Cyber Team is RECATOOLS’ cybersecurity desk, covering vulnerabilities, data breaches, supply-chain attacks, threat intelligence, exploit activity, and security best practices. The desk focuses on practical implications for developers, SMEs, IT teams, and ASEAN organisations.

About this byline

Cyber Team is a specialist RECATOOLS editorial desk focused on cybersecurity coverage. Articles are produced and reviewed under RECATOOLS editorial supervision. The articles listed here keep this byline. New coverage on these beats is published under the persona whose beat it falls in: Kenji Tanaka for vulnerabilities, patching and supply-chain security, and Priya Nair for threat intelligence, attribution and privacy.

Editorial responsibility for this byline rests with Jeffrey Tan (Tan Seng Fei), RECASYS, Singapore. Our Editorial Policy sets out how sources are reviewed, how AI-assisted workflows are used, and how editorial desks and personas are defined.

153
Articles
Cybersecurity
Primary beat
Jan 2026
Writing since
~1054 min
Total reading

Articles Showing 71–80 of 153

A person is typing code on a laptop, focusing on the screen with programming script.
Cybersecurity

Linux 'pedit COW' (CVE-2026-46331) Hands Local Users Root via Page-Cache Corruption — Patch and Reboot

CVE-2026-46331, nicknamed pedit COW, is a Linux kernel local privilege-escalation flaw in the traffic-control act_pedit action: a missing bounds check corrupts page-cache memory and lets a local user gain root. A public proof-of-concept has been available since 17 June; Red Hat rates it Important, Ubuntu rates it High, and vendor fixes or mitigation guidance are now available across several Linux ecosystems.

30 Jun 2026 · 8 min read
Aerial view of the snow-capped mountains in Bușteni, Romania, showcasing rugged terrain.
Cybersecurity

PTC Windchill and FlexPLM RCE CVE-2026-12569 Is Under Active Attack — Patch Now and Hunt for Webshells

CISA added CVE-2026-12569, a critical remote code execution flaw in PTC Windchill PDMLink and FlexPLM, to its Known Exploited Vulnerabilities catalog with a 28 June 2026 federal deadline. Attackers are deploying JSP webshells into the Windchill login directory; PTC has directed customers to version-specific remediation steps and patches.

30 Jun 2026 · 7 min read
Crop unrecognizable computer geek typing on netbook with codes on screen while hacking system in darkness
Cybersecurity

Cisco Unified CM SSRF Flaw CVE-2026-20230 Is Now Being Exploited — Patch by 28 June and Check for Compromise

CISA added CVE-2026-20230, a server-side request forgery flaw in Cisco Unified Communications Manager, to its Known Exploited Vulnerabilities catalog with a 28 June 2026 federal deadline. An unauthenticated attacker can write files that could later be used to escalate to root — but only where the WebDialer service is enabled, which is not the default. Cisco patched it on 3 June.

30 Jun 2026 · 6 min read
Detailed close-up of ethernet cables and network connections on a router, showcasing modern technology.
Cybersecurity

Three Maximum-Severity Ubiquiti UniFi OS Flaws Are Being Exploited — Patch via Bulletin 064 and Check for Compromise

CISA added three maximum-severity Ubiquiti UniFi OS vulnerabilities (CVE-2026-34908, -34909 and -34910) to its Known Exploited Vulnerabilities catalog on 23 June 2026, citing active exploitation. Chained, they enable unauthenticated remote code execution. Ubiquiti patched them on 21 May via Security Advisory Bulletin 064.

30 Jun 2026 · 6 min read
From below of monitor of modern computer with opened files on blue screen
Cybersecurity

Joomla JCE Flaw CVE-2026-48907 (CVSS 10.0) Is Being Actively Exploited — Patch and Check for Compromise

CISA added CVE-2026-48907, a maximum-severity flaw in the Widget Factory Joomla Content Editor extension (JCE / JCE Pro), to its KEV catalog on 16 June 2026, citing active exploitation. An unauthenticated attacker can create editor profiles and upload and run PHP code. A fix shipped in JCE 2.9.99.5.

19 Jun 2026 · 6 min read
A darkened computer screen filled with code, representing a ransomware attack.
Cybersecurity

Palo Alto GlobalProtect Flaw CVE-2026-0257 Is Under Active Exploitation — Patch or Mitigate Now

Palo Alto Networks has confirmed active exploitation of CVE-2026-0257, an authentication-bypass flaw in PAN-OS GlobalProtect that lets a remote attacker establish an unauthorised VPN connection. Fixes and interim mitigations are available, and CISA set a 1 June federal deadline.

19 Jun 2026 · 6 min read
A mysterious silhouette with red binary code projected over the face, set against a dark, moody background.
Cybersecurity

Oracle Patches Actively Exploited PeopleSoft Zero-Day (CVE-2026-35273) as Data-Theft Campaign Hits Universities

Oracle issued an out-of-band alert on 10 June for CVE-2026-35273, a CVSS 9.8 unauthenticated remote-code-execution flaw in PeopleSoft PeopleTools that Mandiant says was exploited as a zero-day from 27 May. Google attributed the data-theft campaign to ShinyHunters and notified 100-plus exposed organisations, most in higher education; the University of Nottingham is the first named victim in public reporting, with breach-notification analysis citing about 454,600 people affected.

16 Jun 2026 · 8 min read
Hands using a contactless credit card on a payment terminal with a stylish minimal background.
Cybersecurity

NFCShare: Android Malware Poses as a Bank App Update to Steal Card Data Through Your Phone's NFC Chip

Researchers at D3Lab say a new wave of the NFCShare Android trojan, running since mid-May 2026, poses as banking-app updates hosted on GitHub and tricks victims into tapping their payment card to the phone — capturing the card details and PIN for NFC relay fraud. The campaign now impersonates Italian and Spanish banks; the defence is simple, and it is mostly about not installing the fake update.

16 Jun 2026 · 7 min read
Close-up of a laptop screen displaying programming code with a cute plush toy reflecting.
Cybersecurity

Miasma Returns With 'Phantom Gyp': npm Worm Sidesteps the Install-Script Defences Teams Just Deployed

On 3 June, two days after the Red Hat npm compromise, the Miasma worm returned with a new delivery trick: a 157-byte binding.gyp file that runs code during npm install without any lifecycle script — bypassing the install-script checks teams had just leaned on. This wave hit 57 packages across 286+ versions (a point-in-time tally) and plants backdoors in AI coding-assistant configs.

11 Jun 2026 · 7 min read
Close-up view of smartphone home screen featuring popular apps like Instagram, Snapchat, and Chrome.
Cybersecurity

One Trojan, Three Lures: MyCERT Warns of Android Banking Malware Hitting Maybank and CIMB Users

MyCERT's 6 June advisory details an active Android banking-trojan campaign using three lure brands — Delivery4U, KerjaExpress and MaxTag — to deliver one malware family that steals banking logins, intercepts OTP/TAC codes and can lock the device. Maybank MAE and CIMB Octo users are the main targets.

7 Jun 2026 · 6 min read
Editorial Policy →