PROVINTELL Cyber Security

PROVINTELL Cyber Security Cyber Threat Intelligence | Continuous Threat Exposure Management (CTEM) | 24x7 AI Cyber Security Operation Center (AI SOC)

We Transform Intelligence Into Response

03/09/2026

Threat actors are actively compromising user accounts through session hijacking attacks powered by commodity malware. The attack chain begins with victims infected by common infostealer malware that extracts active browser session cookies and authentication tokens, allowing attackers to bypass password and multi-factor authentication protections entirely and gain immediate account access without triggering login prompts or security challenges. Once inside, threat actors systematically consume included usage allowances and prepaid credits, and if auto-reload is enabled, continue draining capacity until spending limits are reached or payment methods are exhausted. Organizations using for business operations face dual risks of financial loss through fraudulent usage charges and potential exposure of proprietary prompts, conversations, and uploaded documents containing sensitive business intelligence or customer data, as session hijacking attacks operate within legitimate authentication frameworks and require behavioral analytics to detect unusual consumption patterns or geographic anomalies.



Contributed by: Ahmad Akmal

Selamat Hari Merdeka 2026! As we celebrate 69th Hari Merdeka, let us honor the spirit of independence and embrace the va...
30/08/2026

Selamat Hari Merdeka 2026!

As we celebrate 69th Hari Merdeka, let us honor the spirit of independence and embrace the values of - (Kemampanan), (Kesejahteraan), (Daya Cipta), (Hormat), (Keyakinan), (Ihsan).

May we continue to grow together, strengthen our unity, build and share a more prosperous and inclusive Malaysia.

Together, We Rise. Together, We Progress.

Wishing everyone a joyful and meaningful Merdeka 2026.

Cybersecurity researchers have identified a large-scale campaign dubbed   that has compromised thousands of hashtag  web...
21/08/2026

Cybersecurity researchers have identified a large-scale campaign dubbed that has compromised thousands of hashtag websites by exploiting outdated installations and vulnerable plugins to deploy malicious PHP scripts and a custom must-use plugin for persistent access and remote code ex*****on. Attackers install a fake CAPTCHA plugin that delivers ClickFix-style prompts to Windows visitors, tricking them into executing PowerShell commands that trigger multi-stage infections involving .NET downloaders and loaders. The final-stage toolkit includes ransomware, credential and file stealers, network and USB propagation tools, lock-screen components, and attacker-victim chat utilities, though the campaign often prioritizes covert data theft over encryption. The compromised infrastructure serves as distributed storage for stolen files, screenshots, and activity logs, with over 700 stolen archives identified between May and July 2026 and more than 6,000 victim IP addresses observed by July 24. The campaign demonstrates how poorly maintained websites can be weaponized into resilient infrastructure for malware distribution, command-and-control, lateral movement, and data exfiltration.




Contributed by: Fatini

CODERED VTA StopAndProtect Campaign Exploits Thousands of WordPress Sites for Malware Delivery Medium 18 Aug 2026 Cybersecurity researchers have uncovered a large-scale cybercrime campaign, dubbed StopAndProtect, that has compromised thousands of WordPress websites and repurposed them as infrastruct...

A   at cryptocurrency hardware wallet provider   has compromised order information for approximately 39,798 customers af...
17/08/2026

A at cryptocurrency hardware wallet provider has compromised order information for approximately 39,798 customers after a threat actor exploited a flaw in a plugin related to customer information systems. The attacker successfully executed an exploitation chain involving initial access, privilege escalation, and data exfiltration, with the stolen customer data now being actively sold by the threat actor. While the specific technical details of the vulnerability remain undisclosed, the attack likely incorporated social engineering or phishing tactics to facilitate unauthorized access to sensitive customer records. The incident underscores critical security gaps in cryptocurrency wallet infrastructure, particularly regarding access controls and data encryption, with affected customers now facing elevated risks of identity theft and financial fraud. Organizations in the cryptocurrency and financial sectors must prioritize implementing robust security measures including enhanced access controls, comprehensive data encryption, and continuous security monitoring to prevent similar breaches.



Contributed by: Esther Bala

  has patched a critical authentication bypass vulnerability in  , tracked as   with a CVSS score of 9.1, that allows un...
13/08/2026

has patched a critical authentication bypass vulnerability in , tracked as with a CVSS score of 9.1, that allows unauthenticated attackers to forge JWT tokens and impersonate any site user or administrator. The flaw exploits weaknesses in the JWT token validation pipeline for Bearer service-to-service tokens, enabling attackers to bypass signing key and issuer verification, then leverage the forged token to enumerate domain users via LDAP queries and identify site administrators. Following the release of proof-of-concept exploit code in July 2026, active exploitation has been observed with 12 recorded attempts as of August 13, 2026, including a notable spike of eight attempts on August 12-13.

Organizations running affected servers should immediately apply the July 2026 Patch Tuesday updates to mitigate the risk of unauthorized file disclosure and data modification.



Contributed by: Lim Min Wei

A critical security vulnerability in Microsoft SharePoint has been disclosed, allowing attackers to bypass authentication and perform arbitrary operations as a SharePoint site user or administrator. The vulnerability, identified as CVE-2026-55040, has a CVSS score of 9.1 and affects SharePoint serve...

