Educate, Empower, Secure: Building a Cyber-safe Bhutan
Services We Provide
Bhutan Computer Incident Response Team (BtCIRT) is a part of the Government Technology Agency (GovTech). The BtCIRT is mandated to enhance cyber security in Bhutan by facilitating collaboration and information exchange among stakeholders, rendering assistance in capacity building and through sustained advocacy in computer security. Click here to learn more
Incident
Analysis
Security Event
Monitoring
Security
Awareness
Report Cybersecurity Incident
BtCIRT encourages the reporting of cybersecurity incidents as it enables us to better understand the scope and nature of cyber incidents in Bhutan. This will enable us to issue alerts or advisories on relevant threats, and assist a broader range of individuals and organisations.
Advisories
Critical Authentication Bypass in Proxmox Virtual Environment 7.x and 8.0 (CVE-2023-54391) – 20260902007
September 3, 2026
No Comments
Severity CRITICAL Threat Category Vulnerability – Authentication Bypass (CWE-304) Affected Platforms Proxmox Virtual Environment 7.0 – 7.4 and 8.0 with libpve-access-control 7.0-7 through 8.0.3 (all ...
Read More →
Critical Keycloak Account Takeover Vulnerability (CVE-2026-18963) – 20260828006
August 28, 2026
No Comments
Severity CRITICAL Threat Category Vulnerability – Authentication Bypass/ Account Takeover Affected Platforms Keycloak 26.4.x (before 26.4.15), 26.6.x (before 26.6.6), 26.7.x (before 26.7.2); Red Hat Build ...
Read More →
Critical GeoServer SQL Injection Vulnerability: 20260824005
August 24, 2026
No Comments
Severity CRITICAL Threat Category Vulnerability (SQL Injection, Potential Remote Code Execution) Affected Platforms GeoServer Application versions < 2.27.6, < 2.28.5, and < 3.0.1.GeoTools Core Library: ...
Read More →
Veeam ONE 13 — Remote Unauthenticated Code Execution: 20260807004
August 7, 2026
No Comments
Severity CRITICAL Threat Category Vulnerability (Remote Unauthenticated Code Execution) Affected Platforms Veeam ONE (versions 13.0.2.6723 and earlier Version 13 builds) CVE NVD – CVE-2026-64633 CVSS ...
Read More →
Critical vulnerability in WordPress Core : 20260729003
July 29, 2026
No Comments
Critical “wp2shell” REST API Route Confusion and SQL Injection Vulnerabilities in WordPress Core Severity CRITICAL (CVSS 10.0) Threat Category Vulnerability / Remote Code Execution (RCE) ...
Read More →
Active Global Malware Campaign Abusing Compromised WhatsApp Accounts: 20260706002
July 6, 2026
No Comments
Active Global Malware Campaign Abusing Compromised WhatsApp Accounts to Distribute Malicious VBScript FilesAdd Your Heading Text Here Severity HIGH Threat Category Malware / Social Engineering ...
Read More →
Global Cyber Security News
-
OpenLeash Adds a Human Check to Risky AI Agent Actions
Date: 03-09-26 By Kevin Townsend
-
UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure
Date: 02-09-26 By Kevin Townsend
-
Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products
Date: 02-09-26 By Eduard Kovacs
-
Exploit Published for Fresh Cleo Harmony Vulnerability
Date: 02-09-26 By Ionut Arghire
-
Anthropic Details Response to Security Incidents, Unveils Enterprise Safeguards
Date: 02-09-26 By Eduard Kovacs
Vulnerability Notification
-
VU#889462: Casdoor authentication server is vulnerable to authorization bypass
Published on: 03-09-26
-
VU#456290: Hugging Face Transformers library writes remote code to disk prior to consent check
Published on: 01-09-26
-
VU#308749: Remote Code Execution and Arbitrary File Read Vulnerabilities in Kaltura Servers
Published on: 25-08-26
-
VU#728712: Konami's Metal Gear Online 3 contains a heap-based buffer overflow
Published on: 24-08-26
-
VU#756733: Calix GS7 XGS GS5239XG residential router contains missing authentication vulnerability
Published on: 21-08-26
Publications
REQUEST for EXPRESSION OF INTEREST(REoI) FOR (CONSULTING SERVICES – FIRMS SELECTION)
January 29, 2026
No Comments
The GovTech Agency would like to invite eligible and interested Consulting Firms for the National Cybersecurity Risk Assessment deployment. Interested firms can submit Expression of ...
Read More →
17thDecember related Scams Alert
December 11, 2025
No Comments
The Bhutan Computer Incident Response Team (BtCIRT), Cybersecurity Division GovTech Agency earnestly urges the general public to remain vigilant and avoid falling victim to National ...
Read More →
Cyber Security Awareness
January 25, 2025
No Comments
Cyber Security Awareness Program The Department of Information Technology and Telecom, in its efforts to help promote conducive and safer cyber environment for work and ...
Read More →
National Cybersecurity Strategy of Bhutan
October 30, 2024
No Comments
The Published National Cybersecurity Strategy of Bhutan for the year 2024 to 2029
Read More →
