<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Rectifyq: Threat Intelligence focusing on Malaysia</title>
    <link>https://rectifyq.com/</link>
    <atom:link href="https://rectifyq.com/index.xml" rel="self" type="application/rss+xml" />
    <description>Latest Malaysian threat intelligence from Rectifyq: threat entries, ransomware and data-breach claims, and the monthly Rectifyq Radar.</description>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 11:26:49 GMT</lastBuildDate>
    <item>
      <title>2026-09 September Malaysian Threat Landscape Recap</title>
      <link>https://rectifyq.com/my-threat-landscape/radar/2026-09</link>
      <guid isPermaLink="true">https://rectifyq.com/my-threat-landscape/radar/2026-09</guid>
      <pubDate>Thu, 01 Oct 2026 00:00:00 GMT</pubDate>
      <category>my-threat-landscape/radar</category>
      <description>September 2026 Malaysian Threat Landscape Recap — a cyber incident halts Port of Tanjung Pelepas with Direwolf claiming responsibility, 2 ransomware claims, and the October community calendar.</description>
    </item>
    <item>
      <title>2026-08 August Malaysian Threat Landscape Recap</title>
      <link>https://rectifyq.com/my-threat-landscape/radar/2026-08</link>
      <guid isPermaLink="true">https://rectifyq.com/my-threat-landscape/radar/2026-08</guid>
      <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
      <category>my-threat-landscape/radar</category>
      <description>August 2026 Malaysian Threat Landscape Recap — 8 ransomware claims led by Qilin, a fake Park@Perak site delivering an iOS exploit chain, AI-driven exploitation of a Malaysian government entity, and the September–October community calendar.</description>
    </item>
    <item>
      <title>2026-07 July Malaysian Threat Landscape Recap</title>
      <link>https://rectifyq.com/my-threat-landscape/radar/2026-07</link>
      <guid isPermaLink="true">https://rectifyq.com/my-threat-landscape/radar/2026-07</guid>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
      <category>my-threat-landscape/radar</category>
      <description>July 2026 Malaysian Threat Landscape Recap — 9 ransomware claims, active Android banking trojans, government website compromises, and the August–September community calendar.</description>
    </item>
    <item>
      <title>Defining the Scope of CTI under BNM RMiT</title>
      <link>https://rectifyq.com/tanya-rectifyq/2026-06-what-is-the-scope-of-cti</link>
      <guid isPermaLink="true">https://rectifyq.com/tanya-rectifyq/2026-06-what-is-the-scope-of-cti</guid>
      <pubDate>Sun, 19 Jul 2026 00:00:00 GMT</pubDate>
      <category>tanya-rectifyq</category>
      <description>Anonymized DM guidance on determining the scope of Cyber Threat Intelligence (CTI), evaluating In-house vs Managed TI, and local Malaysian providers for BNM RMiT compliance.</description>
    </item>
    <item>
      <title>TBD</title>
      <link>https://rectifyq.com/my-threat-landscape/vulnerabilities/2026-w28</link>
      <guid isPermaLink="true">https://rectifyq.com/my-threat-landscape/vulnerabilities/2026-w28</guid>
      <pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate>
      <category>my-threat-landscape/vulnerabilities</category>
      <description>TBD</description>
    </item>
    <item>
      <title>2026-06 June Malaysian Threat Landscape Recap</title>
      <link>https://rectifyq.com/my-threat-landscape/radar/2026-06</link>
      <guid isPermaLink="true">https://rectifyq.com/my-threat-landscape/radar/2026-06</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
      <category>my-threat-landscape/radar</category>
      <description>June 2026 Malaysian Threat Landscape recap — 7 ransomware claims, active Android banking trojans, government website compromises, and July's community calendar.</description>
    </item>
    <item>
      <title>2026-06-27 Nacsa says Health Ministry, other govt agency websites hacked; urges immediate patch to fix vulnerability</title>
      <link>https://rectifyq.com/my-threat-landscape/threats/409f7b4d-207e-4bad-8938-248248604dd4</link>
