Back Vietnam.Vn Many Malaysian government agencies were subjected to cyberattacks.
The affected websites include the Malaysian Ministry of Health (MOH), the Malaysian Cooperative Commission, the Handicraft Development Corporation, and the Joint Development for Women (JPW).
Among these incidents, the website of the Malaysian Ministry of Health was reportedly attacked by a group of hackers calling themselves “Mushr00w”, rendering the website inaccessible for a certain period of time.
In a statement, the National Network Command and Control Center (NC4) announced the discovery of a vulnerability in the content editor utility of the Joomla content management system (CMS), allowing hackers to create fake editor accounts, upload and execute PHP code on remote servers without logging in, thereby gaining control of the system even before authentication.
According to NC4, security vulnerabilities can allow hackers to maintain access through "backdoors," thereby stealing data, altering website content, extending intrusions to other servers and systems within the same network, or gaining complete control of the hosting environment. This increases the risk to data security, integrity, and availability.
NC4 has requested that units within Malaysia's National Critical Information Infrastructure (NCII) immediately report any anomalies or incidents as required by Act 854 to facilitate the coordination and sharing of cybersecurity intelligence at the national level.
Meanwhile, Nacsa also recommends that organizations using the Joomla database management system urgently upgrade to the latest version or update with the free "patches" provided by the manufacturer to minimize the risk of exploitation.
Source:
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
