Skip to main content
A Singapore Government Agency Website How to identify
Official website links end with .gov.sg
Secure websites use HTTPS
Look for a lock () or https:// as an added precaution. Share sensitive information only on official, secure websites.
Government officials will never ask you to transfer money or disclose bank log-in details over a phone call.
Cyber Security Agency of Singapore

Alerts & Advisories

Provides alerts and advisories on emerging cyber threats, vulnerabilities, and preventive measures to help individuals and organisations stay secure online.

1241 items

30 September 2026

High-Severity Vulnerability in Apple Products

Attackers can exploit a high-severity vulnerability in Apple products to execute arbitrary code on affected devices. Patch immediately.

30 September 2026

Advisory on CARBONATO Botnet Campaign Targeting Exposed Docker Daemons

Security researchers have identified a botnet campaign known as CARBONATO targeting Docker hosts with unauthenticated Docker Remote APIs exposed to the Internet. Organisations operating Docker environments are advised to review their configurations and assess potentially exposed systems for signs of compromise.

30 September 2026

Security Bulletin 30 Sept 2026 [PDF, 1 MB]

(opens in new tab)

28 September 2026

Active Exploitation of Vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway

Attackers are exploiting multiple vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway. Patch immediately.

24 September 2026

Active Exploitation of High-Severity Vulnerability in WordPress

Attackers are exploiting a high-severity vulnerability in WordPress to achieve remote code execution under specific conditions. Patch immediately.

23 September 2026

Multiple Vulnerabilities in Synology DiskStation Manager (DSM)

Attackers can exploit multiple vulnerabilities in Synology DiskStation Manager (DSM) to read or write arbitrary files and conduct denial-of-service attacks. Patch immediately.

23 September 2026

Security Bulletin 23 Sep 2026 [PDF, 2.6MB]

(opens in new tab)

21 September 2026

Active Exploitation of Vulnerability in Cisco Identity Services Engine

Attackers are exploiting a critical vulnerability in Cisco Identity Services Engine and Cisco Identity Services Engine Passive Identity Connector to bypass authentication and gain unauthorised access. Patch immediately.

18 September 2026

Active Exploitation of Critical Vulnerability in Cisco AsyncOS

Attackers are exploiting a critical vulnerability in Cisco AsyncOS to execute arbitrary commands with root privileges. Patch immediately.

17 September 2026

Active Exploitation of Vulnerability in Vite Development Servers

Attackers are exploiting a high severity vulnerability in Vite development servers to retrieve restricted system and configuration files over HTTP. Patch immediately.