Alerts & Advisories
Provides alerts and advisories on emerging cyber threats, vulnerabilities, and preventive measures to help individuals and organisations stay secure online.
1199 articles
6 August 2026
Ongoing npm Supply Chain Attack Affecting Keyv and Related Packages ("Shai-Hulud" Worm)
Security researchers have identified an active software supply chain attack involving malicious versions of Keyv and related npm packages. The Shai-Hulud malware steals developer credentials and spreads by compromising additional packages. Organisations using Node.js should immediately review their dependencies and treat credentials on affected systems as potentially compromised.
6 August 2026
Active exploitation of Critical Vulnerability in IBM Langflow OSS
Attackers are actively exploiting a critical vulnerability in IBM Langflow OSS to achieve unauthenticated remote code execution (RCE). Users and administrators of affected products are advised to apply the latest security updates immediately.
6 August 2026
CatchPulse – Multiple Vulnerabilities including Improper Access Control, Unprivileged SYSTEM-Level Operations and Denial of Service
Multiple vulnerabilities have been discovered in CatchPulse. SecureAge, the product owner, has rolled out fixes for all reported vulnerabilities. Special thanks to the informer and SecureAge for coordinating through CSA's Responsible Vulnerability Disclosure Policy.
5 August 2026
Critical Vulnerability in cPanel & WHM
Authenticated attackers can exploit a critical vulnerability in cPanel & WHM to gain database root privileges and potentially compromise other customers hosted on the same server. Patch immediately.
5 August 2026
Multiple Critical Vulnerabilities in VMware Products
Attackers can exploit multiple vulnerabilities in VMware products to bypass authentication, execute arbitrary code, access sensitive information or cause denial-of-service. Patch immediately.
5 August 2026
Security Bulletin 5 Aug 2026 [PDF, 2MB]
31 July 2026
Active Exploitation of Vulnerability in Cisco Secure Firewall Management Center
Attackers are exploiting a medium-severity vulnerability in Cisco Secure Firewall Management Center to log in and access sensitive data. Patch immediately.
29 July 2026
Koollab LMS - Multiple Vulnerabilities including Remote Code Execution, SQL Injection, and Authentication Bypass
Multiple vulnerabilities have been discovered in Koollab's Learning Management System (LMS). Three Learning, the product owner, has rolled out fixes for all reported vulnerabilities across all cloud-hosted instances of the LMS. Special thanks to the researchers from Centre for Strategic Infocomm Technologies (CSIT) and Three Learning for coordinating through CSA's Responsible Vulnerability Disclosure Policy.
29 July 2026
Security Bulletin 29 Jul 2026 [PDF, 1.89 MB]
28 July 2026
Joint Advisory by the Cyber Security Agency of Singapore and Infocomm Media Development Authority
The Cyber Security Agency of Singapore and Infocomm Media Development Authority have issued a joint advisory to guide individuals on the safe and secure use of generative AI tools.
