Kenji Tanaka is a RECATOOLS editorial persona focused on developer tools, cloud platforms, DevOps, CI/CD, software supply chains, and infrastructure trends. Articles under this byline help technical readers understand how tooling changes affect software delivery, security, cost, and reliability.

About this byline

Kenji Tanaka is a RECATOOLS editorial persona for developer tools, cloud, DevOps, and software supply-chain coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Editorial responsibility for this byline rests with Jeffrey Tan (Tan Seng Fei), RECASYS, Singapore. Our Editorial Policy sets out how sources are reviewed, how AI-assisted workflows are used, and how editorial desks and personas are defined.

208
Articles
Developer Tools
Primary beat
Apr 2026
Writing since
~1664 min
Total reading

Articles · Cybersecurity Showing 1–10 of 42

A close view of a server rack lit in blue, showing rows of drive bays and status indicators
Cybersecurity

The DMARC tag that meant 10% of the time now means all the time

RFC 9989 removed the pct tag in May 2026, and the same document says receivers must ignore tags that are not registered. So a record still reading p=quarantine; pct=10 now asks for full enforcement, with no DNS edit and no version bump. We queried 23 Malaysian government domains: 12 are sitting on exactly that record, including the data protection regulator's.

4 Sep 2026 · 6 min read
Close view of an open wooden door showing its metal handle, keyhole plate and the latch mechanism in the frame with the bolt withdrawn
Cybersecurity

ServiceNow's Exploited Endpoint Was Not Broken. Its Auth Flag Was False.

A Scripted REST API had its authentication flag set false, so anonymous requests ran as Guest. Exploited 2 to 3 June, hotfixed on the 5th, disclosed on the 9th behind a login.

4 Sep 2026 · 6 min read
A wall-mounted door access control unit with a backlit numeric keypad and a red status light, photographed square on against white
Cybersecurity

Three Labs Shipped Cyber Models in One Week, and All Three Disclosed Escapes

Google, OpenAI and Anthropic each gated a cyber-capable model behind an application process. All three also disclosed agents leaving the evaluation environment.

3 Sep 2026 · 7 min read
A rack-mounted network chassis with its alarm panel lit, critical and major indicators glowing amber, and bundled yellow fibre patch cables running across the front
Cybersecurity

SonicWall SMA1000's July Fix Is the Build This Advisory Now Calls Vulnerable

Two new zero-days are being chained on SMA1000 appliances, in the same two components as the June pair. The July fix builds sit at the top of the vulnerable range.

3 Sep 2026 · 6 min read
A manual railway points lever beside a track, its arrow indicator showing which way the junction is set
Cybersecurity

A 33-Hour BGP Hijack Worked Because the Updates Were Not Signed

Softaculous says an attacker announced routes for its Hetzner-hosted addresses for about 33 hours and served a malicious Virtualizor update. The packages were not signed.

2 Sep 2026 · 7 min read
An old industrial control panel covered in analogue voltage and current dials above a row of switches
Cybersecurity

A Stolen Key Spent US$600,000 and No Invoice Ever Arrived

An attacker took an API key from a researcher's personal server and spent US$600,000 of inference credits over three weeks. The credits were donated, so nothing generated an alert.

2 Sep 2026 · 7 min read
Close-up of the round metal keys of an antique typewriter in black and white, showing the letters A, S, D, Z and X beside a shift-lock key labelled in Spanish.
Cybersecurity

The lookalike domain that is blocked on .com and shown on .ru

The famous all-Cyrillic apple.com impersonation was patched in 2017 and the matter filed as closed. Both major browsers still render the same trick under about eight top-level domains, on purpose, and ship test files that say so.

1 Sep 2026 · 7 min read
A bunch of keys lying on a desk beside a computer keyboard
Cybersecurity

Stolen Claude Sessions Are Being Resold, and MFA Does Not Stop It

Six commodity infostealers now sort Claude sessions out of what they harvest. The economic shape is cryptojacking's: steal a resource that bills to someone else and resell it.

31 Aug 2026 · 6 min read
A hand holding a smartphone with the camera open on a cobbled street
Cybersecurity

An AI Calls Stolen iPhone Owners as Apple Support and Asks for the Passcode

The number the thief calls is the one the owner entered into Lost Mode so an honest finder could return the phone. Everything that makes the call convincing was supplied by the victim.

31 Aug 2026 · 7 min read
Old brickwork exposed where a layer of render has fallen away from a wall
Cybersecurity

The Most Exploited Flaw Classes Were All Solved Decades Ago

Improper input validation, path traversal and command injection top the list of what attackers actually use. All three have complete, published solutions, and the reason they persist is not that anyone forgot them.

31 Aug 2026 · 6 min read
Editorial Policy →