AI Weekly Malaysia

Summaries

Short AI and tech summaries with source links, signal scores, and why each update matters for builders, founders, and Malaysian tech workers.

Reset

Showing 1-6 of 6 results

DateProviderScoreSummary
30 Sep 2026, 7:58 PMThe Hacker News7.0 Know Your Enemy: Browser-Based Attack Techniques in 2026

The Hacker News rounds up six browser-based attack techniques it says security teams should track in 2026, citing Push data and Microsoft's Digital Defense Report. It claims reverse-proxy adversary-in-the-middle phishing kits (Tycoon2FA, Sneaky2FA, Evilginx) relay live credentials and session tokens to bypass most MFA, that roughly 1 in 2 phishing attacks now arrives outside email, and that 89% of phishing domains live under two days. It says ClickFix copy-and-paste attacks hit 47% of observed attacks per Microsoft and 52% of Push's Q2 2026 detections, with four in five ClickFix payloads reached from search engines, and describes an 'InstallFix' variant using malvertised fake install pages for developer tools including Claude Code and NotebookLM where the install command is swapped out.

Why: The concrete action item is the install-command path: if your README, onboarding doc, or YouTube tutorial tells someone to copy a curl/install command, an attacker can rank a fake page above yours and swap that command — and this piece names Claude Code and NotebookLM as already-targeted examples, meaning AI coding tools are now the lure. Second, if your product's MFA is TOTP or push, session-token relay means a phished session can survive login, so passkeys or other origin-bound auth is the thing to evaluate rather than adding another prompt. Note there is no Malaysia-specific detail in the text, so treat this as generic team hygiene, not a local incident.

01 Oct 2026, 12:32 AMThe Hacker News4.5 Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks

Microsoft Security Research reported a phishing campaign, detected in July 2026, that delivers a digitally signed MSP360 RMM v2.5.0.67 installer disguised as meeting invites, PDF readers, software updates, and e-card/RSVP lures (e.g. VIP_ECARD_INVITATION_rmm_v2.5.0.67_oid[redacted].exe, SSA.GOV_STATEMENT_rmm_v2.5.0.67_oid[redacted].exe). The installer relaunches itself through the Windows UAC elevation flow, drops DLLs, registers RMM.Agent.exe and RMM.Agent.Launcher.exe as Windows services with Registry autorun entries, and opens inbound UDP port 48678 in Windows Firewall. It then uses MSP360 to run PowerShell that installs a ConnectWise ScreenConnect client as a second, redundant remote-access channel for tool delivery and credential access. Payloads were staged on both attacker infrastructure and legitimate services including Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase. Microsoft did not attribute the activity to any known threat actor.

Why: The thing that got past defences was a valid vendor signature on a legitimate MSP360 binary, so 'it's signed' is not a trust decision on its own — the detectable signal here is the lure filename pattern (_rmm_v2.5.0.67_oid...) and the combination of an RMM service plus a ScreenConnect install on the same host. If you don't deploy MSP360 RMM anywhere, you can alert or block on RMM.Agent.exe / RMM.Agent.Launcher.exe services, autorun registry entries, and outbound UDP 48678 rather than waiting for an AV signature. If you run any file-hosting or storage product (S3, R2, Dropbox, GitLab, Supabase were all used as staging), treat abuse-reporting and takedown for hosted installers as an operational cost, not an edge case. There is no Malaysia-specific angle in this report, so treat it as a generic endpoint-detection change.

30 Sep 2026, 6:45 PMThe Hacker News4.5 US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access

ANY.RUN researchers traced a phishing campaign dubbed "CSuite" across 351 sandbox analyses, with 51% of submissions from the United States, 18% from India, and further activity in the Philippines, Australia, the UK, and Canada; technology, manufacturing, government, and consulting showed the highest exposure. Lures impersonate Adobe, DocuSign, Zoom, Google Meet, Dropbox, and Microsoft 365, and the chain splits two ways: installers, archives, or BAT/VBS droppers that install legitimate remote-management tools such as ScreenConnect or Action1, or credential-harvesting and device-code phishing flows that capture Microsoft 365 access and active sessions. One analyzed session showed an Adobe-themed lure delivering a BAT file that elevated privileges and installed ScreenConnect.

