SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

CVE Research
Billions of Linux and Windows Systems at Risk due to Critical GRUB2 Vulnerabilities
A team of cybersecurity researchers found multiple vulnerabilities that affect billions of devices that run on either Windows or Linux. Affected devices include laptops, servers, workstations, or even IoT devices. Boot hole vulnerabilities affect Linux and other Operating Systems using GRUB@ boot lo...

CVE Research
F5 BIG-IP Devices Under Active Exploitation (CVE-2020-5902)
F5 BIG-IP is a multi-purpose networking device manufactured by F5 Networks which can be configured to work as a traffic shaping system, firewall, load balancer, access gateway, rate limiter, or SSL middleware. F5 BIG-IP devices are one of the most popular networking products and are widely used in g...

CVE Research
QNAP Addresses Two Critical Vulnerabilities in QTS Operating System and Applications.
QNAP Systems has promptly resolved two critical vulnerabilities, CVE-2023-23368 and CVE-2023-23369, which involved command injection. They were discovered within the QTS operating system and associated applications used on their network-attached storage (NAS) devices. These vulnerabilities could hav...

CVE Research
An Information Security Admin’s Nightmare
‘To patch or not to patch’ is the perplexing dilemma that every security admin goes through almost every day. Patching and applying security patches is the fundamental aspect of increasing an organization’s resilience from malware, ransomware attacks enacted by hackers. To a non-security professiona...

CVE Research
The Vital Role of a Vulnerability Database in Your Vulnerability Management Program
Attackers are continuously looking for new vulnerabilities to take advantage of. They easily exploit the ones that are not remediated and the ones that are still prevalent among the endpoints. At the same time, we come across various tools and strategies to execute Vulnerability Management. Therefor...

CVE Research
The elevation of Privilege Vulnerabilities affects Windows and Linux.
There are two new vulnerabilities that were discovered on Tuesday, which affect Windows and Linux machines. An easily exploitable privilege escalation vulnerability has been identified in Windows 10 build 1809 and above, and its name is SeriousSAM, aka HiveNightmare. SeriousSAM allows a local non-ad...



