Edwin Kwan
  • Home
  • Speaker
  • Podcasts
    • Cyber Bites
    • AppSec Unlocked
    • It’s 5:05 Podcast
  • Journal
  • Publications
Select Page

npm Introduces Human Approval Gates to Counter Software Supply Chain Attacks

May 25, 2026 | Podcast

Staged publishing and new install-time controls for npm GitHub has released two significant security updates for npm, the world’s largest software package registry and the primary distribution channel through which JavaScript developers share and consume...

HackerOne Slashes Bug Bounty Payouts as AI Floods Open-Source Security Programs

May 22, 2026 | Podcast

https://hackerone.com/ibb/bounty_table_versions?change=2026-05-18T20%3A25%3A03.903Z&type=team HackerOne has cut reward payments across its Internet Bug Bounty (IBB) program by more than 75 percent, reducing the payout for a critical vulnerability from $9,250 to...

CISA Credentials Exposed in Public GitHub Repository for Six Months Before Takedown

May 21, 2026 | Podcast

https://blog.gitguardian.com/how-we-got-a-cisa-github-leak-taken-down-in-26-hours Researchers at GitGuardian discovered a public GitHub repository named “Private-CISA” containing 844 megabytes of sensitive data belonging to the United States Cybersecurity...

Google Accidentally Exposes Details of Unpatched Chromium Vulnerability

May 20, 2026 | Podcast

https://infosec.exchange/@rebane2001/116606719764376414 Google briefly made public the technical details of an unpatched security vulnerability in Chromium, the open-source browser engine underpinning Google Chrome, Microsoft Edge, Brave, Opera, and dozens of other...

GitHub Confirms Internal Repository Breach After Employee Device Compromise

May 19, 2026 | Podcast

https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w GitHub has confirmed that an employee device was compromised via a poisoned Microsoft Visual Studio Code extension, resulting in the exfiltration of approximately 3,800 internal repositories....

Grafana Labs Confirms Ransomware Extortion Following TanStack Supply Chain Breach

May 18, 2026 | Podcast

https://grafana.com/blog/grafana-labs-security-update-latest-on-tanstack-npm-supply-chain-ransomware-incident Grafana Labs, the company behind one of the most widely deployed open-source observability platforms in the world, has confirmed it was targeted by a...
« Older Entries
Next Entries »

Latest Posts

  • Quest Apartment Hotels Discloses Customer Data Breach Linked to Third-Party Vulnerability
  • Origin Energy Breach Traced to Former Accenture Employee at Manila Call Centre
  • Developers Report Widespread Security and Privacy Failures in AI Coding Tools
  • ASD and AICD Warn Boards That Frontier AI Is Fundamentally Reshaping Cyber Risk
  • AI Assistant Autonomously Hacks Gym Booking System in First Known Australian Case

Speaking Events

  • Speaker at Melbourne Secure Software And AppSec Summit 2026
  • Guest Lecture at UNSW Business School for INFS5907
  • Speaker at Bugcrowd Luncheon
  • Guest Lecture at UNSW
  • Panelist at SecTalks Legends – 2025

More Content

  • Articles (26)
  • Podcast (841)
  • Posts (29)
  • Publications (1)
  • Speaking (51)
  • X
  • RSS
Edwin Kwan