Cyber Team is RECATOOLS’ cybersecurity desk, covering vulnerabilities, data breaches, supply-chain attacks, threat intelligence, exploit activity, and security best practices. The desk focuses on practical implications for developers, SMEs, IT teams, and ASEAN organisations.

About this byline

Cyber Team is a specialist RECATOOLS editorial desk focused on cybersecurity coverage. Articles are produced and reviewed under RECATOOLS editorial supervision. The articles listed here keep this byline. New coverage on these beats is published under the persona whose beat it falls in: Kenji Tanaka for vulnerabilities, patching and supply-chain security, and Priya Nair for threat intelligence, attribution and privacy.

Editorial responsibility for this byline rests with Jeffrey Tan (Tan Seng Fei), RECASYS, Singapore. Our Editorial Policy sets out how sources are reviewed, how AI-assisted workflows are used, and how editorial desks and personas are defined.

153
Articles
Cybersecurity
Primary beat
Jan 2026
Writing since
~1054 min
Total reading

Articles · Cybersecurity Showing 11–20 of 140

A traveller sitting at an airport gate with a laptop, an aircraft visible through the window behind.
Cybersecurity

Public Wi-Fi: The Warning Is Out of Date, the Exposure Is Not

All eight sites we checked end on HTTPS and all eight set HSTS, so nobody on the café network can read what you send — including to the bank. What they can still see is which sites you visit, because a TLS connection names its destination in the clear before it encrypts anything. The fix exists; one of our eight has it, and that one did not choose it.

11 Aug 2026 · 8 min read
A SIM card resting on its ejected tray beside a black smartphone, gold contacts facing up — the component the researchers treated as the starting point of the attack.
Cybersecurity

A SIM Card Can Order Your Phone Onto 2G. That Is in the Specification.

Birmingham researchers surveyed 26 devices and found nine expose an interface that lets the SIM issue modem commands. The behaviour is not a bug — the cellular standards define it.

11 Aug 2026 · 8 min read
A card on a restaurant table inviting diners to scan a code to order.
Cybersecurity

What Does a QR Code Actually Store? You Cannot Tell by Looking

Two codes pointing at two different sites differ in 35.6 per cent of their squares — and no human can tell, because nobody reads QR patterns. That makes "check before you scan" impossible to follow. What a code can hold besides a link, including a wireless password, and where the only real check actually happens.

11 Aug 2026 · 6 min read
A cast metal letter slot in a door, embossed with the word LETTERS.
Cybersecurity

Is This Email Really From Them? The Check You Cannot See

The sender name is free text and the address can be forged. The real check happens in DNS before the message reaches you. We looked up eight domains: five ask receiving servers to reject forgeries outright, two ask for quarantine, and one publishes nothing at all — which turned out to be ours.

11 Aug 2026 · 6 min read
A rusted brass padlock hanging on a weathered green painted door.
Cybersecurity

What Does the Padlock Actually Prove? We Read Six Real Certificates

It certifies that the connection is encrypted and that the name in the address bar matches the certificate. It says nothing about who is behind it. Four of six certificates we read — including a major Singapore bank's — name no organisation at all, and a lookalike domain gets its own valid certificate free, in minutes.

11 Aug 2026 · 6 min read
A WordPress logo rendered over website code — illustrating the plugin ecosystem through which this compromise reached site dashboards.
Cybersecurity

A Poisoned JSON Feed Made Hidden Admins on WordPress Sites

No plugin update was published. Attackers reached BdThemes storage, poisoned a feed the plugins pull into the admin dashboard, and created administrator accounts hidden from the user list.

11 Aug 2026 · 7 min read
A signup form rendered on a screen — illustrating the page whose fields were read by third-party marketing trackers.
Cybersecurity

A Signup Form Sent Passwords to Facebook and Google for Nearly Two Years

Klaviyo's signup form was misconfigured so third-party marketing trackers captured what users typed, including passwords. The company says fewer than 200 people were affected, based on logs it will not describe.

11 Aug 2026 · 8 min read
A field of wind turbines under open sky — illustrating the unstaffed remote sites whose cellular links became the route into Poland's grid.
Cybersecurity

Poland's Power Plants Were Reached Through the Mobile Network Nobody Watches

CERT Polska has documented the first real-world use of a private APN as a route into operational technology. Thirty wind and solar sites and two heat plants were affected.

11 Aug 2026 · 8 min read
Industrial pipework and valves, illustrating the treatment plant equipment these controllers operate.
Cybersecurity

Water Systems in Twelve States Were Broken Into. The Fix Is a Budget Line, Not Advice.

Water systems in at least twelve US states have been broken into, with attackers changing controller passwords and IP addresses to lock out operators. Retired NSA director Paul Nakasone says the controllers should never have been on the internet — advice that is correct, decade-old, and has never been paired with the money small utilities would need to act on it.

9 Aug 2026 · 8 min read
Macro view of a processor die on a circuit board, illustrating the branch-prediction hardware this attack targets.
Cybersecurity

MIT Broke Spectre v2 Defences. AMD Will Patch, Intel Will Not.

MIT researchers showed that Spectre v2 mitigations can be stepped around on current Intel and AMD processors, breaking KASLR in every run and extracting the root password hash in half of them. AMD has committed to kernel patches, Intel declined to mitigate further, and Arm says the class of attack is not one it protects against.

9 Aug 2026 · 7 min read
Editorial Policy →