Sharing ‘weak signals’ early vital as cyber threat actors refine tactics: cyber agency chief网络机构负责人:尽早分享“微弱信号”至关重要,因为网络威胁行为者正在不断改进策略。
The Digital Defence Hub has been a conduit for partnerships and a dedicated platform for various stakeholders to share cyber threat information early. Read more at straitstimes.com.
Teo said there has been a more proactive sharing of ‘weak signals’ - data that is suspicious but not yet proven to be malicious.
Published Oct 09, 2026, 01:01 PM
Updated Oct 09, 2026, 01:01 PM
- Singapore's cyber defenders are sharing “weak signals” earlier to counter APT groups, following UNC3886’s infiltration of Singapore's critical infrastructure.
- CSIT’s Digital Defence Hub is fostering joint investigations, and has put in place clear data-sharing rules. A new agreement was signed with Google Cloud Security on Oct 9.
- AI will speed up attacks while lowering costs, so cyber defence must be more proactive, with human experts tapping on AI tools, said CSIT chief executive Darren Teo.
SINGAPORE - Singapore’s cyber defenders have continued to encounter attacks by advanced persistent threat (APT) groups since it was publicly revealed in July 2025 that state-sponsored cyber espionage group UNC3886 had infiltrated the city-state’s critical information infrastructure (CII).
But these attacks are being detected and dealt with more effectively than before through more proactive sharing of information between CII operators, cybersecurity firms and government agencies, said Centre for Strategic Infocomm Technologies (CSIT) chief executive Darren Teo.
This greater willingness to collaborate on suspicious network activity that may not cross the threshold into an actual attack - so-called “weak signals” - is crucial as APT groups continue to refine their methods to stay hidden within victims’ networks, he added.
Teo was speaking to The Straits Times ahead of TechCon 2026 on Oct 9, an annual closed-door conference hosted by CSIT, which is an agency under MINDEF focused on developing advanced cybersecurity capabilities to safeguard the Republic’s digital infrastructure.
At the previous TechCon in Oct 2025, Coordinating Minister for National Security K. Shanmugam had announced the setting up of a new digital defence unit within CSIT focused on countering sophisticated cyber threat actors such as APT groups.
One year on, the Digital Defence Hub (DDH) has raised the willingness of the various stakeholders to exchange weak signals early and to carry out joint investigations together, said Teo.
This is a stark change from previous practice, when each part of the industry “more or less stayed in our own lane”, he said. For instance, a CII operator used to only reach out to their IT vendor when they encountered a cyber problem.
“That (wasn’t) the best way, because each of us probably have a little piece of the information needed to deal with our threat,” he said. The infrastructure operators also did not benefit from the broader visibility that agencies like CSIT had due to its capabilities and partnerships with threat intelligence firms.
The attacks by UNC3886 on Singapore’s major telcos was a “good wake-up call” and argument for greater coordination, he added, but even so there was a need to establish ways to share sensitive information while addressing firms’ concerns about data privacy and competition.
CSIT and DDH have thus been building these partnerships. On Oct 9, the agency signed one such agreement with Google Cloud Security, which clearly lays out each party’s obligations when they exchange data and how sensitive information must be protected.
Establishing clear protocols on what can be exchanged and how will hopefully speed up the flow of information, which also aids the proactive hunting of threats in computer networks here, said Teo.
Apart from building partnerships, the agency has also put in place sensors in Singapore’s CII networks to better detect APT activities.
This combination of threat information and telemetric data is crucial to uncovering APT attacks, given that such groups are motivated to be very stealthy and have the resources and advanced technology to stay undetected as they move from network to network, said Teo.
The latest Singapore Cyber Landscape report published on June 30 said APT groups have shifted tactics to prioritise the accumulation of credentials, with the goal of maintaining “persistent network footholds over immediate disruption”.
State-sponsored cyber activity in 2026 will likely continue to focus on gaining access to CII networks and focus on “strategic optionality” over disruptive attacks, the report added.
Teo said cyber agencies here expect artificial intelligence to amplify the speed and scale by which threat groups can launch attacks, though they have not yet resulted in novel methods or exploits.
“It’s the basic stuff that is now being done a lot faster...what used to require a whole team is now just being done by a few people and many tens of thousands of agents acting on their behalf,” he said.
“So you would see that these attacks will probably reduce in cost, because you no longer need to assemble a team of very highly-skilled attackers.”
Cyber defense therefore needs to be significantly more proactive and anticipatory, rather than kicking in only when an attack has happened, he said.
On its part, CSIT has “somebody experimenting with some kind of AI” across each of its functions, which include threat intelligence, cyber security engineering and red-teaming, which refers to simulating a real-world adversary.
For instance, the agency has created a tool called AETHER that uses AI to automate the time-consuming work of reverse engineering malware, so as to detect their presence in computer systems.
Teo said CSIT has always placed very strong emphasis on developing cyber security talent, but it is also investing heavily in its AI efforts.
“We think that AI will make a very, very big impact on cybersecurity work, but at the same time we believe that it is best paired with a human expert,” he said.
“It is the man-machine teaming that will make the most effective cybersecurity capability.”
