Quarter
2 2026 Cyber Incident Summary Report
Cyber999
Incident Response Centre of CyberSecurity Malaysia
TLP
WHITE
1.0
Introduction
The
Cyber Incident Quarterly Summary Report Q2 2026 provides an overview of
computer security incidents handled by the Cyber999 Incident Response Centre of
CyberSecurity Malaysia in Q2 2026.
This
quarterly Cyber Incident Report also highlights statistics of incidents dealt
with by the Cyber999 Incident Response Centre in Q2 2026 according to their
categories and security alerts and advisories released in this quarter. It
should be noted that the statistics provided in this report reflect only the
total number of incidents reported and handled by the Cyber999 Incident
Response Centre, excluding elements such as monetary value or aftermaths of the
incidents. Computer security incidents dealt with by the Cyber999 Incident
Response Centre involved IP addresses and domains from Malaysia.
CyberSecurity
Malaysia works closely with ISPs, CERTs, Special Interest Groups (SIGs) and Law
Enforcement Agencies (LEAs), from local and international, to remediate and
mitigate computer security incidents affecting Malaysia's organisations and the
public.
2.0
Trends Q2 2026
There were 33.59 million internet users in
Malaysia at the start of 2025, while Malaysia was home to 28.68 million social
media users in January 2025, equating to 83.1 percent of the total population
[1]. Meanwhile, a total of RM3.18 billion has been lost to online scams
involving more than 95,800 victims between 2021 and April 2025 [2]. In general,
the Cyber999 Incident Response Centre receives incident reports from Internet
users, members of the public, home users, small and medium enterprises (SMEs),
industries, academia, and non-profit organisations (NGOs). We proactively seek
and gather insights on cyber threats through partnerships and collaborations worldwide
that could impact Internet users and organisations in Malaysia and aid in
mitigating these threats. The Cyber999 Incident Response Centre received 2,715
incidents in Q2 2026, compared to 2,188 incidents in Q1 2026. This indicates a
24.09% increase in Q2 2026.
Tables 1 to 3 below provide details of the
incidents and their figures reported in Q1 2026 and Q2 2026.
Table
1: Comparison of Incidents Reported in Q1 2026 and Q2 2026
|
Categories of Incidents |
Quarters |
Percentage (%) |
|
|
Q1 2026 |
Q2 2026 |
||
|
5 |
1 |
-80.00 |
|
|
Intrusion |
64 |
51 |
-20.31 |
|
Data
Breach |
124 |
175 |
41.13 |
|
Intrusion Attempt |
81 |
91 |
12.35 |
|
Vulnerabilities Report |
26 |
17 |
-35.62 |
|
Malicious
Codes |
28 |
34 |
21.43 |
|
Fraud |
1829 |
2314 |
26.52 |
|
Spam |
31 |
32 |
3.23 |
|
TOTAL |
2188 |
2715 |
24.09 |
Table
2: Breakdown of Incidents Based on Months in Q2 2026
|
Categories of Incidents |
April |
May |
June |
|
Denial of Service |
0 |
0 |
1 |
|
Intrusion |
21 |
14 |
12 |
|
Data Breach |
67 |
61 |
47 |
|
Intrusion Attempt |
33 |
27 |
31 |
|
Vulnerabilities Report |
4 |
4 |
9 |
|
Malicious Codes |
12 |
11 |
11 |
|
Fraud |
759 |
675 |
880 |
|
Spam |
11 |
7 |
14 |
|
TOTAL |
907 |
799 |
1005 |
Table
3: Breakdown of categories and sub-categories of incidents in Q2 2026
|
Categories and Sub-categories of Incidents |
April |
May |
June |
|
Denial of Service |
|
|
|
|
Denial of Service – DoS |
0 |
0 |
1 |
|
Fraud |
|
|
|
|
Fraud -- Bogus Email |
7 |
8 |
10 |
|
Fraud – Business Email Compromise |
0 |
0 |
1 |
|
Fraud – Fraud Site |
9 |
6 |
3 |
|
Fraud – Impersonation & Spoofing |
17 |
9 |
13 |
|
Fraud – Job Scam |
2 |
0 |
1 |
|
Fraud – Love/Parcel Scam |
0 |
0 |
0 |
|
Fraud -- Phishing |
724 |
652 |
852 |
|
