Public section

Cyber Alerts

Actionable vulnerability and active-exploitation alerts supported by authoritative records.

Monitored dailyPublication requires deterministic evidence gates.

Published only

Latest in Cyber Alerts

Cyber Alerts Verified Officially confirmed

Advisory for the Upcoming Merdeka Day Celebration

National Cyber Coordination and Command Centre (NC4) continuously monitor the cyber security threat level in Malaysia. In view of the upcoming Merdeka Day celebration and several long weekends in the month of September, NC4 would like to remind System Administrators and Internet users to implement sufficient cyber security measures to ensure that systems and networks are secure before leaving for the holidays.

Checked 16 Sep 2026 1 evidence record View alert
Cyber Alerts Verified Officially confirmed

High Alert on Phishing Attacks and Web Defacement Based on Current National Health & Political Situation

National Cyber Security Agency (NACSA), National Security Council (NSC) always monitor the current cyber threat level in Malaysia. It has come to our attention of ongoing scam campaigns and phishing attacks leveraging the current Coronavirus (COVID-19) global scale health crisis to steal sensitive information and delivering malware. NACSA has also discovered that, with the latest development in our political scene, several files were circulated that have potential threat to the end users and an increased activities by local hacktivist groups taking advantage of the current political situation.

Checked 16 Sep 2026 1 evidence record View alert
Cyber Alerts Verified Officially confirmed

Advisory on Cyber Threat Using COVID-19 Outbreak As Theme

The National Cyber Coordination and Command Centre (NC4) continuously monitor the cyber threat landscape that may affect national security both locally and globally. We have observed an increased number of cyberattacks, targeting multiple organisations worldwide, taking advantage of Coronavirus (COVID-19) public health issue as a lure to attract victims to fall into their traps. With the recent announcement of Movement Control Order (MCO) by the Prime Minister of Malaysia, which requires all non-essential government and business premises to be closed from 18 to 31 March 2020, the NC4, National Cyber Security Agency (NACSA), National Security Council (NSC) would like to remind everyone to be vigilant and to continue to observe the cyber hygiene practices while working from home.

Checked 16 Sep 2026 1 evidence record View alert
Cyber Alerts Verified Officially confirmed

Beware of Malicious Android App Being Distributed Through A Fraudulent Website Claiming to Be from The Perdana Menteri Malaysia

The National Cyber Security Agency (NACSA), National Security Council (NSC) through the National Cyber Coordination and Command Centre (NC4) has been informed of a malicious Android mobile app and a fraudulent website (http://malaysiagovermentapp.com) claiming to be from the Perdana Menteri Malaysia for the purposes of COVID-19 aid programme.

Checked 16 Sep 2026 1 evidence record View alert
Cyber Alerts Verified Officially confirmed

Potential Attacks towards Malaysian Organisations’ Websites

National Cyber Coordination and Command Centre (NC4) continuously monitor the cybersecurity threat level in Malaysia. In view of the recent development involving a sensitive video parody, it has come to our attention that a campaign to attack and deface Malaysian websites has been launched. NC4 would like to remind System Administrators and Network Administrators to implement sufficient cybersecurity measures to ensure that systems and networks are secure at all times.

Checked 16 Sep 2026 1 evidence record View alert
Cyber Alerts Verified Officially confirmed

Critical Vulnerability on Apache Log4J 2 Library

National Cyber Coordination and Command Centre (NC4) would like to alert everyone about a critical vulnerability concerning the use of Log4J 2 library and a working exploit affecting all applications using the library. The exploits can cause information leak and remote code execution and has been proven that it can be used to gain remote access into the vulnerable server and can potentially be used to attack other resources or hold the server for ransom.

Checked 16 Sep 2026 1 evidence record View alert
Cyber Alerts Verified Officially confirmed

Heightened Alert On Cyber Activity Towards Malaysia

The National Cyber Coordination and Command Centre (NC4), a national centre that continuously monitors the cyber threat landscape in Malaysia has observed an increased number of cyber activities within this region targeting the ICT infrastructure in Malaysia. NC4 would like to remind System Administrators and Network Administrators to implement sufficient cyber security measures to ensure systems and networks are secured at all times.

