Saturday , April 19 2025

BD CIRT announce “Cyber Drill 2024”: Registration open

BGD e-GOV CIRT is excited to announce the Financial Institutions and Critical Information Infrastructure (CII) Cyber Drill 2024, designed for Bangladeshi cybersecurity professionals. This event aims to enhance participants’ skills against evolving cyber threats through realistic scenarios and challenges. Participants will analyze incidents and related artifacts to find solutions, with necessary materials and access provided.

Information those who want to participate:

CVE-2025-2492
ASUS warns of critical auth bypass flaw in routers

Hackers can exploit a vulnerability in Asus routers to execute unauthorized functions. This serious issue, rated 9.2 out of 10,...
Read More
CVE-2025-2492  ASUS warns of critical auth bypass flaw in routers

16,000+ Fortinet devices compromised with symlink backdoor, Mostly in Asia

According to Shadowserver Foundation around 17,000 Fortinet devices worldwide have been compromised using a new technique called "symlink". This number...
Read More
16,000+  Fortinet devices compromised with symlink backdoor, Mostly in Asia

Patch now! Critical Erlang/OTP SSH Vuln Allows UCE

A critical security flaw has been found in the Erlang/Open Telecom Platform (OTP) SSH implementation, allowing an attacker to run...
Read More
Patch now! Critical Erlang/OTP SSH Vuln Allows UCE

CISA warns of increasing risk tied to Oracle legacy Cloud leak

On Wednesday, CISA alerted about increased breach risks due to the earlier compromise of legacy Oracle Cloud servers, emphasizing the...
Read More
CISA warns of increasing risk tied to Oracle legacy Cloud leak

CVE-2025-20236
Cisco Patches Unauthenticated RCE Flaw in Webex App

Cisco issued a security advisory about a serious vulnerability in its Webex App that allows unauthenticated remote code execution (RCE)...
Read More
CVE-2025-20236  Cisco Patches Unauthenticated RCE Flaw in Webex App

Apple released emergency security updates for 2 zero-day vulns

On Wednesday, Apple released urgent operating system updates to address two security vulnerabilities that had already been exploited in highly...
Read More
Apple released emergency security updates for 2 zero-day vulns

Oracle Released Patched for 378 flaws for April 2025

On April 15, 2025, Oracle released a Critical Patch Update for 378 flaws for its products. The patch update covers...
Read More
Oracle Released Patched for 378 flaws for April 2025

CVE-2025-24054
Hackers Exploiting NTLM Spoofing Windows Vuln the in Wild

Check Point Research warns of the active exploitation of a new vulnerability, CVE-2025-24054, which lets hackers leak NTLMv2-SSP hashes using...
Read More
CVE-2025-24054  Hackers Exploiting NTLM Spoofing Windows Vuln the in Wild

Bengaluru firm got ransomware attack, Hacker demanded $70,000

Bengaluru's Whiteboard Technologies Pvt Ltd was hit by a ransomware attack, with hackers demanding a ransom of up to $70,000...
Read More
Bengaluru firm got ransomware attack, Hacker demanded $70,000

MITRE warns: U.S. Govt. Funding for MITRE’s CVE Ends Today

MITRE Vice President Yosry Barsoum warned that U.S. government funding for the Common Vulnerabilities and Exposures (CVE) and Common Weakness...
Read More
MITRE warns: U.S. Govt. Funding for MITRE’s CVE Ends Today

Each team may consist of 5 members from same institution.
Prior to registration, team must pay a registration fee – BDT 10,000 (Ten Thousand).
Participants are free to use any tool they choose.
Participants must not seek help from third-parties for solving Cyber Drill problems.
Violation of organizer’s terms will terminate the player and/or team from the competition.
Registration will close on October 20, 2024
Pre-selection event will be online on October 26, 2024
Thirty teams will take part in an on-site cyber drill on November 9, 2024.

Rules of Engagement:

1. All participants shall be registered in the registration platform, the registration guideline is available at https://www.cirt.gov.bd/cyberdrill2024

2. A team must have 3 to 5 members from the same organization, and all participants must compete as part of that team.

3. Each team must have an organization-appointed leader and an appropriate team name.

4.All members can submit flags, but each challenge has a limited number of attempts.

TeamName_ParticipantName:

5. Participants have the freedom to use any tool including those available on the internet.

6. Participation from outside the country is not allowed.

7. It is strictly forbidden to perform any kind of Brute force, Denial of Service or any Other unwanted and disruptive actions against the drill platforms, servers or associated infrastructure.

8. Any activities or actions that would interfere, obstruct, or disturb other teams participants and event organizers are strictly prohibited.

9. Organizers may provide hint(s) on scenario basis, it will be commonly distributed to every participating teams. But seeking or exchanging flags, write-ups, solutions, or hints for the challenges during the cyber drill, either from or with other participating teams or external entities, is strictly prohibited.

10. Violation of the organizers’ terms and condition may result in the disqualification of the team from the competition. In such cases, the organizers reserve the right to notify the participating organization about the violation.

11. Teams scoring 40% or higher of the total points will receive a certificate of successful participation.

12. Organizers reserve the right to make necessary changes to the event rules and guidelines. Any updates will be communicated through our official website.

Bangladeshi 32.4% government websites face cyber attack: NAS report

 

Check Also

Splunk

Splunk targets Bangladeshi market: Investing in local talent

Splunk, a unified security and observability platform turn its focuses on Bangladeshi market. On Monday …

Leave a Reply

Your email address will not be published. Required fields are marked *