Vulnerabilities Report |
|
|
|
|
Vulnerabilities Report – Misconfiguration
Information Disclosure |
2 |
1 |
4 |
|
Vulnerabilities Report -- System |
1 |
1 |
1 |
|
Vulnerabilities Report -- Web |
1 |
2 |
4 |
|
Intrusion |
|
|
|
|
Intrusion – Account Compromise |
21 |
11 |
10 |
|
Intrusion -- Defacement |
4 |
0 |
2 |
|
Intrusion Attempt |
|
|
|
|
Intrusion Attempt – Login Brute Force |
12 |
8 |
11 |
|
Intrusion Attempt – Port Scanning |
1 |
0 |
0 |
|
Intrusion Attempt – Vulnerability Probes |
20 |
19 |
20 |
|
Malicious Codes |
|
|
|
|
Malicious Codes – Botnet C&C |
0 |
1 |
0 |
|
Malicious Codes – Malware |
7 |
8 |
10 |
|
Malicious Codes – Malware Hosting |
5 |
2 |
1 |
|
|
|
|
|
|
Content Related |
|
|
|
|
Content Related – Data Breach |
67 |
61 |
47 |
|
Spam |
11 |
7 |
14 |
|
TOTAL |
907 |
799 |
1005 |
Figure 1 illustrates and provides an overview of
the incidents reported in Q2 2026 in a chart. Figure 2 illustrates the
percentage of incidents based on their classification.
Figure 1: Breakdown of incidents based on categories
in Q2 2026
Figure
2: Percentage of incidents reported by categories in Q2 2026
Based on the above statistics, total incidents reported to us increased by 24.09 percent in Q2 2026 (2,715incidents) compared to Q1 2026 (2,188 incidents). In Q2 2026, the most frequently reported incidents were Fraud, Data Breach, and Intrusion Attempt. Fraud accounted for the majority, representing 85.23 percent of all reported cases (2,314 incidents), followed by Data Breach at 6.45 percent (175 incidents) and Intrusion Attempt at 3.35 percent (91 incidents). Based on the current trends, fraud incidents will most likely continue to grow in Malaysia in 2026. Data breach incidents have increased by 41.13 percent for this quarter (175 incidents compared to 124 in Q1 2026). However, organisations and Internet users are urged to take proper security measures to prevent data breaches. Meanwhile, for fraud incidents other than phishing URLs, new tactics and techniques in online scams that concatenate social engineering and malicious code could grow in Malaysian cyberspace.
2.1
Top Fraud Incidents Reported in Q2 2026
Fraud
continues to prevail within the community, targeting various citizens, end
users and organisations, from students to professionals, and from large to
small organisations. It has become a preferred method for criminals as
awareness is still lacking among the public, making them an easier target. Two
thousand three hundred and fourteen fraud incidents were handled this quarter,
representing a 26.52 percent increase compared to Q1 2026. All the fraud incidents
were received from organisations and public users. The top fraud incidents
reported to the Cyber999
Incident
Response Centre are as follows:
Table
4: Top Fraud Incidents Reported in Q2 2026
|
Top Fraud incidents |
Number of Incidents |
|
Phishing |
2228 |
|
Impersonation and
Spoofing |
39 |
|
Bogus Email |
25 |
|
Fraudulent Website |
18 |
|
Job Scam |
3 |
|
Business Email
compromised – BEC scam |
1 |
|
Love and parcel scam |
0 |
Our statistics show that over three-quarters of fraud incidents reported are phishing, representing 68 percent of total fraud incidents reported in Q2 2026. We observed the following phishing trends in Malaysia based on the incidents reported to us. These trends are similar in the previous quarter, Q1 2026.
a. Contextualised and Localised Phishing Themes
Government Aid Scams: Phishing emails or SMS
impersonate legitimate government programs (e.g., bantuan/sumbangan kerajaan),
offering financial aid but requiring victims to provide personal details or
click malicious links.
