Skip to main content
A Singapore Government Agency Website How to identify
Official website links end with .gov.sg
Secure websites use HTTPS
Look for a lock () or https:// as an added precaution. Share sensitive information only on official, secure websites.
Government officials will never ask you to transfer money or disclose bank log-in details over a phone call.
Cyber Security Agency of Singapore

Alerts & Advisories

Provides alerts and advisories on emerging cyber threats, vulnerabilities, and preventive measures to help individuals and organisations stay secure online.

1218 items

28 August 2026

Active Exploitation of Vulnerabilities in Microsoft SharePoint

Attackers are exploiting multiple vulnerabilities in Microsoft SharePoint Server to bypass a security feature and run code over a network. Patch immediately.

27 August 2026

Critical Vulnerability in Apache Tomcat

Attackers can exploit a critical vulnerability in Apache Tomcat to bypass security constraints and gain unauthorised access to protected resources. Patch immediately.

26 August 2026

Active Exploitation of Vulnerability in Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-In

Attackers are exploiting a critical vulnerability in Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-In to access, change or delete critical data. Patch immediately.

26 August 2026

Vulnerabilities in Privileged Access Management Application “Admin By Request”

Two vulnerabilities have been discovered in the privileged access management application “Admin By Request” (ABR). The product owner has rolled out fixes for both reported vulnerabilities. Special thanks to the researchers and ABR for coordinating through CSA's Responsible Vulnerability Disclosure Policy.

26 August 2026

Understanding Passwordless Authentication

Passwords have been the primary method of authentication for decades, but they remain a common target for threat actors. It's time to rethink how we verify identities online.

26 August 2026

Security Bullentin 26 Aug 2026 [PDF, 2MB]

(opens in new tab)

21 August 2026

High-Severity Vulnerability in Zimbra Collaboration Suite

Attackers can exploit a high-severity vulnerability in Zimbra Collaboration Suite to achieve remote code execution. Patch immediately.

20 August 2026

Multiple Vulnerabilities in Zoom Products

Attackers can exploit multiple vulnerabilities in Zoom products to perform remote code execution, denial of service or disclose sensitive information. Users and administrators of affected products are advised to apply the latest security updates promptly.

19 August 2026

Security Bulletin 19 Aug 2026 [PDF, 2MB]

(opens in new tab)

18 August 2026

Multiple Vulnerabilities in HPE Aruba Networking Private 5G Core

Attackers can exploit multiple vulnerabilities in HPE Aruba Networking Private 5G Core affecting third-party components Traefik and Grafana to spoof identities and escalate privileges. Patch promptly.