Edwin Kwan
  • Home
  • Speaker
  • Podcasts
    • Cyber Bites
    • AppSec Unlocked
    • It’s 5:05 Podcast
  • Journal
  • Publications
Select Page

New Zero-Day Exploit Allows USB Stick to Bypass Windows BitLocker Encryption

May 14, 2026 | Podcast

https://www.itnews.com.au/news/usb-stick-opens-windows-bitlocker-drives-in-new-zero-day-625859 A newly published zero-day vulnerability dubbed YellowKey allows an attacker with physical access to a Windows device to completely bypass BitLocker disk encryption using...

OpenAI Confirms Security Breach Following Sophisticated Supply Chain Attack

May 13, 2026 | Podcast

https://openai.com/index/our-response-to-the-tanstack-npm-supply-chain-attack OpenAI has confirmed it was caught up in a supply chain attack targeting TanStack, a popular open-source library widely used by JavaScript developers to build web applications and data...

Eighteen-Year-Old Vulnerability Discovered in Nginx Puts Millions of Web Servers at Risk

May 12, 2026 | Podcast

https://depthfirst.com/research/nginx-rift-achieving-nginx-rce-via-an-18-year-old-vulnerability A security vulnerability that has existed in the Nginx web server for eighteen years has been discovered and disclosed, raising serious concerns about the stability and...

Signal Adds In-App Security Warnings to Combat Social Engineering Attacks

May 11, 2026 | Podcast

To help protect Signal users from phishing and social engineering attacks, we’ve introduced additional confirmations and educational messaging in the app to help people better detect fraudulent profiles, especially message requests from scammers posing as Signal. More...

60% of MD5 Password Hashes Now Crackable in Under an Hour With a Single GPU

May 8, 2026 | Podcast

https://www.kaspersky.com/blog/passwords-hacking-research-2026/55743 New research from Kaspersky, released on World Password Day 2026, delivers a wake-up call for organisations still relying on MD5 hashing to protect user credentials. Analyzing a dataset of more than...

Survey Finds 1 in 8 Employees Consider Selling Company Login Credentials Justifiable

May 7, 2026 | Podcast

https://www.cifas.org.uk/workplace-fraud-trends-2025 A alarming report from UK fraud prevention organisation Cifas has revealed that 13 percent of employees either have sold company login credentials in the past year or know someone who has, and an equally troubling...

Malicious OpenClaw Skill Weaponizes AI Agent Framework to Distribute Malwar

May 6, 2026 | Podcast

https://www.zscaler.com/blogs/security-research/malicious-openclaw-skill-distributes-remcos-rat-and-ghostloader Zscaler ThreatLabz researchers have uncovered a campaign in which threat actors weaponised the OpenClaw open-source AI agent framework to distribute both...

ACSC Issues Warning Over ClickFix Attacks Deploying Vidar Stealer Malware

May 5, 2026 | Podcast

https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/clickfix-distributing-vidar-stealer-via-wordpress-targeting-australian-infrastructure Australia’s cybersecurity authorities have issued an official warning regarding an active and...

Cybercriminals Abuse Amazon SES to Launch Undetected Phishing Campaigns

May 4, 2026 | Podcast

https://securelist.com/amazon-ses-phishing-and-bec-attacks/119623 Security researchers have uncovered a new phishing campaign exploiting Amazon Simple Email Service (SES), Amazon’s legitimate cloud-based email platform, to send malicious emails that bypass...

New “ClawHub” and “ClawSwarm” Malware Campaigns Target AI Agents for Crypto Recruitment

May 1, 2026 | Podcast

https://www.manifold.security/blog/clawhub-clawswarm-agent-crypto-recruitment Head of Research, Ax Sharma, at Manifold Security have uncovered a sophisticated new threat campaign leveraging two related malware frameworks — dubbed “ClawHub” and...
« Older Entries
Next Entries »

Latest Posts

  • AI Emerges as a Game-Changer in Cyber Defence, Australian Signals Directorate Reports
  • Anthropic’s Restricted Claude Mythos Model Moves Closer to Public Release
  • Anthropic’s AI Model Finds Over Ten Thousand Critical Vulnerabilities in Global Software Infrastructure
  • npm Introduces Human Approval Gates to Counter Software Supply Chain Attacks
  • HackerOne Slashes Bug Bounty Payouts as AI Floods Open-Source Security Programs

Speaking Events

  • Guest Lecture at UNSW Business School for INFS5907
  • Speaker at Bugcrowd Luncheon
  • Guest Lecture at UNSW
  • Panelist at SecTalks Legends – 2025
  • Keynote Speaker at Sydney AI Security Summit 2025

More Content

  • Articles (26)
  • Podcast (796)
  • Posts (26)
  • Publications (1)
  • Speaking (50)
  • X
  • RSS
Edwin Kwan