Cisco disclosed two CVSS 10.0 vulnerabilities in their Secure Firewall Management Center — the system that manages your entire firewall fleet — exploitable by an unauthenticated attacker with a single HTTP request. HN65 covers that plus a nation-state group mass-producing AI-generated malware, Google largest Android security update in eight years (129 CVEs, one zero-day), Chinese […]
Blog
Cisco and Dell CVSS 10.0 Exploited for YEARS, Claude AI Jailbroken, ScarCruft Jumps Air Gaps | HN 64
How long can a threat actor live inside your network before anyone notices? In the case of Cisco SD-WAN, the answer was two and a half years. HN64 covers two separate CVSS 10.0 vulnerabilities, a jailbroken AI chatbot used to steal 195 million government records, North Korean hackers jumping air-gapped networks via USB and Ruby, […]
600 Firewalls Breached by AI in 5 Weeks, Chrome Zero-Day, CVSS 9.9 RCE and AI-Powered Malware | HN 63
AI is now a weapon on both sides of the security battlefield. HN63 covers the first actively exploited Chrome zero-day of 2026, a CVSS 9.9 in Microsoft AI SDK, hijacked npm packages deploying autonomous agents on developer machines, Android malware using Google Gemini in real time to evade detection, and a Russian-speaking threat actor who […]
6 Zero-Days Exploited NOW, Lazarus Poisons npm, AI-Generated Malware and More | HN 62
Microsoft dropped patches for six actively exploited zero-day vulnerabilities in a single Patch Tuesday — the attackers had keys before the locksmith could change the locks. HN62 covers that plus Lazarus Group poisoning npm packages via fake job postings, nation-state actors weaponizing Google AI, a 6-million-person telecom breach in the Netherlands, and a government contract […]
State Hackers Hit 37 Countries, BeyondTrust CVSS 9.9 RCE, Signal Hijacked and More | HN 61
A state-backed espionage group infiltrated government networks across 37 countries in a single year while scanning infrastructure in 155 more — one in five nations on Earth. That is the lead story in HN61, joined by a CVSS 9.9 RCE in BeyondTrust, Signal accounts hijacked without malware, CISA pulling the plug on aging edge devices, […]
HN60: Microsoft Office Zero-Day, WordPress CVSS 10.0, Chrome Extensions Stealing AI Chats, and More
Welcome to 2026, and welcome back to Exploit Brokers by Forgebound Research. In this packed episode, we’re covering five major cybersecurity stories — any one of which could have been its own episode. From Microsoft’s emergency patch to security professionals turning to the dark side, let’s dive in.





