Edwin Kwan
  • Home
  • Speaker
  • Podcasts
    • Cyber Bites
    • AppSec Unlocked
    • It’s 5:05 Podcast
  • Journal
  • Publications
Select Page

Massive Chrome Extension Caught Harvesting Millions of Users’ AI Chat Conversations

Dec 18, 2025 | Podcast

https://www.koi.ai/blog/urban-vpn-browser-extension-ai-conversations-data-collection A Google Chrome extension with over 6 million users has been observed silently collecting every prompt entered by users into popular AI-powered chatbots, including OpenAI’s...

Scammers Abuse PayPal Subscriptions to Send Fake Purchase Notification Emails

Dec 17, 2025 | Podcast

https://www.bleepingcomputer.com/news/security/beware-paypal-subscriptions-abused-to-send-fake-purchase-emails Cybersecurity researchers have uncovered a new email scam that abuses PayPal’s “Subscriptions” billing feature to send legitimate-looking...

Google Links Additional Chinese Hacking Groups to Widespread Exploitation of Critical React2Shell Vulnerability

Dec 16, 2025 | Podcast

https://cloud.google.com/blog/topics/threat-intelligence/threat-actors-exploit-react2shell-cve-2025-55182 Google’s threat intelligence team has identified five more Chinese cyber-espionage groups joining the ongoing attacks exploiting the critical...

Notepad++ Releases Security Update to Address Traffic Hijacking Vulnerability

Dec 15, 2025 | Podcast

https://notepad-plus-plus.org/news/v889-released The popular text editor Notepad++ has released version 8.8.9 to address a critical security vulnerability affecting its updater, WinGUp. According to security experts, incidents of traffic hijacking have been reported,...

Thousands of Exposed Secrets on Docker Hub Put Organisations at Serious Risk

Dec 12, 2025 | Podcast

https://flare.io/learn/resources/docker-hub-secrets-exposed In just one month of scanning, security researchers found more than 10,000 Docker Hub images have been found to contain leaked secrets, including live credentials to production systems. This breach has...

Cybercriminals Exploit Google Ads and AI Platforms to Spread macOS Infostealer Malware

Dec 11, 2025 | Podcast

Infostealer has entered the chat Researchers have uncovered a new campaign that abuses Google search ads and popular AI platforms like ChatGPT and Grok to lure macOS users into installing the AMOS infostealer malware. The attack, dubbed “ClickFix,” begins...
Threat Exposure Management Insights Editorial

Threat Exposure Management Insights Editorial

Dec 10, 2025 | Publications

I contributed to a report on Threat Exposure Management for ANZ which just got released today The report is available for download at...

Cybercriminals Pivot to Points, Taxes, and Fake Retailers in Surge of SMS Phishing Scams

Dec 10, 2025 | Podcast

https://krebsonsecurity.com/2025/12/sms-phishers-pivot-to-points-taxes-fake-retailers China-based phishing groups, known for relentless scam SMS messages about wayward packages or unpaid toll fees, have now set their sights on a new target: the holiday shopping...

Gartner Recommends Ban on AI-Powered Browser Extensions Amid Growing Security Risks

Dec 9, 2025 | Podcast

https://www.gartner.com/en/documents/7211030 (Member’s access) In a move to address the escalating cybersecurity challenges posed by AI-powered browser extensions, leading research and advisory firm Gartner has issued a strong recommendation for organisations to...

Widespread Exploitation of React2Shell Flaw Compromises Dozens of Organisations

Dec 8, 2025 | Podcast

https://www.bleepingcomputer.com/news/security/react2shell-flaw-exploited-to-breach-30-orgs-77k-ip-addresses-vulnerable Security researchers have sounded the alarm over the critical React2Shell remote code execution vulnerability (CVE-2025-55182), which affects over...
« Older Entries

Latest Posts

  • Massive Chrome Extension Caught Harvesting Millions of Users’ AI Chat Conversations
  • Scammers Abuse PayPal Subscriptions to Send Fake Purchase Notification Emails
  • Google Links Additional Chinese Hacking Groups to Widespread Exploitation of Critical React2Shell Vulnerability
  • Notepad++ Releases Security Update to Address Traffic Hijacking Vulnerability
  • Thousands of Exposed Secrets on Docker Hub Put Organisations at Serious Risk

Speaking Events

  • Panelist at SecTalks Legends – 2025
  • Keynote Speaker at Sydney AI Security Summit 2025
  • Speaker at The Artificial Unintelligence Conference
  • INFS2701 Guest Lecture at UNSW Business School
  • Speaker at ADAPT Cloud & Infrastructure Edge 2025

More Content

  • Articles (26)
  • Podcast (710)
  • Posts (26)
  • Publications (1)
  • Speaking (47)
  • X
  • RSS
Edwin Kwan