After a hiatus, Cipherceval is back — and the channel has a new name: Forgebound Research. In this episode, he explains the rebrand, what’s staying the same, and what’s coming next. Why the Rebrand? The name Exploit Brokers isn’t going away entirely — it’s now officially Exploit Brokers by Forgebound Research. The new name comes […]
Blog
Microsoft AI Discovers 20 Zero-Day Vulnerabilities in Bootloaders | HN 59
Microsoft Security Copilot discovered 20 previously unknown zero-day vulnerabilities in the open-source bootloaders GRUB2 and U-Boot — the software that runs before your operating system even loads. HN59 covers that plus CoffeeLoader, a next-generation malware loader evolving from SmokeLoader with evasion tricks researchers had not documented before. Stories Covered Microsoft AI Finds 20 Zero-Days in […]
Havoc in the Cloud: The Shocking ClickFix Exploit Revealed | HN 58
A new ClickFix phishing campaign is abusing Microsoft SharePoint to deliver the Havoc post-exploitation framework — hiding command-and-control traffic inside legitimate cloud API calls so it blends with normal corporate traffic. HN58 also covers the UAE financial sector’s ransomware surge, where 19 threat groups are actively targeting banks and the exposed attack surface jumped from […]
Unmasking SpyLoan: The Android Malware Preying on Loan Seekers | HN 57
An Android app called Finance Simplified reached 100,000 downloads on Google Play while secretly operating as a predatory loan shark — harvesting contacts, location data every 3 seconds, SMS messages, and clipboard contents, then using that data to harass and blackmail victims who could not repay. HN57 also covers two patched Xerox printer vulnerabilities that […]
Massive Bug Puts Outlook Users at Risk | Kimsuky Gets RDPWrapper | HN 56
A critical remote code execution bug in Microsoft Outlook — CVE-2024-21413, dubbed “Moniker Link” — is actively being exploited in the wild, bypassing Outlook’s protected-view restrictions through a file:// URI trick to steal NTLM credentials and execute arbitrary code. HN56 also covers Kimsuky, the North Korean APT, swapping their noisy PebbleDash backdoor for a custom […]
Double Zipping Danger: The 7-Zip Exploit That Could Hack Your PC | HN 55
A Russian cybercrime group exploited CVE-2025-0411 in 7-Zip — a zero-day at the time — to bypass Windows’ Mark of the Web protections by nesting archives inside archives, slipping SmokeLoader past Windows security prompts and into Ukrainian government systems. HN55 also covers a malicious Go package that typosquatted the legitimate BoltDB library, exploited Go’s indefinite […]





