Sunday , August 23 2026
CPE

Seminar on Continuing Professional Education (CPE) held at BCS

A seminar on Continuing Professional Education (CPE) was held at Bangladesh Computer Society (BCS) premises
where three different time demanding topic has been discussed on Friday. Three veteran industry experts discussed various aspects of cyber security in Bangladesh perspective with global commitment.

About thousands of leaked AWS keys Held Full Admin Rights

More than 9,300 AWS access keys that were made public from August 2022 to August 2026 are still active, says...
Read More
About thousands of leaked AWS keys Held Full Admin Rights

US Bank investigates LockBit’s Data Breach Claims

US Bank is looking into LockBit's claims about a breach and stolen data. The ransomware group says they will share...
Read More
US Bank investigates LockBit’s Data Breach Claims

Five new malware families actively targeting Asian Gov.t infra

Central Asian government agencies have been attacked in a cyber spy operation that used a small but different range of...
Read More
Five new malware families actively targeting Asian Gov.t infra

T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

T-Mobile’s cybersecurity team reportedly physically cut a network cable connecting compromised infrastructure to the outside world. According to Bloomberg, the move...
Read More
T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

Splunk has issued security fixes for 17 weaknesses in different apps and add-ons, such as Splunk MCP Server, Splunk AI...
Read More
Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

“Zombie Card” attack revels expired Visa card may be used for contactless payments

Security experts have shown that expired credit cards can still be used. A study from the University of Massachusetts Amherst,...
Read More
“Zombie Card” attack revels expired Visa card may be used for contactless payments

Critical Zimbra RCE Flaw Actively Exploited in the Wild

CERT Polska has alerted that bad actors are actively exploiting a security flaw in Zimbra Collaboration Suite to execute code...
Read More
Critical Zimbra RCE Flaw Actively Exploited in the Wild

Operation CameraSwarm
A single hacker compromise 1400+ Dahua camera worldwide 

Operation CameraSwarm compromised 14,500+ Dahua IP cameras mostly in Ukraine and Russia. The operation lasted for at least 35 days...
Read More
Operation CameraSwarm  A single hacker compromise 1400+ Dahua camera worldwide 

Cl0p Ransomware Listed 40+ Victims of PTC Windchill Campaign

The Cl0p ransomware group has listed over 40 organizations that they say they targeted in a recent attack. This attack...
Read More
Cl0p Ransomware Listed 40+ Victims of PTC Windchill Campaign

Oracle Issues 943 Security Patches, Including Critical WebLogic Flaw

Oracle has put out 943 new security updates in its August 2026 Critical Security Patch Update. These updates fix problems...
Read More
Oracle Issues 943 Security Patches, Including Critical WebLogic Flaw

Md. Abul Kalam Azad, Head of Information Security at Eastern Bank Ltd, presented “Don’t Get Hacked: Let AI Guard Your Gate.” The talk focused on using AI to strengthen cybersecurity in finance by tackling rising cyber threats and a lack of skilled professionals. AI boosts security through threat hunting, vulnerability management, and faster prediction of attacks compared to humans. Future uses include Advanced Threat Protection (ATP) and AI-powered WAFs, with AI-driven SOCs improving teamwork and efficiency. In summary, AI offers automated and scalable solutions to combat cyberattacks.

Mohammad Shafiuddin Russel discussed “Incident Management through Playbook Creation & Automation in SOAR”. He emphasized that Incident Management (IM) helps quickly restore business operations after security incidents, identifiable by signs like unusual traffic, system failures, unauthorized changes, and suspicious activities. With SOAR (Security Orchestration, Automation, and Response), organizations can automate tasks using playbooks, improve threat hunting, manage incidents with tickets, and connect to threat intelligence sources like VirusTotal and MISP. SOAR’s architecture, combining tools like Wazuh and EITIx, allows for log collection, correlation, ticketing, and reporting. In summary, SOAR improves incident management speed, consistency, visibility, efficiency in alert handling, and compliance support.

Alin Boby, head of IT Security at Janata Bank PLC, talked about “HNDL: emerging security threats,” a new cybersecurity issue. He said, Harvest Now, Decrypt Later (HNDL) is gaining global attention.” This tactic involves intercepting and saving encrypted data now to decrypt it later, using quantum computing. Current encryption methods are safe from classical computers, but Q-Day, when quantum algorithms like Shor’s can crack RSA, ECC, and Diffie-Hellman, could put decades of sensitive data at risk.

Countries like China, Russia, the US, UK, Iran, and North Korea, along with organized crime groups, are already involved in HNDL activities. Their targets include TLS/VPN traffic, cloud storage, backups, emails, and code-signing systems. Industries at highest risk are finance, healthcare, government/defense, and corporate IP, where long-term confidentiality matters.

Experts warn that the convergence of quantum decryption and AI will create a “perfect storm” for cybersecurity, enabling more advanced spear phishing, ransomware, and disinformation attacks. The long-term impacts include severe legal, financial, and reputational damage, often striking years after the initial data theft.

To reduce these risks, organizations should consider using Post-Quantum Cryptography (PQC), combine encryption methods, improve key management practices, protect backups with quantum-safe algorithms, and exchange threat information across industries. As experts stress: prepare today, or pay tomorrow — quantum decryption waits for no one.

SafeLine: A Free Zero Trust Web Application Firewall for 2026

 

 

.

Check Also

National Cyber Drill 2026

NCSA opens registration for “National Cyber Drill- 2026”

National Cyber Security Agency (NCSA), under the Information and Communication Technology Division of Bangladesh, has …