      <guid isPermaLink="true">https://rectifyq.com/my-threat-landscape/threats/409f7b4d-207e-4bad-8938-248248604dd4</guid>
      <pubDate>Sat, 27 Jun 2026 00:00:00 GMT</pubDate>
      <category>my-threat-landscape/threats</category>
      <description>Nacsa says Health Ministry, other govt agency websites hacked; urges immediate patch to fix vulnerability (Jun 2026). Source: thestar.com.my. Rectifyq assessment: Highly Relevant to Malaysia. Report. Targets: Malaysia.</description>
    </item>
    <item>
      <title>2026-06-25 SharpPanda Strike Again</title>
      <link>https://rectifyq.com/my-threat-landscape/threats/c43ea1a9-5308-43d7-a187-048d2b65e20b</link>
      <guid isPermaLink="true">https://rectifyq.com/my-threat-landscape/threats/c43ea1a9-5308-43d7-a187-048d2b65e20b</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate>
      <category>my-threat-landscape/threats</category>
      <description>SharpPanda Strike Again (Jun 2026). Source: research.pelagos-intel.com. Rectifyq assessment: Highly Relevant to Malaysia. Malware analysis. Targets: France, Malaysia.</description>
    </item>
    <item>
      <title>2026-06-22 MA-1464.062026 MyCERT Alert - Malware Campaign Delivering Malicious VBScript via WhatsApp Desktop</title>
      <link>https://rectifyq.com/my-threat-landscape/threats/3c5282e4-a4e0-480a-8928-fe0c8c443494</link>
      <guid isPermaLink="true">https://rectifyq.com/my-threat-landscape/threats/3c5282e4-a4e0-480a-8928-fe0c8c443494</guid>
      <pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate>
      <category>my-threat-landscape/threats</category>
      <description>MA-1464.062026: MyCERT Alert - Malware Campaign Delivering Malicious VBScript via WhatsApp Desktop (Jun 2026). Source: MyCERT. Rectifyq assessment: Highly Relevant to Malaysia. Campaign analysis. Targets: Malaysia.</description>
    </item>
    <item>
      <title>2026-06-22 An unknown actor distributes malicious VBS scripts via WhatsApp</title>
      <link>https://rectifyq.com/my-threat-landscape/threats/ef37da5f-f14c-4d52-88ff-af1dfd7fccd9</link>
      <guid isPermaLink="true">https://rectifyq.com/my-threat-landscape/threats/ef37da5f-f14c-4d52-88ff-af1dfd7fccd9</guid>
      <pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate>
      <category>my-threat-landscape/threats</category>
      <description>An active malware campaign has been discovered distributing malicious VBScript files through WhatsApp direct messages since June 2026. The operation affects users across multiple countries, with Malaysia experiencing the highest concentration of victims.</description>
    </item>
    <item>
      <title>2026-06-FortiBleed</title>
      <link>https://rectifyq.com/my-threat-landscape/breaches/2026-06-fortibleed</link>
      <guid isPermaLink="true">https://rectifyq.com/my-threat-landscape/breaches/2026-06-fortibleed</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <category>my-threat-landscape/breaches</category>
      <description>Massive credential leak and brute-force campaign targeting internet-facing FortiGate firewalls globally, prompting a High-Severity advisory from NC4.</description>
    </item>
    <item>
      <title>2026-06-17 More Than 4,000 Legacy Routers Compromised by AryStinger, Turned into Global Attack Proxies for Hackers</title>
      <link>https://rectifyq.com/my-threat-landscape/threats/65db42c9-e25b-479e-95cf-d21fd34c73ae</link>
      <guid isPermaLink="true">https://rectifyq.com/my-threat-landscape/threats/65db42c9-e25b-479e-95cf-d21fd34c73ae</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <category>my-threat-landscape/threats</category>
      <description>Security researchers discovered AryStinger, a botnet targeting legacy routers and NAS devices to build reconnaissance and attack infrastructure.</description>
    </item>
    <item>
      <title>2026-06-17 Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign</title>
      <link>https://rectifyq.com/my-threat-landscape/threats/f66d7792-44c8-4b5a-8f0e-7357bd8352cb</link>
