Edwin Kwan
  • Home
  • Speaker
  • Podcasts
    • Cyber Bites
    • AppSec Unlocked
    • It’s 5:05 Podcast
  • Journal
  • Publications
Select Page

Grafana Labs Confirms Ransomware Extortion Following TanStack Supply Chain Breach

May 18, 2026 | Podcast

https://grafana.com/blog/grafana-labs-security-update-latest-on-tanstack-npm-supply-chain-ransomware-incident Grafana Labs, the company behind one of the most widely deployed open-source observability platforms in the world, has confirmed it was targeted by a...

Agentic AI Is the Security Blind Spot Organisations Can No Longer Afford to Ignore

May 15, 2026 | Podcast

https://thehackernews.com/2026/05/why-agentic-ai-is-securitys-next-blind.html Agentic AI, artificial intelligence systems that can autonomously execute tasks, make decisions, and take actions across digital environments, is already running in production inside...

New Zero-Day Exploit Allows USB Stick to Bypass Windows BitLocker Encryption

May 14, 2026 | Podcast

https://www.itnews.com.au/news/usb-stick-opens-windows-bitlocker-drives-in-new-zero-day-625859 A newly published zero-day vulnerability dubbed YellowKey allows an attacker with physical access to a Windows device to completely bypass BitLocker disk encryption using...

OpenAI Confirms Security Breach Following Sophisticated Supply Chain Attack

May 13, 2026 | Podcast

https://openai.com/index/our-response-to-the-tanstack-npm-supply-chain-attack OpenAI has confirmed it was caught up in a supply chain attack targeting TanStack, a popular open-source library widely used by JavaScript developers to build web applications and data...

Eighteen-Year-Old Vulnerability Discovered in Nginx Puts Millions of Web Servers at Risk

May 12, 2026 | Podcast

https://depthfirst.com/research/nginx-rift-achieving-nginx-rce-via-an-18-year-old-vulnerability A security vulnerability that has existed in the Nginx web server for eighteen years has been discovered and disclosed, raising serious concerns about the stability and...

Signal Adds In-App Security Warnings to Combat Social Engineering Attacks

May 11, 2026 | Podcast

To help protect Signal users from phishing and social engineering attacks, we’ve introduced additional confirmations and educational messaging in the app to help people better detect fraudulent profiles, especially message requests from scammers posing as Signal. More...
« Older Entries
Next Entries »

Latest Posts

  • Origin Energy Data Breach Affects 900,000 Current and Former Customers
  • JFrog Confirms OpenAI AI Models Exploited Artifactory Zero-Day During Benchmark Escape
  • GitHub Adds Three Day Cooldown to Dependabot Version Updates to Counter Supply Chain Attacks
  • AI Vibe Coding Is Flooding App Stores With Low Quality Software While Downloads Barely Budge
  • Hackblitz 2026

Speaking Events

  • Guest Lecture at UNSW Business School for INFS5907
  • Speaker at Bugcrowd Luncheon
  • Guest Lecture at UNSW
  • Panelist at SecTalks Legends – 2025
  • Keynote Speaker at Sydney AI Security Summit 2025

More Content

  • Articles (26)
  • Podcast (836)
  • Posts (29)
  • Publications (1)
  • Speaking (50)
  • X
  • RSS
Edwin Kwan