Monday , September 14 2026

BD CIRT announce “Cyber Drill 2024”: Registration open

BGD e-GOV CIRT is excited to announce the Financial Institutions and Critical Information Infrastructure (CII) Cyber Drill 2024, designed for Bangladeshi cybersecurity professionals. This event aims to enhance participants’ skills against evolving cyber threats through realistic scenarios and challenges. Participants will analyze incidents and related artifacts to find solutions, with necessary materials and access provided.

Information those who want to participate:

Hackers deploy Casbaneiro Trojan that activates on bank websites

Casbaneiro is going after online banking users by sending fake messages that seem like urgent bills or legal papers. The...
Read More
Hackers deploy Casbaneiro Trojan that activates on bank websites

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Palo Alto Networks has revealed a serious flaw in PAN-OS. It may let a remote attacker without a password run...
Read More
Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Critical Check Point VPN flaws allow remote code execution attacks

Check Point Software has revealed and fixed two major VPN flaws, CVE-2026-85102 and CVE-2026-85103. Both have a top CVSS score...
Read More
Critical Check Point VPN flaws allow remote code execution attacks

Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Cisco has said that a serious security flaw CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being used...
Read More
Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

A Russian-speaking hacker has used artificial intelligence like never before. They sent out hundreds of AI agents to find and...
Read More
Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Six Chinese AI companies ran large-scale attacks on American AI models since late 2024, according to U.S. cybersecurity and intelligence...
Read More
CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

An unknown security expert called Nightmare Eclipse has drops a new Microsoft Defender flaw called "ShieldCrash" right after Microsoft released...
Read More
Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

cPanel has shared CVE-2026-67401, a serious SQL injection flaw in EmailTrack. This flaw could allow attackers with permission to take...
Read More
cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

Each team may consist of 5 members from same institution.
Prior to registration, team must pay a registration fee – BDT 10,000 (Ten Thousand).
Participants are free to use any tool they choose.
Participants must not seek help from third-parties for solving Cyber Drill problems.
Violation of organizer’s terms will terminate the player and/or team from the competition.
Registration will close on October 20, 2024
Pre-selection event will be online on October 26, 2024
Thirty teams will take part in an on-site cyber drill on November 9, 2024.

Rules of Engagement:

1. All participants shall be registered in the registration platform, the registration guideline is available at https://www.cirt.gov.bd/cyberdrill2024

2. A team must have 3 to 5 members from the same organization, and all participants must compete as part of that team.

3. Each team must have an organization-appointed leader and an appropriate team name.

4.All members can submit flags, but each challenge has a limited number of attempts.

TeamName_ParticipantName:

5. Participants have the freedom to use any tool including those available on the internet.

6. Participation from outside the country is not allowed.

7. It is strictly forbidden to perform any kind of Brute force, Denial of Service or any Other unwanted and disruptive actions against the drill platforms, servers or associated infrastructure.

8. Any activities or actions that would interfere, obstruct, or disturb other teams participants and event organizers are strictly prohibited.

9. Organizers may provide hint(s) on scenario basis, it will be commonly distributed to every participating teams. But seeking or exchanging flags, write-ups, solutions, or hints for the challenges during the cyber drill, either from or with other participating teams or external entities, is strictly prohibited.

10. Violation of the organizers’ terms and condition may result in the disqualification of the team from the competition. In such cases, the organizers reserve the right to notify the participating organization about the violation.

11. Teams scoring 40% or higher of the total points will receive a certificate of successful participation.

12. Organizers reserve the right to make necessary changes to the event rules and guidelines. Any updates will be communicated through our official website.

Bangladeshi 32.4% government websites face cyber attack: NAS report

 

Check Also

Incident Reporting

Bangladesh Launches (CIRS) and National ICT & Cyber Security Rating System (NRS)

In an important move to boost the country’s cybersecurity, Bangladesh started the Cyber Incident Reporting …