Cisco & Dell CVSS 10.0 Exploited for YEARS, Claude AI Jailbroken, ScarCruft Jumps Air Gaps | HN64

Cisco & Dell CVSS 10.0 Exploited for YEARS, Claude AI Jailbroken, ScarCruft Jumps Air Gaps | HN64

Two perfect CVSS 10.0 scores in one news cycle. A state-sponsored actor living inside Cisco's SD-WAN platform since 2023. A brand-new lateral movement technique called "Ghost NICs" that leaves no forensic trace. An AI chatbot jailbroken to steal 195 million government records. A North Korean hacking group bridging air-gapped networks with USB drives and an embedded Ruby runtime. And a phishing platform so sophisticated it makes your multi-factor authentication functionally useless.
This is Hacking News Episode 64 from Exploit Brokers by Forgebound Research. Five stories, multiple nation-state actors, and some genuinely novel attack techniques. Let's get into it.

🕐 TIMESTAMPS
0:00 — Cold Open
1:12 — Welcome & CTA
1:55 — Story 1: Cisco SD-WAN Zero-Day (CVE-2026-20127, CVSS 10.0) — Five Eyes Response
6:55 — Story 2: Dell RecoverPoint Zero-Day (CVE-2026-22769, CVSS 10.0) — Ghost NICs
11:35 — Story 3: Claude AI Jailbreak — 195 Million Mexican Government Records
15:27 — Story 4: ScarCruft Air-Gap Bridging — "Ruby Jumper" Campaign
19:55 — Story 5: Starkiller Phishing-as-a-Service — MFA Bypass
25:02 — Recap & 5 Key Takeaways
27:28 — Outro

📚 SOURCES
Story 1 — Cisco SD-WAN:

Cisco Advisory cisco-sa-sdwan-rpa-EHchtZk — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk
CISA Emergency Directive 26-03 — https://www.cisa.gov/emergency-directive-26-03
ASD-ACSC Hunt Guide — https://www.cyber.gov.au/
BleepingComputer — https://www.bleepingcomputer.com/
The Hacker News — https://thehackernews.com/
Dark Reading — https://www.darkreading.com/
SecurityWeek — https://www.securityweek.com/

Story 2 — Dell RecoverPoint:

Google Cloud / Mandiant GTIG Report — https://cloud.google.com/blog/topics/threat-intelligence/
Dell Security Advisory DSA-2026-079 — https://www.dell.com/support/kbdoc/en-us/000426742/
CISA Known Exploited Vulnerabilities Catalog — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
The Hacker News — https://thehackernews.com/
SecurityWeek — https://www.securityweek.com/
CyberScoop — https://cyberscoop.com/

Story 3 — Claude AI Jailbreak:

Bloomberg (Feb 25, 2026) — https://www.bloomberg.com/
VentureBeat — https://venturebeat.com/
Gambit Security Research — https://gambitsecurity.com/

Story 4 — ScarCruft Ruby Jumper:

Zscaler ThreatLabz Report (Feb 27) — https://www.zscaler.com/blogs/security-research/
The Hacker News — https://thehackernews.com/
BleepingComputer — https://www.bleepingcomputer.com/

Story 5 — Starkiller PhaaS:

Krebs on Security — https://krebsonsecurity.com/
Abnormal AI Technical Analysis — https://abnormalsecurity.com/blog/
Dark Reading — https://www.darkreading.com/
Infosecurity Magazine — https://www.infosecurity-magazine.com/


⚠️ DISCLAIMER
The content presented by Exploit Brokers by Forgebound Research is for educational and informational purposes only. Cipherceval is a cybersecurity educator and commentator — not your personal security consultant, legal counsel, or professional advisor. The information shared here reflects publicly available research, industry reporting, and the host's personal perspective. It does not constitute professional security consulting or individualized guidance for your specific environment. Always consult with qualified professionals for decisions affecting your systems and security posture.

🔔 Subscribe for weekly cybersecurity news and analysis.
👍 Like if this episode was helpful.
🔗 Share with your team — awareness is the first line of defense.

