Cyber Team is RECATOOLS’ cybersecurity desk, covering vulnerabilities, data breaches, supply-chain attacks, threat intelligence, exploit activity, and security best practices. The desk focuses on practical implications for developers, SMEs, IT teams, and ASEAN organisations.

About this byline

Cyber Team is a specialist RECATOOLS editorial desk focused on cybersecurity coverage. Articles are produced and reviewed under RECATOOLS editorial supervision. The articles listed here keep this byline. New coverage on these beats is published under the persona whose beat it falls in: Kenji Tanaka for vulnerabilities, patching and supply-chain security, and Priya Nair for threat intelligence, attribution and privacy.

Editorial responsibility for this byline rests with Jeffrey Tan (Tan Seng Fei), RECASYS, Singapore. Our Editorial Policy sets out how sources are reviewed, how AI-assisted workflows are used, and how editorial desks and personas are defined.

153
Articles
Cybersecurity
Primary beat
Jan 2026
Writing since
~1054 min
Total reading

Articles Showing 1–10 of 153

A stylised terminal display of hexadecimal data, illustrating a report on encrypted AI reasoning traces being decoded by cheaper models.
Cybersecurity

Weaker Models Can Read a Frontier Model's Encrypted Reasoning

OpenAI, Anthropic and Google return reasoning to clients as encrypted blocks. Researchers replayed those blocks into cheaper models from the same provider, which transcribed them in plain language. The encryption was never broken - the blocks were simply portable.

15 Aug 2026 · 8 min read
Rows of servers in a data centre, illustrating a report on the Gunra ransomware advisory and its authentication-server backdoor.
Cyber Threat Intel

Gunra Defeated Multi-Factor Authentication by Editing the Authentication Server

A six-agency advisory documents operators who altered a virtual desktop authentication portal so an attacker-chosen one-time code always succeeds. Every user-side MFA control keeps working and none of them helps. Linux victims can recover without paying.

15 Aug 2026 · 8 min read
Rack-mounted network appliances in a server cabinet, illustrating a report on an exploited crash flaw in Cisco firewalls.
Cybersecurity

One Malformed Request Crashes the Firewall. CISA Gave Three Days.

CVE-2026-20349 lets an unauthenticated attacker reload a Cisco ASA or FTD firewall through the remote-access SSL VPN. There is no workaround, the federal deadline was three days, and the device it crashes is both your perimeter and the way your staff get in.

15 Aug 2026 · 8 min read
A close-up of syntax-highlighted PHP and HTML source code on a dark editor screen, shown at an angle with line numbers down the left
Cybersecurity

GLM-5.3 Finds Bugs Like the Frontier. It Is 23 Points Behind at Using Them.

Z.ai's model edges Mythos 5 by 0.7 points on vulnerability detection and trails it by 23.6 on exploit development. The second number is the one that describes the risk - and both are the company's own.

14 Aug 2026 · 8 min read
A vertical run of weathered steel chain links in close focus, each link interlocking with the next, against a blurred grey and green background.
Cybersecurity

What Our Own Security Audit Found

Nine parallel red-team reviews of our own admin panel produced twelve security findings. Eleven are closed, including all five criticals, and one remains open and undescribed here. The bugs were ordinary — what made them survive review is that almost every one lived between two files that were each correct on their own.

14 Aug 2026 · 10 min read
A magnifying lens held over a dictionary page, enlarging the entries love, and low, — two words a single deleted letter apart.
Cybersecurity

How to Check Who Owns the Lookalikes of Your Domain

Five edit rules per character generate the confusable space around a domain name, and DNS says which of those names already have an owner. Run on our own label, 6 of 58 variants are taken. Run on ten well-known brands, 286 of 366 are. The gap is mostly fame rather than brevity — but only a control with invented labels could show that.

14 Aug 2026 · 7 min read
A brass combination padlock and heavy chain fastening a rusted metal gate, green fields blurred behind
Cybersecurity

OpenAI Shipped an Exploit-Writing Model. The Base Model Could Already Do It.

GPT-5.6-Cyber completes 95 per cent of exploit-chain prompts against 1.5 per cent for the general model it is built on. The capability was already there; the refusals were the difference. Access is gated by contract, not code.

14 Aug 2026 · 8 min read
A dense Taipei cityscape at night seen from a wooded hillside, tower blocks lit against a hazy sky
Cyber Threat Intel

Eight Agents, Four Days, and a Government That Calls It Hybrid

Taiwan confirms AI agent-assisted attacks on government agencies in July. A vendor calls it near-autonomous; the ministry calls it hybrid. The gap between those descriptions is where the useful reading sits.

13 Aug 2026 · 9 min read
Fibre optic patch cables plugged into the front panels of rack-mounted servers, photographed close up
Cybersecurity

One Unrevoked Token, Three Tools Deep: Inside the LiteLLM Breach

Two poisoned LiteLLM releases were live on PyPI for forty minutes in March. CloudSEK has now mapped roughly 434,000 captured files to more than 2,500 organisations - and the chain started three tools upstream.

13 Aug 2026 · 8 min read
A person sitting cross-legged in low light, typing on a laptop with lines of code visible on the screen
Cyber Threat Intel

Zoom's Zero-Click Took One Day and Fewer Than 20 Prompts

Zoom patched four flaws in its annotation protocol on 11 August. The researchers say they went from decompiled binary to working zero-click exploit in a single day, driving public AI models through a disassembler and a live tracer.

13 Aug 2026 · 9 min read
Editorial Policy →