Skip to main content
A Singapore Government Agency Website How to identify
Official website links end with .gov.sg
Government agencies communicate via .gov.sg websites (e.g. go.gov.sg/open). Trusted websites
Secure websites use HTTPS
Look for a lock () or https:// as an added precaution. Share sensitive information only on official, secure websites.

Government officials will never ask you to transfer money or disclose bank log-in details over a phone call.

Cyber Security Agency of Singapore

Alerts & Advisories

Provides alerts and advisories on emerging cyber threats, vulnerabilities, and preventive measures to help individuals and organisations stay secure online.

1209 items

18 August 2026

Multiple Vulnerabilities in HPE Aruba Networking Private 5G Core

Attackers can exploit multiple vulnerabilities in HPE Aruba Networking Private 5G Core affecting third-party components Traefik and Grafana to spoof identities and escalate privileges. Patch promptly.

18 August 2026

High-Severity Vulnerability in Cisco Secure Firewall ASA and FTD

Attackers are exploiting a vulnerability in Cisco Secure Firewall ASA and FTD to cause the affected device to reload unexpectedly, resulting in a denial of service condition. Patch immediately.

18 August 2026

Multiple Vulnerabilities in Fortinet FortiWeb, FortiClient Windows, FortiManager, and FortiManager Cloud

Attackers can exploit multiple vulnerabilities in Fortinet FortiWeb, FortiClient Windows, FortiManager, and FortiManager Cloud to bypass authentication, gain unauthorised access or execute arbitrary code. Patch promptly.

18 August 2026

Multiple Vulnerabilities in SAP Products

Attackers can exploit multiple vulnerabilities in SAP products to execute arbitrary code, disclose sensitive information or crash affected systems. Patch immediately.

14 August 2026

SPF-CSA Joint Advisory On Cryptocurrency Scams Involving Fake Job Offers And Compromised Software Systems

The Singapore Police Force (SPF) and Cyber Security Agency of Singapore (CSA) would like to alert members of the public and businesses of a cryptocurrency-related scam involving fake job offers and the compromise of software systems.

12 August 2026

August 2026 Monthly Patch

Microsoft has released security patches to address multiple vulnerabilities in their software and products.

12 August 2026

Security Bulletin 12 Aug 2026 [PDF, 2MB]

7 August 2026

Missing Encryption Vulnerability in Apache Tomcat

Attackers can exploit a missing encryption vulnerability in Apache Tomcat to bypass the EncryptInterceptor, potentially exposing sensitive data transmitted between cluster nodes. Patch immediately.

7 August 2026

Multiple Vulnerabilities in Cisco IOS XE Software

Multiple vulnerabilities have been identified in Cisco IOS XE Software that could allow attackers to execute arbitrary commands, bypass security controls, gain unauthorised access, disclose sensitive information, or affect the operation of vulnerable systems. Patch immediately.

7 August 2026

Multiple Vulnerabilities in Cisco Catalyst SD-WAN Software

Attackers can exploit multiple vulnerabilities in Cisco Catalyst SD-WAN Software to bypass security controls, gain unauthorised access, access or manipulate files, and disclose sensitive information. Patch immediately.