12/08/2026

has issued emergency patches for , a zero-day vulnerability in Secure Firewall and software that enables remote, unauthenticated attackers to trigger denial-of-service conditions by sending specially crafted HTTP requests to the Remote Access SSL VPN service. Active exploitation has been confirmed in the wild since August 2026, with the flaw allowing threat actors to force firewall appliances to reload by exploiting weaknesses in HTTP parsing logic, creating network security blind spots that can mask secondary attacks or data exfiltration. has added the vulnerability to its Known Exploited Vulnerabilities catalog with a federal patching deadline of August 14, marking the twelfth Cisco product vulnerability on the KEV list in 2026 and reflecting sustained adversary focus on Cisco infrastructure including SD-WAN, Unified Communications Manager, and Firepower platforms. The low exploitation complexity combined with no authentication requirement and the critical role of firewalls in network perimeter defense creates an urgent patching imperative for organizations relying on these security appliances.



Contributed by: Anas Danial

A sophisticated software supply chain attack has been discovered targeting   developer tools through 18 malicious   pack...
04/08/2026

A sophisticated software supply chain attack has been discovered targeting developer tools through 18 malicious packages including lib-mtop, aone-kit, and local-config-parser that impersonate legitimate private packages from the scope. The malicious packages contain loaders that fetch remote JavaScript payloads via curl and execute them, establishing a cross-platform remote access trojan on infected systems. The attack chain employs a multi-stage dependency tree where top-layer packages act as decoys to trigger installation of malicious dependencies, with a rule engine executing final payloads that contact command-and-control infrastructure masquerading as Alibaba domains to evade detection. The campaign appears focused on industrial espionage targeting Chinese-speaking developers within Alibaba Group companies, though its full impact remains difficult to assess due to targeted delivery and lateral movement capabilities. Organizations that may have installed these packages should assume compromise, immediately rotate credentials from clean systems, and conduct thorough audits of developer environments for indicators of malicious activity.



Contributed by: Anas Danial

A sophisticated software supply chain attack has been uncovered, targeting users of Alibaba developer tools with a cross-platform remote access trojan. The attack involves 18 malicious npm packages, including lib-mtop, aone-kit, and local-config-parser, which are designed to impersonate private pack...

Security researchers have identified active exploitation of  , a critical remote code ex*****on vulnerability with a CVS...
28/07/2026

Security researchers have identified active exploitation of , a critical remote code ex*****on vulnerability with a CVSS score of 9.0 affecting hashtag versions 1.2.68 through 1.2.83. The flaw enables unauthenticated attackers to execute arbitrary code on vulnerable fat-JAR applications by sending malicious JSON payloads that abuse Fastjson's type resolution mechanism, bypassing validation through annotation-based trust without requiring AutoType enablement or classpath gadgets. Exploitation attempts have been observed targeting financial services, healthcare, retail, and technology sectors, with attacks focusing on applications exposing JSON.parse, JSON.parseObject(String), or JSON.parseObject(String, Class) methods that deserialize user-controlled data into Object or Map fields. No patched Fastjson 1.x release is currently available, prompting recommendations to enable SafeMode, deploy the restricted 1.2.83_noneautotype build as an interim measure, and prioritize migration to hashtag , which remains unaffected by this vulnerability. Organizations running affected configurations should conduct immediate assessments of exposed parsing endpoints and implement compensating controls until full remediation is achievable.



Contributed by: Fatini

Attackers successfully breached Thailand's Ministry of Finance using  , an open-source AI agent framework, to conduct au...
28/07/2026

Attackers successfully breached Thailand's Ministry of Finance using , an open-source AI agent framework, to conduct autonomous reconnaissance and data collection in what represents one of the first documented cases of adversaries weaponizing autonomous for nation-state espionage.

Deployed in unrestricted " without safety guardrails, operated independently to navigate networks, execute lateral movement, and exfiltrate data at machine speed following initial access gained through conventional vectors like spear-phishing. The AI agent's ability to dynamically adjust to environmental feedback and bypass security controls significantly compressed typical dwell times and reduced manual operational overhead for attackers. This incident demonstrates the active deployment of AI-augmented cyber espionage that lowers the skill barrier for adversaries and enables scalable attacks across multiple targets. Organizations must now develop detection strategies focused on identifying autonomous behavior patterns such as unusually rapid enumeration and non-human API timing, while prioritizing strict network segmentation, enhanced logging, and advanced behavioral analytics to counter this emerging threat vector.



Contributed by: Anas Danial

Attackers breached Thailand's Ministry of Finance using Hermes, an open-source AI agent framework, to conduct autonomous reconnaissance and data collection. The Ministry, holding sensitive fiscal and economic intelligence, is a high-value target for nation-state espionage. This incident is one of th...

On 4 April 2026, we will be introducing our CodeRed-AI CoPilot ( ), which is integrated into our upgraded   3.0 providin...
02/04/2026

On 4 April 2026, we will be introducing our CodeRed-AI CoPilot ( ), which is integrated into our upgraded 3.0 providing our SOC analysts and customers with AI-native threat hunting capabilities on external and internal threats.

We named our AI agent "Ask SIMON", in our tribute and memory of The Late Simon Teh Seng Meng, who departed on 4 April 2022. He was our first SOC Manager, and best to be remembered as a good friend and dedicated colleague.

May his legacy and dedication to cybersecurity industry lives on.

Address

A-6-07, Oasis Ara Damansara, No. 2, Jalan PJU 1A/7A
Petaling Jaya
47301

Alerts

Be the first to know and let us send you an email when PROVINTELL Cyber Security posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to PROVINTELL Cyber Security:

Shortcuts

Share