Alerts & Advisories
Provides alerts and advisories on emerging cyber threats, vulnerabilities, and preventive measures to help individuals and organisations stay secure online.
1205 items
14 August 2026
SPF-CSA Joint Advisory On Cryptocurrency Scams Involving Fake Job Offers And Compromised Software Systems
The Singapore Police Force (SPF) and Cyber Security Agency of Singapore (CSA) would like to alert members of the public and businesses of a cryptocurrency-related scam involving fake job offers and the compromise of software systems.
12 August 2026
August 2026 Monthly Patch
Microsoft has released security patches to address multiple vulnerabilities in their software and products.
12 August 2026
Security Bulletin 12 Aug 2026 [PDF, 2MB]
7 August 2026
Missing Encryption Vulnerability in Apache Tomcat
Attackers can exploit a missing encryption vulnerability in Apache Tomcat to bypass the EncryptInterceptor, potentially exposing sensitive data transmitted between cluster nodes. Patch immediately.
7 August 2026
Multiple Vulnerabilities in Cisco IOS XE Software
Multiple vulnerabilities have been identified in Cisco IOS XE Software that could allow attackers to execute arbitrary commands, bypass security controls, gain unauthorised access, disclose sensitive information, or affect the operation of vulnerable systems. Patch immediately.
7 August 2026
Multiple Vulnerabilities in Cisco Catalyst SD-WAN Software
Attackers can exploit multiple vulnerabilities in Cisco Catalyst SD-WAN Software to bypass security controls, gain unauthorised access, access or manipulate files, and disclose sensitive information. Patch immediately.
6 August 2026
CatchPulse – Multiple Vulnerabilities including Improper Access Control, Unprivileged SYSTEM-Level Operations and Denial of Service
Multiple vulnerabilities have been discovered in CatchPulse. SecureAge, the product owner, has rolled out fixes for all reported vulnerabilities. Special thanks to the informer and SecureAge for coordinating through CSA's Responsible Vulnerability Disclosure Policy.
6 August 2026
Active exploitation of Critical Vulnerability in IBM Langflow OSS
Attackers are actively exploiting a critical vulnerability in IBM Langflow OSS to achieve unauthenticated remote code execution (RCE). Users and administrators of affected products are advised to apply the latest security updates immediately.
6 August 2026
Ongoing npm Supply Chain Attack Affecting Keyv and Related Packages ("Shai-Hulud" Worm)
Security researchers have identified an active software supply chain attack involving malicious versions of Keyv and related npm packages. The Shai-Hulud malware steals developer credentials and spreads by compromising additional packages. Organisations using Node.js should immediately review their dependencies and treat credentials on affected systems as potentially compromised.
5 August 2026
Critical Vulnerability in cPanel & WHM
Authenticated attackers can exploit a critical vulnerability in cPanel & WHM to gain database root privileges and potentially compromise other customers hosted on the same server. Patch immediately.
