Priya Nair is a RECATOOLS editorial persona focused on AI governance, data protection, privacy, digital trust, and responsible technology policy. Articles under this byline explain how organisations can adopt AI and data-driven tools while managing legal, operational, and reputational risk.

About this byline

Priya Nair is a RECATOOLS editorial persona for AI governance, privacy, and digital trust coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Editorial responsibility for this byline rests with Jeffrey Tan (Tan Seng Fei), RECASYS, Singapore. Our Editorial Policy sets out how sources are reviewed, how AI-assisted workflows are used, and how editorial desks and personas are defined.

106
Articles
Privacy & Data
Primary beat
May 2026
Writing since
~767 min
Total reading

Articles · Cyber Threat Intel Showing 11–20 of 20

Server front panels lit by blue indicator LEDs behind a mesh door, illustrating a report on attackers exploiting MLflow to steal cloud credentials.
Cyber Threat Intel

Attackers Are Using MLflow To Ask The Cloud For Its Own Credentials

CVE-2026-64849 is an unauthenticated server-side request forgery in MLflow scoring 9.3. Two days after disclosure CISA added it to the exploited catalogue, with honeypots capturing payloads aimed at AWS, GCP and Azure metadata endpoints.

22 Aug 2026 · 8 min read
Singapore's central business district lit at night across Marina Bay, illustrating a report on the financial-sector taskforce formed against AI-driven cyber threats.
Cyber Threat Intel

Singapore's Banks Got an AI Threat Taskforce Before They Got AI Rules

MAS and the Association of Banks stood up the ACT taskforce on 28 July with DBS, OCBC, UOB, SGX, NETS and Banking Computer Services. Eight days later MAS told Parliament that the rules governing banks' own use of agentic AI still have no date.

21 Aug 2026 · 8 min read
Four water filtration vessels connected by blue pipework and valves beside a storage tank, illustrating a report on attacks against water plant controllers.
Cyber Threat Intel

US Agencies Say AI Is Writing The Exploits For Water Plant Controllers

A five-agency advisory names Siemens S7 PLCs at water, energy, chemical and manufacturing sites, with exploitation scripts disguised as monitoring tools. The new fact is not that controllers are attacked. It is who wrote the exploit.

21 Aug 2026 · 8 min read
A red fire extinguisher in its bracket on a plain white wall in a quiet domestic hallway, its instruction label unmarked and its pin still in place, beside a closed panelled door.
Cyber Threat Intel

Can You Prove an Attack Was Prevented?

Early warning is what threat intelligence is sold on, and prevention is the least verifiable claim in security — the evidence is an absence. What the public record actually supports, and why 54.6% of exploited vulnerabilities being five years old says the warning was never the missing part.

19 Aug 2026 · 6 min read
An aerial view of a night market after dark: dozens of rows of stall canopies in red, blue, white and orange, each lit from beneath, packed edge to edge so the individual stalls blur into a grid.
Cyber Threat Intel

Who Sells Threat Intelligence

Four quite different businesses use the same phrase, which is most of why the market is confusing. A map of the categories — public bodies, vendor research arms, commercial platforms and community sources — and the questions that tell you which one you are being sold.

19 Aug 2026 · 5 min read
A glass pour-over coffee brewer on a wooden table, its paper cone still holding a bed of wet spent grounds while the brewed coffee sits dark in the carafe below, beside a small ceramic cup.
Cyber Threat Intel

From Feed to Decision

Buying a threat feed is the easy part. We work through the filtering that free public data already does to a scanner report — and why 54.6% of actively exploited vulnerabilities are five years old or more, which says the missing ingredient is rarely the warning.

19 Aug 2026 · 5 min read
A single dressmaker's pin with a bright green head standing upright in a dense pile of dry straw, its thin steel shaft catching the light against the tangle of stalks around it.
Cyber Threat Intel

What Threat Intelligence Actually Is

380,235 vulnerabilities have been published. 1,670 are confirmed to be exploited in the wild — about one in 228. Telling those apart is the whole discipline, and one number makes the point better than any definition.

19 Aug 2026 · 6 min read
A fibre patch panel with rows of green connectors and yellow patch leads, illustrating a report on a mass exploitation campaign against VMware vCenter.
Cyber Threat Intel

A vCenter Flaw Took 361 Victims In About 72 Hours, And Then It Was Over

CVE-2026-59310 was disclosed on 29 July, exploited from 3 August, and 95 per cent of the campaign's eventual victims were hit by the 5th. When exploitation arrives in a single burst, patching faster buys you nothing.

19 Aug 2026 · 8 min read
Rolled nautical charts on a wooden table, illustrating a report on an unpatched flaw in the GeoServer geospatial platform.
Cyber Threat Intel

GeoServer Was Probed Within Hours of a Disclosure That Had No CVE

An unauthenticated SQL injection reaching remote code execution was posted publicly on 12 August. Scanning began within hours, before a patch existed and before the flaw entered any catalogue a vulnerability programme polls.

18 Aug 2026 · 8 min read
Coiled yellow Ethernet cables on a blue background, illustrating a report on how quickly disclosed vulnerabilities are exploited.
Cyber Threat Intel

Most Exploitation Now Lands Within 48 Hours of the Proof of Concept

CrowdStrike puts 88 per cent of observed proof-of-concept exploitation inside two days, and two China-linked groups inside one. A DPRK-linked group poisoned 131 trusted AI framework packages, which is the finding getting the least attention.

17 Aug 2026 · 8 min read
Editorial Policy →