Edwin Kwan
  • Home
  • Speaker
  • Podcasts
    • Cyber Bites
    • AppSec Unlocked
    • It’s 5:05 Podcast
  • Journal
  • Publications
Select Page

Application Security Crisis Deepens as 62% of Organisations Ship Vulnerable Code Under Deadline Pressure

Aug 5, 2025 | Podcast

https://cypressdefense.com/resources/state-of-application-security-report A new report from Cypress Data Defense has revealed a troubling state of application security, with 62% of organisations knowingly deploying vulnerable code to production environments to meet...

Critical Vulnerability in AI-Powered Cursor IDE Enables Remote Code Execution Through Prompt Injection

Aug 4, 2025 | Podcast

https://www.aim.security/lp/aim-labs-curxecute-blogpost Security researchers at Aim Security have discovered a critical vulnerability dubbed CurXecute in the popular AI-powered code editor Cursor, which affects nearly all versions of the IDE and can be exploited to...

Security Teams Overwhelmed by Threat Intelligence Data Deluge, Study Reveals Growing Cybersecurity Vulnerability

Aug 1, 2025 | Podcast

https://cloud.google.com/blog/products/identity-security/too-many-threats-too-much-data-new-survey-heres-how-to-fix-that A new study commissioned by Google Cloud has revealed that security professionals are drowning in threat intelligence data, with 61 percent of...

Google Launches OSS Rebuild Initiative to Combat Supply Chain Attacks in Open Source Packages

Jul 31, 2025 | Podcast

https://security.googleblog.com/2025/07/introducing-oss-rebuild-open-source.html Google has unveiled OSS Rebuild, a comprehensive security initiative designed to strengthen trust in open source package ecosystems by automatically reproducing and verifying the...

Hackers Compromise Toptal’s GitHub Account, Deploy 10 Malicious npm Packages with Data Theft Capabilities

Jul 30, 2025 | Podcast

https://socket.dev/blog/toptal-s-github-organization-hijacked-10-malicious-packages-published Unknown threat actors successfully breached Toptal’s GitHub organisation account in a sophisticated supply chain attack, using the compromised access to publish 10...

Critical Vulnerability in Google’s Gemini CLI Enables Silent Code Execution on Developer Systems

Jul 29, 2025 | Podcast

https://tracebit.com/blog/code-exec-deception-gemini-ai-cli-hijack Security researchers at Tracebit have discovered a significant vulnerability in Google’s newly released Gemini CLI AI coding assistant that allowed attackers to execute malicious commands and...
« Older Entries
Next Entries »

Latest Posts

  • Predictable Password Patterns Persist as Billions Continue Using Easily Cracked Credentials
  • Attackers Weaponise Zendesk Support Systems in Massive Global Spam Campaign
  • AI-Powered Browsers Reverse Decades of Web Security Advances, Researchers Warn
  • GitLab Releases Emergency Patches for Two-Factor Authentication Bypass and Denial-of-Service Vulnerabilities
  • Fortune 500 Companies Compromised Through Vulnerable Security Testing Applications

Speaking Events

  • Panelist at SecTalks Legends – 2025
  • Keynote Speaker at Sydney AI Security Summit 2025
  • Speaker at The Artificial Unintelligence Conference
  • INFS2701 Guest Lecture at UNSW Business School
  • Speaker at ADAPT Cloud & Infrastructure Edge 2025

More Content

  • Articles (26)
  • Podcast (721)
  • Posts (26)
  • Publications (1)
  • Speaking (47)
  • X
  • RSS
Edwin Kwan