Linux Kernel Unspecified Vulnerability (CVE-2026-53362)
Several security issues were fixed in the Linux kernel.
Malaysia-focused intelligence publication
Know what happened and what to do next. We verify Malaysian scam and cybersecurity developments against official sources, then explain the impact, evidence and practical steps clearly.
Public sections
Every published item answers what happened, why it matters, who is affected, what to do and what remains unknown.
Confirmed Malaysian scam developments, official warnings and what consumers should do next.
View section → Cyber AlertsActionable vulnerability and active-exploitation alerts supported by authoritative records.
View section → Breaches and IncidentsConfirmed breaches and security incidents, who is affected and what remains unknown.
View section → Regulation and EnforcementMalaysian regulatory, enforcement and public-safety developments explained clearly.
View section → Practical GuidesPractical steps drawn from authorities, affected organisations and official vendor guidance.
View section → Daily/Weekly BriefingsDaily monitoring roundups and weekly action briefings for Malaysian consumers and SMEs.
View section → Community DiscussionDiscuss published alerts, ask questions and suggest official sources without turning accusations into evidence.
Join the discussion →Latest published intelligence
Several security issues were fixed in the Linux kernel.
MyCERT is observing an active campaign in which a fake clone of a Malaysian state parking portal is being used as a silent delivery front for a multi-stage iOS exploit chain. The site in question, parkpeark[.]xyz, is a fake site made to look exactly like the real Park@Perak service at park.perak.my. It was registered on 25 August 2026. Figure 1: Screenshot of the fake Park@Perak site at parkpeark[.]xyz. It looks identical to the genuine portal. The only reliable difference is the web address. Always check that you are on park.perak.my.Unlike ordinary phishing sites, this page asks the visitor for nothing. There is no login form, no payment page, and no application to download. A hidden, zero-size frame injected into the first line of the site's home page silently loads an exploit chain hosted on separate infrastructure. On a targeted iPhone, simply opening the page in Safari is enough to compromise the device. No tapping, typing, installation, or permission prompt is involved. Where the chain succeeds, it runs the attacker's own code inside Safari, escapes the browser's protective sandbox, raises its privileges to system level, and installs a command-and-control implant that keeps running on the device until it is restarted.
Akaun bank yang didaftarkan atas nama anda merupakan tanggungjawab anda sepenuhnya. Jangan sesekali membenarkan akaun atau kemudahan perbankan anda digunakan oleh individu lain kerana tindakan tersebut boleh dieksploitasi oleh sindiket jenayah bagi menjalankan aktiviti haram. Penyalahgunaan akaun bank bukan sahaja membuka ruang kepada aktiviti jenayah, malah boleh menyebabkan pemilik akaun disiasat, didakwa di mahkamah dan dikenakan tindakan undang-undang. Ikuti infografik yang disediakan oleh Jabatan Siasatan Jenayah Komersil Kontinjen Selangor sebagai panduan untuk mengenali modus operandi sindiket keldai akaun dan langkah melindungi diri. Sumber: Jabatan Siasatan Jenayah Komersil Kontinjen Selangor
National Cyber Coordination and Command Centre (NC4) is aware of active exploitation on Barracuda Email Security Gateway (ESG) vulnerabilities that could allow an attacker to gain control of an affected system, install backdoors and exfiltrate data. The impact of these vulnerabilities is critical as it was observed can be utilised as vector for espionage activities.
In light of recent developments in the Middle East, the National Cyber Coordination and Command Centre (NC4) is closely monitoring the cyber campaign centred around this conflict. Multiple hacktivists have reportedly gathered and launched cyber attacks, which, based on historical data, include web defacement, document leaks, and distributed denial of service (DDOS) attacks. NC4 would like to remind System Administrators and Network Administrators to implement adequate cyber security measures to ensure systems and networks are always secure.
On June 27 2017, multiple organisations globally had reported of disruptions attributing to ransomware. Based on initial information received, a variant of Petya ransomware may be responsible for the incidents. National Cyber Coordination and Command Centre is currently monitoring closely for any signs of infection or propagation in Malaysia.
On Oct 24, 2017, a few organisation in Ukraine, Russia, Turkey and Germany had reported of disruptions attributing to ransomware. Based on initial information received, a new variant of WannaCry and NotPetya ransomware known as Bad Rabbit are responsible for the incidents. Further analysis of the ransomware has been carried out and details of the ransomware is explained below. National Cyber Coordination and Command Centre is currently monitoring closely for any signs of infection or propagation in Malaysia.
National Cyber Coordination and Command Centre (NC4) is aware of recent revelation of security vulnerabilities in processors that can be exploited to gather sensitive data from computing devices.
For consumers
Understand scam approaches, affected services, official reporting channels and the limits of what is currently known.
For SMEs
See affected software, exploitation status, patch sources and operational steps without wading through raw advisories.