Exploit Brokers is a cybersecurity podcast from Forgebound Research covering the week’s biggest hacking news, data breaches, malware campaigns, and vulnerability disclosures — with the technical depth that practitioners actually want. No vendor marketing. No surface-level recaps. Just clear analysis of what happened, how it worked, and what it means.
What We Cover
Every episode breaks down real-world cybersecurity incidents and the tools and techniques behind them. Whether you’re a working practitioner, a student breaking into the field, or just someone who wants to understand the threat landscape, Exploit Brokers gives you the context to follow along.
- Weekly hacking news breakdowns
- Zero-day and CVE coverage with technical context
- Malware analysis and attack chain walkthroughs
- Threat actor tracking and attribution
- Hacking tutorials and security tool deep dives
Your Host
Exploit Brokers is hosted by Lauro, a cybersecurity practitioner and founder of Forgebound Research. Each episode is researched and delivered with the goal of making complex security topics accessible — without dumbing them down. The show has covered everything from nation-state APT campaigns to beginner-friendly hacking tutorials since 2019.
Listen & Subscribe
New episodes drop weekly. Subscribe on your platform of choice so you never miss a release:
Recent Episodes
Dual CVSS 10.0 Cisco Flaws, AI Malware Assembly Line, Qualcomm Zero-Day & More
Cisco disclosed two CVSS 10.0 vulnerabilities in a single week. Qualcomm pushed patches for an actively exploited zero-day. And AI is now being used to generate and deploy malware at industrial scale. Five stories that all point to the same conclusion: the attack surface is expanding faster than defenders can track.
Cisco & Dell CVSS 10.0 Exploited for YEARS, Claude AI Jailbroken, ScarCruft Jumps Air Gaps
Two perfect CVSS 10.0 scores in a single news cycle. A state-sponsored actor living inside Cisco’s SD-WAN platform undetected since 2023. A brand-new lateral movement technique using Claude AI as a recon tool. And ScarCruft deploying a novel Bluetooth exploit to jump air-gapped networks.
600 Firewalls Breached by AI in 5 Weeks — Plus Chrome Zero-Day, CVSS 9.9 RCE & AI-Powered Malware
AI is reshaping both sides of the cybersecurity battlefield. In this episode: the first Chrome zero-day of 2026, an autonomous AI system that compromised 600 firewalls in five weeks, a CVSS 9.9 remote code execution vulnerability, AI-generated malware caught in the wild, and a supply chain attack targeting GitHub Actions at scale.
6 Zero-Days Exploited NOW, Lazarus Poisons npm, AI-Generated Malware & More
Microsoft patched six actively exploited zero-day vulnerabilities in a single Patch Tuesday. North Korea’s Lazarus Group poisoned npm packages to target developers. AI-generated malware was confirmed in active campaigns. And more from the week in cybersecurity.
State Hackers Hit 37 Countries, BeyondTrust CVSS 9.9 RCE, Signal Hijacked & More
A newly uncovered state-backed espionage group compromised 70 organizations across 37 countries in a single year — while actively scanning infrastructure in 93 countries. Plus: a CVSS 9.9 remote code execution flaw in BeyondTrust’s privileged access platform, Signal accounts hijacked via linked devices, and more.
CRITICAL: Office Zero-Day + WordPress Admin Takeover + Chrome Extensions Stealing AI Chats
Microsoft released an emergency patch for an actively exploited Office zero-day. A WordPress plugin earned a perfect CVSS 10.0 score, allowing unauthenticated admin takeover. And malicious Chrome extensions were caught silently exfiltrating AI chat sessions from users’ browsers.