Edwin Kwan
  • Home
  • Speaker
  • Podcasts
    • Cyber Bites
    • AppSec Unlocked
    • It’s 5:05 Podcast
  • Journal
  • Publications
Select Page

WordPress Plugin Suite Backdoored, Thousands of Sites Silently Compromised Since August 2025

Apr 16, 2026 | Podcast

Someone Bought 30 WordPress Plugins and Planted a Backdoor in All of Them. More than 30 WordPress plugins belonging to the EssentialPlugin suite have been found to contain malicious backdoor code, affecting products with hundreds of thousands of active installations...

Critical Nginx UI Flaw Under Active Exploitation, Enabling Full Server Takeover Without Authentication

Apr 15, 2026 | Podcast

https://pluto.security/blog/mcp-bug-nginx-security-vulnerability-cvss-9-8 A critical authentication bypass vulnerability in Nginx UI, tracked as CVE-2026-33032, is now being actively exploited in the wild, allowing remote attackers to seize complete control of web...

Adobe Issues Emergency Patch for Actively Exploited Acrobat Reader Zero-Day

Apr 14, 2026 | Podcast

https://helpx.adobe.com/security/products/acrobat/apsb26-43.html Adobe has released an emergency security update to address a critical vulnerability in Acrobat and Acrobat Reader, tracked as CVE-2026-34621, which has been exploited in zero-day attacks since at least...

Booking.com Confirms Data Breach Exposing Millions of Travellers’ Reservation Details

Apr 13, 2026 | Podcast

https://www.abc.net.au/news/2026-04-13/booking-com-data-security-breach-personal-details/106557630 Booking.com has confirmed that hackers accessed customer data linked to travel reservations, prompting the company to force PIN resets and notify affected users directly...

Enterprise PCs Found Lagging Behind Macs on Security Patching, New Report Reveals

Mar 27, 2026 | Podcast

https://www.omnissa.com/insights/Omnissa-State-of-Digital-Workspace-2026-press-release A new industry report from device management firm Omnissa has exposed a concerning gap in how enterprises maintain the security of their Windows fleets compared to Apple devices....

TeamPCP Turns Its Hacking Tools Toward Iran, Deploying Data-Destroying Wiper Malware

Mar 26, 2026 | Podcast

https://krebsonsecurity.com/2026/03/canisterworm-springs-wiper-attack-targeting-iran The cybercrime group TeamPCP — already linked to a string of high-profile software supply chain attacks — has pivoted toward geopolitical disruption, deploying a destructive wiper...
« Older Entries
Next Entries »

Latest Posts

  • AI Emerges as a Game-Changer in Cyber Defence, Australian Signals Directorate Reports
  • Anthropic’s Restricted Claude Mythos Model Moves Closer to Public Release
  • Anthropic’s AI Model Finds Over Ten Thousand Critical Vulnerabilities in Global Software Infrastructure
  • npm Introduces Human Approval Gates to Counter Software Supply Chain Attacks
  • HackerOne Slashes Bug Bounty Payouts as AI Floods Open-Source Security Programs

Speaking Events

  • Guest Lecture at UNSW Business School for INFS5907
  • Speaker at Bugcrowd Luncheon
  • Guest Lecture at UNSW
  • Panelist at SecTalks Legends – 2025
  • Keynote Speaker at Sydney AI Security Summit 2025

More Content

  • Articles (26)
  • Podcast (796)
  • Posts (26)
  • Publications (1)
  • Speaking (50)
  • X
  • RSS
Edwin Kwan