Skip to main content
A Singapore Government Agency Website How to identify
Official website links end with .gov.sg
Government agencies communicate via .gov.sg websites (e.g. go.gov.sg/open). Trusted websites
Secure websites use HTTPS
Look for a lock () or https:// as an added precaution. Share sensitive information only on official, secure websites.

Government officials will never ask you to transfer money or disclose bank log-in details over a phone call.

Cyber Security Agency of Singapore

Alerts & Advisories

Provides alerts and advisories on emerging cyber threats, vulnerabilities, and preventive measures to help individuals and organisations stay secure online.

1193 articles

31 July 2026

Active Exploitation of Vulnerability in Cisco Secure Firewall Management Center

ttackers are exploiting a medium-severity vulnerability in Cisco Secure Firewall Management Center to log in and access sensitive data. Patch immediately.

29 July 2026

Koollab LMS - Multiple Vulnerabilities including Remote Code Execution, SQL Injection, and Authentication Bypass

Multiple vulnerabilities have been discovered in Koollab's Learning Management System (LMS). Three Learning, the product owner, has rolled out fixes for all reported vulnerabilities across all cloud-hosted instances of the LMS. Special thanks to the researchers from Centre for Strategic Infocomm Technologies (CSIT) and Three Learning for coordinating through CSA's Responsible Vulnerability Disclosure Policy.

29 July 2026

Security Bulletin 29 Jul 2026 [PDF, 1.89 MB]

28 July 2026

Joint Advisory by the Cyber Security Agency of Singapore and Infocomm Media Development Authority

The Cyber Security Agency of Singapore and Infocomm Media Development Authority have issued a joint advisory to guide individuals on the safe and secure use of generative AI tools.

28 July 2026

Vulnerability in EShare Application

A vulnerability has been discovered in EShare’s application. Special thanks to the informer and EShare for their involvement as part of CSA's Responsible Vulnerability Disclosure Policy.

24 July 2026

Critical Vulnerability in Langflow

Attackers are exploiting a critical severity vulnerability in Langflow to execute arbitrary code. Users and administrators of affected products are advised to apply the latest security updates immediately.

23 July 2026

Multiple Critical Vulnerabilities in SolarWinds Serv-U

Attackers can exploit two critical vulnerabilities in SolarWinds Serv-U to perform remote code execution. Patch immediately.

22 July 2026

Security Bulletin 22 Jul 2026 [PDF, 2.4MB]

16 July 2026

Critical Vulnerability in Zoom Products

Attackers can exploit a critical-severity vulnerability in Zoom to conduct an account takeover via network access. Users and administrators of affected products are advised to apply the latest security updates immediately

15 July 2026

Critical Vulnerabilities in SAP NetWeaver, SAP Approuter and SAP Commerce Cloud

Attackers can exploit critical vulnerabilities in SAP NetWeaver, SAP Approuter and SAP Commerce Cloud to gain unauthorised access, modify data and cause denial of service to affected systems. Patch immediately.