Edwin Kwan
  • Home
  • Speaker
  • Podcasts
    • Cyber Bites
    • AppSec Unlocked
    • It’s 5:05 Podcast
  • Journal
  • Publications
Select Page

Google Accidentally Exposes Details of Unpatched Chromium Vulnerability

May 20, 2026 | Podcast

https://infosec.exchange/@rebane2001/116606719764376414 Google briefly made public the technical details of an unpatched security vulnerability in Chromium, the open-source browser engine underpinning Google Chrome, Microsoft Edge, Brave, Opera, and dozens of other...

GitHub Confirms Internal Repository Breach After Employee Device Compromise

May 19, 2026 | Podcast

https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w GitHub has confirmed that an employee device was compromised via a poisoned Microsoft Visual Studio Code extension, resulting in the exfiltration of approximately 3,800 internal repositories....

Grafana Labs Confirms Ransomware Extortion Following TanStack Supply Chain Breach

May 18, 2026 | Podcast

https://grafana.com/blog/grafana-labs-security-update-latest-on-tanstack-npm-supply-chain-ransomware-incident Grafana Labs, the company behind one of the most widely deployed open-source observability platforms in the world, has confirmed it was targeted by a...

Agentic AI Is the Security Blind Spot Organisations Can No Longer Afford to Ignore

May 15, 2026 | Podcast

https://thehackernews.com/2026/05/why-agentic-ai-is-securitys-next-blind.html Agentic AI, artificial intelligence systems that can autonomously execute tasks, make decisions, and take actions across digital environments, is already running in production inside...

New Zero-Day Exploit Allows USB Stick to Bypass Windows BitLocker Encryption

May 14, 2026 | Podcast

https://www.itnews.com.au/news/usb-stick-opens-windows-bitlocker-drives-in-new-zero-day-625859 A newly published zero-day vulnerability dubbed YellowKey allows an attacker with physical access to a Windows device to completely bypass BitLocker disk encryption using...

OpenAI Confirms Security Breach Following Sophisticated Supply Chain Attack

May 13, 2026 | Podcast

https://openai.com/index/our-response-to-the-tanstack-npm-supply-chain-attack OpenAI has confirmed it was caught up in a supply chain attack targeting TanStack, a popular open-source library widely used by JavaScript developers to build web applications and data...

Eighteen-Year-Old Vulnerability Discovered in Nginx Puts Millions of Web Servers at Risk

May 12, 2026 | Podcast

https://depthfirst.com/research/nginx-rift-achieving-nginx-rce-via-an-18-year-old-vulnerability A security vulnerability that has existed in the Nginx web server for eighteen years has been discovered and disclosed, raising serious concerns about the stability and...

Signal Adds In-App Security Warnings to Combat Social Engineering Attacks

May 11, 2026 | Podcast

To help protect Signal users from phishing and social engineering attacks, we’ve introduced additional confirmations and educational messaging in the app to help people better detect fraudulent profiles, especially message requests from scammers posing as Signal. More...

60% of MD5 Password Hashes Now Crackable in Under an Hour With a Single GPU

May 8, 2026 | Podcast

https://www.kaspersky.com/blog/passwords-hacking-research-2026/55743 New research from Kaspersky, released on World Password Day 2026, delivers a wake-up call for organisations still relying on MD5 hashing to protect user credentials. Analyzing a dataset of more than...

Survey Finds 1 in 8 Employees Consider Selling Company Login Credentials Justifiable

May 7, 2026 | Podcast

https://www.cifas.org.uk/workplace-fraud-trends-2025 A alarming report from UK fraud prevention organisation Cifas has revealed that 13 percent of employees either have sold company login credentials in the past year or know someone who has, and an equally troubling...
« Older Entries
Next Entries »

Latest Posts

  • State-Sponsored Hackers and Criminal Groups Exploited Claude AI for Attacks on Millions of Targets
  • OpenAI Publishes New Framework for Tracking AI Agents That Bypass Their Own Constraints
  • Revolut Confirms Customer Data Exposed After Fraudulent Government Requests Fooled Staff
  • Australia’s Cyber Security Agency Releases Guidance on Securing AI Agent Systems
  • Over One Million Students and Teachers Caught Up in Mathspace Data Breach After Vulnerability Left Unpatched for Weeks

Speaking Events

  • Speaker at Melbourne Secure Software And AppSec Summit 2026
  • Guest Lecture at UNSW Business School for INFS5907
  • Speaker at Bugcrowd Luncheon
  • Guest Lecture at UNSW
  • Panelist at SecTalks Legends – 2025

More Content

  • Articles (26)
  • Podcast (855)
  • Posts (29)
  • Publications (2)
  • Speaking (51)
  • X
  • RSS
Edwin Kwan