LIVE · cybersecurity feed
Live wire
nation-state

Welcoming the Bhutanese Government to Have I Been Pwned

Today, we welcome the 45th government onboarded to Have I Been Pwned’s free gov service: Bhutan. The Bhutan Computer Incident Response Team, BtCIRT, now has access to monitor Bhutanese government domains against the data in HIBP. As Bhutan’

zeroday.news · 68d ago

The government of Bhutan has joined Have I Been Pwned's (HIBP) free service for government entities, the 45th such organization to do so. The Bhutan Computer Incident Response Team (BtCIRT) will now utilize HIBP's capabilities to monitor Bhutanese government domains for potential data breaches.

This partnership grants BtCIRT access to HIBP's extensive database, which contains information on compromised data from numerous breaches. By leveraging this resource, the Bhutanese cybersecurity agency can proactively identify if any government domains or associated data have been exposed in past security incidents.

The HIBP service for governments is designed to provide national cybersecurity agencies with tools to assess their digital exposure. This allows them to better understand the risks associated with publicly accessible data and to take necessary steps to protect citizens and government infrastructure.

By integrating with HIBP, BtCIRT can receive notifications or conduct searches to determine if specific government-related email addresses or domains appear in known data breaches. This information is crucial for incident response and for implementing targeted security measures.

The inclusion of Bhutan signifies a growing global recognition of the importance of proactive threat intelligence and breach monitoring for government entities. Many nations are increasingly adopting such services to bolster their cybersecurity defenses against evolving threats.

While specific details of the integration process or the types of data being monitored were not provided, the core function involves checking for the presence of government domain information within HIBP's breach data. This allows for an assessment of past compromises that might still pose a risk.

The availability of HIBP's services to government bodies underscores the platform's commitment to assisting organizations in managing their digital security posture. This is particularly relevant in an era where data breaches can have far-reaching consequences for national security and public trust.

The Bhutanese government's adoption of this service is a step towards enhancing its cybersecurity resilience. It allows for a more informed approach to identifying and mitigating risks stemming from compromised data, thereby contributing to a safer digital environment for the nation.

nation-state
ShareXLinkedInWhatsAppFacebook

More News

view all →
malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.