Cyber Team is RECATOOLS’ cybersecurity desk, covering vulnerabilities, data breaches, supply-chain attacks, threat intelligence, exploit activity, and security best practices. The desk focuses on practical implications for developers, SMEs, IT teams, and ASEAN organisations.

About this byline

Cyber Team is a specialist RECATOOLS editorial desk focused on cybersecurity coverage. Articles are produced and reviewed under RECATOOLS editorial supervision. The articles listed here keep this byline. New coverage on these beats is published under the persona whose beat it falls in: Kenji Tanaka for vulnerabilities, patching and supply-chain security, and Priya Nair for threat intelligence, attribution and privacy.

Editorial responsibility for this byline rests with Jeffrey Tan (Tan Seng Fei), RECASYS, Singapore. Our Editorial Policy sets out how sources are reviewed, how AI-assisted workflows are used, and how editorial desks and personas are defined.

153
Articles
Cybersecurity
Primary beat
Jan 2026
Writing since
~1054 min
Total reading

Articles Showing 11–20 of 153

A dense curtain of fibre-optic strands lit from within against a dark background.
Cybersecurity

The Post-Quantum Migration Already Started, and Nobody Told You

Quantum computing and encryption is usually framed as a countdown. For the connections you actually use, the migration has already happened: 8 of the 10 sites we probed complete a handshake with nothing on offer but post-quantum key exchange, all negotiating the same hybrid. Almost none of them decided to — infrastructure providers switched it on, this site included.

12 Aug 2026 · 6 min read
A dense tangle of network cables and connectors filling a rack, layered and unlabelled.
Cyber Threat Intel

What "Known Exploited" Actually Means

There is a free, public list of the software flaws attackers are genuinely using, and its shape is not what the phrase suggests. We computed over all 1,665 entries: the median flaw was already a year old when it was declared exploited, one in five was at least five years old, and the oldest was twenty. Mostly this is not zero-days — it is patches nobody applied.

12 Aug 2026 · 6 min read
Two towering stacks of labelled paper files with handwritten date tabs on their edges — illustrative of a monthly patch load large enough to be counted three different ways.
Cybersecurity

Microsoft Fixed 421 Flaws. Or 400. Only One Is Being Exploited.

Three different totals are circulating for the same Patch Tuesday, and all are defensible. The one number that matters is one: a WinSock use-after-free North Korea has had since June.

11 Aug 2026 · 7 min read
A person at a desk opening a paper document beside a laptop, with a cup and flowers on the table.
Cybersecurity

How Many Domains Does Your Bank Send Email From?

Every scam-email guide ends with "check the sender", which assumes a bank is a domain. We read the published records for 25 of them: outright forgery is mostly handled — 16 ask receivers to reject it and all five government domains do — but four of six banking brands protect some of their own domains and not others. Recognising one tells you nothing about the next. Our own record is one of the weak ones, and we say so.

11 Aug 2026 · 7 min read
A traveller sitting at an airport gate with a laptop, an aircraft visible through the window behind.
Cybersecurity

Public Wi-Fi: The Warning Is Out of Date, the Exposure Is Not

All eight sites we checked end on HTTPS and all eight set HSTS, so nobody on the café network can read what you send — including to the bank. What they can still see is which sites you visit, because a TLS connection names its destination in the clear before it encrypts anything. The fix exists; one of our eight has it, and that one did not choose it.

11 Aug 2026 · 8 min read
A SIM card resting on its ejected tray beside a black smartphone, gold contacts facing up — the component the researchers treated as the starting point of the attack.
Cybersecurity

A SIM Card Can Order Your Phone Onto 2G. That Is in the Specification.

Birmingham researchers surveyed 26 devices and found nine expose an interface that lets the SIM issue modem commands. The behaviour is not a bug — the cellular standards define it.

11 Aug 2026 · 8 min read
A card on a restaurant table inviting diners to scan a code to order.
Cybersecurity

What Does a QR Code Actually Store? You Cannot Tell by Looking

Two codes pointing at two different sites differ in 35.6 per cent of their squares — and no human can tell, because nobody reads QR patterns. That makes "check before you scan" impossible to follow. What a code can hold besides a link, including a wireless password, and where the only real check actually happens.

11 Aug 2026 · 6 min read
A cast metal letter slot in a door, embossed with the word LETTERS.
Cybersecurity

Is This Email Really From Them? The Check You Cannot See

The sender name is free text and the address can be forged. The real check happens in DNS before the message reaches you. We looked up eight domains: five ask receiving servers to reject forgeries outright, two ask for quarantine, and one publishes nothing at all — which turned out to be ours.

11 Aug 2026 · 6 min read
A rusted brass padlock hanging on a weathered green painted door.
Cybersecurity

What Does the Padlock Actually Prove? We Read Six Real Certificates

It certifies that the connection is encrypted and that the name in the address bar matches the certificate. It says nothing about who is behind it. Four of six certificates we read — including a major Singapore bank's — name no organisation at all, and a lookalike domain gets its own valid certificate free, in minutes.

11 Aug 2026 · 6 min read
A WordPress logo rendered over website code — illustrating the plugin ecosystem through which this compromise reached site dashboards.
Cybersecurity

A Poisoned JSON Feed Made Hidden Admins on WordPress Sites

No plugin update was published. Attackers reached BdThemes storage, poisoned a feed the plugins pull into the admin dashboard, and created administrator accounts hidden from the user list.

11 Aug 2026 · 7 min read
Editorial Policy →