Resources

New Advisory: (Critical) FortiOS Vulnerability

ⓘ This advisory addresses a critical vulnerability impacting FortiOS systems (CVE-2024-55591). Attention constituent:  A critical vulnerability (CVE-2024-55591) has been identified in Fortinet’s FortiOS systems. This vulnerability stems from an authentication

Read More »

New Advisory: Fake Investment Scams Using Deepfake Videos

ⓘ This advisory addresses fake investment scams. CIRT-BS is urging the public to stay vigilant as new scams circulate online and fraudulent websites are impersonating local media houses to promote a fake investment opportunity linked to Central Bank of The Bahamas. To boost credibility and traffic, the scammers are using artificial intelligence to generate “deepfake” videos of various news personalities as well as Central Bank

Read More »

New Advisory: Active Exploitation of Ivanti Vulnerabilities

ⓘ Attackers are targeting Ivanti Connect Secure appliances using known vulnerabilities. Attackers may sometimes maintain persistent, undetected access even after patching systems. Advisory Overview  Advisory Type Technical Author Marcus Knowles Date 17 April 2025 Ivanti and CISA recently reported active exploitation of several critical vulnerabilities in Ivanti network access security appliances. UNC5221, a China-linked threat group, uses these vulnerabilities to break into networks, deploy custom

Read More »

New Advisory: Critical Exploitation of Known Fortinet Vulnerabilities

ⓘ We are reaching out to let you know about ongoing attacks targeting Fortinet devices using known vulnerabilities. In some cases, the attackers can remain undetected even after patching. Attention constituent: Fortinet and CISA recently reported active exploitation of several known vulnerabilities in Fortinet devices. These include switches, firewalls, and other related products, many of which are widely used for secure remote access. Attackers are

Read More »

New Advisory: Critical Vulnerability Found in Remote Access VPNs

ⓘ Your system could be at risk of being affected by several CVEs targeting SSL VPNs. CIRT-BS is advising that unpatched VPN devices are being actively scanned for vulnerabilities. These include many widely used brands detailed below. The attacks are using previously breached credentials and brute force to bypass weak or misconfigured MFA to access devices and/or deploy ransomware. Advisory Overview Advisory Type Technical Author

Read More »

New Advisory: (Critical) Authentication Bypass Vulnerability (FortiOS, FortiProxy, and FortiSwitch Manager)

ⓘ This advisory addresses a critical vulnerability impacting FortiOS, FortiProxy, and FortiSwitchManager platforms. Attention constituent:  CVE-2022-40684 is a critical authentication bypass vulnerability impacting Fortinet’s FortiOS, FortiProxy, and FortiSwitchManager platforms. This flaw enables attackers to gain unauthorised administrative access, potentially leading to system compromise, data theft, and operational disruption. A leaked list of 15,000 vulnerable IP addresses has heightened the risk of exploitation. Immediate action is

Read More »

New Advisory: (Critical) FortiOS Vulnerability

ⓘ This advisory addresses a critical vulnerability impacting FortiOS systems (CVE-2024-55591). Attention constituent:  A critical vulnerability (CVE-2024-55591) has been identified in Fortinet’s FortiOS systems. This vulnerability stems from an authentication bypass flaw in the FortiOS web management interface. Exploitation of this vulnerability allows remote, unauthenticated attackers to gain unauthorised administrative access and execute arbitrary actions on affected systems. CVE: CVE-2024-55591 Severity: Critical (CVSS: 9.8) Affected Platforms: FortiOS systems

Read More »

WhatsApp Account Hijacking Scams Advisory

ⓘ This advisory addresses an increase in compromised WhatsApp accounts. Attention constituent:  CIRT-BS is advising members of the public to stay alert as a sophisticated scam targeting WhatsApp users is on the rise. Cybercriminals are hacking accounts and deceiving users’ friends and family into sending money by posing as trusted contacts. How the Scam Works Scammers make contact, sometimes with a WhatsApp call, and use fake

Read More »

CrowdStrike Update (Phishing Attempts)

ⓘ This advisory addresses new phishing attempts related to CrowdStrike’s Falcon sensor crash. Attention Constituents:  Since CrowdStrike deployed its international Falcon sensor fix last Friday, 19 July 2024, Crowd Strike Intelligence has identified that threat actors are leveraging this event for malicious purposes such as: Distributing a malicious zip file named “crowdstirke-hotfix.zip”; Establishing fraudulent domains to mimic CrowdStrike; Sending phishing emails posing as CrowdStrike support

