Tuesday , August 4 2026
Steadfast Courier

Hacker offers to sell Bangladeshi courier “Steadfast” full database

Steadfast Courier, a leading logistics and package delivery service operating in Bangladesh, has reportedly been compromised. The hacker offers to sell the full database of the company on a forum for $2,000.

The allegedly compromised data includes:

CVE-2026-18574
Check Point Authentication Bypass Hits Management Server

Check Point fixed a flaw that allowed bypassing authentication on its Security Management and Multi-Domain Security Management servers. This issue...
Read More
CVE-2026-18574  Check Point Authentication Bypass Hits Management Server

TP-Link RCE and SonicWall Zero-Click Flaws Enable Complete Device Compromise

TP-Link has shared a security warning about a serious problem with its TL-WR940N V6 wireless router. This problem, known as...
Read More
TP-Link RCE and SonicWall Zero-Click Flaws Enable Complete Device Compromise

ExfilSquad releases info of over 100,000 UK police officers, staff

A cyberattack on the U.K.'s Police National Legal Database (PNLD) has put the contact information of over 100,000 police officers...
Read More
ExfilSquad releases info of over 100,000 UK police officers, staff

CISA alerts to cyberattacks affecting U.S. water utilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns of a big rise in attacks on internet-connected programmable logic controllers...
Read More
CISA alerts to cyberattacks affecting U.S. water utilities

“CyberStrike” AI-Driven Security Platform for Automated Testing

A new open-source project named CyberStrike aims to be the first AI tool made for offensive security. It can turn...
Read More
“CyberStrike” AI-Driven Security Platform for Automated Testing

AIDCQ Propose to invest $2 billion in AI data center in Bangladesh

Many countries are now showing interest to invest in the data center industry in Banglades especially in AI data centers....
Read More
AIDCQ Propose to invest $2 billion in AI data center in Bangladesh

NVIDIA BlueField Flaw Enables Code Execution Attacks

NVIDIA has revealed a big flaw with its BlueField DPUs and ConnectX networking systems. This issue could let attackers run...
Read More
NVIDIA BlueField Flaw Enables Code Execution Attacks

Massive customer data from India’s Bank of Baroda surfaced online

India's leading state-owned lender Bank of Baroda acknowledged Monday a security incident after reports that approximately 1 terabyte of customer...
Read More
Massive customer data from India’s Bank of Baroda surfaced online

Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

CISA has put the Fortinet FortiOS vulnerability CVE-2025-68686 in its list of known exploited flaws after ongoing attacks. The flaw...
Read More
Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

OpenAI's CEO Sam Altman says that AI has reached a big milestone. The technology can now make itself better, leading...
Read More
Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

Customer full names
Phone numbers
Detailed delivery addresses
Package tracking IDs
Cash-on-Delivery (COD) amounts
Invoice details
Hub and zone information
Shipment weights and creation dates

if the hacker claim is true, it may result in an identity theft and security risks for the customer.

Why Courier Companies Are Targeted
Courier/logistics platforms are attractive to hackers because they contain:
Huge customer databases
Phone numbers and addresses
E-commerce order details
Merchant business data
These can be used for:
Phishing scams
Social engineering
SIM swap attacks
Targeted fraud against online sellers
Common Security Weaknesses in BD Logistics Platforms

Experts said, several systemic weaknesses are often observed across logistics and courier platforms:

Inadequate API authentication mechanisms: Many platforms use weak or poorly set up security controls, which raises the risk of unauthorized access to backend services and sensitive data.

Insufficient database access controls: Inadequate permissions and too many access rights can lead to unauthorized use of important databases.

Absence of robust encryption for sensitive data: Failure to use strong encryption for data in transit and at rest puts customer information at risk.

Security risks introduced by third-party integrations: Unverified tools, APIs, or services may create security holes, increasing the attack surface of logistics platforms.

(Media Disclaimer: This report is based on research conducted internally and externally using OSINT. The information provided here is for reference only, and users are responsible for referring and relying on it. Infosecbulletin is not liable for the accuracy or consequences of using this information by any means)

Check Also

BIOS

Critical Dell BIOS & Zimbra Flaws Expose Enterprise Systems

A critical flaw with how Dell saves BIOS passwords lets anyone quickly recover these passwords …