Linux Kernel Unspecified Vulnerability (CVE-2026-53362)
Several security issues were fixed in the Linux kernel.
Daily monitoring
Published Malaysian scam and cybersecurity developments supported by official or authoritative evidence.
Confirmed Malaysian scam developments, official warnings and what consumers should do next.
Open section → Cyber AlertsActionable vulnerability and active-exploitation alerts supported by authoritative records.
Open section → Breaches and IncidentsConfirmed breaches and security incidents, who is affected and what remains unknown.
Open section → Regulation and EnforcementMalaysian regulatory, enforcement and public-safety developments explained clearly.
Open section → Practical GuidesPractical steps drawn from authorities, affected organisations and official vendor guidance.
Open section → Daily/Weekly BriefingsDaily monitoring roundups and weekly action briefings for Malaysian consumers and SMEs.
Open section → Community DiscussionDiscuss published alerts, ask questions and suggest official sources. Submissions are not treated as evidence.
Open discussion →Published only
Several security issues were fixed in the Linux kernel.
MyCERT is observing an active campaign in which a fake clone of a Malaysian state parking portal is being used as a silent delivery front for a multi-stage iOS exploit chain. The site in question, parkpeark[.]xyz, is a fake site made to look exactly like the real Park@Perak service at park.perak.my. It was registered on 25 August 2026. Figure 1: Screenshot of the fake Park@Perak site at parkpeark[.]xyz. It looks identical to the genuine portal. The only reliable difference is the web address. Always check that you are on park.perak.my.Unlike ordinary phishing sites, this page asks the visitor for nothing. There is no login form, no payment page, and no application to download. A hidden, zero-size frame injected into the first line of the site's home page silently loads an exploit chain hosted on separate infrastructure. On a targeted iPhone, simply opening the page in Safari is enough to compromise the device. No tapping, typing, installation, or permission prompt is involved. Where the chain succeeds, it runs the attacker's own code inside Safari, escapes the browser's protective sandbox, raises its privileges to system level, and installs a command-and-control implant that keeps running on the device until it is restarted.
Akaun bank yang didaftarkan atas nama anda merupakan tanggungjawab anda sepenuhnya. Jangan sesekali membenarkan akaun atau kemudahan perbankan anda digunakan oleh individu lain kerana tindakan tersebut boleh dieksploitasi oleh sindiket jenayah bagi menjalankan aktiviti haram. Penyalahgunaan akaun bank bukan sahaja membuka ruang kepada aktiviti jenayah, malah boleh menyebabkan pemilik akaun disiasat, didakwa di mahkamah dan dikenakan tindakan undang-undang. Ikuti infografik yang disediakan oleh Jabatan Siasatan Jenayah Komersil Kontinjen Selangor sebagai panduan untuk mengenali modus operandi sindiket keldai akaun dan langkah melindungi diri. Sumber: Jabatan Siasatan Jenayah Komersil Kontinjen Selangor
National Cyber Coordination and Command Centre (NC4) is aware of active exploitation on Barracuda Email Security Gateway (ESG) vulnerabilities that could allow an attacker to gain control of an affected system, install backdoors and exfiltrate data. The impact of these vulnerabilities is critical as it was observed can be utilised as vector for espionage activities.
In light of recent developments in the Middle East, the National Cyber Coordination and Command Centre (NC4) is closely monitoring the cyber campaign centred around this conflict. Multiple hacktivists have reportedly gathered and launched cyber attacks, which, based on historical data, include web defacement, document leaks, and distributed denial of service (DDOS) attacks. NC4 would like to remind System Administrators and Network Administrators to implement adequate cyber security measures to ensure systems and networks are always secure.
On June 27 2017, multiple organisations globally had reported of disruptions attributing to ransomware. Based on initial information received, a variant of Petya ransomware may be responsible for the incidents. National Cyber Coordination and Command Centre is currently monitoring closely for any signs of infection or propagation in Malaysia.
On Oct 24, 2017, a few organisation in Ukraine, Russia, Turkey and Germany had reported of disruptions attributing to ransomware. Based on initial information received, a new variant of WannaCry and NotPetya ransomware known as Bad Rabbit are responsible for the incidents. Further analysis of the ransomware has been carried out and details of the ransomware is explained below. National Cyber Coordination and Command Centre is currently monitoring closely for any signs of infection or propagation in Malaysia.
National Cyber Coordination and Command Centre (NC4) is aware of recent revelation of security vulnerabilities in processors that can be exploited to gather sensitive data from computing devices.
National Cyber Coordination and Command Centre (NC4) and MyCERT has received numerous reports of smartphones users being infected with malware through a phishing campaign involving Bank Negara Malaysia (BNM).
National Cyber Cyber Security Agency (NACSA) has detected various attack attempts targeting numerous organisations in Malaysia recently. The type of attacks detected varies; including Intrusion, Intrusion Attempts, Distributed Denial of Service (DDoS), Web Defacement and Malware Infections.
Security researcher at CISCO's Talos Intelligence has discovered an advanced widespread use of a sophisticated modular malware system called "VPNFilter".
National Cyber Security Agency (NACSA) is aware of the recent incidents of data breaches involving personal data of citizens in this region.