Dual CVSS 10.0 Cisco Flaws, AI Malware Assembly Line, Qualcomm Zero-Day & More | HN65

Dual CVSS 10.0 Cisco Flaws, AI Malware Assembly Line, Qualcomm Zero-Day & More | HN65

This week on Hacking News, we're covering five stories that all share one theme: the things we trust most are the things being targeted.
Cisco disclosed two CVSS 10.0 vulnerabilities in their Secure Firewall Management Center — the centralized brain that manages entire firewall fleets — giving unauthenticated attackers root access. Pakistan-linked APT36 has turned AI coding tools into a malware assembly line, flooding Indian government networks with disposable "vibeware" variants in a strategy Bitdefender calls "Distributed Denial of Detection." Google dropped the largest Android security update in almost eight years — 129 vulnerabilities — including a Qualcomm zero-day already under targeted exploitation across 234 chipsets. A China-linked threat cluster called UAT-9244 is burrowing into South American telecom infrastructure with three brand-new malware families spanning Windows, Linux, and edge devices. And LexisNexis confirmed a cloud breach after a threat actor exploited an unpatched React app and found the database password was... Lexis1234.

⏱️ Timestamps
0:00 — Cold Open: What do you call a hackable firewall manager?
1:21 — Welcome & CTA
2:01 — Story 1: Cisco Secure FMC — Two CVSS 10.0 Vulnerabilities (CVE-2026-20079 & CVE-2026-20131)
5:33 — Story 2: APT36 "Vibeware" — AI-Generated Malware at Industrial Scale
9:13 — Story 3: Google Android March 2026 — 129 Patches + Qualcomm Zero-Day (CVE-2026-21385)
12:34 — Story 4: UAT-9244 / FamousSparrow — China-Linked APT Hits South American Telecoms
16:26 — Story 5: LexisNexis Cloud Breach — React2Shell, Weak Passwords, Gov Data
20:14 — Recap & Key Takeaways
22:40 — Outro

🔑 Key Takeaways

Network security appliances are high-value targets. The Cisco FMC vulnerabilities follow the same pattern as the SD-WAN disclosure — if the management plane is compromised, everything downstream is at risk.
AI is changing the economics of malware, not the sophistication. APT36's vibeware shows the real threat is volume, not brilliance. Detection teams may need to rethink approaches for floods of low-quality polyglot variants.
Mobile patching remains the ecosystem's Achilles' heel. 129 Android vulnerabilities, including an exploited Qualcomm zero-day across 234 chipsets. Google releases patches; manufacturers control the timeline.
Telecom targeting is not slowing down. UAT-9244 demonstrates continued investment in multi-platform telecom compromise toolkits — Windows, Linux, and edge devices simultaneously. P2P C2 and ORB expansion make detection exceptionally difficult.
Cloud security basics still matter more than anything. The LexisNexis breach wasn't a zero-day — it was an unpatched app, an overly permissive IAM role, and a weak password. Fundamentals remain the most impactful things any organization can do.


📚 Sources
Story 1 — Cisco FMC:

Cisco Advisory: cisco-sa-onprem-fmc-authbypass-5JPp45V2
Cisco Advisory: cisco-sa-fmc-rce-NKhnULJh
The Stack — "Two CVSS 10s in Cisco firewall management found internally"
Security Affairs — "Cisco fixes maximum-severity Secure FMC bugs"
Singapore CSA: Alert AL-2026-021

Story 2 — APT36 Vibeware:

Bitdefender — "APT36: A Nightmare of Vibeware"
Dark Reading — "Nation-State Actor Embraces AI Malware Assembly Line"
HackRead — "Pakistan-Linked APT36 Floods Indian Govt Networks"
SC Media — "AI-generated vibeware spread in new APT36 campaign"

Story 3 — Android March 2026:

Google Android Security Bulletin — March 2026
CyberScoop — "Google addresses actively exploited Qualcomm zero-day"
The Hacker News — "Google Confirms CVE-2026-21385"
SecurityWeek — "Android Update Patches Exploited Qualcomm Zero-Day"
CISA KEV Catalog — CVE-2026-21385

Story 4 — UAT-9244:

Cisco Talos — "UAT-9244 targets South American telecommunication providers"
BleepingComputer — "Chinese state hackers target telcos with new malware toolkit"
The Hacker News — "China-Linked Hackers Use TernDoor, PeerTime, BruteEntry"

Story 5 — LexisNexis:

BleepingComputer — "LexisNexis confirms data breach as hackers leak stolen files"
The Register — "LexisNexis Legal & Professional confirms data breach"
SecurityWeek — "New LexisNexis Data Breach Confirmed"
The Record — "LexisNexis says hackers accessed legacy data"
Cybernews — "Hackers claim LexisNexis breach exposing 400K users"


⚠️ The content presented by Exploit Brokers by Forgebound Research is for educational and informational purposes only. Cipherceval is a cybersecurity educator and commentator — not your personal security consultant, legal counsel, or professional advisor. The information shared here reflects publicly available research, industry reporting, and the host's personal perspective. It does not constitute professional security consulting or individualized guidance for your specific environment. Always consult with qualified professionals for decisions affecting your systems and security posture.

