
Sign up to save your podcasts
Or


⏱️ Timestamps 0:00 — Cold Open: What do you call a hackable firewall manager? 1:21 — Welcome & CTA 2:01 — Story 1: Cisco Secure FMC — Two CVSS 10.0 Vulnerabilities (CVE-2026-20079 & CVE-2026-20131) 5:33 — Story 2: APT36 "Vibeware" — AI-Generated Malware at Industrial Scale 9:13 — Story 3: Google Android March 2026 — 129 Patches + Qualcomm Zero-Day (CVE-2026-21385) 12:34 — Story 4: UAT-9244 / FamousSparrow — China-Linked APT Hits South American Telecoms 16:26 — Story 5: LexisNexis Cloud Breach — React2Shell, Weak Passwords, Gov Data 20:14 — Recap & Key Takeaways 22:40 — Outro
🔑 Key Takeaways
Network security appliances are high-value targets. The Cisco FMC vulnerabilities follow the same pattern as the SD-WAN disclosure — if the management plane is compromised, everything downstream is at risk. AI is changing the economics of malware, not the sophistication. APT36's vibeware shows the real threat is volume, not brilliance. Detection teams may need to rethink approaches for floods of low-quality polyglot variants. Mobile patching remains the ecosystem's Achilles' heel. 129 Android vulnerabilities, including an exploited Qualcomm zero-day across 234 chipsets. Google releases patches; manufacturers control the timeline. Telecom targeting is not slowing down. UAT-9244 demonstrates continued investment in multi-platform telecom compromise toolkits — Windows, Linux, and edge devices simultaneously. P2P C2 and ORB expansion make detection exceptionally difficult. Cloud security basics still matter more than anything. The LexisNexis breach wasn't a zero-day — it was an unpatched app, an overly permissive IAM role, and a weak password. Fundamentals remain the most impactful things any organization can do.
📚 Sources Story 1 — Cisco FMC:
Cisco Advisory: cisco-sa-onprem-fmc-authbypass-5JPp45V2 Cisco Advisory: cisco-sa-fmc-rce-NKhnULJh The Stack — "Two CVSS 10s in Cisco firewall management found internally" Security Affairs — "Cisco fixes maximum-severity Secure FMC bugs" Singapore CSA: Alert AL-2026-021
Story 2 — APT36 Vibeware:
Bitdefender — "APT36: A Nightmare of Vibeware" Dark Reading — "Nation-State Actor Embraces AI Malware Assembly Line" HackRead — "Pakistan-Linked APT36 Floods Indian Govt Networks" SC Media — "AI-generated vibeware spread in new APT36 campaign"
Story 3 — Android March 2026:
Google Android Security Bulletin — March 2026 CyberScoop — "Google addresses actively exploited Qualcomm zero-day" The Hacker News — "Google Confirms CVE-2026-21385" SecurityWeek — "Android Update Patches Exploited Qualcomm Zero-Day" CISA KEV Catalog — CVE-2026-21385
Story 4 — UAT-9244:
Cisco Talos — "UAT-9244 targets South American telecommunication providers" BleepingComputer — "Chinese state hackers target telcos with new malware toolkit" The Hacker News — "China-Linked Hackers Use TernDoor, PeerTime, BruteEntry"
Story 5 — LexisNexis:
BleepingComputer — "LexisNexis confirms data breach as hackers leak stolen files" The Register — "LexisNexis Legal & Professional confirms data breach" SecurityWeek — "New LexisNexis Data Breach Confirmed" The Record — "LexisNexis says hackers accessed legacy data" Cybernews — "Hackers claim LexisNexis breach exposing 400K users"
⚠️ The content presented by Exploit Brokers by Forgebound Research is for educational and informational purposes only. Cipherceval is a cybersecurity educator and commentator — not your personal security consultant, legal counsel, or professional advisor. The information shared here reflects publicly available research, industry reporting, and the host's personal perspective. It does not constitute professional security consulting or individualized guidance for your specific environment. Always consult with qualified professionals for decisions affecting your systems and security posture.
