Skip to main content
A Singapore Government Agency Website How to identify
Official website links end with .gov.sg
Government agencies communicate via .gov.sg websites (e.g. go.gov.sg/open). Trusted websites
Secure websites use HTTPS
Look for a lock () or https:// as an added precaution. Share sensitive information only on official, secure websites.

Government officials will never ask you to transfer money or disclose bank log-in details over a phone call.

Cyber Security Agency of Singapore

Alerts & Advisories

Provides alerts and advisories on emerging cyber threats, vulnerabilities, and preventive measures to help individuals and organisations stay secure online.

1216 items

26 August 2026

Active Exploitation of Vulnerability in Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-In

Attackers are exploiting a critical vulnerability in Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-In to access, change or delete critical data. Patch immediately.

26 August 2026

Vulnerabilities in Privileged Access Management Application “Admin By Request”

Two vulnerabilities have been discovered in the privileged access management application “Admin By Request” (ABR). The product owner has rolled out fixes for both reported vulnerabilities. Special thanks to the researchers and ABR for coordinating through CSA's Responsible Vulnerability Disclosure Policy.

26 August 2026

Understanding Passwordless Authentication

Passwords have been the primary method of authentication for decades, but they remain a common target for threat actors. It's time to rethink how we verify identities online.

26 August 2026

Security Bullentin 26 Aug 2026 [PDF, 2MB]

21 August 2026

High-Severity Vulnerability in Zimbra Collaboration Suite

Attackers can exploit a high-severity vulnerability in Zimbra Collaboration Suite to achieve remote code execution. Patch immediately.

20 August 2026

Multiple Vulnerabilities in Zoom Products

Attackers can exploit multiple vulnerabilities in Zoom products to perform remote code execution, denial of service or disclose sensitive information. Users and administrators of affected products are advised to apply the latest security updates promptly.

19 August 2026

Security Bulletin 19 Aug 2026 [PDF, 2MB]

18 August 2026

Multiple Vulnerabilities in HPE Aruba Networking Private 5G Core

Attackers can exploit multiple vulnerabilities in HPE Aruba Networking Private 5G Core affecting third-party components Traefik and Grafana to spoof identities and escalate privileges. Patch promptly.

18 August 2026

High-Severity Vulnerability in Cisco Secure Firewall ASA and FTD

Attackers are exploiting a vulnerability in Cisco Secure Firewall ASA and FTD to cause the affected device to reload unexpectedly, resulting in a denial of service condition. Patch immediately.

18 August 2026

Multiple Vulnerabilities in Fortinet FortiWeb, FortiClient Windows, FortiManager, and FortiManager Cloud

Attackers can exploit multiple vulnerabilities in Fortinet FortiWeb, FortiClient Windows, FortiManager, and FortiManager Cloud to bypass authentication, gain unauthorised access or execute arbitrary code. Patch promptly.