Skip to main content
A Singapore Government Agency Website How to identify
Official website links end with .gov.sg
Secure websites use HTTPS
Look for a lock () or https:// as an added precaution. Share sensitive information only on official, secure websites.
Government officials will never ask you to transfer money or disclose bank log-in details over a phone call.
Cyber Security Agency of Singapore

Alerts & Advisories

Provides alerts and advisories on emerging cyber threats, vulnerabilities, and preventive measures to help individuals and organisations stay secure online.

1247 items

7 October 2026

Creative Sound Blaster Katana – Multiple Vulnerabilities in Firmware Verification and Bluetooth Authentication

Multiple vulnerabilities have been discovered in Creative Sound Blaster Katana products. Creative Labs has released firmware updates to address these vulnerabilities. Special thanks to the informer and Creative Labs for coordinating through CSA's Responsible Vulnerability Disclosure Policy.

7 October 2026

Critical Vulnerability in Atlassian Data Center Products

Attackers can exploit a critical vulnerability in multiple Atlassian Data Center products to gain unauthorised access to sensitive files without authentication. Patch immediately.

7 October 2026

Security Bulletin 7 Oct 2026 [PDF, 1859KB]

(opens in new tab)

6 October 2026

Active Exploitation of Vulnerability in Cisco Catalyst SD-WAN Manager

Attackers are exploiting a critical vulnerability in Cisco Catalyst SD-WAN Manager to bypass authentication and gain admin access. Patch immediately.

6 October 2026

Active Exploitation of Vulnerability in Fortinet FortMail

Attackers are exploiting a critical vulnerability in Fortinet FortiMail to write arbitrary files on the underlying system. Patch immediately.

3 October 2026

Active Exploitation of Vulnerability in Roundcube Webmail

Attackers are exploiting a high-severity vulnerability in Roundcube Webmail to perform SQL injection without authentication. Patch immediately.

30 September 2026

High-Severity Vulnerability in Apple Products

Attackers can exploit a high-severity vulnerability in Apple products to execute arbitrary code on affected devices. Patch immediately.

30 September 2026

Advisory on CARBONATO Botnet Campaign Targeting Exposed Docker Daemons

Security researchers have identified a botnet campaign known as CARBONATO targeting Docker hosts with unauthenticated Docker Remote APIs exposed to the Internet. Organisations operating Docker environments are advised to review their configurations and assess potentially exposed systems for signs of compromise.

30 September 2026

Security Bulletin 30 Sept 2026 [PDF, 1 MB]

(opens in new tab)

28 September 2026

Active Exploitation of Vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway

Attackers are exploiting multiple vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway. Patch immediately.