Two perfect CVSS 10.0 scores in one news cycle. A state-sponsored actor living inside Cisco's SD-WAN platform since 2023. A brand-new lateral movement technique called "Ghost NICs" that leaves no forensic trace. An AI chatbot jailbroken to steal 195 million government records. A North Korean hacking group bridging air-gapped networks with USB drives and an embedded Ruby runtime. And a phishing platform so sophisticated it makes your multi-factor authentication functionally useless. This is Hacking News Episode 64 from Exploit Brokers by Forgebound Research. Five stories, multiple nation-state actors, and some genuinely novel attack techniques. Let's get into it.
🕐 TIMESTAMPS 0:00 — Cold Open 1:12 — Welcome & CTA 1:55 — Story 1: Cisco SD-WAN Zero-Day (CVE-2026-20127, CVSS 10.0) — Five Eyes Response 6:55 — Story 2: Dell RecoverPoint Zero-Day (CVE-2026-22769, CVSS 10.0) — Ghost NICs 11:35 — Story 3: Claude AI Jailbreak — 195 Million Mexican Government Records 15:27 — Story 4: ScarCruft Air-Gap Bridging — "Ruby Jumper" Campaign 19:55 — Story 5: Starkiller Phishing-as-a-Service — MFA Bypass 25:02 — Recap & 5 Key Takeaways 27:28 — Outro
📚 SOURCES Story 1 — Cisco SD-WAN:
Cisco Advisory cisco-sa-sdwan-rpa-EHchtZk — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk CISA Emergency Directive 26-03 — https://www.cisa.gov/emergency-directive-26-03 ASD-ACSC Hunt Guide — https://www.cyber.gov.au/ BleepingComputer — https://www.bleepingcomputer.com/ The Hacker News — https://thehackernews.com/ Dark Reading — https://www.darkreading.com/ SecurityWeek — https://www.securityweek.com/
Story 2 — Dell RecoverPoint:
Google Cloud / Mandiant GTIG Report — https://cloud.google.com/blog/topics/threat-intelligence/ Dell Security Advisory DSA-2026-079 — https://www.dell.com/support/kbdoc/en-us/000426742/ CISA Known Exploited Vulnerabilities Catalog — https://www.cisa.gov/known-exploited-vulnerabilities-catalog The Hacker News — https://thehackernews.com/ SecurityWeek — https://www.securityweek.com/ CyberScoop — https://cyberscoop.com/
Story 3 — Claude AI Jailbreak:
Bloomberg (Feb 25, 2026) — https://www.bloomberg.com/ VentureBeat — https://venturebeat.com/ Gambit Security Research — https://gambitsecurity.com/
Story 4 — ScarCruft Ruby Jumper:
Zscaler ThreatLabz Report (Feb 27) — https://www.zscaler.com/blogs/security-research/ The Hacker News — https://thehackernews.com/ BleepingComputer — https://www.bleepingcomputer.com/
Story 5 — Starkiller PhaaS:
Krebs on Security — https://krebsonsecurity.com/ Abnormal AI Technical Analysis — https://abnormalsecurity.com/blog/ Dark Reading — https://www.darkreading.com/ Infosecurity Magazine — https://www.infosecurity-magazine.com/
⚠️ DISCLAIMER The content presented by Exploit Brokers by Forgebound Research is for educational and informational purposes only. Cipherceval is a cybersecurity educator and commentator — not your personal security consultant, legal counsel, or professional advisor. The information shared here reflects publicly available research, industry reporting, and the host's personal perspective. It does not constitute professional security consulting or individualized guidance for your specific environment. Always consult with qualified professionals for decisions affecting your systems and security posture.
🔔 Subscribe for weekly cybersecurity news and analysis. 👍 Like if this episode was helpful. 🔗 Share with your team — awareness is the first line of defense.
#cybersecurity #hackernews #exploitbrokers #cipherceval #infosec #cisco #sdwan #cve #zerodday #ghostnics #dell #recoverpoint #claudeai #jailbreak #scarcruft #northkorea #airgap #starkiller #phishing #mfa #fido2 #passkeys #fiveeyes #cisa #threatintelligence #apisecurity #cyberthreat #nationstatehacking #databreach
A newly uncovered state-backed espionage group has compromised 70 organizations across 37 countries in a single year — and they were scanning infrastructure in 155 more. In this episode of Hacking News, we break down Palo Alto Unit 42's Shadow Campaigns investigation, a CVSS 9.9 pre-authentication RCE in BeyondTrust's remote access tools, a state-sponsored Signal phishing campaign targeting European politicians and military officials without using a single line of malware, CISA's aggressive new directive ordering federal agencies to rip out end-of-life edge devices, and an Everest ransomware claim against Iron Mountain that turned out to be far less than advertised.
