Cyber Team is RECATOOLS’ cybersecurity desk, covering vulnerabilities, data breaches, supply-chain attacks, threat intelligence, exploit activity, and security best practices. The desk focuses on practical implications for developers, SMEs, IT teams, and ASEAN organisations.

About this byline

Cyber Team is a specialist RECATOOLS editorial desk focused on cybersecurity coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

101
Articles
Cybersecurity
Primary beat
Jan 2026
Writing since
~612 min
Total reading

Articles · Cybersecurity Showing 21–30 of 100

Crop unrecognizable computer geek typing on netbook with codes on screen while hacking system in darkness
Cybersecurity

Cisco Unified CM SSRF Flaw CVE-2026-20230 Is Now Being Exploited — Patch by 28 June and Check for Compromise

CISA added CVE-2026-20230, a server-side request forgery flaw in Cisco Unified Communications Manager, to its Known Exploited Vulnerabilities catalog with a 28 June 2026 federal deadline. An unauthenticated attacker can write files that could later be used to escalate to root — but only where the WebDialer service is enabled, which is not the default. Cisco patched it on 3 June.

30 Jun 2026 · 6 min read
Detailed close-up of ethernet cables and network connections on a router, showcasing modern technology.
Cybersecurity

Three Maximum-Severity Ubiquiti UniFi OS Flaws Are Being Exploited — Patch via Bulletin 064 and Check for Compromise

CISA added three maximum-severity Ubiquiti UniFi OS vulnerabilities (CVE-2026-34908, -34909 and -34910) to its Known Exploited Vulnerabilities catalog on 23 June 2026, citing active exploitation. Chained, they enable unauthenticated remote code execution. Ubiquiti patched them on 21 May via Security Advisory Bulletin 064.

30 Jun 2026 · 6 min read
From below of monitor of modern computer with opened files on blue screen
Cybersecurity

Joomla JCE Flaw CVE-2026-48907 (CVSS 10.0) Is Being Actively Exploited — Patch and Check for Compromise

CISA added CVE-2026-48907, a maximum-severity flaw in the Widget Factory Joomla Content Editor extension (JCE / JCE Pro), to its KEV catalog on 16 June 2026, citing active exploitation. An unauthenticated attacker can create editor profiles and upload and run PHP code. A fix shipped in JCE 2.9.99.5.

19 Jun 2026 · 6 min read
Palo Alto GlobalProtect Flaw CVE-2026-0257 Is Under Active Exploitation — Patch or Mitigate Now
Cybersecurity

Palo Alto GlobalProtect Flaw CVE-2026-0257 Is Under Active Exploitation — Patch or Mitigate Now

Palo Alto Networks has confirmed active exploitation of CVE-2026-0257, an authentication-bypass flaw in PAN-OS GlobalProtect that lets a remote attacker establish an unauthorised VPN connection. Fixes and interim mitigations are available, and CISA set a 1 June federal deadline.

19 Jun 2026 · 6 min read
A mysterious silhouette with red binary code projected over the face, set against a dark, moody background.
Cybersecurity

Oracle Patches Actively Exploited PeopleSoft Zero-Day (CVE-2026-35273) as Data-Theft Campaign Hits Universities

Oracle issued an out-of-band alert on 10 June for CVE-2026-35273, a CVSS 9.8 unauthenticated remote-code-execution flaw in PeopleSoft PeopleTools that Mandiant says was exploited as a zero-day from 27 May. Google attributed the data-theft campaign to ShinyHunters and notified 100-plus exposed organisations, most in higher education; the University of Nottingham is the first named victim in public reporting, with breach-notification analysis citing about 454,600 people affected.

16 Jun 2026 · 8 min read
Hands using a contactless credit card on a payment terminal with a stylish minimal background.
Cybersecurity

NFCShare: Android Malware Poses as a Bank App Update to Steal Card Data Through Your Phone's NFC Chip

Researchers at D3Lab say a new wave of the NFCShare Android trojan, running since mid-May 2026, poses as banking-app updates hosted on GitHub and tricks victims into tapping their payment card to the phone — capturing the card details and PIN for NFC relay fraud. The campaign now impersonates Italian and Spanish banks; the defence is simple, and it is mostly about not installing the fake update.

16 Jun 2026 · 7 min read
Close-up of a laptop screen displaying programming code with a cute plush toy reflecting.
Cybersecurity

Miasma Returns With 'Phantom Gyp': npm Worm Sidesteps the Install-Script Defences Teams Just Deployed

On 3 June, two days after the Red Hat npm compromise, the Miasma worm returned with a new delivery trick: a 157-byte binding.gyp file that runs code during npm install without any lifecycle script — bypassing the install-script checks teams had just leaned on. This wave hit 57 packages across 286+ versions (a point-in-time tally) and plants backdoors in AI coding-assistant configs.

11 Jun 2026 · 7 min read
Close-up view of smartphone home screen featuring popular apps like Instagram, Snapchat, and Chrome.
Cybersecurity

One Trojan, Three Lures: MyCERT Warns of Android Banking Malware Hitting Maybank and CIMB Users

MyCERT's 6 June advisory details an active Android banking-trojan campaign using three lure brands — Delivery4U, KerjaExpress and MaxTag — to deliver one malware family that steals banking logins, intercepts OTP/TAC codes and can lock the device. Maybank MAE and CIMB Octo users are the main targets.

7 Jun 2026 · 6 min read
Close-up image of yellow caution tape with blurred background, emphasizing warning and safety.
Cybersecurity

SolarWinds Serv-U Enters CISA KEV After Active Exploitation Warning

SolarWinds Serv-U CVE-2026-28318 is now in CISA’s Known Exploited Vulnerabilities catalogue after a June 2026 hotfix. This is an availability-risk threat intel update: patch Serv-U 15.5.4 Hotfix 1 and avoid unsupported claims about breach or ransomware impact.

7 Jun 2026 · 5 min read
CSA Flags GlobalProtect Auth-Bypass CVE-2026-0257 as Critical While Attackers Forge VPN Cookies in the Wild
Cybersecurity

CSA Flags GlobalProtect Auth-Bypass CVE-2026-0257 as Critical While Attackers Forge VPN Cookies in the Wild

Singapore's CSA rates a GlobalProtect authentication-bypass flaw critical (9.1) — sterner than Palo Alto's own HIGH rating — as Rapid7 confirms attackers forging VPN cookies since 17 May. PAN-OS and Prisma Access teams should patch or disable authentication override now.

7 Jun 2026 · 7 min read
Editorial Policy →