Fake Promotions and Discounts: Popular
brands like Lazada, Shopee, or local retailers are spoofed, luring victims with
fraudulent discounts or free vouchers.
Traffic Summons Scams: Messages
claim unpaid police summons, providing fake payment links to steal financial
credentials.
Subscription Services: Services
like Netflix or Spotify are impersonated, tricking victims into renewing
subscriptions or fixing payment issues on fake websites.
b. Mobile-Focused Phishing (Smishing and App-Based)
Smishing (SMS Phishing): Attackers send fraudulent SMS messages
mimicking banks, e-wallets, or delivery services (e.g., J&T, Pos Malaysia)
with malicious links.
c. Phishing Calls (Vishing)
Phone Scams: Attackers impersonate government agencies (e.g., police or
LHDN, MCMC), banks, companies, or even CyberSecurity Malaysia, pressuring
victims to disclose sensitive information. Common tactics include threats of
legal action, account suspension, or overdue payments.
Therefore,
Internet users and organisations must be vigilant when conducting online
transactions or performing e-commerce transactions to avoid becoming victims of
online fraud.
2.2
Top Malware Incidents Reported in Q2 2026
The
top malware incidents include malware hosting, ransomware, malicious APK,
backdoors, and trojans. The top reported malware incidents are related to
malicious APKs. This type of incident is typically received from Internet
banking users and sometimes from local financial institutions.
A
malicious APK is an Android Package (APK) file
containing malware
designed to harm devices, steal data, or perform unauthorised actions. APK
files are used to distribute and install applications on Android devices, and
malicious versions exploit this format to spread malware. They often mimic
popular apps (e.g., social media, games, or utilities) to trick users into
downloading. Attackers may distribute these files through phishing emails,
social media, fake websites, or third-party app stores.
Table
5: Types of Malicious APKs Reported in Q2 2026
|
Malicious APK |
Total |
|
com.amazon.venezia |
1 |
|
collector.navigator.aggregator |
1 |
|
MaxTagDiscount.apk |
1 |
|
StatementofDebts-.vbs |
2 |
|
Klinik Pergigian
Ophelia.vbs |
1 |
|
irm
steamox.com|iex |
1 |
|
Steamweb64.exe |
1 |
|
Unknown APK |
1 |
The second top-reported incident within the malware category is malware hosting. Malware hosting primarily targeted vulnerable servers with outdated security patches and updates. These incidents are usually received from foreign entities, such as antivirus vendors and special interest groups, regarding servers in Malaysia that are hosting malware. System Administrators must be vigilant and keep systems up to date with the latest patches and security updates to prevent servers from being compromised and hosting malware.
Ransomware
incidents remained steady at 12 incidents in Q2 2026 (the same as 12 incidents
in Q1 2026). Nevertheless, organisations must remain vigilant. Ransomware is
malicious software (malware) that infects a computer and restricts access until
the requested ransom is paid. It is also considered one of the costliest and
most devastating attacks, as it is enormous to recover all the data and rectify
infected machines.
Our findings identified that businesses are
most impacted by ransomware incidents in Malaysia, consistent with trends across
the globe. Active Directory (AD) servers have become primary targets in
Malaysia. Compromising AD servers can significantly amplify the impact of a
ransomware attack. Using tools like PsExec, Group Policy Objects (GPOs), or Windows
Management Instrumentation (WMI) to execute ransomware on all connected
systems. Ryuk and Conti have been observed targeting AD servers for mass
deployment and faster network-wide encryption. We also observed attackers
exploiting vulnerabilities in virtualisation platforms like VMware, and ESXi
servers can be targeted directly, allowing attackers to gain control over
multiple VMs simultaneously. Ransomware operators use phishing attacks, brute
force, or stolen credentials to access VM management consoles or servers.
LockBit has been observed deploying scripts to attack VMware environments,
including deleting backups and snapshots.
