SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

CVE Research
Google Chrome Zero-Day Under Active Exploitation
Google has released a security advisory for its Chrome users on Windows, Mac, and Linux, addressing 47 security vulnerabilities. This release includes one very critical Zero-Day exploit exploited in the wild. This vulnerability tracked as CVE-2021-21166. However, Endpoints that have not been patched...

CVE Research
Microsoft December 2021 Patch Tuesday Addresses 67 Vulnerabilities Including a Zero-Day Being Actively Exploited
Microsoft has released December 2021 Patch Tuesday security updates with a total of 67 Vulnerabilities, including a zero-day being actively exploited. Detected by a vulnerability scanning tool, The products covered in December’s security update include Microsoft Edge, Azure, Microsoft Windows, Micr...

CVE Research
Another Zero-Day in Google Chrome Under Active Exploitation
Google has released a second emergency update for its Chrome Browser this month. Chrome version 89.0.4389.90 for Windows, Mac, and Linux fix five security bugs, one of which is an actively exploited zero-day issue (identified by CVE-2021-21193) which is a Use after free in Chrome’s Blink rendering e...

CVE Research
Microsoft June 2021 Patch Tuesday Addresses 50 CVEs Including Six Zero-Days
Microsoft has released June Patch Tuesday, security updates with a total of 50 vulnerabilities in the family of Windows and Mac operating systems and related products. In the release by Microsoft, 5 were rated as Critical and 45 as Important. The products covered in June’s security update include Mi...

CVE Research
Scan Vulnerabilities In Less Than 5 Minutes! Faster Than Your Coffee Brews.
Who doesn’t love the smell of freshly brewed coffee? There is no better aroma that keeps me up than the smell of freshly brewed coffee. After pondering over my day-to-day tasks, a cup of coffee brings my sanity back and keeps my energy up. This 5-minute brewing time allows me to catch up with my col...
FREAK Attack?
CVE Research
FREAK Attack?
Another potentially dangerous vulnerability called FREAK (Factoring Attack on RSA-EXPORT Keys) is being true to its name and is freaking out all Android and Apple device users. This SSL/TLS vulnerability has over the years exposed millions of Android and Apple devices to attacks when they visit supp...

CVE Research
Cisco IOS XR Zero Day Vulnerabilities Being Actively Exploited in the Wild
The high severity zero-day vulnerabilities found in Cisco IOS XR – An Internetwork Operating System (IOS) that shipped with Cisco’s networking equipment. The vulnerabilities allow an unauthenticated, remote attacker to exhaust process memory. And crash the other processes running on the affected dev...

CVE Research
Are You Sure Uninvited Guests Are Not A Part Of Your Online Meetings?
As the global pandemic, COVID-19 is hitting the world hard, organizations’ workforces are now working from home. No company can easily work without regular meetings, team communications, partner and client calls, webinars, online training, video-conferences etc. Not just corporate organizations, eve...