      <guid isPermaLink="true">https://rectifyq.com/my-threat-landscape/threats/f66d7792-44c8-4b5a-8f0e-7357bd8352cb</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <category>my-threat-landscape/threats</category>
      <description>Cybercriminals orchestrated a sophisticated malvertising operation leveraging Google Ads to impersonate popular AI developer tools including Claude AI, ChatGPT Codex, Perplexity, Cursor IDE, and JetBrains.</description>
    </item>
    <item>
      <title>2026-06-15 Travel Phishing and Cyber Attacks are Surging in 2026, Growing 122% over the last 3 years How Cybercriminals Are Targeting Travelers in 2026</title>
      <link>https://rectifyq.com/my-threat-landscape/threats/be7ce1a3-06b7-40b8-baae-d4fa3adfba87</link>
      <guid isPermaLink="true">https://rectifyq.com/my-threat-landscape/threats/be7ce1a3-06b7-40b8-baae-d4fa3adfba87</guid>
      <pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate>
      <category>my-threat-landscape/threats</category>
      <description>The hospitality and travel sector experienced a dramatic surge in cyberattacks, with organizations facing an average of 2,291 weekly attacks in May 2026, representing a 24% year-over-year increase and a cumulative 122% rise since 2023.</description>
    </item>
    <item>
      <title>2026-06-11 Cyber-Enabled Maritime Sanctions Evasion</title>
      <link>https://rectifyq.com/my-threat-landscape/threats/64d4b916-e459-44a4-80d0-636de8f9c850</link>
      <guid isPermaLink="true">https://rectifyq.com/my-threat-landscape/threats/64d4b916-e459-44a4-80d0-636de8f9c850</guid>
      <pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate>
      <category>my-threat-landscape/threats</category>
      <description>Iranian and Russian shadow fleet vessels are utilizing sophisticated online infrastructure consisting of over 36 inauthentic websites to facilitate sanctions evasion.</description>
    </item>
    <item>
      <title>2026-06-10 Phantom Casino</title>
      <link>https://rectifyq.com/my-threat-landscape/threats/2603f2d2-024d-4874-a26c-074a965ff561</link>
      <guid isPermaLink="true">https://rectifyq.com/my-threat-landscape/threats/2603f2d2-024d-4874-a26c-074a965ff561</guid>
      <pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate>
      <category>my-threat-landscape/threats</category>
      <description>Phantom Casino (Jun 2026). Source: syntx.com.my. Rectifyq assessment: Highly Relevant to Malaysia. Infra profile. Targets: Malaysia.</description>
    </item>
    <item>
      <title>What does TLP:CLEAR actually mean?</title>
      <link>https://rectifyq.com/tanya-rectifyq/2026-06-what-is-tlp</link>
      <guid isPermaLink="true">https://rectifyq.com/tanya-rectifyq/2026-06-what-is-tlp</guid>
      <pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate>
      <category>tanya-rectifyq</category>
      <description>Tanya Rectifyq — Traffic Light Protocol explained for the Malaysian community: what each TLP level allows and why practitioners should care.</description>
    </item>
    <item>
      <title>2026-06-08 Old WinRAR Flaw Fuels Attacks on Ukraine How Unmanaged Software Keeps the Door Open</title>
      <link>https://rectifyq.com/my-threat-landscape/threats/19d42e7a-969a-4f87-8931-af8fecb5aa8b</link>
      <guid isPermaLink="true">https://rectifyq.com/my-threat-landscape/threats/19d42e7a-969a-4f87-8931-af8fecb5aa8b</guid>
      <pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate>
      <category>my-threat-landscape/threats</category>
      <description>Two Russia-aligned campaigns continue exploiting CVE-2025-8088, a WinRAR path traversal vulnerability patched in July 2025, against Ukrainian organizations through April 2026.</description>
    </item>
    <item>
      <title>2026-06-06 MA-1451.062026 MyCERT Advisory - Multi-Variant Android Banking Trojan Campaign Targeting Malaysian Banking Users (Delivery4U / KerjaExpress / MaxTag)</title>
      <link>https://rectifyq.com/my-threat-landscape/threats/c0fb7f53-b749-40f8-99b8-b7339530bb6f</link>
      <guid isPermaLink="true">https://rectifyq.com/my-threat-landscape/threats/c0fb7f53-b749-40f8-99b8-b7339530bb6f</guid>
