Cisco & Dell CVSS 10.0 Exploited for YEARS, Claude AI Jailbroken, ScarCruft Jumps Air Gaps | HN64

MAR 12, 202628 MIN
Exploit Brokers By Forgebound Research - Tech and Hacking News Commentary

Cisco & Dell CVSS 10.0 Exploited for YEARS, Claude AI Jailbroken, ScarCruft Jumps Air Gaps | HN64

MAR 12, 202628 MIN

Description

Two perfect CVSS 10.0 scores in one news cycle. A state-sponsored actor living inside Cisco's SD-WAN platform since 2023. A brand-new lateral movement technique called "Ghost NICs" that leaves no forensic trace. An AI chatbot jailbroken to steal 195 million government records. A North Korean hacking group bridging air-gapped networks with USB drives and an embedded Ruby runtime. And a phishing platform so sophisticated it makes your multi-factor authentication functionally useless. This is Hacking News Episode 64 from Exploit Brokers by Forgebound Research. Five stories, multiple nation-state actors, and some genuinely novel attack techniques. Let's get into it. πŸ• TIMESTAMPS 0:00 β€” Cold Open 1:12 β€” Welcome & CTA 1:55 β€” Story 1: Cisco SD-WAN Zero-Day (CVE-2026-20127, CVSS 10.0) β€” Five Eyes Response 6:55 β€” Story 2: Dell RecoverPoint Zero-Day (CVE-2026-22769, CVSS 10.0) β€” Ghost NICs 11:35 β€” Story 3: Claude AI Jailbreak β€” 195 Million Mexican Government Records 15:27 β€” Story 4: ScarCruft Air-Gap Bridging β€” "Ruby Jumper" Campaign 19:55 β€” Story 5: Starkiller Phishing-as-a-Service β€” MFA Bypass 25:02 β€” Recap & 5 Key Takeaways 27:28 β€” Outro πŸ“š SOURCES Story 1 β€” Cisco SD-WAN: Cisco Advisory cisco-sa-sdwan-rpa-EHchtZk β€” https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk CISA Emergency Directive 26-03 β€” https://www.cisa.gov/emergency-directive-26-03 ASD-ACSC Hunt Guide β€” https://www.cyber.gov.au/ BleepingComputer β€” https://www.bleepingcomputer.com/ The Hacker News β€” https://thehackernews.com/ Dark Reading β€” https://www.darkreading.com/ SecurityWeek β€” https://www.securityweek.com/ Story 2 β€” Dell RecoverPoint: Google Cloud / Mandiant GTIG Report β€” https://cloud.google.com/blog/topics/threat-intelligence/ Dell Security Advisory DSA-2026-079 β€” https://www.dell.com/support/kbdoc/en-us/000426742/ CISA Known Exploited Vulnerabilities Catalog β€” https://www.cisa.gov/known-exploited-vulnerabilities-catalog The Hacker News β€” https://thehackernews.com/ SecurityWeek β€” https://www.securityweek.com/ CyberScoop β€” https://cyberscoop.com/ Story 3 β€” Claude AI Jailbreak: Bloomberg (Feb 25, 2026) β€” https://www.bloomberg.com/ VentureBeat β€” https://venturebeat.com/ Gambit Security Research β€” https://gambitsecurity.com/ Story 4 β€” ScarCruft Ruby Jumper: Zscaler ThreatLabz Report (Feb 27) β€” https://www.zscaler.com/blogs/security-research/ The Hacker News β€” https://thehackernews.com/ BleepingComputer β€” https://www.bleepingcomputer.com/ Story 5 β€” Starkiller PhaaS: Krebs on Security β€” https://krebsonsecurity.com/ Abnormal AI Technical Analysis β€” https://abnormalsecurity.com/blog/ Dark Reading β€” https://www.darkreading.com/ Infosecurity Magazine β€” https://www.infosecurity-magazine.com/ ⚠️ DISCLAIMER The content presented by Exploit Brokers by Forgebound Research is for educational and informational purposes only. Cipherceval is a cybersecurity educator and commentator β€” not your personal security consultant, legal counsel, or professional advisor. The information shared here reflects publicly available research, industry reporting, and the host's personal perspective. It does not constitute professional security consulting or individualized guidance for your specific environment. Always consult with qualified professionals for decisions affecting your systems and security posture. πŸ”” Subscribe for weekly cybersecurity news and analysis. πŸ‘ Like if this episode was helpful. πŸ”— Share with your team β€” awareness is the first line of defense. #cybersecurity #hackernews #exploitbrokers #cipherceval #infosec #cisco #sdwan #cve #zerodday #ghostnics #dell #recoverpoint #claudeai #jailbreak #scarcruft #northkorea #airgap #starkiller #phishing #mfa #fido2 #passkeys #fiveeyes #cisa #threatintelligence #apisecurity #cyberthreat #nationstatehacking #databreach