Cyber Team is RECATOOLS’ cybersecurity desk, covering vulnerabilities, data breaches, supply-chain attacks, threat intelligence, exploit activity, and security best practices. The desk focuses on practical implications for developers, SMEs, IT teams, and ASEAN organisations.

About this byline

Cyber Team is a specialist RECATOOLS editorial desk focused on cybersecurity coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

101
Articles
Cybersecurity
Primary beat
Jan 2026
Writing since
~612 min
Total reading

Articles Showing 41–50 of 101

Server rack in a data centre representing shared hosting infrastructure affected by CVE-2026-48172
Cybersecurity

LiteSpeed cPanel Plugin Zero-Day CVE-2026-48172: Maximum-Severity Root Escalation Under Active Exploitation

CVE-2026-48172 in the LiteSpeed User-End cPanel Plugin carries a CVSS v4.0 score of 10.0 and was added to CISA's KEV catalogue on 26 May 2026. A low-privilege cPanel account is enough to gain root on the entire host. Here is what operators need to know and do now.

1 Jun 2026 · 5 min read
Digital map of Southeast Asia overlaid with network intrusion indicators representing the SHADOW-EARTH-053 espionage campaign
Cybersecurity

SHADOW-EARTH-053: China-Aligned Espionage Campaign Hits Government and Defence Networks Across ASEAN and Beyond

A China-aligned intrusion cluster designated SHADOW-EARTH-053 maintained covert access inside government ministries, defence contractors, and critical infrastructure across eight countries for at least 17 months. TrendAI researchers published findings on 1 May 2026 identifying targets in seven Asian nations plus Poland, with ShadowPad deployed via long-unpatched Exchange and IIS vulnerabilities — including the five-year-old ProxyLogon chain and a newer React Server Components flaw.

1 Jun 2026 · 6 min read
Dark screen of system code and a terminal, illustrating software vulnerabilities being patched.
Cybersecurity

This week's bugs to patch: a critical OTRS flaw and a Linux root hole on CISA's list

A short, practical read of the week's most urgent vulnerabilities: a critical pre-authentication flaw in the OTRS service-desk platform, and a Linux privilege-escalation bug that the US cyber agency has confirmed is being exploited and added to its must-patch catalogue.

1 Jun 2026 · 3 min read
Conceptual cyber scene: green code on a dark laptop over a backlit keyboard — illustrating this week's threat brief.
Cybersecurity

Threat Brief, Week of 18 May 2026: State-Backed Espionage in Malaysia, a Malware-Signing Takedown, and the Defender Itself Under Fire

Our weekly read of the threat landscape: a state-backed actor ran a bespoke espionage operation against Malaysian government networks, Microsoft dismantled a malware-signing-as-a-service business, and CISA flagged two actively exploited zero-days in Microsoft Defender — the very tool meant to catch the attacks. The throughline of the week: adversaries are weaponising trust.

30 May 2026 · 9 min read
Conceptual dark-terminal image reading 'data transfer complete' — evoking the data exfiltration in this Marimo RCE breach.
Cybersecurity

An LLM Agent Drove This Real Intrusion: Marimo RCE to Database Dump in Under an Hour

On 10 May an internet-exposed marimo notebook was breached through CVE-2026-39987 — and then an autonomous LLM agent took the keyboard. Sysdig's threat researchers say the agent improvised the entire post-exploitation chain, pulled an SSH key from AWS Secrets Manager, and dumped an internal database in under two minutes. A Chinese-language planning comment it left in the command stream gave it away.

30 May 2026 · 6 min read
Laravel-Lang Supply Chain Attack — 233 Versions Backdoored Across 700 Repos in a Composer-Autoload Trick
Cybersecurity

Laravel-Lang Supply Chain Attack — 233 Versions Backdoored Across 700 Repos in a Composer-Autoload Trick

On 22 May 2026, an attacker rewrote version tags across the Laravel-Lang ecosystem to deliver a 5,900-line PHP credential stealer via composer autoload. What every Laravel team must check this week.

22 May 2026 · 12 min read
Megalodon Campaign Backdoors 5,561 GitHub Repos in Six Hours — Inside the Largest GitHub Actions Supply-Chain Attack on Record
Cybersecurity

Megalodon Campaign Backdoors 5,561 GitHub Repos in Six Hours — Inside the Largest GitHub Actions Supply-Chain Attack on Record

An automated campaign called Megalodon pushed 5,718 malicious commits to 5,561 GitHub repos between 18-21 May 2026, exfiltrating CI secrets via poisoned GitHub Actions. What to check now.

21 May 2026 · 12 min read
Pwn2Own Berlin 2026 Pays Out $1.4M Across Three Days — Chrome Sandbox, Tesla Infotainment, Linux Kernel All Fall
Cybersecurity

Pwn2Own Berlin 2026 Pays Out $1.4M Across Three Days — Chrome Sandbox, Tesla Infotainment, Linux Kernel All Fall

The OffensiveCon Pwn2Own contest wrapped on Wednesday with $1.4 million paid out across 27 zero-days. A Chrome sandbox escape, a Tesla in-car LPE chain and a Linux kernel use-after-free were among the highest-paid bounties.

19 May 2026 · 8 min read
Anthropic Says It Disrupted the First Reported AI-Orchestrated Cyber-Espionage Campaign Using Claude
Cybersecurity

Anthropic Says It Disrupted the First Reported AI-Orchestrated Cyber-Espionage Campaign Using Claude

In a public write-up, Anthropic describes threat actors who induced Claude — by posing as defensive testers — into mapping internal networks and identifying high-value systems. The company says the sustained pattern is what eventually triggered detection.

18 May 2026 · 9 min read
AWS Confirms First Production Prompt-Injection Compromise in Bedrock Agents — Enterprise Customer Exfiltrated Documents
Cybersecurity

AWS Confirms First Production Prompt-Injection Compromise in Bedrock Agents — Enterprise Customer Exfiltrated Documents

In a quietly-published security bulletin, AWS confirmed an indirect prompt-injection attack in production Bedrock Agents pulled documents out of a customer's S3 bucket. The first publicly-disclosed in-the-wild compromise of an LLM-agent supply chain.

18 May 2026 · 8 min read
Editorial Policy →