Educate, Empower, Secure: Building a Cyber-safe Bhutan
Services We Provide
Bhutan Computer Incident Response Team (BtCIRT) is a part of the Government Technology Agency (GovTech). The BtCIRT is mandated to enhance cyber security in Bhutan by facilitating collaboration and information exchange among stakeholders, rendering assistance in capacity building and through sustained advocacy in computer security. Click here to learn more
Incident
Analysis
Security Event
Monitoring
Security
Awareness
Report Cybersecurity Incident
BtCIRT encourages the reporting of cybersecurity incidents as it enables us to better understand the scope and nature of cyber incidents in Bhutan. This will enable us to issue alerts or advisories on relevant threats, and assist a broader range of individuals and organisations.
Advisories
Unauthenticated Stored Cross-Site Scripting in WPS Limit Login WordPress Plugin (CVE-2026-93622) – 2026092808
October 1, 2026
No Comments
Severity HIGH Threat Category Vulnerability – Stored Cross-Site Scripting (CWE-79) Affected Platforms WordPress sites running the WPS Limit Login plugin (by NicolasKulka), all versions up ...
Read More →
Critical Authentication Bypass in Proxmox Virtual Environment 7.x and 8.0 (CVE-2023-54391) – 20260902007
September 3, 2026
No Comments
Severity CRITICAL Threat Category Vulnerability – Authentication Bypass (CWE-304) Affected Platforms Proxmox Virtual Environment 7.0 – 7.4 and 8.0 with libpve-access-control 7.0-7 through 8.0.3 (all ...
Read More →
Critical Keycloak Account Takeover Vulnerability (CVE-2026-18963) – 20260828006
August 28, 2026
No Comments
Severity CRITICAL Threat Category Vulnerability – Authentication Bypass/ Account Takeover Affected Platforms Keycloak 26.4.x (before 26.4.15), 26.6.x (before 26.6.6), 26.7.x (before 26.7.2); Red Hat Build ...
Read More →
Critical GeoServer SQL Injection Vulnerability: 20260824005
August 24, 2026
No Comments
Severity CRITICAL Threat Category Vulnerability (SQL Injection, Potential Remote Code Execution) Affected Platforms GeoServer Application versions < 2.27.6, < 2.28.5, and < 3.0.1.GeoTools Core Library: ...
Read More →
Veeam ONE 13 — Remote Unauthenticated Code Execution: 20260807004
August 7, 2026
No Comments
Severity CRITICAL Threat Category Vulnerability (Remote Unauthenticated Code Execution) Affected Platforms Veeam ONE (versions 13.0.2.6723 and earlier Version 13 builds) CVE NVD – CVE-2026-64633 CVSS ...
Read More →
Critical vulnerability in WordPress Core : 20260729003
July 29, 2026
No Comments
Critical “wp2shell” REST API Route Confusion and SQL Injection Vulnerabilities in WordPress Core Severity CRITICAL (CVSS 10.0) Threat Category Vulnerability / Remote Code Execution (RCE) ...
Read More →
Global Cyber Security News
-
AI Has Changed Attack Speed, Not Security Fundamentals
Date: 01-10-26 By Joshua Goldfarb
-
Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure
Date: 01-10-26 By Ionut Arghire
-
Kevin Mandia’s Armadin Raises $255 Million at $2.5 Billion Valuation
Date: 01-10-26 By Mike Lennon
-
Treasury Blacklists Most-Wanted ATM Malware Developer and His Network
Date: 01-10-26 By Eduard Kovacs
-
Zammad Zero-Days Exploited in AI-Powered DIVD Hack
Date: 01-10-26 By Ionut Arghire
Vulnerability Notification
-
VU#553437: InsydeH2O IHISI SMM is vulnerable to unsafe memory write operations
Published on: 01-10-26
-
VU#762428: Authlib library contains a signature‑verification bypass vulnerability
Published on: 29-09-26
-
VU#699627: Readwise Reader for Android, version 8.7.2, contains multiple XSS vulnerabilities
Published on: 25-09-26
-
VU#234131: ViewSonic vCast media streaming service allows unauthenticated screen exfiltration and device compromise
Published on: 25-09-26
-
VU#676317: Norwegian Cruise Line door access controller contains an improper authentication vulnerability
Published on: 24-09-26
Publications
REQUEST for EXPRESSION OF INTEREST(REoI) FOR (CONSULTING SERVICES – FIRMS SELECTION)
January 29, 2026
No Comments
The GovTech Agency would like to invite eligible and interested Consulting Firms for the National Cybersecurity Risk Assessment deployment. Interested firms can submit Expression of ...
Read More →
17thDecember related Scams Alert
December 11, 2025
No Comments
The Bhutan Computer Incident Response Team (BtCIRT), Cybersecurity Division GovTech Agency earnestly urges the general public to remain vigilant and avoid falling victim to National ...
Read More →
Cyber Security Awareness
January 25, 2025
No Comments
Cyber Security Awareness Program The Department of Information Technology and Telecom, in its efforts to help promote conducive and safer cyber environment for work and ...
Read More →
National Cybersecurity Strategy of Bhutan
October 30, 2024
No Comments
The Published National Cybersecurity Strategy of Bhutan for the year 2024 to 2029
Read More →
