Edwin Kwan
  • Home
  • Speaker
  • Podcasts
    • Cyber Bites
    • AppSec Unlocked
    • It’s 5:05 Podcast
  • Journal
  • Publications
Select Page

Widespread Exploitation of React2Shell Flaw Compromises Dozens of Organisations

Dec 8, 2025 | Podcast

https://www.bleepingcomputer.com/news/security/react2shell-flaw-exploited-to-breach-30-orgs-77k-ip-addresses-vulnerable Security researchers have sounded the alarm over the critical React2Shell remote code execution vulnerability (CVE-2025-55182), which affects over...

ASX Outage Caused by Security Software Upgrade, Raising Concerns Over Technological Resilience

Dec 5, 2025 | Podcast

https://www.itnews.com.au/news/asx-outage-caused-by-security-software-upgrade-622331 The Australian Securities Exchange (ASX) has faced yet another setback in its ongoing technology overhaul, as a recent outage on its announcement platform was caused by a security...

Thousands of Developer Secrets Exposed in Public GitLab Repositories

Dec 4, 2025 | Podcast

https://trufflesecurity.com/blog/scanning-5-6-million-public-gitlab-repositories-for-secrets Thousands of sensitive developer secrets have been inadvertently exposed through public GitLab repositories. The investigation, conducted by the Checkmarx security team, found...

WA Man Responsible for In-Flight “Evil Twin” WiFi Attacks Sentenced to 7 Years in Prison

Dec 3, 2025 | Podcast

https://www.afp.gov.au/news-centre/media-release/wa-man-jailed-stealing-intimate-material-and-using-evil-twin-wifi A WA man who was responsible for carrying out “evil twin” WiFi attacks on airline passengers has been sentenced to seven years in prison. The...

Widespread Npm Malware Attack Exposes Thousands of Developer Secrets

Dec 2, 2025 | Podcast

https://www.wiz.io/blog/shai-hulud-2-0-aftermath-ongoing-supply-chain-attack Security researchers have uncovered a widespread malware campaign targeting the popular npm package repository. Dubbed “Shai Hulud 2.0,” the attack is estimated to have exposed up...

Fake Calendly Invites Hijack Ad Manager Accounts by Spoofing Top Brands

Dec 1, 2025 | Podcast

https://pushsecurity.com/blog/uncovering-a-calendly-themed-phishing-campaign There’s a new phishing campaign that leverages fake Calendly invitations to hijack ad manager accounts. The attack targets users of popular platforms like Facebook, Google, and Microsoft Ads,...
« Older Entries
Next Entries »

Latest Posts

  • ShinyHunters Targets Approximately 100 Organisations in Okta Single Sign-On Credential Theft Campaign
  • Extortion Group WorldLeaks Claims 1.4 Terabyte Data Theft From Nike in Manufacturing-Focused Breach
  • WhatsApp Launches Strict Account Settings to Shield High-Risk Users From Advanced Spyware Attacks
  • JavaScript Package Managers Vulnerable to Supply Chain Attacks Despite npm’s Shai-Hulud Security Measures
  • Nearly 800,000 Telnet Servers Exposed Globally as Critical Authentication Bypass Vulnerability Faces Active Exploitation

Speaking Events

  • Panelist at SecTalks Legends – 2025
  • Keynote Speaker at Sydney AI Security Summit 2025
  • Speaker at The Artificial Unintelligence Conference
  • INFS2701 Guest Lecture at UNSW Business School
  • Speaker at ADAPT Cloud & Infrastructure Edge 2025

More Content

  • Articles (26)
  • Podcast (726)
  • Posts (26)
  • Publications (1)
  • Speaking (47)
  • X
  • RSS
Edwin Kwan