DNS Flag Day 2019
National Cyber Coordination and Command Centre (NC4), NACSA would like to draw your attention on the DNS Flag Day 2019 which will be in effect starting from 1st February 2019.
Daily monitoring
Published Malaysian scam and cybersecurity developments supported by official or authoritative evidence.
Confirmed Malaysian scam developments, official warnings and what consumers should do next.
Open section → Cyber AlertsActionable vulnerability and active-exploitation alerts supported by authoritative records.
Open section → Breaches and IncidentsConfirmed breaches and security incidents, who is affected and what remains unknown.
Open section → Regulation and EnforcementMalaysian regulatory, enforcement and public-safety developments explained clearly.
Open section → Practical GuidesPractical steps drawn from authorities, affected organisations and official vendor guidance.
Open section → Daily/Weekly BriefingsDaily monitoring roundups and weekly action briefings for Malaysian consumers and SMEs.
Open section → Community DiscussionDiscuss published alerts, ask questions and suggest official sources. Submissions are not treated as evidence.
Open discussion →Published only
National Cyber Coordination and Command Centre (NC4), NACSA would like to draw your attention on the DNS Flag Day 2019 which will be in effect starting from 1st February 2019.
On May 14, 2019, WhatsApp has announced a vulnerability that could be used to target selected WhatsApp users. The National Cyber Coordination and Command Centre (NC4) would like to advise all Malaysian WhatsApp users to update their WhatsApp application to the latest version as recommended by WhatsApp to mitigate this issue.
On May 14, 2019, Microsoft has announced a new vulnerability that exists in older versions of Windows. The vulnerability could lead to new self-propagating malware that bears a striking resemblance to the infamous WannaCry that wreaked havoc on systems around the globe in 2017. The National Cyber Coordination and Command Centre (NC4) would like to advise all users of older version of Microsoft Windows to update your Windows by downloading and installing update as recommended by Microsoft to mitigate this issue.
National Cyber Coordination and Command Centre (NC4) continuously monitor the cyber security threat level in Malaysia. In view of the upcoming Merdeka Day celebration and several long weekends in the month of September, NC4 would like to remind System Administrators and Internet users to implement sufficient cyber security measures to ensure that systems and networks are secure before leaving for the holidays.
National Cyber Security Agency (NACSA), National Security Council (NSC) always monitor the current cyber threat level in Malaysia. It has come to our attention of ongoing scam campaigns and phishing attacks leveraging the current Coronavirus (COVID-19) global scale health crisis to steal sensitive information and delivering malware. NACSA has also discovered that, with the latest development in our political scene, several files were circulated that have potential threat to the end users and an increased activities by local hacktivist groups taking advantage of the current political situation.
The National Cyber Coordination and Command Centre (NC4) continuously monitor the cyber threat landscape that may affect national security both locally and globally. We have observed an increased number of cyberattacks, targeting multiple organisations worldwide, taking advantage of Coronavirus (COVID-19) public health issue as a lure to attract victims to fall into their traps. With the recent announcement of Movement Control Order (MCO) by the Prime Minister of Malaysia, which requires all non-essential government and business premises to be closed from 18 to 31 March 2020, the NC4, National Cyber Security Agency (NACSA), National Security Council (NSC) would like to remind everyone to be vigilant and to continue to observe the cyber hygiene practices while working from home.
The National Cyber Security Agency (NACSA), National Security Council (NSC) through the National Cyber Coordination and Command Centre (NC4) has been informed of a malicious Android mobile app and a fraudulent website (http://malaysiagovermentapp.com) claiming to be from the Perdana Menteri Malaysia for the purposes of COVID-19 aid programme.
A recent breach involving a cybersecurity firm FireEye has uncovered a widespread campaign by an uncategorised advanced persistent threat actor tracked as UNC2452 by FireEye. The actors behind this campaign have gained access to numerous public and private organisations around the world via trojanised updates to SolarWinds’ Orion IT monitoring and management software.
National Cyber Coordination and Command Centre (NC4) continuously monitor the cybersecurity threat level in Malaysia. In view of the recent development involving a sensitive video parody, it has come to our attention that a campaign to attack and deface Malaysian websites has been launched. NC4 would like to remind System Administrators and Network Administrators to implement sufficient cybersecurity measures to ensure that systems and networks are secure at all times.
National Cyber Coordination and Command Centre (NC4) would like to alert everyone about a critical vulnerability concerning the use of Log4J 2 library and a working exploit affecting all applications using the library. The exploits can cause information leak and remote code execution and has been proven that it can be used to gain remote access into the vulnerable server and can potentially be used to attack other resources or hold the server for ransom.
The National Cyber Coordination and Command Centre (NC4), a national centre that continuously monitors the cyber threat landscape in Malaysia has observed an increased number of cyber activities within this region targeting the ICT infrastructure in Malaysia. NC4 would like to remind System Administrators and Network Administrators to implement sufficient cyber security measures to ensure systems and networks are secured at all times.
National Cyber Coordination and Command Centre (NC4) is aware of active exploitation of the zero day vulnerability affecting Microsoft Support Diagnostic Tool (MSDT) in Windows (CVE-2022-30190). This vulnerability can be exploited by an attacker sending a malicious document that utilises Microsoft Word’s external link feature to retrieve the remote malicious file, then using the Microsoft Support Diagnostic Tool to execute PowerShell code. Successful exploitation of the vulnerability will allow an attacker to install programs, view or tamper data, or create new accounts in line with the victim’s user permissions. It can potentially be used to launch attacks towards other resources within the internal network. Proof of Concept (PoC) code to exploit this vulnerability is available online and has been integrated into common exploitation frameworks and tools. Disabling Microsoft Office Macros does not prevent exploitation of this vulnerability.