Over 38,700 exploit attempts on Singapore firms blocked in H1
Kaspersky also detected over 470,000 web threats in Singapore alone.
Cybersecurity firm Kaspersky blocked 38,719 exploit attempts targeting organisations in Singapore in just the first half of 2025.
This figure is part of a broader regional trend, with 1.19 million exploit attempts intercepted across Southeast Asia over the same period, or roughly 6,000 attacks per day, the firm reported.
Exploits are a common tactic used by cybercriminals and advanced persistent threat (APT) groups to gain unauthorised access by taking advantage of known but unpatched vulnerabilities in software or operating systems.
Kaspersky also detected over 470,000 web threats in Singapore alone, out of more than 7.8 million across Southeast Asia.
The most-targeted vulnerabilities globally in the second quarter of 2025 were older Microsoft Office flaws, including CVE-2018-0802, CVE-2017-11882, and CVE-2017-0199—all capable of remote code execution. Despite being years old, these bugs continue to top exploit charts alongside newer vulnerabilities and zero-day threats, according to Kaspersky's data.
Threat actors are increasingly focusing on widely used enterprise tools such as remote-access software, document editors, logging systems, and AI application frameworks, aiming to secure initial entry and escalate privileges for longer-term control.
To mitigate risks, Kaspersky recommended prompt deployment of security updates using automated vulnerability and patch management tools, round-the-clock infrastructure monitoring, and secure environments for analysing suspicious exploits.
The company also advised firms to maintain incident-response playbooks, ensure endpoint protection is active across devices, and leverage real-time threat intelligence to track attacker methods and adjust defenses accordingly.