SecPod

Learn Search

Search across all Learn content

SecPod Labs

Security Research

In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

Featured Article

Open Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF
Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE Research

Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE-2026-19478 is a critical code injection vulnerability in GitLab CE/EE that allows an unauthenticated attacker to modify or delete public projects and user data by abusing a GraphQL directive. A second high-severity issue, CVE-2026-19650, involves cross-site request forgery in the GraphQL multiplex query handler. This article examines how the critical vulnerability works, the availability of a public proof-of-concept, the potential impact on self-managed instances, the affected versions, and the security updates released to remediate both issues.

Aug 19, 2026

Open No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners
No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

CVE Research

No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

Aug 19, 2026

Open Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies
Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

CVE Research

Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

Aug 19, 2026

Open Inside the GeoServer Zero-Day: From jsonArrayContains to Potential RCE
Inside the GeoServer Zero-Day: From jsonArrayContains to Potential RCE

CVE Research

Inside the GeoServer Zero-Day: From jsonArrayContains to Potential RCE

Aug 17, 2026 • 5 min read

Open CVE-2026-62832: Microsoft Patches "LegacyHive" Windows Zero-Day
CVE-2026-62832: Microsoft Patches "LegacyHive" Windows Zero-Day

CVE Research

CVE-2026-62832: Microsoft Patches "LegacyHive" Windows Zero-Day

Aug 14, 2026

Open From PoC to Payload: CVE-2026-55040 SharePoint Auth Bypass Sees Rapid Exploitation
From PoC to Payload: CVE-2026-55040 SharePoint Auth Bypass Sees Rapid Exploitation

CVE Research

From PoC to Payload: CVE-2026-55040 SharePoint Auth Bypass Sees Rapid Exploitation

Aug 14, 2026

Open Inside Operation Dream Job: Lazarus Group Weaponizes a Windows Zero-Day
Inside Operation Dream Job: Lazarus Group Weaponizes a Windows Zero-Day

CVE Research

Inside Operation Dream Job: Lazarus Group Weaponizes a Windows Zero-Day

Aug 14, 2026

Open Gunra Ransomware Exploits Fortinet Auth Bypass Flaws in Global Double Extortion Campaign
Gunra Ransomware Exploits Fortinet Auth Bypass Flaws in Global Double Extortion Campaign

CVE Research

Gunra Ransomware Exploits Fortinet Auth Bypass Flaws in Global Double Extortion Campaign

Gunra, a Conti-derived ransomware-as-a-service group, breaches networks by exploiting Fortinet authentication bypass flaws CVE-2024-55591 and CVE-2025-24472, then exfiltrates data and deploys ChaCha20/RSA-4096 encryption in a double extortion scheme.

Aug 12, 2026