SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

CVE Research
New MOVEit Transfer Vulnerability Under Attack – Urgent Patch Required
A critical security vulnerability in Progress Software’s MOVEit Transfer has been discovered and is known to be under active exploitation. The flaw, identified as CVE-2024-5806, has a CVSS score of 9.1 and involves an authentication bypass affecting several versions of MOVEit Transfer.

CVE Research
Critical Flaw in Cisco Smart Software Manager Allows Attackers to Control the Device
A critical vulnerability in the Cisco Smart Software Manager On-Prem (SSM On-prem) authentication system that allowed unauthenticated, remote attackers to change the password of any user, including that of administrators, has been fixed.

CVE Research
What are Security Controls? Everything You Need to Know
What were the biggest culprits and causes of cyberattacks in the past few years? CVE or software vulnerabilities are the usual suspects, but other security risks being exploited are on the rise and vulnerability management tools are struggling to keep up. It is a trend you must be observing too. The...

CVE Research
The Perks of Vulnerability Management Automation
When you repeatedly perform the same thing over and over again, it becomes tedious and laborious. Lengthy scans, correlation of vulnerabilities and patches, deploying the required patches throughout multiple devices, and finally doing it again add to the frustration and exhaustion. But now, in the m...

CVE Research
What’s the Best Vulnerability Remediation Prioritization Method?
You initiate vulnerability scanning in your network, and the scanner spits out an excel sheet with rows and rows of vulnerabilities that never seem to end. You have a colossal task ahead. The task of fixing the detected vulnerabilities identified by vulnerability scanning can be simplified with a vu...

CVE Research
Microsoft’s April 2024 Patch Tuesday: A Record-Breaking Month for Security Fixes
Microsoft’s April 2024 Patch Tuesday wasn’t your average update day. While a record number of vulnerabilities were addressed (149), a unique aspect emerged – three critical vulnerabilities resided within a single product: Microsoft Defender for IoT. This blog post dives into these critical defenders...



