SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

CVE Research
Google Fixed Actively Exploited Chrome Zero-Day Vulnerability-Patch Now!
A high-severity zero-day flaw tracked as CVE-2022-0609 in Google Chrome is exploited in attacks. It is finally resolving with the release of Chrome 98.0.4758.102 emergency update for Windows, Mac, and Linux. This is the first zero-day vulnerability Google has patched for Chrome this year, but it pro...

CVE Research
Apache Guacamole Critical Vulnerabilities Put Remote Desktops at Risk
Security researchers at Check Point have uncovered multiple critical reverse RDP vulnerabilities in the Apache Guacamole. Apache Guacamole is a clientless remote desktop gateway. It supports standard protocols like VNC, RDP, and SSH, together with MFA (Multi-Factor Authentication), compliance checks...

CVE Research
Critical Alert: Spring Core(SpringShell) Remote Code Execution Vulnerability Exploited In The Wild
The Spring Framework is an application framework and inversion of the control container for the Java platform developed by VMware. Detected vulnerability with CVE-2022-22965 affects Spring Core and allows an attacker to send a specially crafted HTTP request to bypass protections in the library’s HTT...

CVE Research
Why Addressing Vulnerabilities Is A Challenging Process For An IT Security Team
As the IT infrastructure and the business data becomes more complex, security concerns in businesses increase drastically. According to the National Vulnerabilities Database, the number of Common Vulnerabilities and Exploit in a network has tripled since 2016. As a result, cybercriminals are taking ...

CVE Research
Microsoft May 2022 Patch Tuesday Addresses 75 Vulnerabilities Including 3 Zero-Days
Microsoft May 2022 Patch Tuesday has released security updates addressing a total of 75 detected vulnerabilities. On the other hand, 8 are classified as critical, 66 as important, and 1 as low severity. Microsoft may 2022 patch Tuesday products covered in the May security update include Remote Deskt...

CVE Research
Apache Wicket: Defeating Encrypted And Stateful URLs
Apache Wicket is an open-source, server-side, Java web application framework and used by quite a few big sites. It is discovered that the ‘encrypted url feature‘ is expected to protect from CSRF (Cross-Site Request Forgery) attacks, but it fails to provide enough protection against CSRF attacks Apac...

CVE Research
Log4Shell-Critical Remote Code Execution Vulnerability in H2database Console
JFrog has recently disclosed a remote code execution vulnerability on H2 Database consoles. This is based on a Java Naming and Directory Interface(JNDI) vulnerability, and its root cause is similar to the recent Log4Shell vulnerability in Apache Log4j. H2 is an open-source RDBMS in Java that offers...

CVE Research
Apple’s March 2023 Updates Addresses Multiple Security Vulnerabilities!
Apple’s March 2023 Updates released multiple security updates in-order to patch various Apple products affected by multiple vulnerabilities. A total of 126 vulnerabilities were fixed in six of its products on March 27th. An attacker who successfully exploits these flaws could compromise the affected...