#cybersecurity #hackernews #exploitbrokers #cipherceval #infosec #cisco #sdwan #cve #zerodday #ghostnics #dell #recoverpoint #claudeai #jailbreak #scarcruft #northkorea #airgap #starkiller #phishing #mfa #fido2 #passkeys #fiveeyes #cisa #threatintelligence #apisecurity #cyberthreat #nationstatehacking #databreach

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(62)

Dual CVSS 10.0 Cisco Flaws, AI Malware Assembly Line, Qualcomm Zero-Day & More | HN65

Dual CVSS 10.0 Cisco Flaws, AI Malware Assembly Line, Qualcomm Zero-Day & More | HN65

This week on Hacking News, we're covering five stories that all share one theme: the things we trust most are the things being targeted. Cisco disclosed two CVSS 10.0 vulnerabilities in their Secure F...

26 Maalis 23min

600 Firewalls Breached by AI in 5 Weeks — Plus Chrome Zero-Day, CVSS 9.9 RCE & AI-Powered Malware | HN63

600 Firewalls Breached by AI in 5 Weeks — Plus Chrome Zero-Day, CVSS 9.9 RCE & AI-Powered Malware | HN63

AI is reshaping both sides of the cybersecurity battlefield — and fast. In this episode, we break down five stories that prove it: the first Chrome zero-day of 2026 (CVE-2026-2441), a near-perfect CVS...

5 Maalis 28min

6 Zero-Days Exploited NOW, Lazarus Poisons npm, AI-Generated Malware & More | HN62

6 Zero-Days Exploited NOW, Lazarus Poisons npm, AI-Generated Malware & More | HN62

Microsoft just dropped patches for SIX actively exploited zero-day vulnerabilities — and that's just the beginning. In this week's Hacking News, we break down the February 2026 Patch Tuesday emergency...

26 Helmi 24min

State Hackers Hit 37 Countries, BeyondTrust CVSS 9.9 RCE, Signal Hijacked & More | HN Ep. 61

State Hackers Hit 37 Countries, BeyondTrust CVSS 9.9 RCE, Signal Hijacked & More | HN Ep. 61

A newly uncovered state-backed espionage group has compromised 70 organizations across 37 countries in a single year — and they were scanning infrastructure in 155 more. In this episode of Hacking New...

19 Helmi 21min

CRITICAL: Office Zero-Day + WordPress Admin Takeover + Chrome Extensions Stealing AI Chats | EP 60

CRITICAL: Office Zero-Day + WordPress Admin Takeover + Chrome Extensions Stealing AI Chats | EP 60

Microsoft just dropped an emergency patch for an Office zero-day being exploited in the wild. A WordPress plugin has a CVSS 10.0 vulnerability — that's the golden goose of hacking. 900,000 Chrome user...

29 Tammi 24min

I'm Back and Introducing Forgebound Research | The Rebrand

I'm Back and Introducing Forgebound Research | The Rebrand

Exploit Brokers is back—under a new banner. In this episode, I explain why the show went quiet, what Forgebound Research means, and how the podcast is evolving. We're shifting to a hybrid model: some ...

12 Tammi 8min

HN59 - Microsoft AI Discovers 20 Zero-Day Vulnerabilities in Bootloaders!

HN59 - Microsoft AI Discovers 20 Zero-Day Vulnerabilities in Bootloaders!

# Title * HN59 - Microsoft AI Discovers 20 Zero-Day Vulnerabilities in Bootloaders! ## Description 🔍 Microsoft's AI Uncovers 20 Zero-Day Threats | CoffeeLoader Malware Gets Smarter In this episode ...

3 Huhti 202519min

Suosittua kategoriassa Politiikka ja uutiset

uutiscast
aikalisa
politiikan-puskaradio
ootsa-kuullut-tasta-2
rss-ootsa-kuullut-tasta
rss-podme-livebox
tervo-halme
otetaan-yhdet
et-sa-noin-voi-sanoo-esittaa
rss-vaalirankkurit-podcast
rss-kaikki-uusiksi
rss-asiastudio
rss-ulkopoditiikkaa
rss-pinnalla
the-ulkopolitist
rss-sinivalkoinen-islam
rss-hyvaa-huomenta-bryssel