Edwin Kwan
  • Home
  • Speaker
  • Podcasts
    • Cyber Bites
    • AppSec Unlocked
    • It’s 5:05 Podcast
  • Journal
  • Publications
Select Page

WordPress Plugin Suite Backdoored, Thousands of Sites Silently Compromised Since August 2025

Apr 16, 2026 | Podcast

Someone Bought 30 WordPress Plugins and Planted a Backdoor in All of Them. More than 30 WordPress plugins belonging to the EssentialPlugin suite have been found to contain malicious backdoor code, affecting products with hundreds of thousands of active installations...

Critical Nginx UI Flaw Under Active Exploitation, Enabling Full Server Takeover Without Authentication

Apr 15, 2026 | Podcast

https://pluto.security/blog/mcp-bug-nginx-security-vulnerability-cvss-9-8 A critical authentication bypass vulnerability in Nginx UI, tracked as CVE-2026-33032, is now being actively exploited in the wild, allowing remote attackers to seize complete control of web...

Adobe Issues Emergency Patch for Actively Exploited Acrobat Reader Zero-Day

Apr 14, 2026 | Podcast

https://helpx.adobe.com/security/products/acrobat/apsb26-43.html Adobe has released an emergency security update to address a critical vulnerability in Acrobat and Acrobat Reader, tracked as CVE-2026-34621, which has been exploited in zero-day attacks since at least...

Booking.com Confirms Data Breach Exposing Millions of Travellers’ Reservation Details

Apr 13, 2026 | Podcast

https://www.abc.net.au/news/2026-04-13/booking-com-data-security-breach-personal-details/106557630 Booking.com has confirmed that hackers accessed customer data linked to travel reservations, prompting the company to force PIN resets and notify affected users directly...

Enterprise PCs Found Lagging Behind Macs on Security Patching, New Report Reveals

Mar 27, 2026 | Podcast

https://www.omnissa.com/insights/Omnissa-State-of-Digital-Workspace-2026-press-release A new industry report from device management firm Omnissa has exposed a concerning gap in how enterprises maintain the security of their Windows fleets compared to Apple devices....

TeamPCP Turns Its Hacking Tools Toward Iran, Deploying Data-Destroying Wiper Malware

Mar 26, 2026 | Podcast

https://krebsonsecurity.com/2026/03/canisterworm-springs-wiper-attack-targeting-iran The cybercrime group TeamPCP — already linked to a string of high-profile software supply chain attacks — has pivoted toward geopolitical disruption, deploying a destructive wiper...
« Older Entries
Next Entries »

Latest Posts

  • Anthropic Mythos Discovered 271 Security Vulnerabilities in Firefox
  • Malicious Cryptocurrency Wallet Apps Infiltrate China’s Apple App Store
  • Microsoft Teams Becomes Prime Target for Helpdesk Impersonation Scams
  • Apple Patches iOS Bug That Preserved Deleted Notification Data
  • Claude Desktop Raises Privacy Concerns Over Silent Browser Extension Installation

Speaking Events

  • Guest Lecture at UNSW Business School for INFS5907
  • Panelist at SecTalks Legends – 2025
  • Keynote Speaker at Sydney AI Security Summit 2025
  • Speaker at The Artificial Unintelligence Conference
  • INFS2701 Guest Lecture at UNSW Business School

More Content

  • Articles (26)
  • Podcast (772)
  • Posts (26)
  • Publications (1)
  • Speaking (48)
  • X
  • RSS
Edwin Kwan