SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

CVE Research
Google Has Released a Fix For High-Severity RCE Vulnerability in Chrome Browser
Google has released a new version 90 to fix high severity vulnerability in the V8 Javascript component of Google Chrome. Google Chrome RCE Vulnerability is tracked as CVE-2021-21227 is an insufficient data validation vulnerability. Successful exploitation of the vulnerability allows remote attackers...

CVE Research
Intel Addresses 3 High Severity Vulnerabilities in BIOS of Several Processors
Intel has recently disclosed a short advisory with details of high severity for 3 CVEs here. They are CVE-2021-0157, CVE-2021-0158, and CVE-2021-0146. The first two are related to BIOS firmware-based vulnerabilities. Once the attacker accesses the BIOS firmware settings, they can exploit the weaknes...

CVE Research
A Critical Vulnerability in Atlassian Confluence Server Under Active Exploitation
Atlassian Confluence recently published a security advisory to patch a critical OGNL(Object-Graph Navigation Language) injection vulnerability existing in Confluence Server and Data Center instance. This vulnerability allowed authenticated and, in some instances, even unauthenticated users to execu...

CVE Research
3 Years of WannaCry: Millions of Endpoints Are Still Vulnerable Out There!
Are you aware of the worst cyberattack of 2017, the WannaCry ransomware attack? WannaCry was one of the worst-hit ransomware attacks that surfaced around May 2017 in Asia. The malware spread like wildfire and infected more than 230,000 computers in a day. The WannaCry attack mainly affected the Wind...

CVE Research
Mozilla Fixes Critical Vulnerability In Cryptographic Libraries
Mozilla has recently fixed a critical memory corruption vulnerability using their vulnerability manager. This was affecting its cross-platform Network Security Services (NSS) set of cryptographic libraries. Companies like AOL, Red Hat, and Google, as well as other organizations, use Network Securit...

CVE Research
Discourse Patches Critical Remote Code Execution Vulnerability
Discourse is one of the most popular open-source community forums and mailing list management software applications. A critical code execution vulnerability (CVE-2021-41163) identifies in Discourse, allows an attacker to execute arbitrary code on the affected system. This vulnerability recognizes wi...

CVE Research
Your Key to Good Security Posture: Security Vulnerability Management
Cybercriminals are always looking for security weaknesses to steal sensitive and confidential information. Especially in software development environments, IT security admins come across unexpected software flaws which might be potentially dangerous to the organizations. Therefore, IT security admin...

CVE Research
How do you set up your Microsoft Office Patching for Continuous Update Mode?
With every passing day, every vendor seems to release many patches to their software application to fix vulnerabilities. But with so many patches and apps, it becomes cumbersome to keep them all up-to-date manually. Additionally, not patching apps poses a security risk to your organization too. Micr...

CVE Research
Microsoft Exchange Servers Actively Under Exploitation Via ProxyShell Vulnerabilities
Microsoft Exchange Servers are actively exploited in the wild by various threat actors. Attackers are looking for vulnerable instances of Microsoft Exchange Servers and exploiting them via ProxyShell vulnerabilities. ProxyShell is the name given to the set of three vulnerabilities existing in Micros...
