Daily monitoring

All Intelligence

Published Malaysian scam and cybersecurity developments supported by official or authoritative evidence.

Monitored dailyPublication requires deterministic evidence gates.
Scam Intelligence

Confirmed Malaysian scam developments, official warnings and what consumers should do next.

Open section →
Cyber Alerts

Actionable vulnerability and active-exploitation alerts supported by authoritative records.

Open section →
Breaches and Incidents

Confirmed breaches and security incidents, who is affected and what remains unknown.

Open section →
Regulation and Enforcement

Malaysian regulatory, enforcement and public-safety developments explained clearly.

Open section →
Practical Guides

Practical steps drawn from authorities, affected organisations and official vendor guidance.

Open section →
Daily/Weekly Briefings

Daily monitoring roundups and weekly action briefings for Malaysian consumers and SMEs.

Open section →
Community Discussion

Discuss published alerts, ask questions and suggest official sources. Submissions are not treated as evidence.

Open discussion →

Published only

Latest alerts and briefings

Cyber Alerts Verified Officially confirmed

MA-1463.062026: MyCERT Advisory - Best Practices Following Global Targeting of Fortinet Firewalls and VPN Gateways

Recently, a large dataset containing credentials and configuration information associated with approximately 73,000 Fortinet VPN and firewall devices has been publicly disclosed. This dataset was collected through a campaign conducted by threat actors to obtain these credentials, while this does not appear to be linked to a newly discovered Fortinet vulnerability. The exposed data reportedly includes usernames, passwords, VPN configuration details, and other device information. Organisations whose devices have internet-facing management interfaces and credentials may be included in the leaked dataset. This may pose a risk of compromise and should prompt organisations to take immediate action to determine whether there is any evidence of unauthorised access in their organisations.

Checked 02 Aug 2026 1 evidence record View alert
Cyber Alerts Verified Officially confirmed

MA-1464.062026: MyCERT Alert - Malware Campaign Delivering Malicious VBScript via WhatsApp Desktop

MyCERT is observing an active malware campaign that delivers malicious Visual Basic Script (.vbs) files directly through WhatsApp. This campaign is highly targeted at individuals using WhatsApp Desktop or WhatsApp Web on Microsoft Windows operating systems. The risk is entirely confined to Windows environments. VBS files do not execute on iOS, Android, macOS, or Linux devices, and WhatsApp mobile applications will not download or process .vbs attachments as executable files. 2.0 Modus OperandiAttackers contact victims via WhatsApp and attempt to socially engineer them into opening a malicious attachment. The payload is a .vbs file deliberately disguised as a routine financial or administrative document to trick the user into executing it. Recent examples of this social engineering tactic demonstrate the attackers using varied filenames to create urgency or relevance: A legal or debt-themed lure named "Acknowledgment of Debt.vbs"An invoice-themed lure named “Sila semak bil anda..vbs”A financial statement lure named “December statement of account.vbs”A financial reconciliation statement themed lure named "Reconciliation.vbs" If a user clicks and opens these .vbs files on a Windows machine, the script executes and begins the infection process.

Checked 02 Aug 2026 1 evidence record View alert
All published intelligence loaded