SecPod

Learn Search

Search across all Learn content

SecPod Labs

Security Research

In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

Open Google Fixed Actively Exploited Chrome Zero-Day Vulnerability-Patch Now!
Google Fixed Actively Exploited Chrome Zero-Day Vulnerability-Patch Now!

CVE Research

Google Fixed Actively Exploited Chrome Zero-Day Vulnerability-Patch Now!

A high-severity zero-day flaw tracked as CVE-2022-0609 in Google Chrome is exploited in attacks. It is finally resolving with the release of Chrome 98.0.4758.102 emergency update for Windows, Mac, and Linux. This is the first zero-day vulnerability Google has patched for Chrome this year, but it pro...

Apr 30, 2026 • 3 min read

Open Apache Guacamole Critical Vulnerabilities Put Remote Desktops at Risk
Apache Guacamole Critical Vulnerabilities Put Remote Desktops at Risk

CVE Research

Apache Guacamole Critical Vulnerabilities Put Remote Desktops at Risk

Security researchers at Check Point have uncovered multiple critical reverse RDP vulnerabilities in the Apache Guacamole. Apache Guacamole is a clientless remote desktop gateway. It supports standard protocols like VNC, RDP, and SSH, together with MFA (Multi-Factor Authentication), compliance checks...

Apr 30, 2026 • 4 min read

Open Critical Alert: Spring Core(SpringShell) Remote Code Execution Vulnerability Exploited In The Wild
Critical Alert: Spring Core(SpringShell) Remote Code Execution Vulnerability Exploited In The Wild

CVE Research

Critical Alert: Spring Core(SpringShell) Remote Code Execution Vulnerability Exploited In The Wild

The Spring Framework is an application framework and inversion of the control container for the Java platform developed by VMware. Detected vulnerability with CVE-2022-22965 affects Spring Core and allows an attacker to send a specially crafted HTTP request to bypass protections in the library’s HTT...

Apr 30, 2026 • 4 min read

Open Why Addressing Vulnerabilities Is A Challenging Process For An IT Security Team
Why Addressing Vulnerabilities Is A Challenging Process For An IT Security Team

CVE Research

Why Addressing Vulnerabilities Is A Challenging Process For An IT Security Team

As the IT infrastructure and the business data becomes more complex, security concerns in businesses increase drastically. According to the National Vulnerabilities Database, the number of Common Vulnerabilities and Exploit in a network has tripled since 2016. As a result, cybercriminals are taking ...

Apr 30, 2026 • 6 min read

Open Microsoft May 2022 Patch Tuesday Addresses 75 Vulnerabilities Including 3 Zero-Days
Microsoft May 2022 Patch Tuesday Addresses 75 Vulnerabilities Including 3 Zero-Days

CVE Research

Microsoft May 2022 Patch Tuesday Addresses 75 Vulnerabilities Including 3 Zero-Days

Microsoft May 2022 Patch Tuesday has released security updates addressing a total of 75 detected vulnerabilities. On the other hand, 8 are classified as critical, 66 as important, and 1 as low severity. Microsoft may 2022 patch Tuesday products covered in the May security update include Remote Deskt...

Apr 30, 2026 • 5 min read

Open OpenBSD Authentication Bypass and Local Privilege Escalation Vulnerabilities
OpenBSD Authentication Bypass and Local Privilege Escalation Vulnerabilities

CVE Research

OpenBSD Authentication Bypass and Local Privilege Escalation Vulnerabilities

Apr 30, 2026 • 5 min read

Open Apache Wicket: Defeating Encrypted And Stateful URLs
Apache Wicket: Defeating Encrypted And Stateful URLs

CVE Research

Apache Wicket: Defeating Encrypted And Stateful URLs

Apache Wicket is an open-source, server-side, Java web application framework and used by quite a few big sites. It is discovered that the ‘encrypted url feature‘ is expected to protect from CSRF (Cross-Site Request Forgery) attacks, but it fails to provide enough protection against CSRF attacks Apac...

Apr 30, 2026 • 4 min read

Open Log4Shell-Critical Remote Code Execution Vulnerability in H2database Console
Log4Shell-Critical Remote Code Execution Vulnerability in H2database Console

CVE Research

Log4Shell-Critical Remote Code Execution Vulnerability in H2database Console

JFrog has recently disclosed a remote code execution vulnerability on H2 Database consoles. This is based on a Java Naming and Directory Interface(JNDI) vulnerability, and its root cause is similar to the recent Log4Shell vulnerability in Apache Log4j. H2 is an open-source RDBMS  in Java that offers...

Apr 30, 2026 • 4 min read

Open Apple’s March 2023 Updates Addresses Multiple Security Vulnerabilities!
Apple’s March 2023 Updates Addresses Multiple Security Vulnerabilities!

CVE Research

Apple’s March 2023 Updates Addresses Multiple Security Vulnerabilities!

Apple’s March 2023 Updates released multiple security updates in-order to patch various Apple products affected by multiple vulnerabilities. A total of 126 vulnerabilities were fixed in six of its products on March 27th. An attacker who successfully exploits these flaws could compromise the affected...

Apr 30, 2026 • 5 min read