Daily monitoring

All Intelligence

Published Malaysian scam and cybersecurity developments supported by official or authoritative evidence.

Monitored dailyPublication requires deterministic evidence gates.
Scam Intelligence

Confirmed Malaysian scam developments, official warnings and what consumers should do next.

Open section →
Cyber Alerts

Actionable vulnerability and active-exploitation alerts supported by authoritative records.

Open section →
Breaches and Incidents

Confirmed breaches and security incidents, who is affected and what remains unknown.

Open section →
Regulation and Enforcement

Malaysian regulatory, enforcement and public-safety developments explained clearly.

Open section →
Practical Guides

Practical steps drawn from authorities, affected organisations and official vendor guidance.

Open section →
Daily/Weekly Briefings

Daily monitoring roundups and weekly action briefings for Malaysian consumers and SMEs.

Open section →
Community Discussion

Discuss published alerts, ask questions and suggest official sources. Submissions are not treated as evidence.

Open discussion →

Published only

Latest alerts and briefings

Scam Intelligence Verified Officially confirmed

MA-1480.082026: MyCERT Advisory - Malicious Fake Park@Perak Parking Website Targeting iPhone Users

MyCERT is observing an active campaign in which a fake clone of a Malaysian state parking portal is being used as a silent delivery front for a multi-stage iOS exploit chain. The site in question, parkpeark[.]xyz, is a fake site made to look exactly like the real Park@Perak service at park.perak.my. It was registered on 25 August 2026. Figure 1: Screenshot of the fake Park@Perak site at parkpeark[.]xyz. It looks identical to the genuine portal. The only reliable difference is the web address. Always check that you are on park.perak.my.Unlike ordinary phishing sites, this page asks the visitor for nothing. There is no login form, no payment page, and no application to download. A hidden, zero-size frame injected into the first line of the site's home page silently loads an exploit chain hosted on separate infrastructure. On a targeted iPhone, simply opening the page in Safari is enough to compromise the device. No tapping, typing, installation, or permission prompt is involved. Where the chain succeeds, it runs the attacker's own code inside Safari, escapes the browser's protective sandbox, raises its privileges to system level, and installs a command-and-control implant that keeps running on the device until it is restarted.

Checked 16 Sep 2026 1 evidence record View alert
Scam Intelligence Verified Officially confirmed

#BeSmartStayAlert #LetsFightScammerTogether [POSTING PILIHAN] SCAM ALERT: JANGAN JADI KELDAI AKAUN

Akaun bank yang didaftarkan atas nama anda merupakan tanggungjawab anda sepenuhnya. Jangan sesekali membenarkan akaun atau kemudahan perbankan anda digunakan oleh individu lain kerana tindakan tersebut boleh dieksploitasi oleh sindiket jenayah bagi menjalankan aktiviti haram. Penyalahgunaan akaun bank bukan sahaja membuka ruang kepada aktiviti jenayah, malah boleh menyebabkan pemilik akaun disiasat, didakwa di mahkamah dan dikenakan tindakan undang-undang. Ikuti infografik yang disediakan oleh Jabatan Siasatan Jenayah Komersil Kontinjen Selangor sebagai panduan untuk mengenali modus operandi sindiket keldai akaun dan langkah melindungi diri. Sumber: Jabatan Siasatan Jenayah Komersil Kontinjen Selangor

Checked 09 Sep 2026 1 evidence record View alert
Cyber Alerts Verified Officially confirmed

Barracuda Email Security Gateway (ESG) Zero Day Vulnerability

National Cyber Coordination and Command Centre (NC4) is aware of active exploitation on Barracuda Email Security Gateway (ESG) vulnerabilities that could allow an attacker to gain control of an affected system, install backdoors and exfiltrate data. The impact of these vulnerabilities is critical as it was observed can be utilised as vector for espionage activities.

Checked 16 Sep 2026 1 evidence record View alert
Cyber Alerts Verified Officially confirmed

Heightened Alert for Cyber Activities on Domains and Infrastructures in Malaysia

In light of recent developments in the Middle East, the National Cyber Coordination and Command Centre (NC4) is closely monitoring the cyber campaign centred around this conflict. Multiple hacktivists have reportedly gathered and launched cyber attacks, which, based on historical data, include web defacement, document leaks, and distributed denial of service (DDOS) attacks. NC4 would like to remind System Administrators and Network Administrators to implement adequate cyber security measures to ensure systems and networks are always secure.

Checked 15 Sep 2026 2 evidence records View alert
Cyber Alerts Verified Officially confirmed

New Petya Ransomware Variant Advisory

On June 27 2017, multiple organisations globally had reported of disruptions attributing to ransomware. Based on initial information received, a variant of Petya ransomware may be responsible for the incidents. National Cyber Coordination and Command Centre is currently monitoring closely for any signs of infection or propagation in Malaysia.

Checked 15 Sep 2026 1 evidence record View alert
Cyber Alerts Verified Officially confirmed

Bad Rabbit Ransomware - Technical Analysis

On Oct 24, 2017, a few organisation in Ukraine, Russia, Turkey and Germany had reported of disruptions attributing to ransomware. Based on initial information received, a new variant of WannaCry and NotPetya ransomware known as Bad Rabbit are responsible for the incidents. Further analysis of the ransomware has been carried out and details of the ransomware is explained below. National Cyber Coordination and Command Centre is currently monitoring closely for any signs of infection or propagation in Malaysia.

Checked 15 Sep 2026 1 evidence record View alert
Cyber Alerts Verified Officially confirmed

CPU Hardware Security Vulnerability Alert

National Cyber Coordination and Command Centre (NC4) is aware of recent revelation of security vulnerabilities in processors that can be exploited to gather sensitive data from computing devices.

Checked 15 Sep 2026 1 evidence record View alert
Cyber Alerts Verified Officially confirmed

Fake Bank Negara Malicious APK Alert

National Cyber Coordination and Command Centre (NC4) and MyCERT has received numerous reports of smartphones users being infected with malware through a phishing campaign involving Bank Negara Malaysia (BNM).

Checked 15 Sep 2026 1 evidence record View alert
Cyber Alerts Verified Officially confirmed

Potential Cyber Attack on ICT Infrastructures Targeting Malaysia Organisations

National Cyber Cyber Security Agency (NACSA) has detected various attack attempts targeting numerous organisations in Malaysia recently. The type of attacks detected varies; including Intrusion, Intrusion Attempts, Distributed Denial of Service (DDoS), Web Defacement and Malware Infections.

Checked 15 Sep 2026 1 evidence record View alert
Cyber Alerts Verified Officially confirmed

VPNFilter Router Malware

Security researcher at CISCO's Talos Intelligence has discovered an advanced widespread use of a sophisticated modular malware system called "VPNFilter".

Checked 15 Sep 2026 1 evidence record View alert
Breaches and Incidents Verified Officially confirmed

Advisory on Data Breach Prevention

National Cyber Security Agency (NACSA) is aware of the recent incidents of data breaches involving personal data of citizens in this region.

Checked 15 Sep 2026 1 evidence record View alert
Scroll for more intelligence