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(62)

Cisco & Dell CVSS 10.0 Exploited for YEARS, Claude AI Jailbroken, ScarCruft Jumps Air Gaps | HN64

Cisco & Dell CVSS 10.0 Exploited for YEARS, Claude AI Jailbroken, ScarCruft Jumps Air Gaps | HN64

Two perfect CVSS 10.0 scores in one news cycle. A state-sponsored actor living inside Cisco's SD-WAN platform since 2023. A brand-new lateral movement technique called "Ghost NICs" that leaves no fore...

12 Maalis 28min

600 Firewalls Breached by AI in 5 Weeks — Plus Chrome Zero-Day, CVSS 9.9 RCE & AI-Powered Malware | HN63

600 Firewalls Breached by AI in 5 Weeks — Plus Chrome Zero-Day, CVSS 9.9 RCE & AI-Powered Malware | HN63

AI is reshaping both sides of the cybersecurity battlefield — and fast. In this episode, we break down five stories that prove it: the first Chrome zero-day of 2026 (CVE-2026-2441), a near-perfect CVS...

5 Maalis 28min

6 Zero-Days Exploited NOW, Lazarus Poisons npm, AI-Generated Malware & More | HN62

6 Zero-Days Exploited NOW, Lazarus Poisons npm, AI-Generated Malware & More | HN62

Microsoft just dropped patches for SIX actively exploited zero-day vulnerabilities — and that's just the beginning. In this week's Hacking News, we break down the February 2026 Patch Tuesday emergency...

26 Helmi 24min

State Hackers Hit 37 Countries, BeyondTrust CVSS 9.9 RCE, Signal Hijacked & More | HN Ep. 61

State Hackers Hit 37 Countries, BeyondTrust CVSS 9.9 RCE, Signal Hijacked & More | HN Ep. 61

A newly uncovered state-backed espionage group has compromised 70 organizations across 37 countries in a single year — and they were scanning infrastructure in 155 more. In this episode of Hacking New...

19 Helmi 21min

CRITICAL: Office Zero-Day + WordPress Admin Takeover + Chrome Extensions Stealing AI Chats | EP 60

CRITICAL: Office Zero-Day + WordPress Admin Takeover + Chrome Extensions Stealing AI Chats | EP 60

Microsoft just dropped an emergency patch for an Office zero-day being exploited in the wild. A WordPress plugin has a CVSS 10.0 vulnerability — that's the golden goose of hacking. 900,000 Chrome user...

29 Tammi 24min

I'm Back and Introducing Forgebound Research | The Rebrand

I'm Back and Introducing Forgebound Research | The Rebrand

Exploit Brokers is back—under a new banner. In this episode, I explain why the show went quiet, what Forgebound Research means, and how the podcast is evolving. We're shifting to a hybrid model: some ...

12 Tammi 8min

HN59 - Microsoft AI Discovers 20 Zero-Day Vulnerabilities in Bootloaders!

HN59 - Microsoft AI Discovers 20 Zero-Day Vulnerabilities in Bootloaders!

# Title * HN59 - Microsoft AI Discovers 20 Zero-Day Vulnerabilities in Bootloaders! ## Description 🔍 Microsoft's AI Uncovers 20 Zero-Day Threats | CoffeeLoader Malware Gets Smarter In this episode ...

3 Huhti 202519min

Suosittua kategoriassa Politiikka ja uutiset

uutiscast
aikalisa
politiikan-puskaradio
ootsa-kuullut-tasta-2
rss-ootsa-kuullut-tasta
rss-podme-livebox
tervo-halme
otetaan-yhdet
et-sa-noin-voi-sanoo-esittaa
rss-vaalirankkurit-podcast
rss-kaikki-uusiksi
rss-asiastudio
rss-ulkopoditiikkaa
rss-pinnalla
the-ulkopolitist
rss-sinivalkoinen-islam
rss-hyvaa-huomenta-bryssel