SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

CVE Research
SMBLoris – An SMB DoS Vulnerability
SMBLoris is a remote, unauthenticated application-level denial of service (DoS) attack against Microsoft Windows operating systems. A vulnerability of this kind can be tracked using an appropriate vulnerability management tool. The Server Message Block (SMB) network protocol implementation causes it...

CVE Research
The Ultimate Patch Management Checklist to Evaluate the Success of Your Patching Program!
Vulnerabilities are growing exponentially, and it strains IT security admins to remediate them and protect the organization from cyberattacks. Patch management is a daunting and time-consuming task, yet the impact of not patching is devastating! According to a study, 57% of data breaches are attribu...

CVE Research
The Vulnerability Management Dashboard Every CISO Needs!
Vulnerability scans show a large volume of vulnerability data which could be unstructured and complex to analyze. Bulky, hard-to-read data creates chaos during the rating and delays the remediation process. A well-structured, neatly organized vulnerability management dashboard will help CISOs, and t...

CVE Research
Understanding EPSS, a step towards Vulnerability Prioritization
There are too many vulnerabilities. Past research shows firms are able to fix 5%-20% of known vulnerabilities in a month. Moreover, a small subset of vulnerabilities (2%-7%) are seen to be exploited in the wild.

CVE Research
Google Chrome Under Active Exploitation With Two Zero-Days!
Google has released a security advisory for its Chrome users on Windows, Mac, and Linux, addressing two very critical Zero-Day exploits exploited in the wild. These google chrome security vulnerabilities tracked as CVE-2020-16013 and CVE-2020-16017. Endpoints not been patched are advised to deploy p...

CVE Research
Cisco Read-Only Path Traversal Vulnerability (CVE-2020-3452)
Cisco has released a Security Advisory for the actively exploited worldwide CVE-2020-3452. Cisco Read-Only Path Traversal Vulnerability in the web services interface of Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attac...



