
Hosted by Edwin Kwan · ENGLISH

* Cybercriminals Abuse Amazon SES to Launch Undetected Phishing Campaigns* ACSC Issues Warning Over ClickFix Attacks Deploying Vidar Stealer Malware* Malicious OpenClaw Skill Weaponizes AI Agent Framework to Distribute Malware* Survey Finds 1 in 8 Employees Consider Selling Company Login Credentials Justifiable* 60% of MD5 Password Hashes Now Crackable in Under an Hour With a Single GPU This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit edwinkwan.substack.com

* Critical Linux “copyfiles” Vulnerability Grants Root Access on Major Distributions* Critical cPanel & WHM Authentication Bypass Vulnerability Actively Exploited in the Wild* Google Patches Maximum Severity CVSS 10 Flaw in Gemini CLI Amid Growing AI Tool Vulnerabilities* KnowBe4 Research Reveals 86% of Phishing Attacks Are Now AI-Driven* New “ClawHub” and “ClawSwarm” Malware Campaigns Target AI Agents for Crypto Recruitment This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit edwinkwan.substack.com

* Claude Desktop Raises Privacy Concerns Over Silent Browser Extension Installation* Apple Patches iOS Bug That Preserved Deleted Notification Data* Microsoft Teams Becomes Prime Target for Helpdesk Impersonation Scams* Malicious Cryptocurrency Wallet Apps Infiltrate China’s Apple App Store* Anthropic Mythos Discovered 271 Security Vulnerabilities in Firefox This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit edwinkwan.substack.com

* Booking.com Confirms Data Breach Exposing Millions of Travellers’ Reservation Details* Adobe Issues Emergency Patch for Actively Exploited Acrobat Reader Zero-Day* Critical Nginx UI Flaw Under Active Exploitation, Enabling Full Server Takeover Without Authentication* WordPress Plugin Suite Backdoored, Thousands of Sites Silently Compromised Since August 2025* OpenAI Unveils GPT-5.4-Cyber, a Defensive AI Model Purpose-Built for Security Teams This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit edwinkwan.substack.com

* Australia’s Critical Infrastructure Security Laws (SoCI) Branded “Toothless” as Review Calls for Urgent Overhaul* Hacker Claims Breach of US Law Enforcement Tip Platform, Exposing Over 8 Million Confidential Reports* TeamPCP Supply Chain Attack Hits Widely Used AI Tool, Exposing Millions of Systems* TeamPCP Turns Its Hacking Tools Toward Iran, Deploying Data-Destroying Wiper Malware* Enterprise PCs Found Lagging Behind Macs on Security Patching, New Report Reveals This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit edwinkwan.substack.com

* Researchers Exploit AI Browser Reasoning to Train Self-Optimizing Phishing Scams in Under Four Minutes* Meta Collaborates with International Law Enforcement to Dismantle Southeast Asian Scam Operations, Disables 150,000 Accounts* Malicious npm Package Impersonates OpenClaw Installer to Deploy Remote Access Trojan and Harvest macOS Credentials* Microsoft Teams Phishing Campaign Deploys Backdoors to Target Employees* Google’s Cloud Threat Horizons Report: Attackers Exploit Cloud Vulnerabilities More Than Weak Credentials This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit edwinkwan.substack.com

* New South Wales Criminalises AI-Generated Deepfakes and Non-Consensual Intimate Content* DJI Romo Robot Vacuums Exposed Thousands of Devices Through Critical Security Flaws* Developer Faces $82,000 Bill After Stolen Google Gemini API Key Enables Massive Unauthorised Usage* ClawJacked Vulnerability Allows Malicious Websites to Hijack Local OpenClaw AI Agents via WebSocket* Hacktivist Groups Launch 149 DDoS Attacks Against 110 Organisations Following Middle East Military Operations* Iranian Threat Actors Launch Hundreds of Attacks Against IP Surveillance Cameras Across Middle East This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit edwinkwan.substack.com

* Critical Vulnerabilities in Anthropic’s Claude Code Enable Remote Code Execution and Credential Theft* Google Disrupts Chinese Espionage Campaign Using Sheets for Command and Control* Malicious Code Repositories Target Next.js Developers Through Fake Job Interview Projects* AI Excels at Finding Software Bugs But Struggles With Meaningful Remediation* Australian Businesses Making Regular Ransomware Payments Despite Government Warnings This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit edwinkwan.substack.com

* Viral AI Caricature Trend Poses Major Security Risks, Experts Warn* North Korean Hackers Target Developers with Malware-Laced Coding Challenges* Open Source Registries Face Critical Funding Shortfall as Security Threats Mount* Microsoft Copilot Bug Bypasses Security Controls to Summarise Confidential Emails* PromptSpy Android Malware Leverages Gemini AI to Achieve Device Persistence This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit edwinkwan.substack.com

* Apple Patches Critical Zero-Day Vulnerability Exploited in Targeted Attacks* Australian Government Agencies Falling Short on Cyber Incident Reporting, Undermining National Security* Service NSW Launches Pilot for New Digital Identity Verification System* Fake 7-Zip Site Distributes Trojanised Installer Creating Residential Proxy Network* Microsoft Patches Remote Code Execution Flaw in Windows 11 Notepad This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit edwinkwan.substack.com