
← Exploit Brokers By Forgebound Research - Tech and Hacking News Commentary26. März · 23 Min.
Dual CVSS 10.0 Cisco Flaws, AI Malware Assembly Line, Qualcomm Zero-Day & More | HN65
This week on Hacking News, we're covering five stories that all share one theme: the things we trust most are the things being targeted.
Cisco disclosed two CVSS 10.0 vulnerabilities in their Secure Firewall Management Center — the centralized brain that manages entire firewall fleets — giving unauthenticated attackers root access. Pakistan-linked APT36 has turned AI coding tools into a malware assembly line, flooding Indian government networks with disposable "vibeware" variants in a strategy Bitdefender calls "Distributed Denial of Detection." Google dropped the largest Android security update in almost eight years — 129 vulnerabilities — including a Qualcomm zero-day already under targeted exploitation across 234 chipsets. A China-linked threat cluster called UAT-9244 is burrowing into South American telecom infrastructure with three brand-new malware families spanning Windows, Linux, and edge devices. And LexisNexis confirmed a cloud breach after a threat actor exploited an unpatched React app and found the database password was... Lexis1234. ⏱️ Timestamps
0:00 — Cold Open: What do you call a hackable firewall manager?
1:21 — Welcome & CTA
2:01 — Story 1: Cisco Secure FMC — Two CVSS 10.0 Vulnerabilities (CVE-2026-20079 & CVE-2026-20131)
5:33 — Story 2: APT36 "Vibeware" — AI-Generated Malware at Industrial Scale
9:13 — Story 3: Google Android March 2026 — 129 Patches + Qualcomm Zero-Day (CVE-2026-21385)
12:34 — Story 4: UAT-9244 / FamousSparrow — China-Linked APT Hits South American Telecoms
16:26 — Story 5: LexisNexis Cloud Breach — React2Shell, Weak Passwords, Gov Data
20:14 — Recap & Key Takeaways
22:40 — Outro
🔑 Key Takeaways