Today, we welcome the 43rd government onboarded to Have I Been Pwned's free gov service, Bangladesh. The BGD e-GOV CIRT department now has full access to query all their government domains via API, and monitor them against future breaches.

The government of Bangladesh has joined a growing list of nations utilizing the Have I Been Pwned (HIBP) service to enhance its cybersecurity posture. The BGD e-GOV CIRT department has been granted full access to HIBP's free government service, enabling them to monitor their official domains against data breaches.
This partnership allows the Bangladeshi government to proactively identify if any of its domains have been compromised in past data breaches. The access is provided via an API, which facilitates automated querying and continuous monitoring.
By leveraging HIBP's extensive database of compromised credentials and data, the BGD e-GOV CIRT can now assess the risk associated with their online presence. This includes checking for instances where government email addresses or associated data may have appeared in publicly known breaches.
The service is designed to assist government agencies in understanding their exposure to data breaches and to take necessary steps to mitigate potential risks. This proactive approach is crucial in protecting sensitive government information and citizen data from malicious actors.
Bangladesh is the 43rd government to adopt this HIBP initiative, highlighting a global trend towards utilizing specialized cybersecurity tools to combat the ever-present threat of data breaches. The collaboration underscores the importance of international cooperation and the adoption of best practices in cybersecurity.
The BGD e-GOV CIRT department can now use the API to integrate HIBP's breach data into their existing security workflows. This allows for more efficient and effective monitoring of government digital assets.
The free government service offered by Have I Been Pwned aims to provide a valuable resource for national cybersecurity centers. It empowers them with the tools to identify vulnerabilities and respond to potential security incidents more effectively.
This integration is expected to bolster the security of Bangladesh's digital infrastructure and contribute to a safer online environment for its citizens and government operations.

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.