Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Affecting Singapore

View all threats affecting or targeting Singapore. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (2):Country:SingaporeSingapore

Threats Affecting Singapore

Click on any threat for detailed analysis and mitigation recommendations

ZDI-26-454: GIMP PSD File Parsing Integer Overflow Remote Code Execution VulnerabilityCVE-2026-18301
0

This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18301.

Join the discussion
ZDI-26-455: GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityCVE-2026-18302
0

This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18302.

Join the discussion
Analysis of BlueShell Variants Used by APT Groups
0

BlueShell is an open-source remote access trojan developed in Go language, primarily used by Chinese-based threat actors. A variant of BlueShell has been identified in post-intrusion activities by APT groups including BlackTech, targeting organizations in Japan, South Korea, and Thailand. This variant differs from the original through a dedicated dropper mechanism, proxy server-based C2 communication, and anti-forensic capabilities. The dropper deploys the variant to /tmp/kthread, disguises it as a Linux kernel worker process, and removes filesystem traces. Recent variants observed since 2024 include XOR-encoded configuration data and proxy functionality, indicating continuous development. The malware performs hostname verification, validates C2 certificates, and implements commands for file transfer, remote shell, and SOCKS5 proxy capabilities.

Join the discussion
Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day
0

Impacting on-premises deployments, the OS command injection allows attackers to access privileged internal functionality. The post Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day appeared first on SecurityWeek .

Join the discussion
Oracle July 2026 Critical Patch Update Addresses 1235 CVEs
0

Oracle's July 2026 Critical Patch Update (CPU) addresses 1235 unique CVEs with 1449 security patches across 32 product families, including 261 critical severity issues. This is the largest CPU release to date, with Oracle E-Business Suite receiving the highest number of patches (410). The update includes numerous vulnerabilities that can be exploited remotely without authentication, affecting key Oracle products such as Fusion Middleware, Communications, and PeopleSoft. Customers are strongly advised to apply all relevant patches from this CPU to mitigate risks.

Join the discussion
One Misconfigured Server, Three Active Campaigns: Full exposure of three AiTM Phishing Operators
0

A misconfigured Python HTTP server on a Budapest VPS exposed the complete operational infrastructure of three distinct phishing operators. The investigation uncovered codemado, an Egyptian threat actor operating since 2018, running a full AiTM platform with custom tools including MaDoO Blaster; saroula01, deploying OAuth Device Code Flow attacks that accumulated 218 victims across 12 countries over a year; and mail-argenta, a Nigerian operator identified through infostealer logs containing his own credentials. All three actors leveraged customized Evilginx forks and AI-assisted development to build MFA-bypass infrastructure from public GitHub repositories. The campaigns targeted Microsoft 365 accounts primarily, with codemado maintaining ties to RockyBelling's "The Quarry" cybercrime ecosystem. The exposed server contained phishing configurations, credential logs, RMM installers, combolists, and Telegram session files, revealing sustained operations from at least January 2025 through May 2026.

Join the discussion

Showing 1 to 6 of 6 results

Filters:Country: Singapore
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses