Edwin Kwan
  • Home
  • Speaker
  • Podcasts
    • Cyber Bites
    • AppSec Unlocked
    • It’s 5:05 Podcast
  • Journal
  • Publications
Select Page

Attackers Weaponise Zendesk Support Systems in Massive Global Spam Campaign

Jan 22, 2026 | Podcast

Your Inbox Is Under Attack — Even Trusted Support Emails Are Being Abused A widespread spam campaign exploited unsecured Zendesk customer support systems to flood users worldwide with hundreds of automated emails from legitimate companies beginning around January 18....

AI-Powered Browsers Reverse Decades of Web Security Advances, Researchers Warn

Jan 21, 2026 | Podcast

https://www.darkreading.com/application-security/ai-agents-undermine-progress-browser-security Agentic browsers powered by artificial intelligence are undermining years of progress in web security by reintroducing vulnerabilities that modern browsers had largely...

GitLab Releases Emergency Patches for Two-Factor Authentication Bypass and Denial-of-Service Vulnerabilities

Jan 20, 2026 | Podcast

https://about.gitlab.com/releases/2026/01/21/patch-release-gitlab-18-8-2-released/#cve-2026-0723—unchecked-return-value-issue-in-authentication-services-impacts-gitlab-ceee GitLab has addressed a critical security issue that permitted attackers with knowledge of...

Fortune 500 Companies Compromised Through Vulnerable Security Testing Applications

Jan 19, 2026 | Podcast

When the Lab Door Stays Open: Exposed Training Apps Exploited for Fortune 500 Cloud Breaches Cybercriminals are targeting intentionally vulnerable web applications that organisations use for security training and penetration testing, gaining unauthorised access to...

Thousands of New Zealanders Impacted by Manage My Health Data Breach

Jan 16, 2026 | Podcast

https://www.privacy.org.nz/tuhono-connect/statements-media-releases/information-for-people-impacted-by-the-manage-my-health-data-breach The Office of the Privacy Commissioner of New Zealand has issued a statement regarding a serious cyber incident that has affected...

Instagram Denies Data Breach Amid Claims of 17 Million Account Data Leak

Jan 15, 2026 | Podcast

Instagram Password Reset Surge Linked To Resurfaced 2024 Data Leak Affecting Millions Instagram, owned by Meta, has denied a data breach after claims emerged that data from over 17 million Instagram accounts had been scraped and leaked online. The company stated that...

Notorious BreachForums Hacking Site Hit by Data Breach, Over 324,000 Accounts Exposed

Jan 14, 2026 | Podcast

https://www.bleepingcomputer.com/news/security/breachforums-hacking-forum-database-leaked-exposing-324-000-accounts The latest iteration of the notorious BreachForums hacking site has suffered a data breach, with its user database table containing over 323,000 member...

WhatsApp Worm Spreads Astaroth Banking Trojan Across Brazil via Contact Auto-Messaging

Jan 13, 2026 | Podcast

https://www.acronis.com/en/tru/posts/boto-cor-de-rosa-campaign-reveals-astaroth-whatsapp-based-worm-activity-in-brazil Cybersecurity researchers have uncovered a new campaign that leverages WhatsApp as a distribution vector for a Windows banking trojan called...

FBI Warns of North Korean Hackers Using Malicious QR Codes in Spear-Phishing Attacks

Jan 12, 2026 | Podcast

https://www.ic3.gov/CSA/2026/260108.pdf The U.S. Federal Bureau of Investigation (FBI) has released an advisory warning of North Korean state-sponsored threat actors, specifically the Kimsuky group, leveraging malicious QR codes in spear-phishing campaigns targeting...
Google to Discontinue Its Dark Web Report Security Feature in 2026

Google to Discontinue Its Dark Web Report Security Feature in 2026

Dec 19, 2025 | Podcast

Google has announced that it will be shutting down its “dark web report” security tool, which notifies users if their email address or other personal information has been found on the dark web. The tech giant stated that it wants to focus on other tools it...
« Older Entries
Next Entries »

Latest Posts

  • New “ClawHub” and “ClawSwarm” Malware Campaigns Target AI Agents for Crypto Recruitment
  • KnowBe4 Research Reveals 86% of Phishing Attacks Are Now AI-Driven
  • Google Patches Maximum Severity CVSS 10 Flaw in Gemini CLI Amid Growing AI Tool Vulnerabilities
  • Critical cPanel & WHM Authentication Bypass Vulnerability Actively Exploited in the Wild
  • Critical Linux “copyfiles” Vulnerability Grants Root Access on Major Distributions

Speaking Events

  • Guest Lecture at UNSW Business School for INFS5907
  • Speaker at Bugcrowd Luncheon
  • Guest Lecture at UNSW
  • Panelist at SecTalks Legends – 2025
  • Keynote Speaker at Sydney AI Security Summit 2025

More Content

  • Articles (26)
  • Podcast (777)
  • Posts (26)
  • Publications (1)
  • Speaking (50)
  • X
  • RSS
Edwin Kwan