SecPod

Learn Search

Search across all Learn content

SecPod Labs

Security Research

In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

Open Metasploit Module – Freefloat FTP Server APPE Command Overflow

Metasploit Module – Freefloat FTP Server APPE Command Overflow

CVE Research

Metasploit Module – Freefloat FTP Server APPE Command Overflow

SecPod Research Team member (Veerendra G.G) wrote Metasploit module for Freefloat FTP Server APPE Command Overflow Vulnerability.

Apr 28, 2026 • 2 min read

Open Microsoft’s October 2021 Patch Tuesday Squashes 4 Zero-days and a Total of 81 Vulnerabilities
Microsoft’s October 2021 Patch Tuesday Squashes 4 Zero-days and a Total of 81 Vulnerabilities

CVE Research

Microsoft’s October 2021 Patch Tuesday Squashes 4 Zero-days and a Total of 81 Vulnerabilities

Microsoft has released October Patch Tuesday security updates with a total of 81 vulnerabilities, which include Four Zero-Days, Three CVEs rated as critical, and 70 rated as important by a vulnerability scanning tool. The products covered in October’s security update include Microsoft Office, Window...

Apr 28, 2026 • 3 min read

Open Pandora Ransomware Hits Toyota’s Automotive Supplier Denso
Pandora Ransomware Hits Toyota’s Automotive Supplier Denso

CVE Research

Pandora Ransomware Hits Toyota’s Automotive Supplier Denso

A Pandora ransomware attack targeted Denso Corp, a supplier of Toyota Motor Corporation. The confirmation came after the Pandora Ransomware group leaked the stolen data and claimed responsibility. However, the attack has not resulted in any disruption in Denso’s operations. This is why it is essenti...

Apr 28, 2026 • 3 min read

Open SonicWall Zero-Day Vulnerability Is Being Exploited in the Wild
SonicWall Zero-Day Vulnerability Is Being Exploited in the Wild

CVE Research

SonicWall Zero-Day Vulnerability Is Being Exploited in the Wild

The Sonicwall Zero day Attack. NCC Group recently reported that an active zero-day SonicWall SMA 100 zero-day vulnerability being exploited in the wild. Sonicwall commented that it affects the SMA 100 series (SMA 200, SMA 210, SMA 400, SMA 410, SMA 500v) line of remote access appliances. However, bo...

Apr 28, 2026 • 3 min read

Open Beware : NXNSAttack on DNS Servers Could Bring Down Major Sections of the Internet
Beware : NXNSAttack on DNS Servers Could Bring Down Major Sections of the Internet

CVE Research

Beware : NXNSAttack on DNS Servers Could Bring Down Major Sections of the Internet

A new vulnerability in the architecture of the global Domain Name System (DNS) was brought to light. By a team of Israeli researchers. The team also published a paper highlighting how this flaw could be leveraged with an attack. Dubbed as NXNSAttack to bring down target websites. A vulnerability man...

Apr 28, 2026 • 3 min read

Open Vulnerability Scanning Software: Inspections of Your Endpoints’ Infections
Vulnerability Scanning Software: Inspections of Your Endpoints’ Infections

CVE Research

Vulnerability Scanning Software: Inspections of Your Endpoints’ Infections

Every security admins’ nightmare is detecting the vulnerabilities lurking within the network. Whether its potentially dangerous malware to hidden backdoor programs with the systems, it is important to discover these vulnerabilities and remediate them using vulnerability management tool. But to carry...

Apr 28, 2026 • 9 min read

Open Google Fixes First Zero-Day Chrome vulnerability of 2024
Google Fixes First Zero-Day Chrome vulnerability of 2024

CVE Research

Google Fixes First Zero-Day Chrome vulnerability of 2024

On January 16, 2024, Google released a security patch to address CVE-2024-0519 an out-of-bound security vulnerability exploited in ongoing attacks . This patch specifically targets and fixes the first zero-day vulnerability discovered in the Chrome browser this year.A remote attacker can take advant...

Apr 28, 2026 • 1 min read

Open Apple’s December 2023 Updates Addresses Multiple Security Vulnerabilities!
Apple’s December 2023 Updates Addresses Multiple Security Vulnerabilities!

CVE Research

Apple’s December 2023 Updates Addresses Multiple Security Vulnerabilities!

Apr 28, 2026 • 3 min read

Open A Critical Vulnerability in vm2 Allows a Remote Attacker to Break Out of the Sandbox!
A Critical Vulnerability in vm2 Allows a Remote Attacker to Break Out of the Sandbox!

CVE Research

A Critical Vulnerability in vm2 Allows a Remote Attacker to Break Out of the Sandbox!

vm2 is a node module for creating a real sandbox in the node. It is also the most widely used Javascript sandbox library, which receives about 17.5 million downloads each month. A critical vulnerability(CVE-2022-36067) in vm2 can enable a remote attacker to escape the sandbox and execute arbitrary c...

Apr 28, 2026 • 3 min read