has a limited number of attempts.

TeamName_ParticipantName:

5. Participants have the freedom to use any tool including those available on the internet.

6. Participation from outside the country is not allowed.

7. It is strictly forbidden to perform any kind of Brute force, Denial of Service or any Other unwanted and disruptive actions against the drill platforms, servers or associated infrastructure.

8. Any activities or actions that would interfere, obstruct, or disturb other teams participants and event organizers are strictly prohibited.

9. Organizers may provide hint(s) on scenario basis, it will be commonly distributed to every participating teams. But seeking or exchanging flags, write-ups, solutions, or hints for the challenges during the cyber drill, either from or with other participating teams or external entities, is strictly prohibited.

10. Violation of the organizers’ terms and condition may result in the disqualification of the team from the competition. In such cases, the organizers reserve the right to notify the participating organization about the violation.

11. Teams scoring 40% or higher of the total points will receive a certificate of successful participation.

12. Organizers reserve the right to make necessary changes to the event rules and guidelines. Any updates will be communicated through our official website.

Bangladeshi 32.4% government websites face cyber attack: NAS report

 

Check Also

NVDP

BCSI officially announce National Vulnerability Disclosure Program (NVDP)

Bangladesh Cyber Security Intelligence (BCSI) officially launch the National Vulnerability Disclosure Program (NVDP) to enhance …

Leave a Reply

Your email address will not be published. Required fields are marked *