      <pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate>
      <category>my-threat-landscape/threats</category>
      <description>MA-1451.062026: MyCERT Advisory - Multi-Variant Android Banking Trojan Campaign Targeting Malaysian Banking Users (Delivery4U / KerjaExpress / MaxTag) (Jun 2026). Source: MyCERT. Rectifyq assessment: Highly Relevant to Malaysia. Campaign analysis. Targets: Malaysia.</description>
    </item>
    <item>
      <title>2026-06-03 The Demon Arrives Later A Havoc Stager Hides Behind Microsoft Defender DLP</title>
      <link>https://rectifyq.com/my-threat-landscape/threats/636a805b-58f3-442e-9a0a-72b9d7e7f244</link>
      <guid isPermaLink="true">https://rectifyq.com/my-threat-landscape/threats/636a805b-58f3-442e-9a0a-72b9d7e7f244</guid>
      <pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate>
      <category>my-threat-landscape/threats</category>
      <description>Cybercriminals in Brazil are exploiting the country's electronic invoice system (Nota Fiscal eletrônica) to deliver Havoc framework implants.</description>
    </item>
    <item>
      <title>2026-06-03 TA4922 The Suspected Chinese Crime Group is Going Global</title>
      <link>https://rectifyq.com/my-threat-landscape/threats/6a7790d3-55d8-46c0-9903-9a5dc28211d9</link>
      <guid isPermaLink="true">https://rectifyq.com/my-threat-landscape/threats/6a7790d3-55d8-46c0-9903-9a5dc28211d9</guid>
      <pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate>
      <category>my-threat-landscape/threats</category>
      <description>TA4922 is a highly sophisticated Chinese-speaking threat actor demonstrating rapid operational tempo and continually evolving malware capabilities.</description>
    </item>
    <item>
      <title>2026-05-20 Premium Deception Uncovering a Global Android Carrier Billing Fraud Campaign</title>
      <link>https://rectifyq.com/my-threat-landscape/threats/441a0a60-4abf-4afc-8318-eee24dbf5b68</link>
      <guid isPermaLink="true">https://rectifyq.com/my-threat-landscape/threats/441a0a60-4abf-4afc-8318-eee24dbf5b68</guid>
      <pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate>
      <category>my-threat-landscape/threats</category>
      <description>Premium Deception: Uncovering a Global Android Carrier Billing Fraud Campaign (May 2026). Source: zimperium.com. Rectifyq assessment: Highly Relevant to Malaysia. Campaign analysis. Targets: Croatia, Malaysia, Romania, Thailand.</description>
    </item>
    <item>
      <title>2026-05-15 Custom Attack Tooling Including Undisclosed C2 Infrastructure Targeting Malaysian Organizations</title>
      <link>https://rectifyq.com/my-threat-landscape/threats/a30d2c51-b056-4b55-ad4d-971722af82d8</link>
      <guid isPermaLink="true">https://rectifyq.com/my-threat-landscape/threats/a30d2c51-b056-4b55-ad4d-971722af82d8</guid>
      <pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate>
      <category>my-threat-landscape/threats</category>
      <description>Custom Attack Tooling Including Undisclosed C2 Infrastructure Targeting Malaysian Organizations (May 2026). Source: oasis-security.io. Rectifyq assessment: Highly Relevant to Malaysia. Infra profile. Targets: Malaysia.</description>
    </item>
    <item>
      <title>2026-05-12 MA-1439.052026 MyCERT Alert - &quot;Boss Impersonation&quot; Scam Email</title>
      <link>https://rectifyq.com/my-threat-landscape/threats/322e6c2d-3cb5-48ba-a8fa-1f01eb2c380f</link>
      <guid isPermaLink="true">https://rectifyq.com/my-threat-landscape/threats/322e6c2d-3cb5-48ba-a8fa-1f01eb2c380f</guid>
      <pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
      <category>my-threat-landscape/threats</category>
      <description>MA-1439.052026: MyCERT Alert - &quot;Boss Impersonation&quot; Scam Email (May 2026). Source: MyCERT. Rectifyq assessment: Highly Relevant to Malaysia. Campaign analysis. Targets: Malaysia.</description>
    </item>
    <item>
      <title>2026-05-05 InstallFix and Claude Code How Fake Install Pages Lead to Real Compromise</title>
