SecPod

Learn Search

Search across all Learn content

SecPod Labs

Security Research

In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

Open The Return of TA488: Persistent Attacks Against Outlook Web Access
The Return of TA488: Persistent Attacks Against Outlook Web Access

CVE Research

The Return of TA488: Persistent Attacks Against Outlook Web Access

Jul 31, 2026

Open CISA Confirms Active Exploitation of Cisco FMC Zero-Day - CVE-2026-20316
CISA Confirms Active Exploitation of Cisco FMC Zero-Day - CVE-2026-20316

CVE Research

CISA Confirms Active Exploitation of Cisco FMC Zero-Day - CVE-2026-20316

A hard-coded, low-privilege account built into Cisco Secure FMC's web interface is letting unauthenticated attackers log in remotely, and CISA confirms the flaw is already being exploited against internet-facing devices.

Jul 31, 2026

Open T1190 in Focus: Exploiting Public-Facing Applications
T1190 in Focus: Exploiting Public-Facing Applications

CVE Research

T1190 in Focus: Exploiting Public-Facing Applications

Jul 31, 2026

Open Inside VMSA-2026-0006: How Two vCenter Bugs Chain Into Full Infrastructure Compromise
Inside VMSA-2026-0006: How Two vCenter Bugs Chain Into Full Infrastructure Compromise

CVE Research

Inside VMSA-2026-0006: How Two vCenter Bugs Chain Into Full Infrastructure Compromise

Jul 31, 2026

Open One Request, Total Persistence: Inside the SharePoint Flaw Attackers Are Exploiting
One Request, Total Persistence: Inside the SharePoint Flaw Attackers Are Exploiting

CVE Research

One Request, Total Persistence: Inside the SharePoint Flaw Attackers Are Exploiting

A critical SharePoint deserialization flaw, CVE-2026-50522 (CVSS 9.8), is under active exploitation just weeks after its July 2026 patch, following a public PoC. Attackers are using it to steal IIS machine keys in a single request, gaining persistence that survives patching alone. Now on CISA's KEV list, it's the third actively exploited SharePoint flaw in recent months, patch immediately and rotate machine keys.

Jul 24, 2026

Open Five Vulnerabilities, Five Lessons: A Comparative Analysis of CVE-2013-3900, CVE-2016-2183, CVE-2022-0001, CVE-2025-20352, and CVE-2025-49844
Five Vulnerabilities, Five Lessons: A Comparative Analysis of CVE-2013-3900, CVE-2016-2183, CVE-2022-0001, CVE-2025-20352, and CVE-2025-49844

CVE Research

Five Vulnerabilities, Five Lessons: A Comparative Analysis of CVE-2013-3900, CVE-2016-2183, CVE-2022-0001, CVE-2025-20352, and CVE-2025-49844

Jul 24, 2026

Open ENCFORGE Ransomware: Anatomy of an AI-Focused Cyber Attack
ENCFORGE Ransomware: Anatomy of an AI-Focused Cyber Attack

CVE Research

ENCFORGE Ransomware: Anatomy of an AI-Focused Cyber Attack

Jul 22, 2026 • 6 min read

Open UTA0533 Weaponizes KNUCKLEBALL: Inside the SonicWall SMA Zero-Day Exploitation Chain
UTA0533 Weaponizes KNUCKLEBALL: Inside the SonicWall SMA Zero-Day Exploitation Chain

CVE Research

UTA0533 Weaponizes KNUCKLEBALL: Inside the SonicWall SMA Zero-Day Exploitation Chain

Jul 20, 2026

Open One Email, Full Session Takeover: Inside Zimbra's Critical Classic Web Client Code Execution Flaw
One Email, Full Session Takeover: Inside Zimbra's Critical Classic Web Client Code Execution Flaw

CVE Research

One Email, Full Session Takeover: Inside Zimbra's Critical Classic Web Client Code Execution Flaw

Jul 20, 2026