Whether you're a cybersecurity professional, IT admin, or just someone who wants to stay informed about the threats facing our digital world — this episode has critical takeaways you can act on today.
🔒 Key Topics Covered: • TGR-STA-1030 "Shadow Campaigns" — state-backed espionage across 37 countries • BeyondTrust CVE-2026-1731 — CVSS 9.9 pre-auth RCE in remote access tools • Signal Phishing Campaign — German BfV/BSI advisory on account hijacking • CISA BOD 26-02 — Binding directive to eliminate end-of-support edge devices • Iron Mountain / Everest Ransomware — 1.4TB breach claims vs. reality
⏱️ Timestamps: 0:00 — Cold Open: One group, 37 countries breached 1:10 — Forge OS Intro 1:14 — Welcome & CTA 1:38 — Shadow Campaigns: State-Backed Espionage at Unprecedented Scale 7:04 — BeyondTrust CVE-2026-1731: CVSS 9.9 Pre-Auth RCE 11:07 — Signal Phishing: Hijacking Accounts Without Malware 14:10 — CISA BOD 26-02: Rip Out Your End-of-Life Edge Devices 16:55 — Iron Mountain vs. Everest Ransomware: Claims vs. Reality 19:38 — Recap & Key Takeaways 21:40 — Outro
📌 Resources & Sources: • Unit 42 Shadow Campaigns Report: https://unit42.paloaltonetworks.com/shadow-campaigns-uncovering-global-espionage/ • BeyondTrust Security Advisory BT26-02: https://www.beyondtrust.com/trust-center/security-advisories/bt26-02 • German BfV/BSI Signal Phishing Advisory: https://thehackernews.com/2026/02/german-agencies-warn-of-signal-phishing.html • CISA BOD 26-02 Directive: https://www.cisa.gov/news-events/directives/bod-26-02-mitigating-risk-end-support-edge-devices • Iron Mountain / Everest Coverage: https://cybernews.com/security/iron-mountain-data-breach-claims/
🎧 Listen on Spotify & Apple Podcasts — search "Exploit Brokers by Forgebound Research" and hit follow!
💬 Found this valuable? Share it with a coworker or friend who touches a computer.
— Exploit Brokers by Forgebound Research Host: Cipherceval "Learn more about the threats we face and gain a bit more knowledge than yesterday."
Microsoft just dropped an emergency patch for an Office zero-day being exploited in the wild. A WordPress plugin has a CVSS 10.0 vulnerability — that's the golden goose of hacking. 900,000 Chrome users had their ChatGPT conversations stolen by malicious extensions with Google's Featured badge. And two cybersecurity professionals pleaded guilty to moonlighting as ransomware affiliates.
Welcome to 2026. It's gonna be a fun year.
In this episode:
Key takeaway: Update your stuff. A patch does you no good if it isn't installed.
Subscribe for weekly cybersecurity news, vulnerability breakdowns, and threat intelligence.
https://forgeboundresearch.com/podcasts/
Exploit Brokers is back—under a new banner.
In this episode, I explain why the show went quiet, what Forgebound Research means, and how the podcast is evolving. We're shifting to a hybrid model: some episodes will be news commentary with technical insight, others will be lab-driven deep dives where I actually pull apart the malware or the vulnerable code.
Beyond the podcast, I'm launching The Forgebound Lab on YouTube—security research, hardware teardowns, creative engineering, maker builds, and learning in public.
Same host. Same mission. New chapter.
Welcome to Forgebound Research.
—Cipherceval
🔗 YouTube: https://www.youtube.com/@ForgeboundResearch 🐦 Podcast Twitter: https://x.com/exploitbrokers
🐦 Forgebound Twitter: https://x.com/ForgeboundLabs
From the publisher's feed