SecPod

Learn Search

Search across all Learn content

SecPod Labs

Security Research

In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

Open Billions of Linux and Windows Systems at Risk due to Critical GRUB2 Vulnerabilities
Billions of Linux and Windows Systems at Risk due to Critical GRUB2 Vulnerabilities

CVE Research

Billions of Linux and Windows Systems at Risk due to Critical GRUB2 Vulnerabilities

A team of cybersecurity researchers found multiple vulnerabilities that affect billions of devices that run on either Windows or Linux. Affected devices include laptops, servers, workstations, or even IoT devices. Boot hole vulnerabilities affect Linux and other Operating Systems using GRUB@ boot lo...

Apr 30, 2026 • 4 min read

Open F5 BIG-IP Devices Under Active Exploitation (CVE-2020-5902)
F5 BIG-IP Devices Under Active Exploitation (CVE-2020-5902)

CVE Research

F5 BIG-IP Devices Under Active Exploitation (CVE-2020-5902)

F5 BIG-IP is a multi-purpose networking device manufactured by F5 Networks which can be configured to work as a traffic shaping system, firewall, load balancer, access gateway, rate limiter, or SSL middleware. F5 BIG-IP devices are one of the most popular networking products and are widely used in g...

Apr 30, 2026 • 3 min read

Open QNAP Addresses Two Critical Vulnerabilities in QTS Operating System and Applications.
QNAP Addresses Two Critical Vulnerabilities in QTS Operating System and Applications.

CVE Research

QNAP Addresses Two Critical Vulnerabilities in QTS Operating System and Applications.

QNAP Systems has promptly resolved two critical vulnerabilities, CVE-2023-23368 and CVE-2023-23369, which involved command injection. They were discovered within the QTS operating system and associated applications used on their network-attached storage (NAS) devices. These vulnerabilities could hav...

Apr 30, 2026 • 3 min read

Open An Information Security Admin’s Nightmare
An Information Security Admin’s Nightmare

CVE Research

An Information Security Admin’s Nightmare

‘To patch or not to patch’ is the perplexing dilemma that every security admin goes through almost every day. Patching and applying security patches is the fundamental aspect of increasing an organization’s resilience from malware, ransomware attacks enacted by hackers. To a non-security professiona...

Apr 30, 2026 • 6 min read

Open ALERT: Apple Emergency Update (CVE-2019-8605)
ALERT: Apple Emergency Update (CVE-2019-8605)

CVE Research

ALERT: Apple Emergency Update (CVE-2019-8605)

Apr 30, 2026 • 2 min read

Open The Vital Role of a Vulnerability Database in Your Vulnerability Management Program
The Vital Role of a Vulnerability Database in Your Vulnerability Management Program

CVE Research

The Vital Role of a Vulnerability Database in Your Vulnerability Management Program

Attackers are continuously looking for new vulnerabilities to take advantage of. They easily exploit the ones that are not remediated and the ones that are still prevalent among the endpoints. At the same time, we come across various tools and strategies to execute Vulnerability Management. Therefor...

Apr 30, 2026 • 5 min read

Open Tens of Thousands of vBulletin Forums Wildly Being Exploited (CVE-2019-16759)
Tens of Thousands of vBulletin Forums Wildly Being Exploited (CVE-2019-16759)

CVE Research

Tens of Thousands of vBulletin Forums Wildly Being Exploited (CVE-2019-16759)

Apr 30, 2026 • 3 min read

Open ALERT: iTerm2 Critical Remote Code Execution Vulnerability
ALERT: iTerm2 Critical Remote Code Execution Vulnerability

CVE Research

ALERT: iTerm2 Critical Remote Code Execution Vulnerability

.

Apr 30, 2026 • 2 min read

Open The elevation of Privilege Vulnerabilities affects Windows and Linux.
The elevation of Privilege Vulnerabilities affects Windows and Linux.

CVE Research

The elevation of Privilege Vulnerabilities affects Windows and Linux.

There are two new vulnerabilities that were discovered on Tuesday, which affect Windows and Linux machines. An easily exploitable privilege escalation vulnerability has been identified in Windows 10 build 1809 and above, and its name is SeriousSAM, aka HiveNightmare. SeriousSAM allows a local non-ad...

Apr 30, 2026 • 4 min read