Looking at the current trends, ransomware
incidents will continue to grow in Malaysia in 2026. Organisations, especially
businesses, must always take proper security measures against ransomware
incidents. Good backup management, system and network configuration, patch
management and password security, with cyber security awareness are essential
in combating ransomware. Implementing good backup procedures, policies, and
best practices among organisations and public users is also essential in
mitigating ransomware attacks.
Table
6: Ransomware Variants Reported in Q2 2026
|
Ransomware
Variant |
Number of
Incidents |
|
SHINYHUNTERS Ransomware |
1 |
|
Payload Ransomware |
1 |
|
Mario
Ransomware |
1 |
|
White Rabbit
Ransomware |
1 |
|
BlackCat
(ALPHV) |
1 |
|
Gentlemen
Ransomware |
1 |
|
MedusaLocker
Ransomware |
2 |
|
Lamashtu
Ransomware |
1 |
|
Qilin
Ransomware |
1 |
|
NA (Not
identified specific name of the ransomware) |
4 |
Apart from ransomware and malware hosting, we also handled incidents related to infostealers in Q2 2026. Infostealer is malicious software created to breach computer systems and steal sensitive information, including login details. Generally, data from the infostealers contained login credentials from various sources, including information saved on web browsers (such as passwords and credit logins), auto-filled logins, FTP clients, email apps, instant messaging clients, and VPNs.
Below
is a list of infostealers associated with data breaches reported to us in Q2 2026:
Table 7: Info stealers reported in Q2 2026
|
Number of Incidents |
|
|
PRIMO
CLOUD InfoStealer |
1 |
|
FRESH
InfoStealer |
1 |
|
ClickFix |
1 |
|
VIDAR
Stealer |
8 |
2.3
Data Breach Incidents Growing in Malaysia
Data
breach incidents are growing in Malaysia, with a 41.13 percent increase this
quarter (175 cases in Q2 2026 compared to 124 cases in Q1 2026), underscoring
the need for better security measures to ensure national security and public
trust. High-profile breaches often involve massive datasets, including personal
identifier information (PII) like identification numbers, addresses, and
financial details, and often involve PII from national databases. Serious security
measures must consistently be implemented to prevent and mitigate data
breaches, especially for personal data.
We
identified that a large number of data breaches are preceded by ransomware
attacks, whereby attackers exfiltrate data from ransomware-impacted
organisations and sell them in the dark web. Perpetrators exfiltrate or steal
sensitive data from organisations and hold the data hostage in the majority of
ransomware attacks. Perpetrators will then threaten the organisation to release
or sell the data on the dark web unless the organisation pays ransom within a
timeframe set by the perpetrators. In the case of extortion by perpetrators, we
always advise organisations to refer the matter to the LEAs, such as the police,
for assistance. Other trends we observed in this quarter include the resurfacing
of previous data breaches. Perpetrators claimed and posted on the dark web that
they have recently breached data belonging to specific organisations.
However, our cross-checks confirmed these are resurfacings of previous data breaches that happened a few years back and not new breaches.
Table 8: Data Breaches Reported in Q2 2026
|
Types of Data Breach
|
Description |
|
Personal Identifier
Information (PII) |
Full name, identity
card numbers, home address, age, handphone number, date of birth,
and salary.
|
|
Account Credential |
Username and password
of email accounts, username and password of Internet banking
accounts.
|
|
Appliances Credential |
Admin panel access,
Joomla, wordpress, ftp access, wp-admin access and etc.
|
3.0
Security Advisories and Alerts Released in Q2 2026
In
Q2 2026, the Cyber999 Incident Response Centre issued 73 Security Advisories
and one Alert. Each with descriptions, mitigation steps, and recommendations
for organisations and Internet users to follow. The security advisories
involved Mozilla, Microsoft, Apple, VMware, and several other CVEs listed in
Table 10. The security alerts concern growing online fraud and malware threats that
we identified as potentially serious to citizens and organisations in Malaysia.
If not correctly identified and mitigated, such threats could have serious
consequences for citizens and organisations.
