Cyber Team is RECATOOLS’ cybersecurity desk, covering vulnerabilities, data breaches, supply-chain attacks, threat intelligence, exploit activity, and security best practices. The desk focuses on practical implications for developers, SMEs, IT teams, and ASEAN organisations.

About this byline

Cyber Team is a specialist RECATOOLS editorial desk focused on cybersecurity coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

101
Articles
Cybersecurity
Primary beat
Jan 2026
Writing since
~612 min
Total reading

Articles · Cybersecurity Showing 11–20 of 100

Close-up of colorful source code on a monitor, showcasing programming and technology concepts.
Cybersecurity

Accenture Says It Remediated an 'Isolated Matter' — a Seller Claims 35GB of Source Code and Cloud Keys

A forum seller claims to have taken 35GB of Accenture source code and cloud credentials; Accenture acknowledges an isolated matter it says it has remediated. The scope is unverified — but the claimed credential types make precautionary rotation worthwhile.

11 Jul 2026 · 6 min read
Adobe ColdFusion CVE-2026-48282: A Perfect-Score Path-Traversal Flaw CISA Says Is Being Exploited
Cybersecurity

Adobe ColdFusion CVE-2026-48282: A Perfect-Score Path-Traversal Flaw CISA Says Is Being Exploited

CISA added a maximum-severity Adobe ColdFusion path-traversal flaw to its exploited-vulnerabilities catalog on 7 July, with a federal patch deadline of 10 July. Patched builds have shipped since 30 June — apply them and check exposed servers now.

11 Jul 2026 · 6 min read
Langflow Becomes the First AI-Agent Platform on CISA's Exploited-Vulnerability List
Cybersecurity

Langflow Becomes the First AI-Agent Platform on CISA's Exploited-Vulnerability List

On 7 July 2026, CISA added an actively-exploited vulnerability in Langflow — a popular open-source framework for building AI agents — to its Known Exploited Vulnerabilities catalog, ordering US federal agencies to patch it by 10 July. It is the first time an AI-agent orchestration platform has appeared in the KEV catalog, and it caps roughly fourteen months in which Langflow has drawn at least seven separate exploited flaws. The reason is structural: AI-agent frameworks concentrate high-value credentials and system-level code execution in one place, making them a rich target. The fix is to update to Langflow 1.9.2 or later — and, if the instance was internet-exposed, to rotate every API key stored in it.

9 Jul 2026 · 8 min read
A classroom setting featuring laptops and desks, capturing a modern educational environment.
Cybersecurity

CVE-2026-8451: A CitrixBleed-Class NetScaler Flaw Was Exploited Within a Day of Disclosure

CVE-2026-8451 is a CitrixBleed-class, unauthenticated memory-overread flaw in Citrix NetScaler ADC and Gateway appliances configured as a SAML Identity Provider. Citrix disclosed and patched it on 30 June 2026, and SecurityWeek reported that Lupovis observed active exploitation within 24 hours. The leak is more constrained than earlier CitrixBleed flaws and specific data exposure is unconfirmed, but affected operators should upgrade to Citrix's patched builds or disable SAML IdP until they can patch.

7 Jul 2026 · 8 min read
Google and the FBI Disrupt NetNut, a 2-Million-Device Residential Proxy Network Fuelled by Smart TVs
Cybersecurity

Google and the FBI Disrupt NetNut, a 2-Million-Device Residential Proxy Network Fuelled by Smart TVs

Google's Threat Intelligence Group, working with the FBI, Lumen and other partners, has disrupted NetNut — a residential-proxy network also tracked as Popa that Google estimates involved more than two million hijacked consumer devices worldwide, many of them Android smart TVs and streaming boxes. Google disabled accounts tied to NetNut's control infrastructure and flagged its SDK in Play Protect; Reuters reported that Alarum, NetNut's parent company, was informed of FBI domain seizures and said it would cooperate with law enforcement. As with earlier proxy takedowns, the operation degrades the network without ending a market that keeps re-forming through resellers and white-labelled brands.

6 Jul 2026 · 9 min read
Detailed shot of a rusty padlock on a weathered door conveying security and time passage.
Cybersecurity

SharePoint RCE CVE-2026-45659 Added to CISA KEV: A 'Less Likely' May Patch Is Now Actively Exploited

CISA added CVE-2026-45659, a CVSS 8.8 deserialization remote-code-execution flaw in on-premises Microsoft SharePoint Server, to its Known Exploited Vulnerabilities catalog on 1 July 2026, citing active exploitation and setting a 4 July federal remediation due date — changing the priority on a May security update that Microsoft had rated 'Exploitation Less Likely.' An authenticated attacker with only low-privilege Site Member access can execute code on the server, and the fix is to verify the May 2026 update across the whole SharePoint farm.

6 Jul 2026 · 7 min read
Close-up of a modern building facade with vertical symmetry in New Delhi, showcasing architectural aesthetics.
Cybersecurity

Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245: Netadmin-to-Root, Exploited for Months Before Disclosure

Cisco disclosed CVE-2026-20245 on 5 June 2026, a high-severity command-injection flaw in Catalyst SD-WAN Manager that Mandiant found had been exploited as a zero-day for months. An authenticated attacker with netadmin privileges can escalate to root via a crafted file upload; the fix is to upgrade to the patched releases and, given the attacker's heavy anti-forensics, to treat detection as incident response rather than routine patching.

2 Jul 2026 · 7 min read
A person photographing a cityscape with a smartphone during sunset, showcasing vibrant city lights.
Cybersecurity

FortiBleed: FortiGate Credential Exposure Hits Tens of Thousands of Devices — And It Is Not a New CVE

FortiBleed is a large-scale credential-exposure campaign against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. Recorded Future says the dataset covers 73,932 FortiGate URLs across 194 countries, with sampled administrator credentials validated; Fortinet says the activity is not a new vulnerability but stems from credential reuse, brute force, weak hygiene and missing MFA.

2 Jul 2026 · 10 min read
A person is typing code on a laptop, focusing on the screen with programming script.
Cybersecurity

Linux 'pedit COW' (CVE-2026-46331) Hands Local Users Root via Page-Cache Corruption — Patch and Reboot

CVE-2026-46331, nicknamed pedit COW, is a Linux kernel local privilege-escalation flaw in the traffic-control act_pedit action: a missing bounds check corrupts page-cache memory and lets a local user gain root. A public proof-of-concept has been available since 17 June; Red Hat rates it Important, Ubuntu rates it High, and vendor fixes or mitigation guidance are now available across several Linux ecosystems.

30 Jun 2026 · 8 min read
Aerial view of the snow-capped mountains in Bușteni, Romania, showcasing rugged terrain.
Cybersecurity

PTC Windchill and FlexPLM RCE CVE-2026-12569 Is Under Active Attack — Patch Now and Hunt for Webshells

CISA added CVE-2026-12569, a critical remote code execution flaw in PTC Windchill PDMLink and FlexPLM, to its Known Exploited Vulnerabilities catalog with a 28 June 2026 federal deadline. Attackers are deploying JSP webshells into the Windchill login directory; PTC has directed customers to version-specific remediation steps and patches.

30 Jun 2026 · 7 min read
Editorial Policy →