SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

CVE Research
Multiple Zero-Days in Microsoft Exchange Server Actively Exploited in the Wild
Microsoft has released patches for Exchange Server. The advisory addresses the following vulnerabilities – CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065. Microsoft has also reported that zero-day exploits were being used to attack Microsoft Exchange Server in the wild. Microsoft...

CVE Research
Second Zero-Day Exploit for Google Chrome in the Same Week
Google Chrome users who were relieved by patching the recent zero-day advisory are taken aback by the news of another PoC exploit posted on Twitter by a security researcher, Frust. This affects the recent version of Chrome, 89.0.4389.128, which was the fix for the first zero-day vulnerability of the...

CVE Research
ALERT: phpMyAdmin configured servers vanish with a click!
phpMyAdmin is a free tool millions worldwide use to manage MySQL and MariaDB databases over the web. Joomla, WordPress, etc., are some popular products that use phpMyAdmin. Manuel Garcia Cardenas, a security researcher, discovered a CSRF vulnerability that can meddle with the server configurations i...

CVE Research
Closing the Ever-Widening Gap Between Vulnerability Scanning and Patch Management
Security risk management is a complicated and time-consuming affair. Organizations spend many resources to ensure all their business operations and data are running and stored by risk-free assets. Patch management tools are the most common tools to manage and mitigate risks. You scan, detect and reg...

CVE Research
CVE-2014-1761: Zero-day vulnerability in Microsoft Word
A zero-day vulnerability (CVE-2014-1761) in Microsoft Word is being exploited in the wild, which was discovered by the Google security team. A good vulnerability management software can prevent these attacks.

CVE Research
SanerNow Automated Patch Management Process: Speed-up Patching Cycle!
Being an IT security admin feels like you are the “Mr. Fix-It” of your organization. But we know that IT security admins are so much more than that. Vulnerabilities emerge daily, and spending your time and attention on this recurring task is not the best use of your time. You can better serve to put...

CVE Research
Chrome Zero-Day Under Active Exploitation – Patch Now
We all know the popularity and extensive audience of the Google Chrome browser, which can be used on Windows, Mac, or Linux computers and Android devices. To those currently using the same and who have not yet deployed the patch, it’s time to update their Chrome browsers to the latest version, 86.0....