Table
10: List of Significant CVEs in Q2 2026
Here
is the table with the CVEs and their descriptions:
|
CVE ID |
Description |
|
CVE-2026-41940 |
WebPros cPanel & WHM and WP2 (WordPress
Squared) Missing Authentication for Critical Function Vulnerability
May allow an unauthenticated attacker to bypass
authentication and gain administrative-level access to affected cPanel, WHM,
or WP Squared (WP2) systems. |
|
CVE-2026-7431 |
Remote code execution
vulnerability in Ivanti Secure Access Client.
An incorrect permission assignment for critical
resource of Ivanti Secure Access Client before 22.8R6 allows a
local authenticated user to read or modify sensitive log data via write
access to a shared memory section. |
|
CVE-2026-7432 |
Privilege escalation /
information disclosure vulnerability in Ivanti Secure Access Client.
A race condition in
Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user
to escalate privileges to SYSTEM |
|
CVE-2026-8043 |
Unauthorized access or
possible code execution vulnerability in Ivanti Xtraction.
External control of a file name in Ivanti
Xtraction before version 2026.2 allows a remote authenticated attacker to
read sensitive files and write arbitrary HTML files to a web directory,
leading to information disclosure and possible client-side attacks. |
|
CVE-2026-8051 |
Service disruption or
remote code execution vulnerability in Ivanti Virtual Traffic Manager (vTM)
OS command injection in Ivanti Virtual Traffic
Manager before version 22.9r4 allows a remote authenticated attacker with
admin privileges to achieve remote code execution. |
|
CVE-2026-8110 |
Privilege escalation
vulnerability in Ivanti Endpoint Manager (EPM).
Incorrect permissions assignment in the agent of
Ivanti Endpoint Manager before version 2024 SU6 allows a local authenticated
attacker to escalate their privileges. |
|
CVE-2026-8111 |
Information disclosure
vulnerability in Ivanti Endpoint Manager (EPM). SQL injection in the web console of Ivanti
Endpoint Manager before version 2024 SU6 allows a remote authenticated
attacker to achieve remote code execution. |
|
CVE-2026-0300 |
PAN-OS: Unauthenticated user initiated Buffer
Overflow Vulnerability in User-ID™ Authentication Portal
A buffer overflow vulnerability in the User-ID™
Authentication Portal (aka Captive Portal) service of Palo Alto Networks
PAN-OS software allows an unauthenticated attacker to execute arbitrary code
with root privileges on the PA-Series and VM-Series firewalls by sending
specially crafted packets. The risk of this issue is greatly reduced if you
secure access to the User-ID™ Authentication Portal per the best practice
guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by
restricting access to only trusted internal IP addresses. Prisma Access,
Cloud NGFW and Panorama appliances are not impacted by this vulnerability. |
|
CVE-2026-23918 |
Apache HTTP Server: http2: double free and
possible RCE on early reset
Double Free and possible RCE vulnerability in
Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP
Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which
fixes the issue. |
|
CVE-2026-24072 |
Apache HTTP Server: mod_rewrite elevation of
privileges via ap_expr
An escalation of privilege bug in various modules
in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read
files with the privileges of the httpd user. Users are recommended to upgrade
to version 2.4.67, which fixes this issue. |
|
CVE-2026-28780 |
Apache HTTP Server: buffer overflow in
mod_proxy_ajp via ajp_msg_check_header()
Heap-based Buffer Overflow vulnerability in
mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious
AJP server this AJP server can send a malicious AJP message back to
mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end
of a heap based buffer. This issue affects Apache HTTP Server: through
2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the
issue. |
|
CVE-2026-29168 |
Apache HTTP Server: mod_md unrestricted OCSP
response
Allocation of Resources Without Limits or
Throttling vulnerability in Apache HTTP Server's mod_md via OCSP response data. This issue
affects Apache HTTP Server: from 2.4.30 through 2.4.66. Users are recommended
to upgrade to version 2.4.67, which fixes the issue. |
|
CVE-2026-29169 |
Apache HTTP Server: mod_dav_lock indirect lock
crash
A NULL pointer dereference in mod_dav_lock in
Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the
server with a malicious request.mod_dav_lock is not used internally by
mod_dav or mod_dav_fs. The only known use-case for mod_dav_lock was
mod_dav_svn from Apache Subversion earlier than version 1.2.0. Users are
recommended to upgrade to version 2.4.66, which fixes this issue, or remove
mod_dav_lock. |
|
CVE-2026-33006 |
Apache HTTP Server: mod_auth_digest timing attack
A timing attack against mod_auth_digest in Apache
HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote
attacker. Users are recommended to upgrade to version 2.4.67, which fixes
this issue. |
|
CVE-2026-33007 |
Apache HTTP Server: mod_authn_socache crash
A NULL pointer dereference in the
mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an
unauthenticated remote user to crash a child process in a caching forward
proxy configuration. Users are recommended to upgrade to version 2.4.67,
which fixes this issue. |
|
CVE-2026-33523 |
Apache HTTP Server: HTTP response splitting
forwarding malicious status line
HTTP response splitting vulnerability in multiple
Apache HTTP Server modules with untrusted or compromised backend servers.
