SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.
Featured Article

CVE Research
Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF
CVE-2026-19478 is a critical code injection vulnerability in GitLab CE/EE that allows an unauthenticated attacker to modify or delete public projects and user data by abusing a GraphQL directive. A second high-severity issue, CVE-2026-19650, involves cross-site request forgery in the GraphQL multiplex query handler. This article examines how the critical vulnerability works, the availability of a public proof-of-concept, the potential impact on self-managed instances, the affected versions, and the security updates released to remediate both issues.

CVE Research
Gunra Ransomware Exploits Fortinet Auth Bypass Flaws in Global Double Extortion Campaign
Gunra, a Conti-derived ransomware-as-a-service group, breaches networks by exploiting Fortinet authentication bypass flaws CVE-2024-55591 and CVE-2025-24472, then exfiltrates data and deploys ChaCha20/RSA-4096 encryption in a double extortion scheme.