Checked 16 Sep 2026 1 evidence record View alert
Cyber Alerts Verified Officially confirmed

Microsoft Support Diagnostic Tool (MSDT) Vulnerability

National Cyber Coordination and Command Centre (NC4) is aware of active exploitation of the zero day vulnerability affecting Microsoft Support Diagnostic Tool (MSDT) in Windows (CVE-2022-30190). This vulnerability can be exploited by an attacker sending a malicious document that utilises Microsoft Word’s external link feature to retrieve the remote malicious file, then using the Microsoft Support Diagnostic Tool to execute PowerShell code. Successful exploitation of the vulnerability will allow an attacker to install programs, view or tamper data, or create new accounts in line with the victim’s user permissions. It can potentially be used to launch attacks towards other resources within the internal network. Proof of Concept (PoC) code to exploit this vulnerability is available online and has been integrated into common exploitation frameworks and tools. Disabling Microsoft Office Macros does not prevent exploitation of this vulnerability.

Checked 16 Sep 2026 2 evidence records View alert
Cyber Alerts Verified Officially confirmed

Alert on Potential Cyber Attack on Malaysian Domains

The National Cyber Coordination and Command Centre (NC4) monitors cyber threats in Malaysia and has observed an increase of cyber activities on Malaysian domains based on the current ongoing campaign. In this regard, NC4 reminds system and network administrators to immediately implement sufficient cyber security measures to ensure the systems and networks are secured at all times.

Checked 16 Sep 2026 1 evidence record View alert
Cyber Alerts Verified Officially confirmed

MA-1479.072026: MyCERT Advisory - Recent Ransomware Activities Observed: Best Practices for Prevention and Mitigation

Recently, the Cyber999 Incident Response Centre has been observing a notable increase in ransomware-related incidents targeting organisations across Malaysia. These attacks have affected a wide range of sectors, including businesses, hence highlighting the growing threat posed by ransomware threat actors. Ransomware activity continued at a significant pace into 2026. Building on the 51 incidents recorded throughout 2025, the first two quarters of 2026 alone accounted for 29 incidents (17 in Q1, 12 in Q2), signalling that ransomware remains a sustained operational risk rather than a diminishing one. Active Threat Groups identified across Q1 and Q2 2026 include LockBit, The DragonHorse, Qilin, Akira, Lynx Group, Black Shatrac, Thegentlemen, CrySiS, Obscura, Skynet, Ransom24 Group, DeadLock, and INC Ransom, alongside several unidentified variants. Threat actors continue to leverage compromised credentials (often harvested via Infostealers), unpatched vulnerabilities, and social engineering to gain initial entry. Organisations must reinforce infrastructure defences and ensure rapid incident reporting to mitigate nationwide impact. 2.0 Impacts Below is the list of ransomware impacts that could be devastating to organisations: Service Interruption: Customer-facing services may go offline, damaging trust and reputation.System and network infrastructure compromised.Files on the infected computer are encrypted, and the owner cannot access the files until a ransom (usually in a cryptocurrency such as Bitcoin) is paid.System Downtime: Ransomware often encrypts critical data and systems, halting business operations.Business operations are disrupted due to permanent or temporary loss of sensitive or proprietary data belonging to an organisation.Aside from financial gain, it exploits sensitive data and uses it as a levy. If the ransom is not paid within time, organisations’ confidential data are exposed, and trade secrets are compromised.Financial loss: Some organisations may feel pressured to pay the ransom, which can be substantial. Restoring systems, conducting forensics, and improving security can be very expensive. A data breach can result in reputational harm to the government and diminish trust in government digital transformation programmes.

Checked 15 Sep 2026 1 evidence record View alert
Scroll for more intelligence