Multiple Malaysian government websites have been compromised in a series of cyberattacks, the National Cyber Security Agency (NACSA) confirmed. The attacks are believed to have exploited a critical security flaw in a widely used website content management system (CMS) called Joomla, in which hackers managed to perform remote code execution (RCE) via the compromised software.
The affected government websites include those of the Ministry of Health (MOH), the Malaysia Co-operative Societies Commission (SKM), the Handicraft Development Corporation (Kraftangan Malaysia), and the Women’s Development Department (JPW). The MOH’s official portal, moh.gov.my, was rendered inaccessible following the attack, with screenshots of the defaced homepage rapidly circulating on social media.
NACSA: Critical Joomla Bug Exposes Govt Websites To Hackers
In an advisory published on June 26 via the National Cyber Coordination and Command Centre (NC4) website, NACSA identified a critical vulnerability in a content editing extension used by Joomla. This exploit allows a remote attacker to create rogue CMS editor profiles and upload and execute arbitrary PHP code, resulting in full pre-authentication remote code execution (RCE) on the affected web server. In other words, hackers could gain complete control of a website without ever needing a valid login.
According to NACSA’s advisory, a successful exploit of this vulnerability – rated at full CVSS 10.0 score, meaning the highest level of criticality – could enable attackers to deface websites, steal sensitive data, establish persistent backdoor for future access, move laterally across connected systems within the same hosting environment, and in the most extreme cases, achieve a complete takeover of the hosting environment.

MOH earlier confirmed the hack and urged the public to avoid accessing www.moh.gov.my until further notice; since then, the website has entered maintenance status to get it back online. “The ministry takes this incident seriously and is working closely with relevant agencies to strengthen system security and prevent a recurrence,” MOH said, adding that all official health information and announcements would continue to be channeled through its social media platforms and other verified channels during the disruption.
At the same time, NACSA has called on all Malaysian government agencies and organizations using Joomla’s content management system to take immediate action. Key recommendations include updating the Joomla Content Editor to version 2.9.99.6, or at minimum version 2.9.99.5; for organizations unable to meet the system requirements for these versions, free patches are available from the software provider.
All organizations are also urged to report any indicators of compromise or cybersecurity incidents to NC4 in accordance with the Cyber Security Act 2024 (Act 854), which mandates reporting for National Critical Information Infrastructure (NCII) entities. “Malaysian NCII entities affected by this advisory are advised to report indicators or incidents to NC4 as per required under Act 854 for national coordination and intelligence sharing,” the agency stated.
Sources: The Star | Malay Mail
Pokdepinion: There’s an important lesson to be learned here: always make sure security is up to snuff.