This issue affects Apache HTTP Server: from through 2.4.66. Users are
recommended to upgrade to version 2.4.67, which fixes the issue. |
|
CVE-2026-33857 |
Apache HTTP Server: Off-by-one OOB reads in AJP
getter functions
Out-of-bounds Read vulnerability in mod_proxy_ajp
of Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue. |
|
CVE-2026-34059 |
Apache HTTP Server: mod_proxy_ajp: Heap Over-Read
and memory disclosure in ajp_parse_data()
Buffer Over-read vulnerability in Apache HTTP
Server. This issue affects Apache HTTP Server: through 2.4.66. Users are
recommended to upgrade to version 2.4.67, which fixes the issue. |
|
CVE-2026-42838 |
Microsoft Edge (Chromium-based) Elevation of
Privilege Vulnerability
Improper neutralization of special elements in
output used by a downstream component ('injection') in Microsoft Edge
(Chromium-based) allows an unauthorized attacker to elevate privileges over a
network. |
|
CVE-2026-40416 |
Microsoft Edge (Chromium-based) for Android
Spoofing Vulnerability
User interface (ui) misrepresentation of critical
information in Microsoft Edge (Chromium-based) allows an unauthorized
attacker to perform spoofing over a network |
|
CVE-2026-41107 |
Microsoft Edge (Chromium-based) Information
Disclosure Vulnerability
External control of file name or path in
Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose
information over a network. |
|
CVE-2026-42838 |
Microsoft Edge (Chromium-based) Elevation of
Privilege Vulnerability
Improper neutralization of special elements in
output used by a downstream component ('injection') in Microsoft Edge
(Chromium-based) allows an unauthorized attacker to elevate privileges over a
network. |
|
CVE-2025-34291 |
Langflow <= 1.6.9 CORS Misconfiguration to
Token Hijack & RCE
Langflow versions up to and including 1.6.9
contain a chained vulnerability that enables account takeover and remote code
execution. An overly permissive CORS configuration (allow_origins='*' with
allow_credentials=True) combined with a refresh token cookie configured as
SameSite=None allows a malicious webpage to perform cross-origin requests
that include credentials and successfully call the refresh endpoint. An
attacker-controlled origin can therefore obtain fresh access_token /
refresh_token pairs for a victim session. Obtained tokens permit access to
authenticated endpoints — including built-in code-execution functionality —
allowing the attacker to execute arbitrary code and achieve full system
compromise. |
|
CVE-2026-20230 |
Cisco Unified Communications Manager Server-Side
Request Forgery Vulnerability
A vulnerability in Cisco Unified Communications
Manager (Unified CM) and Cisco Unified Communications Manager Session
Management Edition (Unified CM SME) could allow an unauthenticated, remote
attacker to conduct server-side request forgery (SSRF) attacks through an
affected device. This vulnerability is due to improper input validation for
specific HTTP requests. An attacker could exploit this vulnerability by
sending a crafted HTTP request to an affected device. A successful exploit
could allow the attacker to write files to the underlying operating system
that could be used later to elevate to root. Note: Cisco has assigned this
security advisory a Security Impact Rating (SIR) of Critical rather than High
as the score indicates. The reason is that exploitation of this vulnerability
could result in an attacker elevating privileges to root. Note: To exploit
this vulnerability, the WebDialer service must be enabled. WebDialer is
disabled by default. |
|
CVE-2022-0492 |
A vulnerability was found in the Linux kernel’s
cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This
flaw, under certain circumstances, allows the use of the cgroups v1
release_agent feature to escalate privileges and bypass the namespace
isolation unexpectedly. |
|
CVE-2026-28318 |
SolarWinds Serv-U Unauthenticated Denial of
Service Vulnerability
SolarWinds Serv-U is susceptible to specially
crafted POST requests that crash the Serv-U service without authentication
using Content-Encoding: deflate. Mitigation steps are provided to secure
customer environments in the SolarWinds Trust Center if you are unable to
deploy the update |
|
CVE-2026-50751 |
User Authentication Bypass in VPN Remote Access
and Mobile Access
A logic flow weakness in Remote Access and Mobile
