AI Weekly Malaysia

Summaries

Short AI and tech summaries with source links, signal scores, and why each update matters for builders, founders, and Malaysian tech workers.

Reset

Showing 1-2 of 2 results

DateProviderScoreSummary
11 Aug 2026, 5:16 PMThe Hacker News3.5 Gunra Ransomware Exploits Fortinet FortiOS, FortiProxy Flaws to Breach Networks

Gunra ransomware, a Conti-derived operation active since April 2025 with 51 listed victims, gains initial access by exploiting Fortinet FortiOS/FortiProxy (CVE-2025-24472) and Schneider Electric PowerLogic P5 (CVE-2024-5559) flaws, then deploys double-extortion using Salsa20/ChaCha20 encryption. The group launched a formal RaaS affiliate program in January 2026 with Windows and Linux lockers, though the Linux builds reportedly contain a catastrophic cryptographic weakness. Most victims are in South Korea, Brazil, Spain, Thailand, and Hong Kong, with targets spanning healthcare, financial services, and government sectors.

Why: If your startup or employer runs Fortinet FortiOS/FortiProxy or Schneider Electric PowerLogic P5 appliances exposed to the internet, patch CVE-2025-24472 and CVE-2024-5559 immediately—these are confirmed initial-access vectors for an active ransomware campaign. The Southeast Asian victim concentration (Thailand, Hong Kong) means regional infrastructure is being targeted. Beyond patching, there is little here for builders not running these specific appliances.

11 Aug 2026, 12:38 AMThe Hacker News2.5 China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

Microsoft reports that China-linked threat actor Storm-1175 has switched from Medusa ransomware to a new C++ strain called StormEncryptor, which appends .encrypted to files and drops a !!!README_FIRST!!!.txt ransom note. Initial access likely exploits CVE-2026-18577, a patch bypass for CVE-2026-18556 in N-able N-central, both allowing authentication bypass and account takeover; CISA has flagged them as actively exploited. Post-compromise behavior includes AnyDesk or SimpleHelp abuse, Advanced IP Scanner for discovery, and Mimikatz for LSASS dumping.

Why: If your team or MSP runs N-able N-central, patch immediately for CVE-2026-18577 and CVE-2026-18556 and audit for AnyDesk, SimpleHelp, Advanced IP Scanner, and Mimikatz activity as compromise indicators. For everyone else not running N-central, no action is required from this specific report.

Top