Threats Affecting Singapore
View all threats affecting or targeting Singapore. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Affecting Singapore
Click on any threat for detailed analysis and mitigation recommendations
ZDI-26-454: GIMP PSD File Parsing Integer Overflow Remote Code Execution VulnerabilityCVE-2026-18301 0 This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18301. Join the discussion | Zero Day Initiative | 07/29/2026, 05:00:00 UTC Added: 07/30/2026, 15:59:04 UTC |
ZDI-26-455: GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityCVE-2026-18302 0 This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18302. Join the discussion | Zero Day Initiative | 07/29/2026, 05:00:00 UTC Added: 07/30/2026, 15:59:04 UTC |
Analysis of BlueShell Variants Used by APT Groups 0 BlueShell is an open-source remote access trojan developed in Go language, primarily used by Chinese-based threat actors. A variant of BlueShell has been identified in post-intrusion activities by APT groups including BlackTech, targeting organizations in Japan, South Korea, and Thailand. This variant differs from the original through a dedicated dropper mechanism, proxy server-based C2 communication, and anti-forensic capabilities. The dropper deploys the variant to /tmp/kthread, disguises it as a Linux kernel worker process, and removes filesystem traces. Recent variants observed since 2024 include XOR-encoded configuration data and proxy functionality, indicating continuous development. The malware performs hostname verification, validates C2 certificates, and implements commands for file transfer, remote shell, and SOCKS5 proxy capabilities. Join the discussion | AlienVault OTX General | 07/29/2026, 08:57:15 UTC Added: 07/29/2026, 11:52:25 UTC |
Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day 0 Impacting on-premises deployments, the OS command injection allows attackers to access privileged internal functionality. The post Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day appeared first on SecurityWeek . Join the discussion | SecurityWeek | 07/28/2026, 06:40:36 UTC Added: 07/28/2026, 06:52:06 UTC |
Oracle July 2026 Critical Patch Update Addresses 1235 CVEs 0 Oracle's July 2026 Critical Patch Update (CPU) addresses 1235 unique CVEs with 1449 security patches across 32 product families, including 261 critical severity issues. This is the largest CPU release to date, with Oracle E-Business Suite receiving the highest number of patches (410). The update includes numerous vulnerabilities that can be exploited remotely without authentication, affecting key Oracle products such as Fusion Middleware, Communications, and PeopleSoft. Customers are strongly advised to apply all relevant patches from this CPU to mitigate risks. Join the discussion | Tenable Research | 07/21/2026, 21:07:46 UTC Added: 07/22/2026, 01:54:57 UTC |
One Misconfigured Server, Three Active Campaigns: Full exposure of three AiTM Phishing Operators 0 A misconfigured Python HTTP server on a Budapest VPS exposed the complete operational infrastructure of three distinct phishing operators. The investigation uncovered codemado, an Egyptian threat actor operating since 2018, running a full AiTM platform with custom tools including MaDoO Blaster; saroula01, deploying OAuth Device Code Flow attacks that accumulated 218 victims across 12 countries over a year; and mail-argenta, a Nigerian operator identified through infostealer logs containing his own credentials. All three actors leveraged customized Evilginx forks and AI-assisted development to build MFA-bypass infrastructure from public GitHub repositories. The campaigns targeted Microsoft 365 accounts primarily, with codemado maintaining ties to RockyBelling's "The Quarry" cybercrime ecosystem. The exposed server contained phishing configurations, credential logs, RMM installers, combolists, and Telegram session files, revealing sustained operations from at least January 2025 through May 2026. Join the discussion | AlienVault OTX General | 07/13/2026, 10:36:53 UTC Added: 07/13/2026, 11:03:04 UTC |
Showing 1 to 6 of 6 results