Advisories by BGD e-GOV CIRT

Post Image
Axios NPM Package Compromise Deploying RAT Affecting Node.js Environments
In this incident, attackers gained unauthorized access to the npm maintainer account and published malicious versions of the Axios package containing ....
01-Apr-2026 16:00:00
Read Details
Post Image
Nymaim or Avalanche-Nymaim Loader Malware Activity Detected in Bangladesh
Nymaim is a multi-stage malware loader historically used to distribute banking trojans, ransomware, and credential-stealing malware. It was closely as....
01-Apr-2026 11:25:00
Read Details
Post Image
Exposure of End-of-Life Microsoft IIS Servers in Bangladesh
BGD e-GOV CIRT strongly recommends that every organization in Bangladesh using Microsoft IIS immediately inventory their systems, isolate exposed serv....
24-Mar-2026 14:00:00
Read Details
Post Image
Critical Vulnerability in n8n (CVE-2026-21858) affects Hosts in Bangladesh
A critical unauthenticated remote code execution (RCE) vulnerability, tracked as CVE-2026- 21858 and dubbed "Ni8mare," has been identified in n8n, an ....
11-Jan-2026 16:00:00
Read Details
Post Image
MongoBleed Vulnerability (CVE-2025-14847) Exposes MongoDB Instances in Bangladesh
A nationwide assessment identified 80 internet-exposed MongoDB database instances in Bangladesh that are improperly secured or misconfigured and runni....
01-Jan-2026 16:00:00
Read Details
Post Image
Critical Remote Code Execution Vulnerability in React Server Components (CVE-2025-55182)
A CVE-2025-55182 is a critical, unauthenticated remote code execution (RCE) in React Server Components (RSC) that can allow attackers to execute arbit....
04-Dec-2025 16:00:00
Read Details