Access certificate validation in deprecated IKEv1 key exchange allows an
unauthenticated remote attacker to bypass user authentication and establish a
remote access VPN connection without a valid user password. |
|
CVE-2026-11645 |
Out of bounds read and write in V8 in Google
Chrome
Allowed a remote attacker to execute arbitrary
code inside a sandbox via a crafted HTML page. |
|
CVE-2026-20245 |
Cisco Catalyst SD-WAN Controller Authenticated
Privilege Escalation Vulnerability
A vulnerability in the CLI of Cisco Catalyst
SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager,
formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN
vBond, could allow an authenticated, local attacker to execute arbitrary
commands as root by supplying a crafted file to the affected system. This
vulnerability is due to insufficient validation of user-supplied input. An
attacker could exploit this vulnerability by uploading a crafted file to the
affected system. A successful exploit could allow the attacker to perform
command injection attacks on an affected system and elevate their privileges
as the root user. To exploit this vulnerability, the attacker must have netadmin
privileges on the affected system. This would require valid credentials or
exploitation of or . Cisco is not aware of successful exploitation by other
methods. Cisco has observed limited cases where the exploitation of this bug
resulted in a configuration change pushed to edge devices. Cisco recommends
that customers upgrade to the fixed software that is documented in the that
was published on May 14, 2026, and verify the configuration of the edge
devices. |
|
CVE-2026-20262 |
Cisco Catalyst SD-WAN Manager Arbitrary File
Write Vulnerability
A vulnerability in the web UI of Cisco Catalyst
SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote
attacker to create a file or overwrite any file on the filesystem of an
affected system. This vulnerability exists because the affected software does
not properly validate user-supplied input during a file upload process. An
attacker could exploit this vulnerability by sending a crafted HTTP request
to an affected API endpoint of the affected system. A successful exploit
could allow the attacker to create or overwrite any file on the underlying
operating system. This file could later be used to elevate to root. To
exploit this vulnerability, the attacker must have valid credentials with at
least a lower-privileged, single-task user account. |
|
CVE-2026-35273 |
PeopleSoft Enterprise PeopleTools
Vulnerability in the PeopleSoft Enterprise
PeopleTools product of Oracle PeopleSoft (component: Updates Environment
Management). Supported versions that are affected are 8.61 and 8.62. Easily
exploitable vulnerability allows unauthenticated attacker with network access
via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks
of this vulnerability can result in takeover of PeopleSoft Enterprise
PeopleTools. |
|
CVE-2026-54420 |
Remote Administration Daemon component
Vulnerability in the Oracle Solaris product of
Oracle Systems (component: Remote Administration Daemon). The supported
version that is affected is 11.4. Easily exploitable vulnerability allows
unauthenticated attacker with network access via HTTPS to compromise Oracle
Solaris. While the vulnerability is in Oracle Solaris, attacks may
significantly impact additional products (scope change). Successful attacks
of this vulnerability can result in unauthorized creation, deletion or
modification access to critical data or all Oracle Solaris accessible data as
well as unauthorized access to critical data or complete access to all Oracle
Solaris accessible data. |
|
CVE-2026-49261 |
MariaDB server has unsafe parameter handling in
`wsrep_notify_cmd`
MariaDB server is a community developed fork of
MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17,
11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with
`wsrep_notify_cmd` enabled would execute shell commands embedded in the name
of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and
12.3.2. As a workaround, anyone who cannot upgrade now should disable
`wsrep_notify_cmd`. |
|
CVE-2026-48165 |
MariaDB: unsafe usage of
`wsrep_sst_receive_address` values on the joiner side
MariaDB server is a community developed fork of
MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before
