Kenji Tanaka is a RECATOOLS editorial persona focused on developer tools, cloud platforms, DevOps, CI/CD, software supply chains, and infrastructure trends. Articles under this byline help technical readers understand how tooling changes affect software delivery, security, cost, and reliability.

About this byline

Kenji Tanaka is a RECATOOLS editorial persona for developer tools, cloud, DevOps, and software supply-chain coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Editorial responsibility for this byline rests with Jeffrey Tan (Tan Seng Fei), RECASYS, Singapore. Our Editorial Policy sets out how sources are reviewed, how AI-assisted workflows are used, and how editorial desks and personas are defined.

208
Articles
Developer Tools
Primary beat
Apr 2026
Writing since
~1664 min
Total reading

Articles Showing 101–110 of 208

A blue coin-operated seafront viewer on a concrete plinth, pointed out across flat grey water under a heavy overcast sky, with a low treeline on the far shore.
Cybersecurity

What Your Own Domain Tells a Stranger

OSINT needs no budget and no access. We ran it against our own domain and found 26 robots.txt rules naming /admin/ and /sudo, a reverse proxy volunteered in a header, and a certificate log that cannot be un-published.

19 Aug 2026 · 6 min read
A market stall wall hung with dozens of near-identical festival masks, each a smiling face fringed with feathers and coloured beadwork, repeating in rows so that individual masks are hard to tell apart.
Cyber Threat Intel

What a Threat Actor Name Buys You

Reporting names adversaries with real confidence — APT29, Lazarus, Sandworm — and it is worth asking how much a name actually tells you. We counted the public catalogue: 176 tracked groups, 425 aliases between them, a median group accounting for 2.7% of known techniques, and a third of documented behaviour attributed to nobody at all.

19 Aug 2026 · 5 min read
A large rusted iron padlock hanging from the hasp of a heavy studded wooden door. Its shackle is swung open and unlatched, so the lock is in place but fastening nothing.
Cybersecurity

Many Security Policies Permit the Attacks They Are Meant to Block

Eighteen ASEAN banks, government portals and telcos send a mean of 3.7 of 5 browser-protection headers, which is better than expected. But of the twelve that ship a content security policy, eight permit inline scripts — the exact thing the policy is best known for stopping.

19 Aug 2026 · 6 min read
A weathered NO TRESPASSING sign and a second sign reading RIGHT TO PASS BY PERMISSION, both nailed to a post on a sagging wire fence. To the right of the post the fence has been pulled open, leaving a gap into the dry field beyond.
AI & ML

Who Actually Blocks the AI Crawlers

robots.txt is the one place a publisher's position on AI training has to be written down in public. We read it for 19 news outlets against 12 AI crawlers. It is not a spectrum: six block nearly everything, nine block nothing, and ASEAN publishers block half as many as global ones.

19 Aug 2026 · 6 min read
Several bare hard disk drives stacked on a white surface with their circuit boards exposed, illustrating a report on the sale of a bankrupt company data archive.
AI & ML

Google Bought A Bankrupt Airline's Emails For US$10m, And Nobody Who Wrote Them Was Asked

100 million emails, 500 million Teams messages and 30 million lines of code, won at auction from Spirit Airlines' estate for AI training. Bankruptcy has become a supply channel for training data, and de-identifying conversation is not the same job as de-identifying a database.

19 Aug 2026 · 8 min read
A laptop half-open in a dark room, its keyboard and screen lit in red, green and blue, illustrating a report on a critical WordPress plugin vulnerability.
Cybersecurity

A WordPress Form Plugin Flaw Left 300,000 Sites Open, And The Patch Has Been Free Since July

CVE-2026-15748 gives an unauthenticated visitor a path from a contact form to a shell on Forminator installations. The fix shipped on 31 July. Roughly half the 600,000-site base has not taken it, and that gap says more about who owns small-business websites than about the flaw.

19 Aug 2026 · 8 min read
A worker in a frost-covered jacket and heavy gloves aims a handheld barcode scanner at a cardboard box in a cold-storage warehouse, the scanner's red beam falling across the box while breath fogs the freezing air. Racking recedes into the dark blue background.
AI & ML

What You Are Trusting When You Download a Model

We checked the 1,000 most-downloaded models on the Hugging Face Hub. 99% ship a model card, so documentation is not what is missing — but only 20.5% declare their training data in a readable field, and counting prose too, roughly four in ten disclose it nowhere at all.

19 Aug 2026 · 6 min read
A dark data centre aisle with network iconography overlaid, illustrating a report on an exploited flaw in the Ray framework.
Cybersecurity

A Browser Can Now Reach Into the Framework Your AI Cluster Runs On

CVE-2025-62593 reaches Ray's unauthenticated job endpoints through a victim's browser, and one campaign turns unpatched clusters with Nvidia GPUs into a self-replicating mining botnet. The design decision underneath it was documented for years.

19 Aug 2026 · 8 min read
The rear of a server rack, rows of stacked machines with blue and grey network cables running between labelled ports and small green status lights.
Developer Tools

What Our Own Site Sends, and Why We Can't Tell You Exactly

We tried to measure our own monthly egress with root on the machine. Three sources gave three answers, and extrapolating the most precise one produced 97% of the entire server's traffic — a figure that disproves itself.

18 Aug 2026 · 7 min read
Three studio condenser microphones, illustrating a report on India-trained voice models for government-to-citizen services.
AI & ML

IBM and Sarvam Pair a Governance Layer With Models Trained in India

Sovereign AI usually means a data centre in the right country. This arrangement aims at the harder half: reasoning, language and voice models trained from scratch for the languages citizens actually use, with a joint hub in Lucknow.

18 Aug 2026 · 8 min read
Editorial Policy →