Edwin Kwan
  • Home
  • Speaker
  • Podcasts
    • Cyber Bites
    • AppSec Unlocked
    • It’s 5:05 Podcast
  • Journal
  • Publications
Select Page

Widespread Exploitation of React2Shell Flaw Compromises Dozens of Organisations

Dec 8, 2025 | Podcast

https://www.bleepingcomputer.com/news/security/react2shell-flaw-exploited-to-breach-30-orgs-77k-ip-addresses-vulnerable Security researchers have sounded the alarm over the critical React2Shell remote code execution vulnerability (CVE-2025-55182), which affects over...

ASX Outage Caused by Security Software Upgrade, Raising Concerns Over Technological Resilience

Dec 5, 2025 | Podcast

https://www.itnews.com.au/news/asx-outage-caused-by-security-software-upgrade-622331 The Australian Securities Exchange (ASX) has faced yet another setback in its ongoing technology overhaul, as a recent outage on its announcement platform was caused by a security...

Thousands of Developer Secrets Exposed in Public GitLab Repositories

Dec 4, 2025 | Podcast

https://trufflesecurity.com/blog/scanning-5-6-million-public-gitlab-repositories-for-secrets Thousands of sensitive developer secrets have been inadvertently exposed through public GitLab repositories. The investigation, conducted by the Checkmarx security team, found...

WA Man Responsible for In-Flight “Evil Twin” WiFi Attacks Sentenced to 7 Years in Prison

Dec 3, 2025 | Podcast

https://www.afp.gov.au/news-centre/media-release/wa-man-jailed-stealing-intimate-material-and-using-evil-twin-wifi A WA man who was responsible for carrying out “evil twin” WiFi attacks on airline passengers has been sentenced to seven years in prison. The...

Widespread Npm Malware Attack Exposes Thousands of Developer Secrets

Dec 2, 2025 | Podcast

https://www.wiz.io/blog/shai-hulud-2-0-aftermath-ongoing-supply-chain-attack Security researchers have uncovered a widespread malware campaign targeting the popular npm package repository. Dubbed “Shai Hulud 2.0,” the attack is estimated to have exposed up...

Fake Calendly Invites Hijack Ad Manager Accounts by Spoofing Top Brands

Dec 1, 2025 | Podcast

https://pushsecurity.com/blog/uncovering-a-calendly-themed-phishing-campaign There’s a new phishing campaign that leverages fake Calendly invitations to hijack ad manager accounts. The attack targets users of popular platforms like Facebook, Google, and Microsoft Ads,...
« Older Entries
Next Entries »

Latest Posts

  • HackerOne Slashes Bug Bounty Payouts as AI Floods Open-Source Security Programs
  • CISA Credentials Exposed in Public GitHub Repository for Six Months Before Takedown
  • Google Accidentally Exposes Details of Unpatched Chromium Vulnerability
  • GitHub Confirms Internal Repository Breach After Employee Device Compromise
  • Grafana Labs Confirms Ransomware Extortion Following TanStack Supply Chain Breach

Speaking Events

  • Guest Lecture at UNSW Business School for INFS5907
  • Speaker at Bugcrowd Luncheon
  • Guest Lecture at UNSW
  • Panelist at SecTalks Legends – 2025
  • Keynote Speaker at Sydney AI Security Summit 2025

More Content

  • Articles (26)
  • Podcast (792)
  • Posts (26)
  • Publications (1)
  • Speaking (50)
  • X
  • RSS
Edwin Kwan