Priya Nair is a RECATOOLS editorial persona focused on AI governance, data protection, privacy, digital trust, and responsible technology policy. Articles under this byline explain how organisations can adopt AI and data-driven tools while managing legal, operational, and reputational risk.

About this byline

Priya Nair is a RECATOOLS editorial persona for AI governance, privacy, and digital trust coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Editorial responsibility for this byline rests with Jeffrey Tan (Tan Seng Fei), RECASYS, Singapore. Our Editorial Policy sets out how sources are reviewed, how AI-assisted workflows are used, and how editorial desks and personas are defined.

106
Articles
Privacy & Data
Primary beat
May 2026
Writing since
~767 min
Total reading

Articles Showing 41–50 of 106

Server front panels lit by blue indicator LEDs behind a mesh door, illustrating a report on attackers exploiting MLflow to steal cloud credentials.
Cyber Threat Intel

Attackers Are Using MLflow To Ask The Cloud For Its Own Credentials

CVE-2026-64849 is an unauthenticated server-side request forgery in MLflow scoring 9.3. Two days after disclosure CISA added it to the exploited catalogue, with honeypots capturing payloads aimed at AWS, GCP and Azure metadata endpoints.

22 Aug 2026 · 8 min read
A close-up of a row of pale locker doors, each fitted with its own separate lock
Privacy & Data

How to Stop an Agent Returning Documents the User Should Not See

A vector search scoped three ways, and measured each time. Unfiltered, four in five results belonged to another team; filtering afterwards in application code stopped the leak and answered sixteen of twenty questions with silence.

21 Aug 2026 · 6 min read
Singapore's central business district lit at night across Marina Bay, illustrating a report on the financial-sector taskforce formed against AI-driven cyber threats.
Cyber Threat Intel

Singapore's Banks Got an AI Threat Taskforce Before They Got AI Rules

MAS and the Association of Banks stood up the ACT taskforce on 28 July with DBS, OCBC, UOB, SGX, NETS and Banking Computer Services. Eight days later MAS told Parliament that the rules governing banks' own use of agentic AI still have no date.

21 Aug 2026 · 8 min read
Loose receipts, printed sheets and paperclips scattered across a white desk, illustrating a report on the gap between claimed and verified breach record counts.
Privacy & Data

An Extortion Group Claimed 25 Million Records. 218,000 Appeared.

ShinyHunters listed Alcon on 2 August alleging more than 25 million Salesforce records. The data later published held 218,000 email addresses and corporate contact fields. Only one of those numbers can be checked.

21 Aug 2026 · 8 min read
Four water filtration vessels connected by blue pipework and valves beside a storage tank, illustrating a report on attacks against water plant controllers.
Cyber Threat Intel

US Agencies Say AI Is Writing The Exploits For Water Plant Controllers

A five-agency advisory names Siemens S7 PLCs at water, energy, chemical and manufacturing sites, with exploitation scripts disguised as monitoring tools. The new fact is not that controllers are attacked. It is who wrote the exploit.

21 Aug 2026 · 8 min read
An antique brass weighing scale with a curved dial and metal pan, illustrating a report on a regulator requiring comparable consent prompts from a platform owner.
Privacy & Data

Germany Made Apple Redesign The Tracking Prompt It Wrote For Rivals

The Bundeskartellamt closed a four-year case after Apple agreed to align its own consent prompts with the ones third-party apps must show, drop discouraging wording, and let publishers merge the prompt with GDPR consent.

20 Aug 2026 · 8 min read
A clipped hedge maze photographed from above, illustrating a report on a data broker penalised for an obstructive opt-out process.
Privacy & Data

A Data Broker Wanted Your SSN Before It Would Stop Selling Your Data

California fined LocateSmarter US$116,490 for demanding unnecessary personal information to process an opt-out. The fine is small; applying data minimisation to the rights mechanism itself is the part that travels.

20 Aug 2026 · 8 min read
A red fire extinguisher in its bracket on a plain white wall in a quiet domestic hallway, its instruction label unmarked and its pin still in place, beside a closed panelled door.
Cyber Threat Intel

Can You Prove an Attack Was Prevented?

Early warning is what threat intelligence is sold on, and prevention is the least verifiable claim in security — the evidence is an absence. What the public record actually supports, and why 54.6% of exploited vulnerabilities being five years old says the warning was never the missing part.

19 Aug 2026 · 6 min read
An aerial view of a night market after dark: dozens of rows of stall canopies in red, blue, white and orange, each lit from beneath, packed edge to edge so the individual stalls blur into a grid.
Cyber Threat Intel

Who Sells Threat Intelligence

Four quite different businesses use the same phrase, which is most of why the market is confusing. A map of the categories — public bodies, vendor research arms, commercial platforms and community sources — and the questions that tell you which one you are being sold.

19 Aug 2026 · 5 min read
A glass pour-over coffee brewer on a wooden table, its paper cone still holding a bed of wet spent grounds while the brewed coffee sits dark in the carafe below, beside a small ceramic cup.
Cyber Threat Intel

From Feed to Decision

Buying a threat feed is the easy part. We work through the filtering that free public data already does to a scanner report — and why 54.6% of actively exploited vulnerabilities are five years old or more, which says the missing ingredient is rarely the warning.

19 Aug 2026 · 5 min read
Editorial Policy →