Saturday , March 29 2025

BD CIRT announce “Cyber Drill 2024”: Registration open

BGD e-GOV CIRT is excited to announce the Financial Institutions and Critical Information Infrastructure (CII) Cyber Drill 2024, designed for Bangladeshi cybersecurity professionals. This event aims to enhance participants’ skills against evolving cyber threats through realistic scenarios and challenges. Participants will analyze incidents and related artifacts to find solutions, with necessary materials and access provided.

Information those who want to participate:

FBI investigating cyberattack at Oracle, Bloomberg News reports

The Federal Bureau of Investigation (FBI) is probing the cyberattack at Oracle (ORCL.N), opens new tab that has led to...
Read More
FBI investigating cyberattack at Oracle, Bloomberg News reports

OpenAI Offering $100K Bounties for Critical Vulns

OpenAI has increased its maximum bug bounty payout to $100,000, up from $20,000, to encourage the discovery of critical vulnerabilities...
Read More
OpenAI Offering $100K Bounties for Critical Vulns

Splunk Alert User RCE and Data Leak Vulns

Splunk has released a security advisory about critical vulnerabilities in Splunk Enterprise and Splunk Cloud Platform. These issues could lead...
Read More
Splunk Alert User RCE and Data Leak Vulns

CIRT alert Situational Awareness for Eid Holidays

As the Eid holidays near, cybercriminals may try to take advantage of weakened security during this time. The CTI unit...
Read More
CIRT alert Situational Awareness for Eid Holidays

Cyberattack on Malaysian airports: PM rejected $10 million ransom

Operations at Kuala Lumpur International Airport (KLIA) were unaffected by a cyber attack in which hackers demanded US$10 million (S$13.4...
Read More
Cyberattack on Malaysian airports: PM rejected $10 million ransom

Micropatches released for Windows zero-day leaking NTLM hashes

Unofficial patches are available for a new Windows zero-day vulnerability that allows remote attackers to steal NTLM credentials by deceiving...
Read More
Micropatches released for Windows zero-day leaking NTLM hashes

VMware Patches Authentication Bypass Flaw in Windows Tool

On Tuesday, VMware issued an urgent fix for a security flaw in its VMware Tools for Windows. CVE-2025-22230 allows a...
Read More
VMware Patches Authentication Bypass Flaw in Windows Tool

IngressNightmare
Over 40% of cloud environments are vulnerable to RCE

Kubernetes users of the Ingress NGINX Controller are advised to fix four newly found remote code execution ( RCE) vulnerabilities,...
Read More
IngressNightmare  Over 40% of cloud environments are vulnerable to RCE

(CVE-2025-29927)
Urgently Patch Your Next.js for Authorization Bypass

Next.js, a widely used React framework for building full-stack web applications, has fixed a serious security vulnerability. Used by many...
Read More
(CVE-2025-29927)  Urgently Patch Your Next.js for Authorization Bypass

Oracle refutes breach after hacker claims 6 million data theft

A hacker known as “rose87168” claims to have stolen six million records from Oracle Cloud servers. The stolen data includes...
Read More
Oracle refutes breach after hacker claims 6 million data theft

Each team may consist of 5 members from same institution.
Prior to registration, team must pay a registration fee – BDT 10,000 (Ten Thousand).
Participants are free to use any tool they choose.
Participants must not seek help from third-parties for solving Cyber Drill problems.
Violation of organizer’s terms will terminate the player and/or team from the competition.
Registration will close on October 20, 2024
Pre-selection event will be online on October 26, 2024
Thirty teams will take part in an on-site cyber drill on November 9, 2024.

Rules of Engagement:

1. All participants shall be registered in the registration platform, the registration guideline is available at https://www.cirt.gov.bd/cyberdrill2024

2. A team must have 3 to 5 members from the same organization, and all participants must compete as part of that team.

3. Each team must have an organization-appointed leader and an appropriate team name.

4.All members can submit flags, but each challenge has a limited number of attempts.

TeamName_ParticipantName:

5. Participants have the freedom to use any tool including those available on the internet.

6. Participation from outside the country is not allowed.

7. It is strictly forbidden to perform any kind of Brute force, Denial of Service or any Other unwanted and disruptive actions against the drill platforms, servers or associated infrastructure.

8. Any activities or actions that would interfere, obstruct, or disturb other teams participants and event organizers are strictly prohibited.

9. Organizers may provide hint(s) on scenario basis, it will be commonly distributed to every participating teams. But seeking or exchanging flags, write-ups, solutions, or hints for the challenges during the cyber drill, either from or with other participating teams or external entities, is strictly prohibited.

10. Violation of the organizers’ terms and condition may result in the disqualification of the team from the competition. In such cases, the organizers reserve the right to notify the participating organization about the violation.

11. Teams scoring 40% or higher of the total points will receive a certificate of successful participation.

12. Organizers reserve the right to make necessary changes to the event rules and guidelines. Any updates will be communicated through our official website.

Bangladeshi 32.4% government websites face cyber attack: NAS report

 

Check Also

“Workshop on Cybersecurity Awareness and Needs Analysis” held at BBTA

A time-demanding workshop on “Cybersecurity Awareness and Needs Analysis” was held on Thursday (December 19) …

Leave a Reply

Your email address will not be published. Required fields are marked *