SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

CVE Research
Understanding Stake-holder Specific Vulnerability Categorization (SSVC) for Risk Prioritization
Risk Prioritization is not a new technology in the cyber security space. Cybersecurity professionals look for products that can integrate with existing vulnerability assessment reports to help prioritize risks, most often just software vulnerabilities. Primitive modus operandi such as Prioritization...

CVE Research
Vulnerability Management Controls for Critical Security Frameworks
The most common security framework policies, like HIPAA, PCI, NIST, etc., talk about vulnerability management controls, which are a set of recommended safeguards that help mitigate risks and prevent cyber-attacks in your network.

CVE Research
Zoho Patches Critical Zero-day Flaw in its ADSelfService plus Exploited in The Wild
Zoho Patches Critical Zero-day Flaw in ADSelfService to patch a remote code execution (RCE) vulnerability existing in Zoho ADSelfService plus. The vulnerability allows the execution of unauthenticated remote arbitrary code on the affected systems. A vulnerability management solution can remediate th...

CVE Research
The Most Notorious Security Risks Tagging Along from 2020
2020 has been a disaster for many organizations: multiple data breaches, ransomware attacks, and internal threats. After 2020, IT as a department and a role have changed for the good. Leaders are more receptive to the opinions and initiatives of CIO/CISO/IT Head roles. Every IT professional now give...

CVE Research
Patch Tuesday: Microsoft Security Bulletin Summary for April 2021
Microsoft Security Bulletin April 2021 has released Patch Tuesday, security updates with a total of 108 vulnerabilities in the family of Windows operating systems and related products. In the release by Microsoft, 19 were rated as Critical and 89 as Important. Six Chromium Edge vulnerabilities relea...

CVE Research
Why IT Security Experts Should Consider Continuous and Automated Vulnerability Remediation
The impact of the pandemic has brought a multitude of security challenges for the IT security team and chief information security officers. One of the main challenges includes remediation of security flaws in a complex IT network and patch vulnerabilities using a patch management tool whenever neces...

CVE Research
Microsoft August 2023 Patch Tuesday Fixes 87 Vulnerabilities, Including 2 Zero-Day Exploits!
On this August 2023 Patch Tuesday, Microsoft addresses security issues in 87 vulnerabilities. Two vulnerabilities are currently being exploited, and twenty-three vulnerabilities could lead to remote code execution. A Vulnerability Management System can prevent these attacks and keep your system safe...

CVE Research
Thousands of VMware Centers Exposed to New Remote Code Execution Vulnerability
The CVE-2021-21972 remote code execution vulnerability was reported by Mikhail Klyuchnikov from Positive Technologies. A vulnerability management tool discovered this. The organization also published a detailed write-up for this vulnerability to share the impact of the flaw.

