Cyber Team is RECATOOLS’ cybersecurity desk, covering vulnerabilities, data breaches, supply-chain attacks, threat intelligence, exploit activity, and security best practices. The desk focuses on practical implications for developers, SMEs, IT teams, and ASEAN organisations.

About this byline

Cyber Team is a specialist RECATOOLS editorial desk focused on cybersecurity coverage. Articles are produced and reviewed under RECATOOLS editorial supervision. The articles listed here keep this byline. New coverage on these beats is published under the persona whose beat it falls in: Kenji Tanaka for vulnerabilities, patching and supply-chain security, and Priya Nair for threat intelligence, attribution and privacy.

Editorial responsibility for this byline rests with Jeffrey Tan (Tan Seng Fei), RECASYS, Singapore. Our Editorial Policy sets out how sources are reviewed, how AI-assisted workflows are used, and how editorial desks and personas are defined.

153
Articles
Cybersecurity
Primary beat
Jan 2026
Writing since
~1054 min
Total reading

Articles Showing 21–30 of 153

A signup form rendered on a screen — illustrating the page whose fields were read by third-party marketing trackers.
Cybersecurity

A Signup Form Sent Passwords to Facebook and Google for Nearly Two Years

Klaviyo's signup form was misconfigured so third-party marketing trackers captured what users typed, including passwords. The company says fewer than 200 people were affected, based on logs it will not describe.

11 Aug 2026 · 8 min read
A field of wind turbines under open sky — illustrating the unstaffed remote sites whose cellular links became the route into Poland's grid.
Cybersecurity

Poland's Power Plants Were Reached Through the Mobile Network Nobody Watches

CERT Polska has documented the first real-world use of a private APN as a route into operational technology. Thirty wind and solar sites and two heat plants were affected.

11 Aug 2026 · 8 min read
A desk laid out with printed reports, charts, a notebook and a laptop — illustrating the finance and operations managers this campaign selected for.
Cyber Threat Intel

Ransomware Went After the 46-Year-Old Manager, Not the Administrator

Zscaler tracked 351 victims across 334 organisations in one campaign. Sixty-two per cent were managers or above, the average age was 46, and information technology was only 14.6% of them.

10 Aug 2026 · 8 min read
A dimly lit server room, illustrating the estates these claimed attacks are counted against.
Cyber Threat Intel

799 Ransomware Attacks in July. Victims Confirmed 51 of Them.

July produced 799 ransomware attacks by the standard count, second only to March in 2026. Victims confirmed 51 of them. The gap is the story: these figures are assembled from attacker leak sites, and two groups claimed a third of the month between them.

9 Aug 2026 · 8 min read
Industrial pipework and valves, illustrating the treatment plant equipment these controllers operate.
Cybersecurity

Water Systems in Twelve States Were Broken Into. The Fix Is a Budget Line, Not Advice.

Water systems in at least twelve US states have been broken into, with attackers changing controller passwords and IP addresses to lock out operators. Retired NSA director Paul Nakasone says the controllers should never have been on the internet — advice that is correct, decade-old, and has never been paired with the money small utilities would need to act on it.

9 Aug 2026 · 8 min read
A courthouse exterior, illustrating the prosecution stage this two-year-old breach campaign has now reached.
Cyber Threat Intel

The Snowflake Extortionist Pleaded Guilty. The Way In Was Still Just a Password.

Connor Riley Moucka, 26, pleaded guilty on 6 August over the campaign that took data from more than 165 organisations using Snowflake, including over 100 million AT&T call and text records. No Snowflake vulnerability was ever involved: the entry was stolen credentials against accounts with no multi-factor authentication, and every ingredient of that is still available today.

9 Aug 2026 · 7 min read
Macro view of a processor die on a circuit board, illustrating the branch-prediction hardware this attack targets.
Cybersecurity

MIT Broke Spectre v2 Defences. AMD Will Patch, Intel Will Not.

MIT researchers showed that Spectre v2 mitigations can be stepped around on current Intel and AMD processors, breaking KASLR in every run and extracting the root password hash in half of them. AMD has committed to kernel patches, Intel declined to mitigate further, and Arm says the class of attack is not one it protects against.

9 Aug 2026 · 7 min read
Rack-mounted servers in a data centre aisle, illustrating the managed estates an MSP console reaches.
Cybersecurity

N-able's Patch Did Not Hold. The Second Hotfix Came Four Days Later.

N-able patched a critical authentication bypass in N-central, attackers found a path the patch did not block, and a second hotfix followed four days after the first. After gaining admin access, attackers used the product's own Take Control feature to reach managed endpoints and registered a Cloudflare tunnel service for persistence.

8 Aug 2026 · 8 min read
Server rack cabling seen through a perforated mesh door.
Cybersecurity

Four VMware Flaws, and the One That Scores Lowest Is the One Hosting Providers Should Fix First

Two flaws score 9.8. The 9.3 lets an attacker with admin rights inside a virtual machine execute code on the host beneath it, which in a rented estate is a purchase rather than a breach.

7 Aug 2026 · 8 min read
A fibre optic patch panel with cables connected to network ports.
Cybersecurity

The Tomcat Flaw Being Exploited Today Was Created by a Security Fix

CVE-2026-34486 exists because of the fix for CVE-2026-29146. CSA reports active exploitation, and the catalogue lists the bypass rather than the flaw it bypasses.

7 Aug 2026 · 8 min read
Editorial Policy →