      <link>https://rectifyq.com/my-threat-landscape/threats/e30b1a07-b830-46e2-bf69-e67eee29d4af</link>
      <guid isPermaLink="true">https://rectifyq.com/my-threat-landscape/threats/e30b1a07-b830-46e2-bf69-e67eee29d4af</guid>
      <pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate>
      <category>my-threat-landscape/threats</category>
      <description>InstallFix and Claude Code: How Fake Install Pages Lead to Real Compromise (May 2026). Source: trendmicro.com. Rectifyq assessment: Highly Relevant to Malaysia. Malware analysis. Targets: Malaysia, Netherlands, Thailand, United States.</description>
    </item>
    <item>
      <title>2026-05-04 Fake PAIP Berhad Site Stealing Pahang Customers' Data and Water Bill Payments</title>
      <link>https://rectifyq.com/my-threat-landscape/threats/0a0479bf-0a6f-4a68-a7c4-4f464b202596</link>
      <guid isPermaLink="true">https://rectifyq.com/my-threat-landscape/threats/0a0479bf-0a6f-4a68-a7c4-4f464b202596</guid>
      <pubDate>Mon, 04 May 2026 00:00:00 GMT</pubDate>
      <category>my-threat-landscape/threats</category>
      <description>Fake PAIP Berhad Site Stealing Pahang Customers' Data and Water Bill Payments (May 2026). Source: penipu.my. Rectifyq assessment: Highly Relevant to Malaysia. Campaign analysis. Targets: Malaysia.</description>
    </item>
    <item>
      <title>2026-04-30 Inside Shadow-Earth-053 A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia</title>
      <link>https://rectifyq.com/my-threat-landscape/threats/327326e7-354a-45ba-b25e-363984f01010</link>
      <guid isPermaLink="true">https://rectifyq.com/my-threat-landscape/threats/327326e7-354a-45ba-b25e-363984f01010</guid>
      <pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate>
      <category>my-threat-landscape/threats</category>
      <description>Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia (Apr 2026). Source: trendmicro.com. Rectifyq assessment: Highly Relevant to Malaysia. Campaign analysis. Targets: India, Malaysia, Myanmar, Pakistan and others.</description>
    </item>
    <item>
      <title>2026-04-29 Phoenix Rising Exposing the PhaaS Kit Behind Global Mass Phishing Campaigns</title>
      <link>https://rectifyq.com/my-threat-landscape/threats/5109a940-ef8e-4cf9-a5c8-fdfc684aa6ae</link>
      <guid isPermaLink="true">https://rectifyq.com/my-threat-landscape/threats/5109a940-ef8e-4cf9-a5c8-fdfc684aa6ae</guid>
      <pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate>
      <category>my-threat-landscape/threats</category>
      <description>Phoenix Rising: Exposing the PhaaS Kit Behind Global Mass Phishing Campaigns (Apr 2026). Source: group-ib.com. Rectifyq assessment: Highly Relevant to Malaysia. Campaign analysis. Targets: Argentina, Australia, Belgium, Chile and others.</description>
    </item>
    <item>
      <title>2026-04-21 GhostCargo, a 5-years campaign</title>
      <link>https://rectifyq.com/my-threat-landscape/threats/9c16b2b8-dd25-4533-958e-97d8d1c92cca</link>
      <guid isPermaLink="true">https://rectifyq.com/my-threat-landscape/threats/9c16b2b8-dd25-4533-958e-97d8d1c92cca</guid>
      <pubDate>Tue, 21 Apr 2026 00:00:00 GMT</pubDate>
      <category>my-threat-landscape/threats</category>
      <description>GhostCargo, a 5-years campaign (Apr 2026). Source: syntx.com.my. Rectifyq assessment: Highly Relevant to Malaysia. Intrusion analysis. Targets: Malaysia.</description>
    </item>
    <item>
      <title>2026-04-08 A new Mac stealer targeting $10K+ crypto wallets</title>
      <link>https://rectifyq.com/my-threat-landscape/threats/c4af9327-6041-4a3b-99f2-33c7af75c9ad</link>
      <guid isPermaLink="true">https://rectifyq.com/my-threat-landscape/threats/c4af9327-6041-4a3b-99f2-33c7af75c9ad</guid>
      <pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate>
      <category>my-threat-landscape/threats</category>
      <description>A sophisticated macOS stealer called notnullOSX emerged in March 2026, developed by threat actor alh1mik (formerly 0xFFF) who returned after a 2023 exit from underground forums.</description>
    </item>
  </channel>
</rss>
