SecPod

Learn Search

Search across all Learn content

SecPod Labs

Security Research

In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

Open SMBLoris – An SMB DoS Vulnerability
SMBLoris – An SMB DoS Vulnerability

CVE Research

SMBLoris – An SMB DoS Vulnerability

SMBLoris is a remote, unauthenticated application-level denial of service (DoS) attack against Microsoft Windows operating systems. A vulnerability of this kind can be tracked using an appropriate vulnerability management tool. The Server Message Block (SMB) network protocol implementation causes it...

Apr 30, 2026 • 4 min read

Open Microsoft’s March 22 Patch Tuesday Addresses 92 Security Vulnerabilities Including 3 Zero-days
Microsoft’s March 22 Patch Tuesday Addresses 92 Security Vulnerabilities Including 3 Zero-days

CVE Research

Microsoft’s March 22 Patch Tuesday Addresses 92 Security Vulnerabilities Including 3 Zero-days

Apr 30, 2026 • 3 min read

Open The Ultimate Patch Management Checklist to Evaluate the Success of Your Patching Program!
The Ultimate Patch Management Checklist to Evaluate the Success of Your Patching Program!

CVE Research

The Ultimate Patch Management Checklist to Evaluate the Success of Your Patching Program!

Vulnerabilities are growing exponentially, and it strains IT security admins to remediate them and protect the organization from cyberattacks. Patch management is a daunting and time-consuming task, yet the impact of not patching is devastating! According to a study, 57% of data breaches are attribu...

Apr 30, 2026 • 9 min read

Open The Vulnerability Management Dashboard Every CISO Needs!
The Vulnerability Management Dashboard Every CISO Needs!

CVE Research

The Vulnerability Management Dashboard Every CISO Needs!

Vulnerability scans show a large volume of vulnerability data which could be unstructured and complex to analyze. Bulky, hard-to-read data creates chaos during the rating and delays the remediation process. A well-structured, neatly organized vulnerability management dashboard will help CISOs, and t...

Apr 30, 2026 • 6 min read

Open Understanding EPSS, a step towards Vulnerability Prioritization
Understanding EPSS, a step towards Vulnerability Prioritization

CVE Research

Understanding EPSS, a step towards Vulnerability Prioritization

There are too many vulnerabilities. Past research shows firms are able to fix 5%-20% of known vulnerabilities in a month. Moreover, a small subset of vulnerabilities (2%-7%) are seen to be exploited in the wild.

Apr 30, 2026 • 5 min read

Open ALERT: Active Exploitation: Windows Elevation of Privilege Vulnerability (CVE-2019-0859)
ALERT: Active Exploitation: Windows Elevation of Privilege Vulnerability (CVE-2019-0859)

CVE Research

ALERT: Active Exploitation: Windows Elevation of Privilege Vulnerability (CVE-2019-0859)

Apr 30, 2026 • 3 min read

Open Google Chrome Under Active Exploitation With Two Zero-Days!
Google Chrome Under Active Exploitation With Two Zero-Days!

CVE Research

Google Chrome Under Active Exploitation With Two Zero-Days!

Google has released a security advisory for its Chrome users on Windows, Mac, and Linux, addressing two very critical Zero-Day exploits exploited in the wild. These google chrome security vulnerabilities tracked as CVE-2020-16013 and CVE-2020-16017. Endpoints not been patched are advised to deploy p...

Apr 30, 2026 • 2 min read

Open Microsoft April 2023 Patch Tuesday Addresses 97 Vulnerabilities, Including a Zero-Day!
Microsoft April 2023 Patch Tuesday Addresses 97 Vulnerabilities, Including a Zero-Day!

CVE Research

Microsoft April 2023 Patch Tuesday Addresses 97 Vulnerabilities, Including a Zero-Day!

Apr 30, 2026 • 4 min read

Open Cisco Read-Only Path Traversal Vulnerability (CVE-2020-3452)
Cisco Read-Only Path Traversal Vulnerability (CVE-2020-3452)

CVE Research

Cisco Read-Only Path Traversal Vulnerability (CVE-2020-3452)

Cisco has released a Security Advisory for the actively exploited worldwide CVE-2020-3452. Cisco Read-Only Path Traversal Vulnerability in the web services interface of Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attac...

Apr 30, 2026 • 3 min read