SecPod

Blog Posts

Megalodon Supply Chain Attack Compromises 5,500+ GitHub Repositories Through Malicious CI/CD Workflows

Read more →

CVE-2026-41940: The Complete Guide to the cPanel & WHM Authentication Bypass, Attack Chain, Detection, and Remediation

Read more →

CVE-2026-41940 - Critical cPanel Vulnerability Exploited in Mr_Rot13 Backdoor campaign

Read more →

CVE-2026-41940 Attacks, Examples, and Real-World Incidents

Read more →

Vulnerability backlog is not just a remediation problem

Read more →

Breaking Down the FortiClient Breach: CVE-2026-35616 and the Rise of EKZ Infostealer

Read more →

Three Zero-Days, 206 Flaws Fixed: Microsoft Delivers Record-Breaking June 2026 Patch Tuesday

The second Tuesday of June 2026 marked Microsoft's largest Patch Tuesday release on record, delivering security updates for a massive range of vulnerabilities affecting Windows, Microsoft Office, Azure, Exchange, Hyper-V, Active Directory, Remote Desktop, BitLocker, and numerous core operating system components.

Read more →

Two Actors, One Flaw: Gamaredon and UAC-0226 Leverage Delayed WinRAR Patching

Two Russia-aligned threat groups, Gamaredon and UAC-0226, are actively exploiting CVE-2025-8088, a high-severity WinRAR path traversal vulnerability, against Ukrainian government, military, and critical infrastructure organizations. Nearly a year after a patch was made available, both groups continued to operate unimpeded.

Read more →

Tracking Gafgyt C0XMO: How a New Malware Variant Spreads Across Platforms

A newly identified Gafgyt botnet variant, C0XMO, is actively targeting internet-exposed devices through a combination of vulnerability exploitation, weak-credential attacks, and automated lateral movement. Unlike traditional Gafgyt campaigns, C0XMO separates its propagation logic into a dedicated Python-based scanner, enabling it to compromise a wider range of architectures and device types while scaling infections more efficiently.

Read more →

CVE-2026-41089: Public PoC, Active Exploit Analysis, and Windows Netlogon Risk

Read more →

CVE-2026-41089: Windows Netlogon RCE - One-Packet CLDAP Attack, LSASS Crash, and Active Directory Risk

Read more →

CVE-2026-41089: Windows Netlogon Patch, IOCs, Detection, and Mitigation Guide

Read more →

HTTP/2 Bomb: How an AI Chained Two Decade-Old Techniques Into a Devastating Remote DoS

Cybersecurity researchers have discovered a remote denial-of-service exploit that affects major web servers, including NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora. The vulnerability has been codenamed HTTP/2 Bomb.

Read more →

CVE-2026-41089: MITRE ATT&CK Mapping, SIEM Queries, and Domain Controller Hardening

Read more →

Qilin Ransomware and CVE-2026-50751: How Threat Actors Weaponized Check Point VPN Infrastructure

Read more →

I Asked AI to Break Into My Lab Server. It Changed How I Think About Security.

Read more →

Why Enterprise IT Security Teams Need a Unified CNAPP Approach

Read more →

How CVEM can transform enterprise security posture

Read more →

Key mistakes in endpoint and cloud exposure management

Read more →

Breaking Down CVE-2026-25089: Unauthenticated Command Injection in FortiSandbox, FortiSandbox Cloud & FortiSandbox PaaS

Read more →

AI Assisted CTF: Same Systems. Two Scans. Before and After Saner

What changed when AI tested the lab before and after Saner reduced the usable attack surface

Read more →

Why Risk Remediation Is Critical to Attack Surface Reduction

Read more →

Compliance-driven security or risk-based security

Read more →

How to Prioritize Remediation at Scale: Fixing What Matters First

Learn how to prioritize remediation at scale by fixing reachable, exploitable, and business-critical risks first instead of relying on CVSS alone.

Read more →

1,500 Devices and Growing: Meet the JDY Botnet

Read more →