Cyber Team is RECATOOLS’ cybersecurity desk, covering vulnerabilities, data breaches, supply-chain attacks, threat intelligence, exploit activity, and security best practices. The desk focuses on practical implications for developers, SMEs, IT teams, and ASEAN organisations.

About this byline

Cyber Team is a specialist RECATOOLS editorial desk focused on cybersecurity coverage. Articles are produced and reviewed under RECATOOLS editorial supervision. The articles listed here keep this byline. New coverage on these beats is published under the persona whose beat it falls in: Kenji Tanaka for vulnerabilities, patching and supply-chain security, and Priya Nair for threat intelligence, attribution and privacy.

Editorial responsibility for this byline rests with Jeffrey Tan (Tan Seng Fei), RECASYS, Singapore. Our Editorial Policy sets out how sources are reviewed, how AI-assisted workflows are used, and how editorial desks and personas are defined.

153
Articles
Cybersecurity
Primary beat
Jan 2026
Writing since
~1054 min
Total reading

Articles Showing 91–100 of 153

Cisco Catalyst SD-WAN Controller authentication bypass CVE-2026-20182 zero-day vulnerability diagram
Cybersecurity

Cisco Patches Sixth SD-WAN Zero-Day of 2026 as UAT-8616 Gains Admin Access via CVSS 10.0 Auth Bypass

Cisco has disclosed CVE-2026-20182, a CVSS 10.0 authentication bypass in its Catalyst SD-WAN Controller — the sixth actively exploited SD-WAN zero-day of 2026. Researchers at Rapid7 traced the flaw to a missing device-type check in the vbond_proc_challenge_ack() function, which allowed threat group UAT-8616 to gain persistent high-privileged access and, via a separately chained older vulnerability, escalate to root. CISA ordered federal agencies to patch by 17 May 2026.

1 Jun 2026 · 5 min read
Microsoft Exchange Server OWA zero-day CVE-2026-42897 actively exploited vulnerability alert
Cybersecurity

Microsoft Exchange OWA Zero-Day CVE-2026-42897 Actively Exploited With No Permanent Patch

Microsoft confirmed active exploitation of CVE-2026-42897, a cross-site scripting flaw in Exchange's Outlook Web Access component, on 14 May 2026 — two days after a Patch Tuesday that addressed 138 separate vulnerabilities. No permanent fix exists. CISA added the flaw to its Known Exploited Vulnerabilities catalogue the same day, giving federal agencies until 29 May to remediate. On-premises Exchange 2016, 2019, and SE are affected; Exchange Online is not.

1 Jun 2026 · 8 min read
Server rack in a data centre representing shared hosting infrastructure affected by CVE-2026-48172
Cybersecurity

LiteSpeed cPanel Plugin Zero-Day CVE-2026-48172: Maximum-Severity Root Escalation Under Active Exploitation

CVE-2026-48172 in the LiteSpeed User-End cPanel Plugin carries a CVSS v4.0 score of 10.0 and was added to CISA's KEV catalogue on 26 May 2026. A low-privilege cPanel account is enough to gain root on the entire host. Here is what operators need to know and do now.

1 Jun 2026 · 7 min read
Digital map of Southeast Asia overlaid with network intrusion indicators representing the SHADOW-EARTH-053 espionage campaign
Cybersecurity

SHADOW-EARTH-053: China-Aligned Espionage Campaign Hits Government and Defence Networks Across ASEAN and Beyond

A China-aligned intrusion cluster designated SHADOW-EARTH-053 maintained covert access inside government ministries, defence contractors, and critical infrastructure across eight countries for at least 17 months. TrendAI researchers published findings on 1 May 2026 identifying targets in seven Asian nations plus Poland, with ShadowPad deployed via long-unpatched Exchange and IIS vulnerabilities — including the five-year-old ProxyLogon chain and a newer React Server Components flaw.

1 Jun 2026 · 6 min read
Dark screen of system code and a terminal, illustrating software vulnerabilities being patched.
Cybersecurity

This week's bugs to patch: a critical OTRS flaw and a Linux root hole on CISA's list

A short, practical read of the week's most urgent vulnerabilities: a critical pre-authentication flaw in the OTRS service-desk platform, and a Linux privilege-escalation bug that the US cyber agency has confirmed is being exploited and added to its must-patch catalogue.

1 Jun 2026 · 3 min read
Conceptual cyber scene: green code on a dark laptop over a backlit keyboard — illustrating this week's threat brief.
Cybersecurity

Threat Brief, Week of 18 May 2026: State-Backed Espionage in Malaysia, a Malware-Signing Takedown, and the Defender Itself Under Fire

Our weekly read of the threat landscape: a state-backed actor ran a bespoke espionage operation against Malaysian government networks, Microsoft dismantled a malware-signing-as-a-service business, and CISA flagged two actively exploited zero-days in Microsoft Defender — the very tool meant to catch the attacks. The throughline of the week: adversaries are weaponising trust.

30 May 2026 · 9 min read
Conceptual dark-terminal image reading 'data transfer complete' — evoking the data exfiltration in this Marimo RCE breach.
Cybersecurity

An LLM Agent Drove This Real Intrusion: Marimo RCE to Database Dump in Under an Hour

On 10 May an internet-exposed marimo notebook was breached through CVE-2026-39987 — and then an autonomous LLM agent took the keyboard. Sysdig's threat researchers say the agent improvised the entire post-exploitation chain, pulled an SSH key from AWS Secrets Manager, and dumped an internal database in under two minutes. A Chinese-language planning comment it left in the command stream gave it away.

30 May 2026 · 6 min read
An abstract red glitch-art render of fragmented city blocks
Cybersecurity

Laravel-Lang Supply Chain Attack — 233 Versions Backdoored Across 700 Repos in a Composer-Autoload Trick

On 22 May 2026, an attacker rewrote version tags across the Laravel-Lang ecosystem to deliver a 5,900-line PHP credential stealer via composer autoload. What every Laravel team must check this week.

22 May 2026 · 12 min read
A red backlit keyboard below a screen of falling green code
Cybersecurity

Megalodon Campaign Backdoors 5,561 GitHub Repos in Six Hours — Inside the Largest GitHub Actions Supply-Chain Attack on Record

An automated campaign called Megalodon pushed 5,718 malicious commits to 5,561 GitHub repos between 18-21 May 2026, exfiltrating CI secrets via poisoned GitHub Actions. What to check now.

21 May 2026 · 12 min read
A person using a laptop showing a VPN app in a cafe, a latte beside them
Cybersecurity

Pwn2Own Berlin 2026 Pays Out $1.4M Across Three Days — Chrome Sandbox, Tesla Infotainment, Linux Kernel All Fall

The OffensiveCon Pwn2Own contest wrapped on Wednesday with $1.4 million paid out across 27 zero-days. A Chrome sandbox escape, a Tesla in-car LPE chain and a Linux kernel use-after-free were among the highest-paid bounties.

19 May 2026 · 8 min read
Editorial Policy →