SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.
Metasploit Module: Fitnesse Wiki Remote Command Execution

CVE Research
Microsoft August 2021 Patch Tuesday Addresses 44 CVEs, Including Three Zero-Days
Microsoft has released August Patch Tuesday security updates with a total of 44 vulnerabilities in the family of Windows and Mac operating systems and related products. In the release by Microsoft, 7 were rated as Critical and 37 as Important. Hence, the products covered in August’s security update ...

CVE Research
Apple Has Addressed A Zero-Day Vulnerability Which Is Being Actively Exploited In The Wild
This year, Apple released security updates for their third zero-day vulnerability. Apple addresses a zero-day vulnerability in its Feb 2022 update. However, the affected software processes maliciously crafted web content, leading to arbitrary code execution in WebKit, which is a component included i...

CVE Research
High-Severity Remote Code Execution Vulnerability in Google Chrome
A high-severity ‘use-after-free vulnerability tracked as CVE-2020-6492 with a CVSSv3 base score of 8.3 exists in WebGL [Web Graphics Library] component of the Google Chrome web browser that could be used to execute arbitrary code in the context of the browser process.

CVE Research
SolarWinds Releases Updates to Address Vulnerability Exploited by SUPERNOVA Malware
SolarWinds has released an advisory on 27th December 2020 to address the vulnerability being exploited by SUPERNOVA malware. The vulnerability resides in the SolarWinds Orion API, making it vulnerable to an authentication bypass that can further lead to remote code execution. The vulnerability has b...

CVE Research
Cloud-based Vulnerability Scanning with SanerNow
Twenty years ago, the talks of cloud technology were still in their inception. But today, it has taken over the world and completely revolutionized how everything works, especially in the vulnerability management solution tech space, where the impact is obvious.

CVE Research
VMware vCenter Servers Under Active Attack, Patch Now!
VMware, the virtualization giant, has patched 19 vulnerabilities, including one critical vulnerability, ten important vulnerabilities, and eight moderate vulnerabilities, in its latest security advisory VMSA-2021-0020. The vulnerabilities tracked as CVE-2021-21991, CVE-2021-21992, CVE-2021-21993, CV...


