Cyber Team is RECATOOLS’ cybersecurity desk, covering vulnerabilities, data breaches, supply-chain attacks, threat intelligence, exploit activity, and security best practices. The desk focuses on practical implications for developers, SMEs, IT teams, and ASEAN organisations.

About this byline

Cyber Team is a specialist RECATOOLS editorial desk focused on cybersecurity coverage. Articles are produced and reviewed under RECATOOLS editorial supervision. The articles listed here keep this byline. New coverage on these beats is published under the persona whose beat it falls in: Kenji Tanaka for vulnerabilities, patching and supply-chain security, and Priya Nair for threat intelligence, attribution and privacy.

Editorial responsibility for this byline rests with Jeffrey Tan (Tan Seng Fei), RECASYS, Singapore. Our Editorial Policy sets out how sources are reviewed, how AI-assisted workflows are used, and how editorial desks and personas are defined.

153
Articles
Cybersecurity
Primary beat
Jan 2026
Writing since
~1054 min
Total reading

Articles · Cybersecurity Showing 1–10 of 140

A stylised terminal display of hexadecimal data, illustrating a report on encrypted AI reasoning traces being decoded by cheaper models.
Cybersecurity

Weaker Models Can Read a Frontier Model's Encrypted Reasoning

OpenAI, Anthropic and Google return reasoning to clients as encrypted blocks. Researchers replayed those blocks into cheaper models from the same provider, which transcribed them in plain language. The encryption was never broken - the blocks were simply portable.

15 Aug 2026 · 8 min read
Rack-mounted network appliances in a server cabinet, illustrating a report on an exploited crash flaw in Cisco firewalls.
Cybersecurity

One Malformed Request Crashes the Firewall. CISA Gave Three Days.

CVE-2026-20349 lets an unauthenticated attacker reload a Cisco ASA or FTD firewall through the remote-access SSL VPN. There is no workaround, the federal deadline was three days, and the device it crashes is both your perimeter and the way your staff get in.

15 Aug 2026 · 8 min read
A close-up of syntax-highlighted PHP and HTML source code on a dark editor screen, shown at an angle with line numbers down the left
Cybersecurity

GLM-5.3 Finds Bugs Like the Frontier. It Is 23 Points Behind at Using Them.

Z.ai's model edges Mythos 5 by 0.7 points on vulnerability detection and trails it by 23.6 on exploit development. The second number is the one that describes the risk - and both are the company's own.

14 Aug 2026 · 8 min read
A vertical run of weathered steel chain links in close focus, each link interlocking with the next, against a blurred grey and green background.
Cybersecurity

What Our Own Security Audit Found

Nine parallel red-team reviews of our own admin panel produced twelve security findings. Eleven are closed, including all five criticals, and one remains open and undescribed here. The bugs were ordinary — what made them survive review is that almost every one lived between two files that were each correct on their own.

14 Aug 2026 · 10 min read
A magnifying lens held over a dictionary page, enlarging the entries love, and low, — two words a single deleted letter apart.
Cybersecurity

How to Check Who Owns the Lookalikes of Your Domain

Five edit rules per character generate the confusable space around a domain name, and DNS says which of those names already have an owner. Run on our own label, 6 of 58 variants are taken. Run on ten well-known brands, 286 of 366 are. The gap is mostly fame rather than brevity — but only a control with invented labels could show that.

14 Aug 2026 · 7 min read
A brass combination padlock and heavy chain fastening a rusted metal gate, green fields blurred behind
Cybersecurity

OpenAI Shipped an Exploit-Writing Model. The Base Model Could Already Do It.

GPT-5.6-Cyber completes 95 per cent of exploit-chain prompts against 1.5 per cent for the general model it is built on. The capability was already there; the refusals were the difference. Access is gated by contract, not code.

14 Aug 2026 · 8 min read
Fibre optic patch cables plugged into the front panels of rack-mounted servers, photographed close up
Cybersecurity

One Unrevoked Token, Three Tools Deep: Inside the LiteLLM Breach

Two poisoned LiteLLM releases were live on PyPI for forty minutes in March. CloudSEK has now mapped roughly 434,000 captured files to more than 2,500 organisations - and the chain started three tools upstream.

13 Aug 2026 · 8 min read
A dense curtain of fibre-optic strands lit from within against a dark background.
Cybersecurity

The Post-Quantum Migration Already Started, and Nobody Told You

Quantum computing and encryption is usually framed as a countdown. For the connections you actually use, the migration has already happened: 8 of the 10 sites we probed complete a handshake with nothing on offer but post-quantum key exchange, all negotiating the same hybrid. Almost none of them decided to — infrastructure providers switched it on, this site included.

12 Aug 2026 · 6 min read
Two towering stacks of labelled paper files with handwritten date tabs on their edges — illustrative of a monthly patch load large enough to be counted three different ways.
Cybersecurity

Microsoft Fixed 421 Flaws. Or 400. Only One Is Being Exploited.

Three different totals are circulating for the same Patch Tuesday, and all are defensible. The one number that matters is one: a WinSock use-after-free North Korea has had since June.

11 Aug 2026 · 7 min read
A person at a desk opening a paper document beside a laptop, with a cup and flowers on the table.
Cybersecurity

How Many Domains Does Your Bank Send Email From?

Every scam-email guide ends with "check the sender", which assumes a bank is a domain. We read the published records for 25 of them: outright forgery is mostly handled — 16 ask receivers to reject it and all five government domains do — but four of six banking brands protect some of their own domains and not others. Recognising one tells you nothing about the next. Our own record is one of the weak ones, and we say so.

11 Aug 2026 · 7 min read
Editorial Policy →