Cyber Team is RECATOOLS’ cybersecurity desk, covering vulnerabilities, data breaches, supply-chain attacks, threat intelligence, exploit activity, and security best practices. The desk focuses on practical implications for developers, SMEs, IT teams, and ASEAN organisations.

About this byline

Cyber Team is a specialist RECATOOLS editorial desk focused on cybersecurity coverage. Articles are produced and reviewed under RECATOOLS editorial supervision. The articles listed here keep this byline. New coverage on these beats is published under the persona whose beat it falls in: Kenji Tanaka for vulnerabilities, patching and supply-chain security, and Priya Nair for threat intelligence, attribution and privacy.

Editorial responsibility for this byline rests with Jeffrey Tan (Tan Seng Fei), RECASYS, Singapore. Our Editorial Policy sets out how sources are reviewed, how AI-assisted workflows are used, and how editorial desks and personas are defined.

153
Articles
Cybersecurity
Primary beat
Jan 2026
Writing since
~1054 min
Total reading

Articles · Cybersecurity Showing 81–90 of 140

Server rack in a data centre representing shared hosting infrastructure affected by CVE-2026-48172
Cybersecurity

LiteSpeed cPanel Plugin Zero-Day CVE-2026-48172: Maximum-Severity Root Escalation Under Active Exploitation

CVE-2026-48172 in the LiteSpeed User-End cPanel Plugin carries a CVSS v4.0 score of 10.0 and was added to CISA's KEV catalogue on 26 May 2026. A low-privilege cPanel account is enough to gain root on the entire host. Here is what operators need to know and do now.

1 Jun 2026 · 7 min read
Digital map of Southeast Asia overlaid with network intrusion indicators representing the SHADOW-EARTH-053 espionage campaign
Cybersecurity

SHADOW-EARTH-053: China-Aligned Espionage Campaign Hits Government and Defence Networks Across ASEAN and Beyond

A China-aligned intrusion cluster designated SHADOW-EARTH-053 maintained covert access inside government ministries, defence contractors, and critical infrastructure across eight countries for at least 17 months. TrendAI researchers published findings on 1 May 2026 identifying targets in seven Asian nations plus Poland, with ShadowPad deployed via long-unpatched Exchange and IIS vulnerabilities — including the five-year-old ProxyLogon chain and a newer React Server Components flaw.

1 Jun 2026 · 6 min read
Dark screen of system code and a terminal, illustrating software vulnerabilities being patched.
Cybersecurity

This week's bugs to patch: a critical OTRS flaw and a Linux root hole on CISA's list

A short, practical read of the week's most urgent vulnerabilities: a critical pre-authentication flaw in the OTRS service-desk platform, and a Linux privilege-escalation bug that the US cyber agency has confirmed is being exploited and added to its must-patch catalogue.

1 Jun 2026 · 3 min read
Conceptual cyber scene: green code on a dark laptop over a backlit keyboard — illustrating this week's threat brief.
Cybersecurity

Threat Brief, Week of 18 May 2026: State-Backed Espionage in Malaysia, a Malware-Signing Takedown, and the Defender Itself Under Fire

Our weekly read of the threat landscape: a state-backed actor ran a bespoke espionage operation against Malaysian government networks, Microsoft dismantled a malware-signing-as-a-service business, and CISA flagged two actively exploited zero-days in Microsoft Defender — the very tool meant to catch the attacks. The throughline of the week: adversaries are weaponising trust.

30 May 2026 · 9 min read
Conceptual dark-terminal image reading 'data transfer complete' — evoking the data exfiltration in this Marimo RCE breach.
Cybersecurity

An LLM Agent Drove This Real Intrusion: Marimo RCE to Database Dump in Under an Hour

On 10 May an internet-exposed marimo notebook was breached through CVE-2026-39987 — and then an autonomous LLM agent took the keyboard. Sysdig's threat researchers say the agent improvised the entire post-exploitation chain, pulled an SSH key from AWS Secrets Manager, and dumped an internal database in under two minutes. A Chinese-language planning comment it left in the command stream gave it away.

30 May 2026 · 6 min read
An abstract red glitch-art render of fragmented city blocks
Cybersecurity

Laravel-Lang Supply Chain Attack — 233 Versions Backdoored Across 700 Repos in a Composer-Autoload Trick

On 22 May 2026, an attacker rewrote version tags across the Laravel-Lang ecosystem to deliver a 5,900-line PHP credential stealer via composer autoload. What every Laravel team must check this week.

22 May 2026 · 12 min read
A red backlit keyboard below a screen of falling green code
Cybersecurity

Megalodon Campaign Backdoors 5,561 GitHub Repos in Six Hours — Inside the Largest GitHub Actions Supply-Chain Attack on Record

An automated campaign called Megalodon pushed 5,718 malicious commits to 5,561 GitHub repos between 18-21 May 2026, exfiltrating CI secrets via poisoned GitHub Actions. What to check now.

21 May 2026 · 12 min read
A person using a laptop showing a VPN app in a cafe, a latte beside them
Cybersecurity

Pwn2Own Berlin 2026 Pays Out $1.4M Across Three Days — Chrome Sandbox, Tesla Infotainment, Linux Kernel All Fall

The OffensiveCon Pwn2Own contest wrapped on Wednesday with $1.4 million paid out across 27 zero-days. A Chrome sandbox escape, a Tesla in-car LPE chain and a Linux kernel use-after-free were among the highest-paid bounties.

19 May 2026 · 8 min read
A man in round glasses in profile, green code projected across his face
Cybersecurity

Anthropic Says It Disrupted the First Reported AI-Orchestrated Cyber-Espionage Campaign Using Claude

In a public write-up, Anthropic describes threat actors who induced Claude — by posing as defensive testers — into mapping internal networks and identifying high-value systems. The company says the sustained pattern is what eventually triggered detection.

18 May 2026 · 9 min read
A woman in glasses standing with arms folded in a blue-lit server room
Cybersecurity

AWS Confirms First Production Prompt-Injection Compromise in Bedrock Agents — Enterprise Customer Exfiltrated Documents

In a quietly-published security bulletin, AWS confirmed an indirect prompt-injection attack in production Bedrock Agents pulled documents out of a customer's S3 bucket. The first publicly-disclosed in-the-wild compromise of an LLM-agent supply chain.

18 May 2026 · 8 min read
Editorial Policy →