Edwin Kwan
  • Home
  • Speaker
  • Podcasts
    • Cyber Bites
    • AppSec Unlocked
    • It’s 5:05 Podcast
  • Journal
  • Publications
Select Page

Malicious OpenClaw Skill Weaponizes AI Agent Framework to Distribute Malwar

May 6, 2026 | Podcast

https://www.zscaler.com/blogs/security-research/malicious-openclaw-skill-distributes-remcos-rat-and-ghostloader Zscaler ThreatLabz researchers have uncovered a campaign in which threat actors weaponised the OpenClaw open-source AI agent framework to distribute both...

ACSC Issues Warning Over ClickFix Attacks Deploying Vidar Stealer Malware

May 5, 2026 | Podcast

https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/clickfix-distributing-vidar-stealer-via-wordpress-targeting-australian-infrastructure Australia’s cybersecurity authorities have issued an official warning regarding an active and...

Cybercriminals Abuse Amazon SES to Launch Undetected Phishing Campaigns

May 4, 2026 | Podcast

https://securelist.com/amazon-ses-phishing-and-bec-attacks/119623 Security researchers have uncovered a new phishing campaign exploiting Amazon Simple Email Service (SES), Amazon’s legitimate cloud-based email platform, to send malicious emails that bypass...

New “ClawHub” and “ClawSwarm” Malware Campaigns Target AI Agents for Crypto Recruitment

May 1, 2026 | Podcast

https://www.manifold.security/blog/clawhub-clawswarm-agent-crypto-recruitment Head of Research, Ax Sharma, at Manifold Security have uncovered a sophisticated new threat campaign leveraging two related malware frameworks — dubbed “ClawHub” and...

KnowBe4 Research Reveals 86% of Phishing Attacks Are Now AI-Driven

Apr 30, 2026 | Podcast

https://www.knowbe4.com/press/knowbe4-research-finds-86-of-phishing-attacks-are-ai-driven New research from cybersecurity awareness training firm KnowBe4 has uncovered a striking and alarming trend in the phishing threat landscape: a staggering 86% of phishing attacks...

Google Patches Maximum Severity CVSS 10 Flaw in Gemini CLI Amid Growing AI Tool Vulnerabilities

Apr 29, 2026 | Podcast

A CVSS 10.0 in Gemini CLI: How Agentic Workflows Are Reshaping Supply Chain Risk Google has patched a critical, maximum-severity vulnerability in its Gemini CLI tool — the @google/gemini-cli npm package and the google-github-actions/run-gemini-cli GitHub Actions...

Critical cPanel & WHM Authentication Bypass Vulnerability Actively Exploited in the Wild

Apr 28, 2026 | Podcast

https://www.rapid7.com/blog/post/etr-cve-2026-41940-cpanel-whm-authentication-bypass On April 28, 2026, cPanel issued an emergency security update addressing CVE-2026-41940, a critical authentication bypass vulnerability affecting cPanel & WHM and WP Squared...

Critical Linux “copyfiles” Vulnerability Grants Root Access on Major Distributions

Apr 27, 2026 | Podcast

https://xint.io/blog/copy-fail-linux-distributions A newly discovered Linux vulnerability, dubbed “copy_file_range” or “CopyFail,” is sending shockwaves through the cybersecurity community after researchers found it can be exploited to grant...

Anthropic Mythos Discovered 271 Security Vulnerabilities in Firefox

Apr 24, 2026 | Podcast

The zero-days are numbered  Mozilla has announced a groundbreaking collaboration with Anthropic that leveraged advanced AI models to identify and fix 271 security vulnerabilities in Firefox 150, marking a potential paradigm shift in software security. The Firefox team...

Malicious Cryptocurrency Wallet Apps Infiltrate China’s Apple App Store

Apr 23, 2026 | Podcast

https://securelist.com/fakewallet-cryptostealer-ios-app-store/119474 China’s Apple App Store has been compromised by a wave of fraudulent cryptocurrency wallet applications designed to steal users’ digital assets, according to recent security research....
« Older Entries
Next Entries »

Latest Posts

  • State-Sponsored Hackers and Criminal Groups Exploited Claude AI for Attacks on Millions of Targets
  • OpenAI Publishes New Framework for Tracking AI Agents That Bypass Their Own Constraints
  • Revolut Confirms Customer Data Exposed After Fraudulent Government Requests Fooled Staff
  • Australia’s Cyber Security Agency Releases Guidance on Securing AI Agent Systems
  • Over One Million Students and Teachers Caught Up in Mathspace Data Breach After Vulnerability Left Unpatched for Weeks

Speaking Events

  • Speaker at Melbourne Secure Software And AppSec Summit 2026
  • Guest Lecture at UNSW Business School for INFS5907
  • Speaker at Bugcrowd Luncheon
  • Guest Lecture at UNSW
  • Panelist at SecTalks Legends – 2025

More Content

  • Articles (26)
  • Podcast (855)
  • Posts (29)
  • Publications (2)
  • Speaking (51)
  • X
  • RSS
Edwin Kwan