10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, a
high-privileged MariaDB user could've used wsrep_sst_receive_address or
wsrep_sst_donor global system variables to execute shell commands as the uid
of the mariadbd process on the galera joiner node. This issue has been
patched in versions 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. |
|
CVE-2026-48163 |
MariaDB: wsrep SST unsafe parameter handling on
the donor side (rsync)
MariaDB server is a community developed fork of
MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before
10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1,
during the SST the donor node is interpolating parameters that the joiner
sent into the command line. Not all parameters were properly validated which
could allow a malicious joiner to execute arbitrary shell commands on the
donor side via the rsync SST method. This issue has been patched in versions
10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. |
|
CVE-2026-42530 |
NGINX Open-Source ngx_http_v3_module
vulnerability
NGINX Open Source has a vulnerability in the
ngx_http_v3_module module. When NGINX Open Source is configured to use the
HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions
beyond their control can use a specially crafted HTTP/3 session to reopen a
QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker
process leading to a restart. Additionally, attackers can execute code on
systems with Address Space Layout Randomization (ASLR) disabled or when the
attacker can bypass ASLR. Note: Software versions which have reached End of
Technical Support (EoTS) are not evaluated. |
|
CVE-2026-42055 |
NGINX ngx_http_proxy_v2_module and
ngx_http_grpc_module vulnerability
NGINX Plus and NGINX Open Source have a
vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module
modules. This vulnerability exists when the proxy_http_version to 2 or
grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers
directive is set to off, and the large_client_header_buffers directive size
is larger than 2 megabytes. A remote, unauthenticated attacker, along with
conditions beyond their control, could send large headers while creating an
upstream request. This may cause a heap-based buffer overflow in the NGINX
worker process leading to a restart. Additionally, attackers can execute code
on systems with Address Space Layout Randomization (ASLR) disabled or when
the attacker can bypass ASLR. Note: Software versions which have reached End
of Technical Support (EoTS) are not evaluated. |
4.0
Conclusion
Overall,
the number of computer security incidents reported to the Cyber999 Incident
Response Centre in Q2 2026 was 2,715, representing an increase of 24% compared
to Q1 2026. No significant or severe incidents were observed during this
quarter. Nevertheless, organisations and individuals must always be vigilant
with readiness and preventive and mitigation steps against potential threats.
Perpetrators are very motivated, eager, and determined to use new and
sophisticated tactics and techniques to execute cyber-attacks.
Hence,
we strongly recommend that all internet users be constantly aware of today's
cybercrime trends and adhere to the best cyber hygiene practices. This also
includes secure handling of emails from unknown sources, safe web browsing,
purchasing goods online, and using social media applications. Users must keep
systems up to date with the latest security patches and updates to prevent
their computers from being compromised or infected with malware. Always check
the legitimacy of the applications, portals, merchants, services, and products
before conducting any online transaction.
As
the complexity of cyber threats continues to increase, organisations and
individuals could be potential targets if they are not equipped with security
awareness. Providing security awareness campaigns to citizens and organisations
is among the best efforts to improve national cyber security and public trust
Malaysian
Internet users and organisations may contact us to report cyber security
incidents at the below contact:
E-mail:
cyber999[at]cybersecurity.my
Phone:
1-300-88-2999 (monitored during business hours)
Mobile:
+60 19 2665850 (24x7 call incident reporting)
Business
Hours: Mon - Fri 08:30 -17:30 MYT
Web:
https://www.cybersecurity.my
5.0 References: