Cyber Team is RECATOOLS’ cybersecurity desk, covering vulnerabilities, data breaches, supply-chain attacks, threat intelligence, exploit activity, and security best practices. The desk focuses on practical implications for developers, SMEs, IT teams, and ASEAN organisations.

About this byline

Cyber Team is a specialist RECATOOLS editorial desk focused on cybersecurity coverage. Articles are produced and reviewed under RECATOOLS editorial supervision. The articles listed here keep this byline. New coverage on these beats is published under the persona whose beat it falls in: Kenji Tanaka for vulnerabilities, patching and supply-chain security, and Priya Nair for threat intelligence, attribution and privacy.

Editorial responsibility for this byline rests with Jeffrey Tan (Tan Seng Fei), RECASYS, Singapore. Our Editorial Policy sets out how sources are reviewed, how AI-assisted workflows are used, and how editorial desks and personas are defined.

153
Articles
Cybersecurity
Primary beat
Jan 2026
Writing since
~1054 min
Total reading

Articles · Cyber Threat Intel Showing 1–10 of 12

Rows of servers in a data centre, illustrating a report on the Gunra ransomware advisory and its authentication-server backdoor.
Cyber Threat Intel

Gunra Defeated Multi-Factor Authentication by Editing the Authentication Server

A six-agency advisory documents operators who altered a virtual desktop authentication portal so an attacker-chosen one-time code always succeeds. Every user-side MFA control keeps working and none of them helps. Linux victims can recover without paying.

15 Aug 2026 · 8 min read
A dense Taipei cityscape at night seen from a wooded hillside, tower blocks lit against a hazy sky
Cyber Threat Intel

Eight Agents, Four Days, and a Government That Calls It Hybrid

Taiwan confirms AI agent-assisted attacks on government agencies in July. A vendor calls it near-autonomous; the ministry calls it hybrid. The gap between those descriptions is where the useful reading sits.

13 Aug 2026 · 9 min read
A person sitting cross-legged in low light, typing on a laptop with lines of code visible on the screen
Cyber Threat Intel

Zoom's Zero-Click Took One Day and Fewer Than 20 Prompts

Zoom patched four flaws in its annotation protocol on 11 August. The researchers say they went from decompiled binary to working zero-click exploit in a single day, driving public AI models through a disassembler and a live tracer.

13 Aug 2026 · 9 min read
A dense tangle of network cables and connectors filling a rack, layered and unlabelled.
Cyber Threat Intel

What "Known Exploited" Actually Means

There is a free, public list of the software flaws attackers are genuinely using, and its shape is not what the phrase suggests. We computed over all 1,665 entries: the median flaw was already a year old when it was declared exploited, one in five was at least five years old, and the oldest was twenty. Mostly this is not zero-days — it is patches nobody applied.

12 Aug 2026 · 6 min read
A desk laid out with printed reports, charts, a notebook and a laptop — illustrating the finance and operations managers this campaign selected for.
Cyber Threat Intel

Ransomware Went After the 46-Year-Old Manager, Not the Administrator

Zscaler tracked 351 victims across 334 organisations in one campaign. Sixty-two per cent were managers or above, the average age was 46, and information technology was only 14.6% of them.

10 Aug 2026 · 8 min read
A dimly lit server room, illustrating the estates these claimed attacks are counted against.
Cyber Threat Intel

799 Ransomware Attacks in July. Victims Confirmed 51 of Them.

July produced 799 ransomware attacks by the standard count, second only to March in 2026. Victims confirmed 51 of them. The gap is the story: these figures are assembled from attacker leak sites, and two groups claimed a third of the month between them.

9 Aug 2026 · 8 min read
A courthouse exterior, illustrating the prosecution stage this two-year-old breach campaign has now reached.
Cyber Threat Intel

The Snowflake Extortionist Pleaded Guilty. The Way In Was Still Just a Password.

Connor Riley Moucka, 26, pleaded guilty on 6 August over the campaign that took data from more than 165 organisations using Snowflake, including over 100 million AT&T call and text records. No Snowflake vulnerability was ever involved: the entry was stolen credentials against accounts with no multi-factor authentication, and every ingredient of that is still available today.

9 Aug 2026 · 7 min read
Close-up of smartphone on wooden surface displaying a bank alert message.
Cyber Threat Intel

Southeast Asia Hosts the Scam Compounds. East Asia and Australasia Lose the Money

UNODC puts 2025 scam losses at US$88.3–114.1 billion across three sub-regions. On its own breakdown South-East Asia accounts for 8.4 to 13.2 per cent of them.

6 Aug 2026 · 9 min read
An aerial view of a city skyline illuminated at night.
Cyber Threat Intel

ThreatBook Puts a Number on APAC's Year: 15,205 Incidents, and Indonesia Growing Fastest

The firm's first mid-year Asia-Pacific report covers twelve months and more than nineteen markets. Singapore ranks sixth by volume, Malaysia tenth, and dual extortion is now the default in Indonesian ransomware cases.

29 Jul 2026 · 6 min read
An empty office chair pushed back from a desk at night, a single monitor still running
Cyber Threat Intel

An AI Agent Ran Unsupervised Inside Thailand's Finance Ministry — Doing the Legwork, Not the Break-In

Researchers recovered five logs showing an open-source AI agent enumerating a ministry host without per-command approval. How the intruder got in is still unknown, and the target-specific work was written by a person.

29 Jul 2026 · 6 min read
Editorial Policy →