Kenji Tanaka is a RECATOOLS editorial persona focused on developer tools, cloud platforms, DevOps, CI/CD, software supply chains, and infrastructure trends. Articles under this byline help technical readers understand how tooling changes affect software delivery, security, cost, and reliability.

About this byline

Kenji Tanaka is a RECATOOLS editorial persona for developer tools, cloud, DevOps, and software supply-chain coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Editorial responsibility for this byline rests with Jeffrey Tan (Tan Seng Fei), RECASYS, Singapore. Our Editorial Policy sets out how sources are reviewed, how AI-assisted workflows are used, and how editorial desks and personas are defined.

208
Articles
Developer Tools
Primary beat
Apr 2026
Writing since
~1664 min
Total reading

Articles · Cybersecurity Showing 21–30 of 42

A close-up of an email inbox on a computer screen showing a large unread message count beside the cursor.
Cybersecurity

Microsoft Took Eight Months to Patch a One-Click Copilot Data Theft Chain

Varonis reported the chain in December 2025 and the fix shipped on 18 August 2026. In between, one link could make Copilot Personal read a user's Gmail, Drive and Calendar and post the contents to an attacker's webhook.

24 Aug 2026 · 7 min read
A keyboard and coffee cup on an office desk with a monitor out of focus behind, illustrating a report on an exploited flaw in Zimbra Collaboration mail servers.
Cybersecurity

The Zimbra Patch Was Out For A Month Before Anyone Noticed It Being Exploited

CVE-2026-73570 gives an unauthenticated attacker shell commands as the zimbra user, but only where an optional SNMP package is installed and notifications are on. Version 10.1.20 shipped on 20 July. CERT Polska saw exploitation on 17 August.

23 Aug 2026 · 8 min read
Rows of sealed laboratory tubes with coloured screw caps, a containment illustration for a report on an escape from the isolated-vm JavaScript sandbox.
Cybersecurity

The Sandbox Everyone Uses To Run Untrusted JavaScript Can Be Escaped

A type-confusion flaw in isolated-vm's ExternalCopy lets sandboxed code corrupt host memory and potentially reach remote code execution. It affects every version through 7.0.0, is fixed in 6.2.0 and 7.0.1, and has no CVE identifier.

22 Aug 2026 · 8 min read
Numbered ethernet ports on a network switch, illustrating a report on maximum-severity vulnerabilities in Cisco's network automation platform.
Cybersecurity

Cisco Found Nine Flaws In Its Own Network Automation Platform. Five Score 10.0.

The August hardening release for Crosswork and Secure Workload fixes SQL injection, missing authentication and file-system control, all unauthenticated, all in the system that configures the network. Cisco found them internally and none is known to be exploited.

22 Aug 2026 · 8 min read
Rows of rack-mounted network equipment in a data centre, illustrating a report on a maximum-severity vulnerability in Microsoft's cloud identity service.
Cybersecurity

Microsoft Fixed a Perfect-10 Entra ID Flaw Before Telling Anyone It Was Exploited

CVE-2026-69836 scores 10.0, needs no account and no user interaction, and was exploited in the wild. Microsoft mitigated it inside its own cloud, credits a staff engineer with finding it, and has published no scope, no timeline and no indicators.

22 Aug 2026 · 8 min read
High-voltage insulators and switchgear at an electrical substation, illustrating a report on Singapore updating its cybersecurity code of practice for critical information infrastructure.
Cybersecurity

Singapore Will Hold Infrastructure Boards Accountable for Recovery, Not Just Defence

CSA said on 22 July that the rewritten Code of Practice will require critical-infrastructure boards to maintain an annually reviewed cyber resilience framework and Cyber Trust Mark Level 5. A separate cloud code follows this half, with companion guides written alongside AWS, Google Cloud and Microsoft Azure.

21 Aug 2026 · 10 min read
An empty clinical corridor lined with closed doors under fluorescent light, illustrating a report on medical offices shut by a ransomware attack.
Cybersecurity

A Ransomware Group Posted Its Demands On The Hospital's Own Facebook Page

AnMed closed 83 medical offices after a July attack, with ten still shut a week later. On 11 August the attackers took their pressure campaign to the health system's own channel, which is a rung of the extortion ladder nobody had used.

21 Aug 2026 · 8 min read
A hand plugging a white network cable into the LAN port of a black home router, illustrating a report on Macs exposed to the internet through remote access.
Cybersecurity

A macOS Screen Sharing Bug Apple Called 7.1 Is Being Used To Root Macs

CISA rescored CVE-2026-65400 to 9.8 and catalogued it. Attackers are taking root on Macs with port 5900 exposed and installing Monero miners. The gap between the two scores is a disagreement about how the product is deployed.

20 Aug 2026 · 8 min read
An abstract render of dense red and blue circuitry with a dark cross-shaped void at its centre, illustrating a report on a memory-handling flaw in an image parser.
Cybersecurity

Apple Patched An Image-Parsing Flaw, The Class That Starts Spyware Cases

CVE-2026-65346 is an integer overflow in ImageIO that could run code when a device processes a picture. No exploitation is disclosed, and nothing published says whether it is reachable without a tap.

20 Aug 2026 · 8 min read
Four banks of narrow metal mailboxes mounted on a weathered wooden wall, each box a different faded colour and several numbered by hand, with a rusted tin canopy above them.
Cybersecurity

Three DNS Records Almost Nobody Publishes

DNSSEC, CAA and MTA-STS each protect people who will never know they exist. Across 18 major ASEAN banks, government portals and telcos: 38.9%, 16.7% — and for MTA-STS, zero. Nine of the eighteen publish none of the three.

19 Aug 2026 · 5 min read
Editorial Policy →