Malaysia-focused intelligence publication

Malaysia scam alerts and cybersecurity intelligence.

Know what happened and what to do next. We verify Malaysian scam and cybersecurity developments against official sources, then explain the impact, evidence and practical steps clearly.

Public sections

Intelligence for consumers and SMEs

Every published item answers what happened, why it matters, who is affected, what to do and what remains unknown.

Latest published intelligence

Recently checked alerts and briefings

Scam Intelligence Verified Officially confirmed

MA-1480.082026: MyCERT Advisory - Malicious Fake Park@Perak Parking Website Targeting iPhone Users

MyCERT is observing an active campaign in which a fake clone of a Malaysian state parking portal is being used as a silent delivery front for a multi-stage iOS exploit chain. The site in question, parkpeark[.]xyz, is a fake site made to look exactly like the real Park@Perak service at park.perak.my. It was registered on 25 August 2026. Figure 1: Screenshot of the fake Park@Perak site at parkpeark[.]xyz. It looks identical to the genuine portal. The only reliable difference is the web address. Always check that you are on park.perak.my.Unlike ordinary phishing sites, this page asks the visitor for nothing. There is no login form, no payment page, and no application to download. A hidden, zero-size frame injected into the first line of the site's home page silently loads an exploit chain hosted on separate infrastructure. On a targeted iPhone, simply opening the page in Safari is enough to compromise the device. No tapping, typing, installation, or permission prompt is involved. Where the chain succeeds, it runs the attacker's own code inside Safari, escapes the browser's protective sandbox, raises its privileges to system level, and installs a command-and-control implant that keeps running on the device until it is restarted.

Checked 16 Sep 2026 1 evidence record View alert
Scam Intelligence Verified Officially confirmed

#BeSmartStayAlert #LetsFightScammerTogether [POSTING PILIHAN] SCAM ALERT: JANGAN JADI KELDAI AKAUN

Akaun bank yang didaftarkan atas nama anda merupakan tanggungjawab anda sepenuhnya. Jangan sesekali membenarkan akaun atau kemudahan perbankan anda digunakan oleh individu lain kerana tindakan tersebut boleh dieksploitasi oleh sindiket jenayah bagi menjalankan aktiviti haram. Penyalahgunaan akaun bank bukan sahaja membuka ruang kepada aktiviti jenayah, malah boleh menyebabkan pemilik akaun disiasat, didakwa di mahkamah dan dikenakan tindakan undang-undang. Ikuti infografik yang disediakan oleh Jabatan Siasatan Jenayah Komersil Kontinjen Selangor sebagai panduan untuk mengenali modus operandi sindiket keldai akaun dan langkah melindungi diri. Sumber: Jabatan Siasatan Jenayah Komersil Kontinjen Selangor

Checked 09 Sep 2026 1 evidence record View alert
Cyber Alerts Verified Officially confirmed

Barracuda Email Security Gateway (ESG) Zero Day Vulnerability

National Cyber Coordination and Command Centre (NC4) is aware of active exploitation on Barracuda Email Security Gateway (ESG) vulnerabilities that could allow an attacker to gain control of an affected system, install backdoors and exfiltrate data. The impact of these vulnerabilities is critical as it was observed can be utilised as vector for espionage activities.

Checked 16 Sep 2026 1 evidence record View alert
Cyber Alerts Verified Officially confirmed

Heightened Alert for Cyber Activities on Domains and Infrastructures in Malaysia

In light of recent developments in the Middle East, the National Cyber Coordination and Command Centre (NC4) is closely monitoring the cyber campaign centred around this conflict. Multiple hacktivists have reportedly gathered and launched cyber attacks, which, based on historical data, include web defacement, document leaks, and distributed denial of service (DDOS) attacks. NC4 would like to remind System Administrators and Network Administrators to implement adequate cyber security measures to ensure systems and networks are always secure.

Checked 15 Sep 2026 2 evidence records View alert
Cyber Alerts Verified Officially confirmed

New Petya Ransomware Variant Advisory

On June 27 2017, multiple organisations globally had reported of disruptions attributing to ransomware. Based on initial information received, a variant of Petya ransomware may be responsible for the incidents. National Cyber Coordination and Command Centre is currently monitoring closely for any signs of infection or propagation in Malaysia.

Checked 15 Sep 2026 1 evidence record View alert
Cyber Alerts Verified Officially confirmed

Bad Rabbit Ransomware - Technical Analysis

On Oct 24, 2017, a few organisation in Ukraine, Russia, Turkey and Germany had reported of disruptions attributing to ransomware. Based on initial information received, a new variant of WannaCry and NotPetya ransomware known as Bad Rabbit are responsible for the incidents. Further analysis of the ransomware has been carried out and details of the ransomware is explained below. National Cyber Coordination and Command Centre is currently monitoring closely for any signs of infection or propagation in Malaysia.

Checked 15 Sep 2026 1 evidence record View alert
Cyber Alerts Verified Officially confirmed

CPU Hardware Security Vulnerability Alert

National Cyber Coordination and Command Centre (NC4) is aware of recent revelation of security vulnerabilities in processors that can be exploited to gather sensitive data from computing devices.

Checked 15 Sep 2026 1 evidence record View alert

View all published intelligence

For consumers

Clear protective steps

Understand scam approaches, affected services, official reporting channels and the limits of what is currently known.

For SMEs

Actionable cyber guidance

See affected software, exploitation status, patch sources and operational steps without wading through raw advisories.