Edwin Kwan
  • Home
  • Speaker
  • Podcasts
    • Cyber Bites
    • AppSec Unlocked
    • It’s 5:05 Podcast
  • Journal
  • Publications
Select Page

Chinese State Hackers Hijacked Notepad++ Update Feature for Six Months

Feb 4, 2026 | Podcast

https://notepad-plus-plus.org/news/hijacked-incident-info-update Chinese state-sponsored threat actors successfully compromised the Notepad++ update infrastructure for nearly half a year, intercepting and redirecting update requests from targeted users to malicious...

Iron Mountain Downplays Data Breach Claimed by Everest Extortion Gang

Feb 3, 2026 | Podcast

Iron Mountain, a major data storage and recovery services provider serving over 240,000 customers globally including 95% of the Fortune 1000, has confirmed a security incident following claims by the Everest extortion group that it stole 1.4 terabytes of internal...

Apple Introducing Privacy Feature to Reduce Carrier Location Tracking on Select Devices

Feb 2, 2026 | Podcast

https://support.apple.com/en-us/126101 Apple will be rolling out a new privacy enhancement called “Limit Precise Location” with iOS 26.3, allowing users of select iPhone and iPad models to restrict the precision of location data shared with cellular...

ShinyHunters Targets Approximately 100 Organisations in Okta Single Sign-On Credential Theft Campaign

Jan 30, 2026 | Podcast

https://www.okta.com/blog/threat-intelligence/phishing-kits-adapt-to-the-script-of-callers ShinyHunters has targeted around 100 organisations in its latest Okta single sign-on credential stealing campaign using evolved voice-phishing techniques to compromise SSO...

Extortion Group WorldLeaks Claims 1.4 Terabyte Data Theft From Nike in Manufacturing-Focused Breach

Jan 29, 2026 | Podcast

Nike confirmed it is investigating a potential cybersecurity incident after extortion crew WorldLeaks claimed to have stolen 1.4 terabytes containing 188,347 files from the sportswear giant’s systems and posted samples on its leak site. The published data...

WhatsApp Launches Strict Account Settings to Shield High-Risk Users From Advanced Spyware Attacks

Jan 28, 2026 | Podcast

https://blog.whatsapp.com/whatsapps-latest-privacy-protection-strict-account-settings Meta announced it is adding Strict Account Settings on WhatsApp to secure certain users against sophisticated cyber attacks, functioning similarly to Apple’s Lockdown Mode and...

JavaScript Package Managers Vulnerable to Supply Chain Attacks Despite npm’s Shai-Hulud Security Measures

Jan 27, 2026 | Podcast

https://www.koi.ai/blog/packagegate-6-zero-days-in-js-package-managers-but-npm-wont-act Defence mechanisms that npm introduced following the Shai-Hulud supply-chain attacks contain critical weaknesses allowing threat actors to bypass protections through Git...

Nearly 800,000 Telnet Servers Exposed Globally as Critical Authentication Bypass Vulnerability Faces Active Exploitation

Jan 26, 2026 | Podcast

https://www.bleepingcomputer.com/news/security/nearly-800-000-telnet-servers-exposed-to-remote-attacks Internet security watchdog Shadowserver is tracking nearly 800,000 IP addresses with Telnet fingerprints amid ongoing attacks exploiting a critical authentication...

Predictable Password Patterns Persist as Billions Continue Using Easily Cracked Credentials

Jan 23, 2026 | Podcast

https://www.welivesecurity.com/en/cybersecurity/old-habits-die-hard-2025-most-common-passwords The password “123456” continues to reign as the most commonly used password globally across all age groups, with a full 25 percent of the top 1,000 most-used...

Attackers Weaponise Zendesk Support Systems in Massive Global Spam Campaign

Jan 22, 2026 | Podcast

Your Inbox Is Under Attack — Even Trusted Support Emails Are Being Abused A widespread spam campaign exploited unsecured Zendesk customer support systems to flood users worldwide with hundreds of automated emails from legitimate companies beginning around January 18....
« Older Entries
Next Entries »

Latest Posts

  • AI Emerges as a Game-Changer in Cyber Defence, Australian Signals Directorate Reports
  • Anthropic’s Restricted Claude Mythos Model Moves Closer to Public Release
  • Anthropic’s AI Model Finds Over Ten Thousand Critical Vulnerabilities in Global Software Infrastructure
  • npm Introduces Human Approval Gates to Counter Software Supply Chain Attacks
  • HackerOne Slashes Bug Bounty Payouts as AI Floods Open-Source Security Programs

Speaking Events

  • Guest Lecture at UNSW Business School for INFS5907
  • Speaker at Bugcrowd Luncheon
  • Guest Lecture at UNSW
  • Panelist at SecTalks Legends – 2025
  • Keynote Speaker at Sydney AI Security Summit 2025

More Content

  • Articles (26)
  • Podcast (796)
  • Posts (26)
  • Publications (1)
  • Speaking (50)
  • X
  • RSS
Edwin Kwan