Bhutan Computer Incident Response Team
btcirt.bt
Imported from official source
Government body in Bhutan; cybersecurity publications from its own official source.
Publications 10
-
Unauthenticated Stored Cross-Site Scripting in WPS Limit Login WordPress Plugin (CVE-2026-93622) – 2026092808
Severity HIGH Threat Category Vulnerability – Stored Cross-Site Scripting (CWE-79) Affected Platforms WordPress sites running the WPS Limit Login plugin […] The post Unauthenticated Stored Cross-Si...
Announcement -
Critical Authentication Bypass in Proxmox Virtual Environment 7.x and 8.0 (CVE-2023-54391) – 20260902007
Severity CRITICAL Threat Category Vulnerability – Authentication Bypass (CWE-304) Affected Platforms Proxmox Virtual Environment 7.0 – 7.4 and 8.0 with […] The post Critical Authentication Bypass i...
Announcement -
Critical Keycloak Account Takeover Vulnerability (CVE-2026-18963) – 20260828006
Severity CRITICAL Threat Category Vulnerability – Authentication Bypass/ Account Takeover Affected Platforms Keycloak 26.4.x (before 26.4.15), 26.6.x (before 26.6.6), 26.7.x […] The post Crit...
Announcement -
Critical GeoServer SQL Injection Vulnerability: 20260824005
Severity CRITICAL Threat Category Vulnerability (SQL Injection, Potential Remote Code Execution) Affected Platforms GeoServer Application versions < 2.27.6, < 2.28.5, […] The post Critical Ge...
Announcement -
Veeam ONE 13 — Remote Unauthenticated Code Execution: 20260807004
Severity CRITICAL Threat Category Vulnerability (Remote Unauthenticated Code Execution) Affected Platforms Veeam ONE (versions 13.0.2.6723 and earlier Version 13 builds) […] The post Veeam ONE 13 —...
Announcement -
Critical vulnerability in WordPress Core : 20260729003
Critical “wp2shell” REST API Route Confusion and SQL Injection Vulnerabilities in WordPress Core Severity CRITICAL (CVSS 10.0) Threat Category Vulnerability […] The post Critical vulnerability in W...
Announcement -
Active Global Malware Campaign Abusing Compromised WhatsApp Accounts: 20260706002
Active Global Malware Campaign Abusing Compromised WhatsApp Accounts to Distribute Malicious VBScript FilesAdd Your Heading Text Here Severity HIGH Threat […] The post Active Global Malware Campaig...
Announcement -
Apache HTTP/2 Flaw: 20260507001
Critical “mod_http2” Denial of Service and Remote Code Execution Vulnerability in Apache HTTP Server Severity CRITICAL (CVSS ~9.8–10.0, depending on […] The post Apache HTTP/2 Flaw: 20260507001 fir...
Announcement -
Fake Telegram Channel Alert
Fake Telegram Channel Alert The Bhutan Computer Incident Response Team (BtCIRT), Cybersecurity Division, GovTech Agency, earnestly urges the general public […] The post Fake Telegram Channel Alert ...
Announcement -
Security Advisory on supply chain attack targeting axios javascript package
A recent supply chain attack involving the widely used axios library has raised significant security concerns across the JavaScript ecosystem. […] The post Security Advisory on supply chain attack ...
Announcement