Your unpatched systems may be a ticking bomb.
Latest data from cybersecurity and privacy company Kaspersky revealed that existing vulnerabilities in business networks continue to leave Malaysian enterprises exposed to cyberattacks.
As Malaysia accelerates its digitalisation agenda, with the digital economy expected to contribute 30% of national GDP by 2030, local businesses are increasingly at risk. In the first half of 2025 alone, Kaspersky’s enterprise solutions blocked more than 190,556 exploit attempts, averaging over 1,050 attacks a day. This marks a 16% increase from the same period last year, indicating a clear upward trend as digital infrastructure expands.
Within Southeast Asia, Malaysia ranks third in terms of exploit volume, behind Indonesia (524,657) and Vietnam (301,800).
Exploits are malicious programs designed to take advantage of bugs or vulnerabilities in software or operating systems to gain unauthorised access. When left unpatched, these weak points act as open doors for cybercriminals.
Globally, in Q2 2025, the most common exploits targeted vulnerable Microsoft Office products with unpatched security flaws, according to Kaspersky’s findings. Its solutions detected the most exploits on the Windows platform for the following vulnerabilities:
- CVE-2018-0802: Remote code execution vulnerability in the Equation Editor component
- CVE-2017-11882: Another remote code execution vulnerability in Equation Editor
- CVE-2017-0199: Vulnerability in Microsoft Office and WordPad allowing attackers to gain control of the system
The report also revealed that the top 10 most exploited vulnerabilities included both new zero-day flaws and older unpatched issues that organisations continue to overlook. A zero-day vulnerability is a software flaw discovered by attackers before the vendor is aware of it. As no patch exists at the time, zero-day attacks often succeed.
Cybercriminals — and, in some cases, advanced persistent threat (APT) groups — are increasingly targeting widely used tools such as remote access software, document editors, and logging systems. Notably, low-code/no-code (LCNC) platforms and frameworks for AI-powered applications have also entered the list, signalling that attackers are adapting quickly to exploit newer technologies. Their goals remain consistent: to gain system access and escalate privileges, granting long-term control inside corporate networks.
LCNC platforms are development tools that allow users to build applications through visual interfaces and drag-and-drop components, with minimal coding knowledge. These enable both non-technical users and IT teams to create web and mobile apps more efficiently.
“A 16% jump in exploit attempts against Malaysian businesses in just six months highlights how relentless these attackers have become. As the country’s online economy expands, closing the gap in unpatched systems is not just about avoiding attacks but fortifying the nation’s digital progress. Threat intelligence tells us exactly where attackers are focusing, so Malaysian enterprises can strengthen defences before the damage is done,” said Adrian Hia, Managing Director for Asia Pacific at Kaspersky.
Overall, companies in Malaysia encountered 1,703,788 B2B web-based threats in the first six months of 2025, making Malaysia the second most targeted country in Southeast Asia — surpassing Indonesia (1,626,984) and trailing only Thailand (2,524,439).
Web threats refer to malware programs that target users during online activity. While they primarily exploit internet access points, they can also cause harm offline after initial infection.
Recommendations
In light of the rising threat landscape, Kaspersky recommends organisations:
Use the latest Threat Intelligence to understand evolving tactics, techniques, and procedures (TTPs) used by threat actors.
Investigate vulnerability exploits within secure virtual environments.
Ensure 24/7 infrastructure monitoring, with emphasis on perimeter defences.
Maintain a robust patch management process by promptly installing security updates.
Deploy comprehensive cybersecurity solutions that include incident response, employee training, and access to updated threat intelligence.