Kenji Tanaka is a RECATOOLS editorial persona focused on developer tools, cloud platforms, DevOps, CI/CD, software supply chains, and infrastructure trends. Articles under this byline help technical readers understand how tooling changes affect software delivery, security, cost, and reliability.

About this byline

Kenji Tanaka is a RECATOOLS editorial persona for developer tools, cloud, DevOps, and software supply-chain coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Editorial responsibility for this byline rests with Jeffrey Tan (Tan Seng Fei), RECASYS, Singapore. Our Editorial Policy sets out how sources are reviewed, how AI-assisted workflows are used, and how editorial desks and personas are defined.

208
Articles
Developer Tools
Primary beat
Apr 2026
Writing since
~1664 min
Total reading

Articles · Cybersecurity Showing 31–40 of 42

A blue coin-operated seafront viewer on a concrete plinth, pointed out across flat grey water under a heavy overcast sky, with a low treeline on the far shore.
Cybersecurity

What Your Own Domain Tells a Stranger

OSINT needs no budget and no access. We ran it against our own domain and found 26 robots.txt rules naming /admin/ and /sudo, a reverse proxy volunteered in a header, and a certificate log that cannot be un-published.

19 Aug 2026 · 6 min read
A large rusted iron padlock hanging from the hasp of a heavy studded wooden door. Its shackle is swung open and unlatched, so the lock is in place but fastening nothing.
Cybersecurity

Many Security Policies Permit the Attacks They Are Meant to Block

Eighteen ASEAN banks, government portals and telcos send a mean of 3.7 of 5 browser-protection headers, which is better than expected. But of the twelve that ship a content security policy, eight permit inline scripts — the exact thing the policy is best known for stopping.

19 Aug 2026 · 6 min read
A laptop half-open in a dark room, its keyboard and screen lit in red, green and blue, illustrating a report on a critical WordPress plugin vulnerability.
Cybersecurity

A WordPress Form Plugin Flaw Left 300,000 Sites Open, And The Patch Has Been Free Since July

CVE-2026-15748 gives an unauthenticated visitor a path from a contact form to a shell on Forminator installations. The fix shipped on 31 July. Roughly half the 600,000-site base has not taken it, and that gap says more about who owns small-business websites than about the flaw.

19 Aug 2026 · 8 min read
A dark data centre aisle with network iconography overlaid, illustrating a report on an exploited flaw in the Ray framework.
Cybersecurity

A Browser Can Now Reach Into the Framework Your AI Cluster Runs On

CVE-2025-62593 reaches Ray's unauthenticated job endpoints through a victim's browser, and one campaign turns unpatched clusters with Nvidia GPUs into a self-replicating mining botnet. The design decision underneath it was documented for years.

19 Aug 2026 · 8 min read
A cellular communications mast silhouetted against cloud, illustrating a report on a Unisoc modem exploit chain.
Cybersecurity

A Unisoc Modem Flaw Turns an Answered Video Call Into Android Kernel Access

Researchers published the second stage of an exploit chain that crosses from modem firmware into the Android kernel. There is no patch, the disclosing team says the chipmaker did not reply, and the affected silicon sits at the end of the market this region buys from.

18 Aug 2026 · 8 min read
A close-up of a brushed steel combination dial set into a pale safe door, its numbered ring running from zero to ninety around a knurled centre knob.
Cybersecurity

What Shor's Algorithm Actually Breaks

Shor's method is ordinary arithmetic with one quantum step inside it. We ran the classical part exhaustively over sixteen numbers: it works for 73.8% of starting values on average, and never below 50.8%.

18 Aug 2026 · 6 min read
Red, yellow and green network patch cables plugged into the lit ports of a rack-mounted switch, with more cabling running out of focus behind it.
Cybersecurity

How Big Are Post-Quantum Encryption Keys?

We measured two live handshakes to our own site. Hybrid post-quantum key exchange adds 1,178 bytes to the ClientHello — six times over — and the ServerHello grows by exactly ML-KEM’s published ciphertext size.

16 Aug 2026 · 7 min read
Two black rubber stamps with cream-coloured pads stand on a sheet of white paper beside a pair of ballpoint pens, a black binder clip and a row of red, green and blue paper clips, against a deep blue background.
Cybersecurity

How Much of ISO 27001 Can You Actually Automate?

ISO/IEC 27001:2022 has 93 Annex A controls. Our 27 automated compliance checks cover 18 of them — not quite a fifth — and most of the gap is structural rather than lazy. Counting them also turned up two checks citing control identifiers from a revision withdrawn in 2022.

15 Aug 2026 · 9 min read
Rows of numbered ports on a fibre patch panel, green connectors threaded with yellow leads — illustrative of the networked estate a three-day patch deadline has to cover.
Cybersecurity

Three Days to Patch. CISA's Deadline Used to Be Three Weeks.

Every vulnerability CISA catalogued in the first week of August carried a three-day federal deadline. We measured the catalogue's own dates, and the median has fallen from 21 days to three since February.

11 Aug 2026 · 7 min read
A red network patch cable coiled in front of a server rack — illustrating the remote-access gateway at the centre of this campaign.
Cybersecurity

You Patched SonicWall in Three Days. That May Not Have Been Enough.

Ransomware crews are now chaining two SonicWall SMA1000 flaws that CISA gave federal agencies three days to fix. If your gateway was reached at root, patching closed the door and left the keys outside.

11 Aug 2026 · 6 min read
Editorial Policy →