Skip to main content
A Singapore Government Agency Website How to identify
Official website links end with .gov.sg
Government agencies communicate via .gov.sg websites (e.g. go.gov.sg/open). Trusted websites
Secure websites use HTTPS
Look for a lock () or https:// as an added precaution. Share sensitive information only on official, secure websites.

Government officials will never ask you to transfer money or disclose bank log-in details over a phone call.

Cyber Security Agency of Singapore

Advisories

Information on high-impact cybersecurity activity affecting Singapore.

108 items

6 August 2026

Ongoing npm Supply Chain Attack Affecting Keyv and Related Packages ("Shai-Hulud" Worm)

Security researchers have identified an active software supply chain attack involving malicious versions of Keyv and related npm packages. The Shai-Hulud malware steals developer credentials and spreads by compromising additional packages. Organisations using Node.js should immediately review their dependencies and treat credentials on affected systems as potentially compromised.

Advisory

28 July 2026

Joint Advisory by the Cyber Security Agency of Singapore and Infocomm Media Development Authority

The Cyber Security Agency of Singapore and Infocomm Media Development Authority have issued a joint advisory to guide individuals on the safe and secure use of generative AI tools.

Advisory

22 June 2026

Advisory on Credential Compromise of FortiGate Devices ("FortiBleed")

A threat actor has leaked credentials of over 70,000 FortiGate devices worldwide, making them vulnerable to network intrusions. Check access control configurations of FortiGate devices immediately.

Advisory

10 June 2026

Joint Advisory on Technical Support Scams Involving the Impersonation of Microsoft

The Singapore Police Force (SPF) and the Cyber Security Agency of Singapore (CSA) would like to alert members of the public to remain vigilant against technical support scams involving impersonation of Microsoft.

Advisory

28 May 2026

Advisory on Cybersecurity Risks of OpenClaw

Autonomous AI agents, such as OpenClaw, offer real productivity benefits but introduce serious cybersecurity risks. This advisory draws attention to IMDA's Case Study on the Responsible Deployment of OpenClaw, and highlights the key cybersecurity risks.

Advisory

15 April 2026

Advisory on Risks associated with Frontier AI Models

Frontier Artificial Intelligence (AI) models are the most recent advanced AI models available. These frontier AI models can reportedly reduce the time taken to identify vulnerabilities and engineer exploits cutting short the duration from months to hours, but this capability could also be misused by cyber threat actors. This advisory outlines how organisations can plan ahead and strengthen their cybersecurity posture to guard against such risks.

Advisory

7 April 2026

Advisory on Securing the Software Supply Chain and Development Workflows

Threat actors are increasingly targeting the software supply chain. A single compromised external tool can grant attackers deep access to internal systems, leading to data theft, operational downtime, and severe reputational damage. Organisations are strongly encouraged to enforce strict governance over their internal development environments.

Advisory

6 April 2026

Protecting Your Website From Cyber-Attacks

Advisory

1 April 2026

Advisory on Axios Supply Chain Attack via Compromised npm Account

A critical software supply chain compromise has been identified affecting the widely used JavaScript HTTP client Axios. Organisations using affected versions of the product are advised to assess their systems and networks for potential compromise.

Advisory

27 March 2026

Ongoing 'TeamPCP' Supply-Chain Campaign

Security researchers have identified an ongoing supply-chain campaign compromising open-source projects to distribute malware. Organisations using affected components of such projects are advised to assess their environments for potential compromise.

Advisory