Friday , July 11 2025
CIRT

BD CIRT published advisory on Web Application and Database Security

BDG e-GOV CIRT’s Cyber Threat Intelligence Unit has noticed a concerning increase in cyber-attacks against web applications and database servers in Bangladesh. Hackers are trying to deface government websites, steal important information, and disrupt online services through DDoS attacks. Organizations are advised to take precautions to protect themselves online.

CIRT identifies top threats and attack trends, including DoS/DDoS attacks, database and software vulnerabilities exploitation, SQL/NoSQL injection attacks, insecure direct object reference (IDOR) vulnerability exploitation, and breaches of compromised organizational databases from web and mobile applications.

AMD discloses 4 new CPU flaws Affecting Many CPUs

AMD has revealed four new vulnerabilities that could enable attackers to access sensitive data via timing-based side-channel attacks. These vulnerabilities,...
Read More
AMD discloses 4 new CPU flaws Affecting Many CPUs

GitLab patched XSS and Authorization Bypass Flaws

GitLab has released security updates for its Community Edition (CE) and Enterprise Edition (EE) to fix vulnerabilities that could enable...
Read More
GitLab patched XSS and Authorization Bypass Flaws

CVE-2025-7206
Critical D-Link DIR-825 Router Flaw Remote Crash Via Buffer Overflow

A newly found vulnerability (CVE-2025-7206) in the D-Link DIR-825 router firmware version 2.10 poses a significant risk to home and...
Read More
CVE-2025-7206  Critical D-Link DIR-825 Router Flaw Remote Crash Via Buffer Overflow

Urgently patch now: Zoom Patches 6 Flaws

Zoom released a security update addressing six newly discovered vulnerabilities in its Workplace, Rooms, and SDK products for Windows, macOS,...
Read More
Urgently patch now: Zoom Patches 6 Flaws

Whatsapp rival ‘Bitchat’, message without internet

Jack Dorsey, co-founder of Twitter and Block Head, launched a new peer-to-peer messaging app called Bitchat, which operates solely over...
Read More
Whatsapp rival ‘Bitchat’, message without internet

Splunk Addresses Third-Party Package Vulns in SOAR Versions

Splunk has issued critical security updates for SOAR versions 6.4.0 and 6.4 to fix several vulnerabilities in third-party packages. The...
Read More
Splunk Addresses Third-Party Package Vulns in SOAR Versions

Texas-based Tax Credit Consultancy agency exposed PII, ID Numbers, & SSNs

Cybersecurity researcher Jeremiah Fowler found an unsecured database with 245,949 records, reported to vpnMentor. It likely belonged to a tax...
Read More
Texas-based Tax Credit Consultancy agency exposed PII, ID Numbers, & SSNs

CVE-2025-25257
Fortinet Addresses Major SQL Injection Flaw in FortiWeb

Fortinet has issued a critical patch for a critical vulnerability in its FortiWeb product, a web application firewall commonly used...
Read More
CVE-2025-25257  Fortinet Addresses Major SQL Injection Flaw in FortiWeb

Microsoft July 2025 Patch Tuesday: One zero-day, 137 flaws

Microsoft's Patch Tuesday in July 2025 is critical, featuring updates for 137 vulnerabilities, including a zero-day in Microsoft SQL Server....
Read More
Microsoft July 2025 Patch Tuesday: One zero-day, 137 flaws

Android malware Anatsa infiltrates Google Play targeting banks worldwide

ThreatFabric researchers have discovered a new sophisticated campaign by the Anatsa banking trojan targeting mobile banking users in the U.S....
Read More
Android malware Anatsa infiltrates Google Play targeting banks worldwide

CIRT discovered root causes of attacks on web, mobile applications, and databases. Web and mobile applications face several security issues:

1. Secure coding practices are not followed.
2. Default parameters are used for configuration.
3. Lack of proper authorization and authentication in API development.
4. Absence of error handling capabilities.
5. Weak session management controls.
6. Insecure communication protocols.
7. Default configurations for applications and databases.
8. Negligence in software, OS, and database updates.
9. Insufficient logging and monitoring practices.
10. Weak control over administrative access roles.
11. Lack of website protection measures.

Databases:

1. Database software vulnerabilities being exploited.
2. Attackers exploit remote login to application and database servers, which is enabled for continuous maintenance by vendors, designers, and developers.
3. Threat actors using leaked or exposed administrative credentials.
4. Insufficient authorization, authentication, and user verification, including multifactor authentication (MFA) for administrative access roles.
5. Failure to monitor attack surface and implement continuous remediation strategies.

CIRT suggest some remediation Strategies:

To secure databases and applications:
– Use parameterized queries or ORM frameworks.
– Validate and sanitize user inputs regularly.
– Encode user inputs before displaying them.
– Implement Content Security Policy (CSP).

For database access management (DAM):
– Restrict database access to authorized users.
– Continuously monitor database activities.

For software maintenance:

– Patch software and plugins frequently.

For log monitoring (SIEM):

– Monitor logs for real-time threat detection.
– Detect anomalies and unusual activities.

For web application security:

– Use WAF to safeguard against web threats.
– Deploy anti-DDoS solutions.

Full report here.

 

Check Also

Microsoft Exchange Servers

Hacker Target 70+ Microsoft Exchange Servers to Steal Credentials with Keyloggers

Unidentified hackers are targeting exposed Microsoft Exchange servers to inject harmful code into login pages …

Leave a Reply

Your email address will not be published. Required fields are marked *