Cyber Team is RECATOOLS’ cybersecurity desk, covering vulnerabilities, data breaches, supply-chain attacks, threat intelligence, exploit activity, and security best practices. The desk focuses on practical implications for developers, SMEs, IT teams, and ASEAN organisations.

About this byline

Cyber Team is a specialist RECATOOLS editorial desk focused on cybersecurity coverage. Articles are produced and reviewed under RECATOOLS editorial supervision. The articles listed here keep this byline. New coverage on these beats is published under the persona whose beat it falls in: Kenji Tanaka for vulnerabilities, patching and supply-chain security, and Priya Nair for threat intelligence, attribution and privacy.

Editorial responsibility for this byline rests with Jeffrey Tan (Tan Seng Fei), RECASYS, Singapore. Our Editorial Policy sets out how sources are reviewed, how AI-assisted workflows are used, and how editorial desks and personas are defined.

153
Articles
Cybersecurity
Primary beat
Jan 2026
Writing since
~1054 min
Total reading

Articles Showing 31–40 of 153

An open combination padlock resting on a laptop keyboard.
Cybersecurity

The Langflow Patch Deadline Is Today. Singapore Reported Active Exploitation Yesterday

CVE-2026-9198 gives unauthenticated remote code execution on default Langflow deployments. CISA allowed three days; CSA reported exploitation on day two.

7 Aug 2026 · 8 min read
Close-up of smartphone on wooden surface displaying a bank alert message.
Cyber Threat Intel

Southeast Asia Hosts the Scam Compounds. East Asia and Australasia Lose the Money

UNODC puts 2025 scam losses at US$88.3–114.1 billion across three sub-regions. On its own breakdown South-East Asia accounts for 8.4 to 13.2 per cent of them.

6 Aug 2026 · 9 min read
Two ring binders of paper records stacked on a wooden desk.
Cybersecurity

The Test Data Was Supposed to Be Fake. It Held 70,000 Real NRIC Numbers

A Singapore Land Authority test dataset created in 1998 was meant to hold only mock records. It held real names, NRIC numbers and addresses for 70,000 people.

5 Aug 2026 · 7 min read
A black alarm clock on a desk beside a laptop, showing a few minutes to twelve.
Cybersecurity

Three Days to Patch N-able. A Year Ago 92% of KEV Entries Got Three Weeks

CISA gave three days to fix an actively exploited N-able bypass. Across the catalogue, the three-week remediation window has stopped being the norm.

4 Aug 2026 · 8 min read
Close-up of a smartphone displaying a fraud alert notification on a wooden surface.
Cybersecurity

Singapore's Cyber Command Ran Its First Scam Sweep. It Was the Third in Six Weeks

Singapore stood up a dedicated Cyber Command on 3 July. Its first islandwide scam sweep was the third such operation in six weeks, and the smallest.

3 Aug 2026 · 8 min read
A small microcontroller board resting on hand-drawn circuit design sketches beside its enclosure
Cybersecurity

The Coldcard Entropy Failure Was a Build-Configuration Bug, Not a Cryptography Bug

A macro was defined and set to zero. One guard tested whether it existed rather than what it held, the linker bound silently, and five years of hardware wallets seeded themselves from a software PRNG. The lesson is not about Bitcoin.

2 Aug 2026 · 14 min read
A hand holding a bare printed circuit board with its main controller chip visible
Cybersecurity

Attackers Sweep 1,367 Bitcoin From Coldcard Wallets After Five-Year Firmware Flaw

Three waves of automated sweeps have taken about $89 million in bitcoin from 4,585 addresses since 30 July. The cause is a firmware defect that weakened the randomness behind wallet keys for five years.

2 Aug 2026 · 6 min read
Yellow network patch cables plugged into the numbered ports of a rack-mounted switch
Cybersecurity

A Password Was Built Into Cisco's Firewall Manager. It Is Being Exploited, and Agencies Had Three Days to Fix It

CVE-2026-20316 scores 5.3 — a medium. CISA still gave federal agencies three days and told them to check for compromise. The gap between those two facts is the story.

1 Aug 2026 · 8 min read
A wide harvested field with a scattering of hay bales running to the horizon — illustrating a small confirmed-exploitation set inside a very large body of disclosures.
Cybersecurity

Vulnerability Disclosures Will Pass Last Year's Record by August. The Share Anyone Actually Exploits Is Falling

AI code scanning has pushed disclosures to 45,207 in seven months. Our own count of the exploited-vulnerabilities catalogue shows the confirmed-exploitation side rising far more slowly.

1 Aug 2026 · 5 min read
Aerial view of a municipal water treatment works with circular settling tanks — illustrating the kind of small utility reached in this attack.
Cybersecurity

Thirty Minnesota Water Utilities Were Hit in One Weekend. The Flaw at the Centre Is Five Years Old and Has No Patch

A coordinated attack reached operational technology at more than 30 municipal water systems. One plant went offline for two hours, and staff recovered it by hand.

1 Aug 2026 · 5 min read
Editorial Policy →