Edwin Kwan
  • Home
  • Speaker
  • Podcasts
    • Cyber Bites
    • AppSec Unlocked
    • It’s 5:05 Podcast
  • Journal
  • Publications
Select Page

Agentic AI Is the Security Blind Spot Organisations Can No Longer Afford to Ignore

May 15, 2026 | Podcast

https://thehackernews.com/2026/05/why-agentic-ai-is-securitys-next-blind.html Agentic AI, artificial intelligence systems that can autonomously execute tasks, make decisions, and take actions across digital environments, is already running in production inside...

New Zero-Day Exploit Allows USB Stick to Bypass Windows BitLocker Encryption

May 14, 2026 | Podcast

https://www.itnews.com.au/news/usb-stick-opens-windows-bitlocker-drives-in-new-zero-day-625859 A newly published zero-day vulnerability dubbed YellowKey allows an attacker with physical access to a Windows device to completely bypass BitLocker disk encryption using...

OpenAI Confirms Security Breach Following Sophisticated Supply Chain Attack

May 13, 2026 | Podcast

https://openai.com/index/our-response-to-the-tanstack-npm-supply-chain-attack OpenAI has confirmed it was caught up in a supply chain attack targeting TanStack, a popular open-source library widely used by JavaScript developers to build web applications and data...

Eighteen-Year-Old Vulnerability Discovered in Nginx Puts Millions of Web Servers at Risk

May 12, 2026 | Podcast

https://depthfirst.com/research/nginx-rift-achieving-nginx-rce-via-an-18-year-old-vulnerability A security vulnerability that has existed in the Nginx web server for eighteen years has been discovered and disclosed, raising serious concerns about the stability and...

Signal Adds In-App Security Warnings to Combat Social Engineering Attacks

May 11, 2026 | Podcast

To help protect Signal users from phishing and social engineering attacks, we’ve introduced additional confirmations and educational messaging in the app to help people better detect fraudulent profiles, especially message requests from scammers posing as Signal. More...

60% of MD5 Password Hashes Now Crackable in Under an Hour With a Single GPU

May 8, 2026 | Podcast

https://www.kaspersky.com/blog/passwords-hacking-research-2026/55743 New research from Kaspersky, released on World Password Day 2026, delivers a wake-up call for organisations still relying on MD5 hashing to protect user credentials. Analyzing a dataset of more than...

Survey Finds 1 in 8 Employees Consider Selling Company Login Credentials Justifiable

May 7, 2026 | Podcast

https://www.cifas.org.uk/workplace-fraud-trends-2025 A alarming report from UK fraud prevention organisation Cifas has revealed that 13 percent of employees either have sold company login credentials in the past year or know someone who has, and an equally troubling...

Malicious OpenClaw Skill Weaponizes AI Agent Framework to Distribute Malwar

May 6, 2026 | Podcast

https://www.zscaler.com/blogs/security-research/malicious-openclaw-skill-distributes-remcos-rat-and-ghostloader Zscaler ThreatLabz researchers have uncovered a campaign in which threat actors weaponised the OpenClaw open-source AI agent framework to distribute both...

ACSC Issues Warning Over ClickFix Attacks Deploying Vidar Stealer Malware

May 5, 2026 | Podcast

https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/clickfix-distributing-vidar-stealer-via-wordpress-targeting-australian-infrastructure Australia’s cybersecurity authorities have issued an official warning regarding an active and...

Cybercriminals Abuse Amazon SES to Launch Undetected Phishing Campaigns

May 4, 2026 | Podcast

https://securelist.com/amazon-ses-phishing-and-bec-attacks/119623 Security researchers have uncovered a new phishing campaign exploiting Amazon Simple Email Service (SES), Amazon’s legitimate cloud-based email platform, to send malicious emails that bypass...
« Older Entries

Latest Posts

  • Agentic AI Is the Security Blind Spot Organisations Can No Longer Afford to Ignore
  • New Zero-Day Exploit Allows USB Stick to Bypass Windows BitLocker Encryption
  • OpenAI Confirms Security Breach Following Sophisticated Supply Chain Attack
  • Eighteen-Year-Old Vulnerability Discovered in Nginx Puts Millions of Web Servers at Risk
  • Signal Adds In-App Security Warnings to Combat Social Engineering Attacks

Speaking Events

  • Guest Lecture at UNSW Business School for INFS5907
  • Speaker at Bugcrowd Luncheon
  • Guest Lecture at UNSW
  • Panelist at SecTalks Legends – 2025
  • Keynote Speaker at Sydney AI Security Summit 2025

More Content

  • Articles (26)
  • Podcast (787)
  • Posts (26)
  • Publications (1)
  • Speaking (50)
  • X
  • RSS
Edwin Kwan