Teo表示,目前对“弱信号”(即可疑但尚未证实为恶意的数据)的分享更加积极主动。
发布于 2026 年 10 月 9 日下午 1:01
更新于2026年10月9日下午1:01
- 在 UNC3886 入侵新加坡关键基础设施之后,新加坡的网络防御者正在更早地发出“微弱信号”来对抗 APT 组织。
- CSIT的数字防御中心正在推动联合调查,并制定了明确的数据共享规则。10月9日,该中心与谷歌云安全部门签署了一项新协议。
CSIT首席执行官Darren Teo表示,人工智能将加快攻击速度,同时降低成本,因此网络防御必须更加积极主动,让人类专家利用人工智能工具。
新加坡——自 2025 年 7 月公开披露国家支持的网络间谍组织 UNC3886 已渗透新加坡的关键信息基础设施 (CII) 以来,新加坡的网络防御人员一直遭受高级持续威胁 (APT) 组织的攻击。
战略信息通信技术中心 (CSIT) 首席执行官 Darren Teo 表示,通过 CII 运营商、网络安全公司和政府机构之间更积极主动地共享信息,这些攻击正比以前更有效地被检测和处理。
他补充说,这种更愿意合作处理可能尚未达到实际攻击门槛的可疑网络活动(即所谓的“弱信号”)的意愿至关重要,因为 APT 组织不断改进其方法,以隐藏在受害者的网络中。
Teo在10月9日举行的TechCon 2026之前接受了《海峡时报》的采访。TechCon 2026是由CSIT主办的年度闭门会议,CSIT是国防部下属的一个机构,专注于发展先进的网络安全能力,以保护共和国的数字基础设施。
在 2025 年 10 月举行的上一届 TechCon 大会上,国家安全统筹部长尚穆根宣布在 CSIT 内设立一个新的数字防御部门,专注于打击 APT 组织等复杂的网络威胁行为者。
张先生表示,一年过去了,数字防御中心(DDH)提高了各利益相关方及早交换弱信号并共同开展联合调查的意愿。
他表示,这与以往的做法截然不同,过去行业内的各个环节“或多或少都各自为政”。例如,关键信息基础设施运营商过去只有在遇到网络安全问题时才会联系其IT供应商。
他说:“那(并非)最佳方案,因为我们每个人可能都只掌握应对威胁所需的一小部分信息。” 基础设施运营商也未能像网络安全信息技术研究所 (CSIT) 那样,凭借其自身能力和与威胁情报公司的合作关系,获得更广泛的信息可见性。
他补充说,UNC3886 对新加坡主要电信公司的攻击是一个“很好的警钟”,也是加强协调的论据,但即便如此,仍然需要建立共享敏感信息的方法,同时解决企业对数据隐私和竞争的担忧。
CSIT和DDH一直在积极构建此类合作关系。10月9日,该机构与谷歌云安全签署了一项协议,明确规定了双方在数据交换时的义务以及如何保护敏感信息。
Teo表示,制定关于可以交换什么以及如何交换的明确协议,有望加快信息流动,这也有助于主动搜寻本地计算机网络中的威胁。
除了建立合作伙伴关系外,该机构还在新加坡的关键信息基础设施网络中部署了传感器,以便更好地检测高级持续性威胁 (APT) 活动。
Teo表示,鉴于APT组织有很强的隐蔽性,并且拥有资源和先进技术,能够在网络间转移时保持不被发现,因此威胁信息和遥测数据的结合对于发现APT攻击至关重要。
新加坡于 6 月 30 日发布的最新网络安全形势报告称,APT 组织已改变策略,优先考虑积累凭证,其目标是“维持持久的网络立足点,而不是立即造成破坏”。
报告还指出,2026 年国家支持的网络活动可能会继续集中于获取关键信息基础设施 (CII) 网络访问权限,并侧重于“战略选择权”而非破坏性攻击。
Teo表示,本地网络安全机构预计人工智能将加快威胁组织发动攻击的速度和规模,尽管目前尚未出现新的攻击方法或漏洞。
“现在基本的事情完成得快多了……以前需要整个团队才能完成的事情,现在只需要几个人就能完成,而且还有成千上万的代理人代表他们行事,”他说。
“因此你会发现,这些攻击的成本可能会降低,因为你不再需要组建一支技术非常高超的攻击者团队。”
他表示,因此网络防御需要更加积极主动、更具预见性,而不是仅仅在攻击发生后才启动。
就 CSIT 而言,它的各个职能部门都在“尝试使用某种人工智能”,这些职能部门包括威胁情报、网络安全工程和红队演练(即模拟现实世界中的对手)。
例如,该机构创建了一个名为 AETHER 的工具,该工具利用人工智能自动执行耗时的恶意软件逆向工程工作,从而检测计算机系统中是否存在恶意软件。
Teo表示,CSIT一直非常重视网络安全人才的培养,同时也在人工智能领域投入巨资。
他说:“我们认为人工智能将对网络安全工作产生非常非常大的影响,但与此同时,我们也相信它最好与人类专家结合使用。”
“只有人机协作才能打造最有效的网络安全能力。”