Read More »

New Advisory: CrowdStrike Update Crashes Windows Systems Worldwide

ⓘ This advisory addresses a recent update to CrowdStrike’s Falcon sensor which has led to widespread Blue Screen of Death errors. Attention Microsoft service users:  A recent update to CrowdStrike’s Falcon sensor has led to widespread Blue Screen of Death (BSOD) errors on Windows hosts, resulting in disruptions locally to several services, including payment processing, and global disruptions. CrowdStrike has deployed a fix for this

Read More »
CIRT-BS Cyber Monday

The Deal on Cyber Monday

Cyber Monday is a great time to score on big deals; however, cyber criminals use this day to try to score big with your wallet and personal identifiable information as well. As you shop online, especially throughout the holiday season, remember these few tips: Before You Shop Enrol in payment alerts. Some card issuers offer payment alerts so you are always aware of your transactional

Read More »
Importance of Software Updates

Cybersecurity Awareness Month: The Truth About Software Updates

Those pesky updates. They’re annoying but so critical to do! While, at times, they may seem inconvenient, these updates ensure that your devices and apps remain protected from the latest threats. An Apple Example In 2019, Apple introduced a group FaceTime feature. Shortly after its release, a 14-year-old initiated a group call and discovered a major security flaw: they could eavesdrop on a call recipient

Read More »

Cybersecurity Awareness Month: Now That’s a Red Flag: Watch Out for Phish!

Did you know that one of the most common cyber attacks reported at the National CIRT originate from a phishing attempt that an unlucky victim fell for? This unfortunate fact reminds us why learning to recognise and report phishing attempts is critical. Below we list five red flags to look out for as you become more sensitive to phishing attempts. A message tone that is

Read More »

Cybersecurity Awareness Month: Enable MFA; Disable the Hackers

Last week, we kicked off Cybersecurity Awareness Month, detailing strong passwords as your first line of defence against a cyber attack; this week, we cover the second: multi-factor authentication (MFA). Multi-factor Authentication adds an extra layer of security by requiring two or more methods of verification to access your accounts. Rather than relying solely on a password, MFA can come in several forms. These include

Read More »

Cybersecurity Awareness Month: Use a Strong Password + a Password Manager

Cybersecurity professionals always say it, but it’s true: passwords are your first line of defence against data breaches. Because of this, it is crucial to make them strong and difficult to crack. Remember these three keys to make your passwords stronger: Make them long. The longer a password is, the more challenging to crack. CIRT-BS and other industry experts recommend passwords of 16 characters minimum.

Read More »
CIRT-BS Cybersecurity Awareness Month

Help Secure Our World this Cybersecurity Awareness Month 

Welcome to Cybersecurity Awareness Month, an international initiative that educates everyone about online safety and empowers individuals and organisations to protect their data from cybercrime. Amidst large-scale data breaches and cyber-attacks, Cybersecurity Awareness Month reminds us about simple, effective ways to remain safe online, protect personal data, and ultimately help secure our world. The National Computer Incident Response Team of The Bahamas (CIRT-BS) is proud

Read More »

Cash or Card? 10 Tips to Outsmart Card Fraud

In its 2022 Annual Report, the Bahamian monetary regulator, Central Bank of The Bahamas, reported over $15M in fraud complaints from debit and credit card users.[1] In many instances, better handling of financial cards could help to protect potential victims. This article shares ten practical but effective recommendations for protecting your financial accounts through your bank cards. (1) Invest in an RFID-blocking wallet to store

Read More »
Don't Get Reeled In! Recognising Different Types of Phishing Attacks

Don’t Get Reeled In! Recognising and Reporting Phishing

Have you ever received an email from a foreigner requesting financial assistance? How about a text message claiming you’ve won a particular prize for a competition you’ve never entered? In cybersecurity, these scams are commonly known as “phishing” attempts.   Believed to come from the term “phoney fishing,” the Internet Engineering Task Force defines phishing as a technique for attempting to acquire sensitive data (e.g.

Read More »
Spring Forward into Cyber Hygiene

Spring Forward into Cyber Hygiene

Remember that time changes this Sunday! We move forward one hour. As you take time to update your clocks and declutter your homes this weekend, CIRT-BS reminds you to ensure that your cyber hygiene is being taken care of, too!   Organise Your Files Clean folders make spotting malicious files and viruses easier.   Review Bank Statements Check for unauthorised transactions and query them.  

Read More »
Scroll to Top
Skip to content