SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

CVE Research
Patch Tuesday: The Fix You cannot Miss
How many times have you blissfully ignored the update notification and clicked on “remind me later”? Yes, in the busy life, the severity of the updates goes unnoticed, and it often becomes the Achilles heel in the ‘trojan’ war. Patching and securing the endpoints has become a supreme task over the y...

CVE Research
Endpoint Detection and Response: The Forthcoming of Incident Response and Cybersecurity
Data breach responders work to recognize the source of the breach, use knowledge and technique to prevent/ fix a breach. But the data breach analogy ends there. A data breach responder cannot assure that another breach will not happen, as the possibility of the occurrence of a breach exists. To ensu...

CVE Research
SolarWinds SUNBURST Backdoor Compromises Multiple Global Victims
Highly evasive hackers breached Orion IT monitoring and management software of SolarWinds and deployed malware updates to it. It is known as solarwinds sunburst. As a result, attackers have gained access to government, consulting, technology, telecom, and extractive entities in North America, Europe...

CVE Research
Microsoft HEVC emergency security updates for critical RCE vulnerabilities
Microsoft has released patches to fix two remote code execution vulnerabilities in Microsoft Windows Codecs Library. HEVC or Windows codecs library is responsible for handling large media files and decoding them for playback. HEVC by developers as it supports a multitude of different file formats. T...

CVE Research
Google Revealed Sickly Patched Windows Zero-Day Vulnerability
Google’s Project Zero team of security analysts has released the details of an improperly patched 0-Day vulnerability. The issue can be tracked as CVE-2020-17008 in Windows print spooler API that attackers could exploit to execute arbitrary code on the affected systems. A reliable vulnerability mana...

CVE Research
Google Chrome Zero-Days Under Active Exploitation
Google has released a security advisory for its Chrome users on Windows, Mac, and Linux, addressing seven security vulnerabilities. However, this release is including two very critical Zero-Day exploits exploited in the wild. Hence, these google chrome security vulnerabilities are tracking as CVE-20...

CVE Research
Critical Jenkins Vulnerability can Cause Memory Corruption and Disclose Sensitive Information
Jenkins, an open-source automation server software released an advisory pertaining to a critical vulnerability present in its application. Jenkins enables developers to build, test, and deploy applications. This vulnerability tracked as CVE-2019-17638 using a vulnerability scanning tool when exploi...