Why: The device-code phishing path is the one most startup teams have not locked down: if your Microsoft 365 tenant allows the device-code flow, a lure alone can hand over live sessions without a password prompt, and the RMM path means an endpoint ends up with ScreenConnect or Action1 installed under attacker control. Concretely, check whether your Entra ID conditional access blocks device-code flow, and whether anyone would notice a ScreenConnect or Action1 install on a work laptop — small teams without a SOC typically would not. This is a US-concentrated campaign, so treat it as a check-your-config item rather than an imminent local threat; the text gives no Malaysia-specific figures.

30 Sep 2026, 1:20 AMThe Hacker News4.0 Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor

Microsoft says Russia's Star Blizzard ran at least 13 larger phishing campaigns since January against 100+ organizations tied to Ukraine, mostly in the U.S. and U.K., with at least one machine confirmed infected. The lures impersonate think tanks and NGOs such as Chatham House and the Atlantic Council, and the first email carries no attachment: only if the target replies does the group send a password-protected RAR or ZIP with the password shown in an image. Delivery this year uses a method Microsoft calls RedFlick, which abuses Windows scheduled tasks to install a backdoor named CosmicPulse, replacing 2025's ClickFix fake-CAPTCHA approach, and since March the emails have come from compromised WordPress and cPanel site accounts instead of free services like Proton.

Why: The reply-gated, password-in-an-image archive is a concrete gap: nothing malicious arrives in the first message, so attachment sandboxing and link scanners see a clean email. If your team's playbook says 'no attachment, no risk,' it needs a rule about replying to unexpected event or conference invitations. The WordPress/cPanel detail also matters locally — if you or a client run mail on shared cPanel hosting, a compromised mailbox there can be repurposed to send these lures, so check outbound mail logs and scheduled tasks, not just inbound filters.

30 Sep 2026, 8:16 AMMalay Mail Tech3.0 Spam isn’t just in your email: How a rogue calendar invite could disrupt your workday

A Malay Mail Tech piece (published 30 Sep 2026) argues that spam has moved beyond email into internet-connected calendars, citing cybersecurity reports from Sublime that show a sharp increase in spam calendar invites, particularly affecting Google Workspace users, with predictions of continued growth. The article's stated remedies are reviewing calendar settings, limiting access, and consulting trusted cybersecurity experts. It names no figures, versions, affected organisations, or specific attack tooling.

Why: There is little here to act on: no incident counts, no named vulnerabilities, no Malaysia-specific detail, and the mitigation advice is generic. The one concrete claim is that calendar invites are now a spam/phishing channel aimed at Google Workspace users — so if your team runs Workspace, treat calendar invites as a second inbox and decide who can add events to shared calendars, rather than assuming email filtering covers you. Beyond that, this article does not justify a settings change on its own; wait for a report with numbers or a vendor advisory before reconfiguring anything.

01 Oct 2026, 5:35 PMSoyaCincau2.5 Kaspersky warns Formula 1 fans in Malaysia about scam merchandise stores ahead of Sepang return

Kaspersky is warning that fake Formula 1 merchandise storefronts are targeting fans in Malaysia ahead of F1's return to Sepang International Circuit from 2 to 4 October 2026, after a 9-year absence. The scam sites copy real team logos and driver imagery, offer search, accounts, carts and 'global delivery', then capture card details at checkout without shipping anything. Kaspersky's Asia Pacific MD Adrian Hia attributes this to fans dropping their guard during major events, and the article advises checking URLs, buying only from LazMall or Shopee Mall verified stores, and reporting to the National Scam Response Centre on 997.

Why: This is a consumer scam-awareness notice, not a technical disclosure — there are no new attack techniques, no IOCs, and nothing here changes how you build or ship software. The only concrete operational detail worth keeping is the Malaysian reporting path: victims are told to call the National Scam Response Centre on 997, and the advice names LazMall and Shopee Mall as the verification markers on local marketplaces. If your product touches Malaysian ecommerce checkout or payment flows, that's the extent of the actionable content.

Top