top of page
All Posts


KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials
In mid September 2026, cybersecurity research uncovered a Brazilian banking malware operation delivering a complex threat toolkit named KREMLIN. Tracked by researchers as REF9334 and active since at least May 2025, the threat cluster predominantly targets Brazilian financial institutions and banking users through localized lures written in Portuguese. Despite its name, the operation shows no connection to Russian state actors. The core objective of the toolkit is to bypass Ch
akidh2
2 days ago2 min read


Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
In mid September 2026, cybersecurity research detailed active campaigns by three distinct threat activity clusters targeting Russian commercial and government organizations. The operations, conducted by groups identified as NightEagle, Hacking Cat, and Toy Ghouls, demonstrate a convergence of cyber espionage, pro Ukrainian hacktivism, and financial extortion. The campaigns weaponize valid credentials, Microsoft Exchange vulnerabilities, and specialized remote management tools
akidh2
2 days ago2 min read


DeepSeek Harness Flaw Allows AI Agents to Disable Their Own File Sandbox
In early September 2026, cybersecurity researchers disclosed a critical security vulnerability in DeepSeek Harness, an open source local framework for running AI coding agents on developer machines. Tracked as CVE-2026-82533 with a CVSS severity score of 9.4, the flaw allowed sandboxed AI coding agents to unilaterally turn off their own sandbox restrictions and disable user approval prompts using a single shell command. Technical Architecture and Sandbox Escape Mechanics Th
akidh2
Sep 101 min read


Four Espionage Groups Share BlueMoon Exploit Kit Within One Week
In early September 2026, cybersecurity researchers revealed that four distinct cyber espionage groups deployed an undocumented exploit kit called BlueMoon within a single week. Initially observed in late August 2026 during operations linked to the China aligned threat group APT31, the exploit kit quickly spread across multiple threat clusters, predominantly with suspected China nexuses. The rapid sharing of a fully weaponized exploit chain across multiple state sponsored grou
akidh2
Sep 102 min read


Active Exploitation of Chrome V8 Zero Day Allows Remote Code Execution inside Sandbox
In early September 2026, Google released emergency security updates for Google Chrome across Windows, macOS, and Linux platforms to address a high severity vulnerability actively exploited in the wild. Tracked as CVE-2026-85046, the flaw marks the sixth actively exploited zero day vulnerability resolved in the Chrome browser during 2026. The underlying security defect resides within V8, the open source JavaScript and WebAssembly execution engine that powers Chrome and downstr
akidh2
Sep 101 min read


Threat Actors Do Not Want Better Attacks, They Want Repeatable Ones
In early September 2026, cybersecurity analysis highlighted a fundamental shift in cybercrime economics, demonstrating that modern threat actors prioritize standardized, repeatable operations over novel or complex attack techniques. Cybercrime functions primarily as a volume business under financial pressure, where falling revenue per intrusion incentivizes adversaries to minimize operational costs. Instead of crafting unique exploits for every target, attack groups scale the
akidh2
Sep 21 min read


Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds
In early September 2026, cybersecurity researchers identified thirteen malicious Composer theme packages hosted on the official Packagist repository. Published across five distinct vendor namespaces, these libraries masquerade as legitimate, high quality front end themes for popular open source PHP content management systems like OphimCMS and KKPhim, which are widely used to power video streaming and online comic websites. Once an unsuspecting platform administrator installs
akidh2
Sep 22 min read


Critical Vulnerability in JFrog Artifactory Exploited to Mint Admin Tokens
In late August 2026, security researchers warned that threat actors began actively exploiting a newly disclosed critical security vulnerability in JFrog Artifactory. Tracked as CVE-2026-82329 with a maximum CVSS severity score of 9.8, the flaw allows unauthenticated attackers with network access to bypass authentication and gain full administrative privileges on vulnerable self-hosted instances under default configurations. Exploitation Dynamics and Attacker Activity Security
akidh2
Sep 21 min read


The Widening Gap in Financial Impact and the Rise of Shadow AI
The latest findings from IBM's annual cybersecurity research reveal a major geographical divergence in the financial impact of data breaches across the globe. While the global average cost of a breach dropped by nine percent to 4.44 million dollars, marking the first major decline in five years, the average cost in the United States surged by nine percent to reach an all-time record high of 10.22 million dollars per incident. This global cost reduction is primarily driven by
akidh2
Aug 102 min read


SourTrade: The Campaign That Turns Your Browser into a Malware Factory
In late July 2026, security researchers exposed a clever malvertising campaign named SourTrade that had been active since late 2024. This operation targets cryptocurrency investors and financial traders across twelve countries by setting up deceptive ads that impersonate well-known trading platforms such as TradingView, Solana, and Luno. What makes SourTrade exceptionally dangerous is not merely the cloned websites, but the novel way it delivers its payload to the victim. Ins
akidh2
Jul 273 min read


