Edwin Kwan
  • Home
  • Speaker
  • Podcasts
    • Cyber Bites
    • AppSec Unlocked
    • It’s 5:05 Podcast
  • Journal
  • Publications
Select Page

Critical Nginx UI Flaw Under Active Exploitation, Enabling Full Server Takeover Without Authentication

Apr 15, 2026 | Podcast

https://pluto.security/blog/mcp-bug-nginx-security-vulnerability-cvss-9-8 A critical authentication bypass vulnerability in Nginx UI, tracked as CVE-2026-33032, is now being actively exploited in the wild, allowing remote attackers to seize complete control of web...

Adobe Issues Emergency Patch for Actively Exploited Acrobat Reader Zero-Day

Apr 14, 2026 | Podcast

https://helpx.adobe.com/security/products/acrobat/apsb26-43.html Adobe has released an emergency security update to address a critical vulnerability in Acrobat and Acrobat Reader, tracked as CVE-2026-34621, which has been exploited in zero-day attacks since at least...

Booking.com Confirms Data Breach Exposing Millions of Travellers’ Reservation Details

Apr 13, 2026 | Podcast

https://www.abc.net.au/news/2026-04-13/booking-com-data-security-breach-personal-details/106557630 Booking.com has confirmed that hackers accessed customer data linked to travel reservations, prompting the company to force PIN resets and notify affected users directly...

Enterprise PCs Found Lagging Behind Macs on Security Patching, New Report Reveals

Mar 27, 2026 | Podcast

https://www.omnissa.com/insights/Omnissa-State-of-Digital-Workspace-2026-press-release A new industry report from device management firm Omnissa has exposed a concerning gap in how enterprises maintain the security of their Windows fleets compared to Apple devices....

TeamPCP Turns Its Hacking Tools Toward Iran, Deploying Data-Destroying Wiper Malware

Mar 26, 2026 | Podcast

https://krebsonsecurity.com/2026/03/canisterworm-springs-wiper-attack-targeting-iran The cybercrime group TeamPCP — already linked to a string of high-profile software supply chain attacks — has pivoted toward geopolitical disruption, deploying a destructive wiper...

TeamPCP Supply Chain Attack Hits Widely Used AI Tool, Exposing Millions of Systems

Mar 25, 2026 | Podcast

https://www.endorlabs.com/learn/teampcp-isnt-done A hacker group known as TeamPCP has been caught planting malicious code inside litellm, a popular AI software library downloaded roughly 95 million times per month. Two versions of the package – 1.82.7 and 1.82.8...
« Older Entries
Next Entries »

Latest Posts

  • New “ClawHub” and “ClawSwarm” Malware Campaigns Target AI Agents for Crypto Recruitment
  • KnowBe4 Research Reveals 86% of Phishing Attacks Are Now AI-Driven
  • Google Patches Maximum Severity CVSS 10 Flaw in Gemini CLI Amid Growing AI Tool Vulnerabilities
  • Critical cPanel & WHM Authentication Bypass Vulnerability Actively Exploited in the Wild
  • Critical Linux “copyfiles” Vulnerability Grants Root Access on Major Distributions

Speaking Events

  • Guest Lecture at UNSW Business School for INFS5907
  • Speaker at Bugcrowd Luncheon
  • Guest Lecture at UNSW
  • Panelist at SecTalks Legends – 2025
  • Keynote Speaker at Sydney AI Security Summit 2025

More Content

  • Articles (26)
  • Podcast (777)
  • Posts (26)
  • Publications (1)
  • Speaking (50)
  • X
  • RSS
Edwin Kwan