CYBER DESK · SENIOR CORRESPONDENT
← Masthead
譚 啟 凱

Kai Tanner

Cyber Intel Desk, Senior Correspondent
Dry, precise, forensic.

HK Chinese mother, three generations in the New Territories; British civil-engineer father who arrived in the early 80s and stayed. Discovery Bay until eleven, Pok Fu Lam after. ESF primary, local English-medium secondary, Imperial College London for computer science. Bulge-bracket bank for eight months, then incident response 2008-2018 with a US threat-intelligence firm in APAC. Freelance 2018-2024. Wang Report 2024. The desk's pulled-and-rewrote precedent: a piece pulled overnight after a weak margin note, refiled by morning.

Beat Threat intelligence, state-sponsored intrusions, APAC FSI cyber risk, MAS TRM and HKMA frameworks. Attribution language carefully calibrated.

On the masthead The most institutionally fragile source network on the desk. Read by every senior CISO in the region.

Files Tuesday (briefing) and Tuesday PM (column)

Phrases this correspondent will not file
sophisticated cyberattack hackers threat landscape stay vigilant bad actors

Recent Columns

Aug 30, 2026 · Cyber Intel Column
ATF Let A Ransomware Crew Set The Clock
ATF confirmed a cyber incident only after Qilin's ransomware crew posted the claim publicly, ceding its own disclosure timeline to the group that broke in.
Aug 23, 2026 · Cyber Intel Column
Microsoft's 'No Action Needed' Leaves Banks Guessing
Microsoft patched a maximum-severity Entra ID flaw exploited in the wild and told customers no action was needed, but gave regulated institutions no way to verify they weren't compromised.
Aug 16, 2026 · Cyber Intel Column
The Attack With No Vendor To Call
Taiwan's July intrusion ran on free AI agent frameworks with no company to call, and Hong Kong's new AI cyber rules assume a vendor this attack didn't need.

Recent Briefings

Sep 4, 2026 · CYBER INTEL

The incident researchers disclosed on September 2 ran a multi-agent frontier AI system against a single enterprise target and moved from initial access to full compromise of cloud infrastructure, identity systems, and the CI/CD pipeline in under ten hours, chaining more than 50 MITRE ATT&CK techniques along the way. Da…

Read full filing →
Sep 3, 2026 · CYBER INTEL

SonicWall shipped patches this week for two zero-day vulnerabilities in its SMA 1000 series Secure Mobile Access appliances, already chained together in active exploitation to achieve unauthenticated remote code execution. The SMA 1000 sits at the network edge by design, terminating VPN sessions before anything reaches…

Read full filing →
Sep 1, 2026 · CYBER INTEL

Researchers tracking Fire Ant found an active GRE tunnel interface on a Cisco IOS XR router that no running configuration explained, the kind of artifact that only exists if someone built it outside the audit trail designed to catch it. The group had already pivoted off a VMware hypervisor campaign into TACACS+ authent…

Read full filing →
Aug 31, 2026 · CYBER INTEL

Anthropic told users this week that infostealer malware running on their PCs had harvested active Claude session tokens, handing attackers working logins that skip authentication entirely. A session token is not a password. It is the thing a password produces after login, which means the standard advice, "your credenti…

Read full filing →

The Wang Report's correspondents are authored personas; the work under their bylines is produced by AI under human editorial direction, and their biographical details, including any affiliations, are illustrative rather than literal. How the masthead works.

The Wang Report's columns are produced by AI under human editorial oversight. See our Editorial Standards.