Risk Assessment and Reporting (Quarterly Basis)
Cyber risks continue to evolve rapidly, making cybersecurity a continuous process rather than a one-time effort. Regular risk assessments are essential for organizations to identify new vulnerabilities, evaluate emerging threats, and ensure that existing security controls remain effective over time. Conducting risk assessments on a quarterly basis allows organizations to maintain visibility into their security posture while adapting to changes in technology, business operatio
akid95
May 212 min read


Developer Workstations Are Now Part of the Software Supply Chain
Recent cybersecurity research and industry reporting highlight how developer workstations are becoming a major target in modern cyberattacks and software supply chain operations. Rather than focusing only on servers or traditional endpoints, attackers are increasingly targeting developer environments because they often contain privileged access to source code repositories, cloud infrastructure, CI/CD pipelines, containers, and sensitive enterprise systems. As organizations co
akid95
May 203 min read


MyCERT Report - Cyber Incident Quarterly Summary Report - Q4 2025
Recent advisories and reports published by CyberSecurity Malaysia and the MyCERT Advisory Portal highlight the growing volume and sophistication of cyber threats affecting both organizations and individual users in Malaysia. Through its Cyber999 Incident Response Centre, CyberSecurity Malaysia continues to monitor, investigate, and publish alerts related to malware, phishing, mobile threats, vulnerabilities, and large-scale cyber incidents impacting the country. Rising Threat
akid95
May 182 min read


Android Adds Intrusion Logging for Sophisticated Spyware Forensics
Google has introduced a new security capability called Android Intrusion Logging, aimed at improving the detection and forensic investigation of advanced mobile spyware and targeted surveillance operations. The feature is being rolled out as part of Android Advanced Protection Mode and is designed primarily for high-risk users such as journalists, activists, government officials, and human rights defenders who are more likely to face sophisticated mobile attacks. Unlike tradi
akid95
May 153 min read


Unlimited Remote Support for EDR and Firewall
Effective cybersecurity is not only about deploying security solutions but it is also about ensuring those solutions are continuously supported, maintained, and optimized. Through unlimited remote support for Endpoint Detection and Response (EDR) and firewall technologies, organizations gain direct access to experienced security professionals who can assist with day-to-day security operations, troubleshooting, and incident-related concerns. This support helps reduce operation
akid95
May 141 min read


Microsoft Patches 138 Vulnerabilities, Including DNS and Netlogon RCE Flaws
Microsoft’s May 2026 Patch Tuesday release addressed 138 security vulnerabilities across its ecosystem, including Windows, Office, Azure, Edge, SQL Server, .NET, and Copilot-related products. Among these, 30 vulnerabilities were rated Critical, reflecting the growing complexity and scale of security risks affecting modern enterprise environments. Several of the patched flaws impact core Windows networking and authentication components such as DNS Client and Netlogon, making t
akid95
May 142 min read


Fake Call History Apps Stole Payments From Users After 7.3 Million Play Store Downloads
A large-scale Android scam campaign known as CallPhantom has recently been uncovered, involving deceptive applications distributed through the official Google Play Store. The apps falsely claimed they could provide access to sensitive information such as call histories, SMS records, and WhatsApp call logs for any phone number capabilities that legitimate Android applications cannot technically or legally perform. Despite these unrealistic claims, the campaign successfully att
akid95
May 133 min read


Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE
Modern web services depend heavily on stability at the infrastructure layer, and few components are as widely trusted as the Apache HTTP Server. That’s exactly why the disclosure of CVE-2026-23918 is drawing serious attention across the cybersecurity landscape. This newly identified flaw targets Apache’s HTTP/2 implementation (mod_http2) and carries a high severity rating (CVSS 8.8). What makes it particularly concerning isn’t just the technical detail, but the real-world imp
akid95
May 63 min read


Meet Bluekit: The AI-Powered All-in-One Phishing Kit
Phishing has steadily evolved from simple email scams into highly organized operations, but Bluekit marks a notable shift in how these attacks are built and delivered. Designed as a phishing-as-a-service (PhaaS) platform, Bluekit consolidates the entire attack lifecycle into a single, accessible interface, allowing attackers to launch campaigns with minimal technical effort. Its integration of AI-driven assistance further amplifies its effectiveness, enabling the rapid creati
akid95
May 44 min read


Gap Analysis (One-Time) Aligned with NIST CSF and RMF
Cybersecurity frameworks and standards play a critical role in helping organizations establish a structured and consistent approach to managing cyber risks. For organizations in Malaysia and across the globe, adopting recognized best practices ensures that security efforts are not only effective, but also aligned with international expectations and regulatory requirements. Frameworks provide a common language for assessing security posture, identifying gaps, and implementing
akid95
Apr 302 min read
bottom of page
