SingCERT has received multiple reports of scammers impersonating CSA officers and the Police using fake court orders sent through fraudulent emails.
Read the alert here.
csa.gov.sg/alerts-advisor…
Attackers can exploit critical vulnerabilities in SAP NetWeaver and SAP Commerce Cloud to gain unauthorised access and compromise affected systems. Users and administrators are advised to patch immediately.
🔗:csa.gov.sg/alerts-and-adv…
Attackers can exploit a critical vulnerability in Fortinet FortiSandbox via HTTP requests to execute unauthorised commands on the affected system. Patch immediately.
🔗:csa.gov.sg/alerts-and-adv…
Oracle has released security updates to address a critical vulnerability in Oracle PeopleSoft Enterprise PeopleTools that could allow unauthenticated attackers to perform remote code execution and fully compromise the affected system. Patch quickly.
đź”—:
⚠️ SPF and CSA would like to alert members of the public to remain vigilant against scams involving the impersonation of Microsoft. At least $1.7 million was lost to these scams since February 2026.
Know the signs and protect yourself.
🔗csa.gov.sg/alerts-and-adv…
Attackers are actively exploiting a critical vulnerability in Check Point VPN to bypass authentication and gain unauthorised remote access. Apply security updates immediately.
🔗: csa.gov.sg/alerts-and-adv…
Attackers are exploiting a vulnerability in SolarWinds Serv-U to crash the file transfer service without authentication, causing a denial of service condition. Patch immediately.
🔗: csa.gov.sg/alerts-and-adv…
Attackers are actively exploiting a 2022 Linux kernel vulnerability to escalate privileges and escape containerised environments. Patch your systems immediately.
Details: csa.gov.sg/alerts-and-adv…
Cisco has released security updates addressing a critical vulnerability in Cisco Unified Communications Manager and Cisco UCM Session Management Edition. Attackers can gain root privileges if exploited. Update immediately.
Details: csa.gov.sg/alerts-and-adv…
Mirasvit has released a security update addressing a critical vulnerability in its Full Page Cache Warmer extension for Magento 2. Update to the latest version immediately.
Details: csa.gov.sg/alerts-and-adv…
Oracle has released security updates to address multiple vulnerabilities that could allow unauthenticated attackers to compromise affected systems. Update to the latest versions immediately.
More info: csa.gov.sg/alerts-and-adv…
Palo Alto Networks has identified a critical vulnerability affecting the GlobalProtect portal, gateway of Palo Alto Networks PAN-OS software and Prisma Access that allows attackers to establish unauthorised VPN connections. 🔗: csa.gov.sg/alerts-and-adv…