SecPod

Learn Search

Search across all Learn content

SecPod Labs

Security Research

In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

Open Security Products, not an impediment for RobbinHood Ransomware
Security Products, not an impediment for RobbinHood Ransomware

CVE Research

Security Products, not an impediment for RobbinHood Ransomware

Apr 30, 2026 • 3 min read

Open CVE-2014-2526: BarracudaDrive Multiple XSS Vulnerabilities

CVE-2014-2526: BarracudaDrive Multiple XSS Vulnerabilities

CVE Research

CVE-2014-2526: BarracudaDrive Multiple XSS Vulnerabilities

SecPod Research Team member (Prabhu S Angadi) has found Multiple Cross-Site Scripting Vulnerability in BarracudaDrive. The vulnerability is caused by improper validation of various parameters in various pages. This may allow an attacker to steal cookie-based authentication credentials, compromise th...

Apr 30, 2026 • 1 min read

Open The First Step Towards Endpoint Security Brilliance
The First Step Towards Endpoint Security Brilliance

CVE Research

The First Step Towards Endpoint Security Brilliance

This year has forced us into a lot of new challenges in the digital world. During the first half of 2020, Microsoft has seen a 150% increase in vulnerabilities than the entirety of 2019. Security breaches and ransomware attacks are being reported at an alarming rate this year. Cybercriminals now hav...

Apr 30, 2026 • 2 min read

Open SMBs – Antivirus Just Not Enough
SMBs – Antivirus Just Not Enough

CVE Research

SMBs – Antivirus Just Not Enough

Small and medium size businesses mainly known as SMBs are focused towards growing. Spending on security software is not one of their priorities. But just like every other business, protection of their data and systems are equally important. The perception that since the business is small all they’ll...

Apr 30, 2026 • 3 min read

Open BarracudaDrive Multiple XSS Vulnerabilities

BarracudaDrive Multiple XSS Vulnerabilities

CVE Research

BarracudaDrive Multiple XSS Vulnerabilities

SecPod Research Team member (Shakeel Bhat) has found Multiple Cross-Site Scripting Vulnerability in BarracudaDrive. The vulnerability is caused by improper validation of various parameter in various pages. This may allow an attacker to steal cookie-based authentication credentials, compromise the ap...

Apr 30, 2026 • 1 min read

Open Mozilla Patches Zero-Day and High-Severity Vulnerabilities
Mozilla Patches Zero-Day and High-Severity Vulnerabilities

CVE Research

Mozilla Patches Zero-Day and High-Severity Vulnerabilities

Mozilla has released three security advisories to address the vulnerabilities present in Firefox, Firefox ESR, and Thunderbird. A zero-day vulnerability (CVE-2020-15999) has also been addressed in the latest version of Firefox. Firefox version 83 also introduces a new “HTTPS-only mode“, if enabled a...

Apr 30, 2026 • 2 min read

Open MSSPs Take on Outsourced Security Challenge
MSSPs Take on Outsourced Security Challenge

CVE Research

MSSPs Take on Outsourced Security Challenge

The increased cost and complexity of securing the business IT infrastructure has opened the door for managed security service providers (MSSPs). In particular, small and medium businesses (SMBs) generally don’t have the security experience or resources to adequately protect their business from today...

Apr 30, 2026 • 2 min read

Open Multiple Flaws in Orbit Fox WordPress Plugin Allow a Complete Takeover of Sites
Multiple Flaws in Orbit Fox WordPress Plugin Allow a Complete Takeover of Sites

CVE Research

Multiple Flaws in Orbit Fox WordPress Plugin Allow a Complete Takeover of Sites

The Threat Intelligence team of Wordfence discovered two security vulnerabilities in the Orbit Fox WordPress plugin on November 19, 2020. This plugin was developed by ThemeIsle to extend the theme functionalities with various modules like Social Media Share Buttons & Icons, Uptime Monitoring, Google...

Apr 30, 2026 • 3 min read

Open PowerWare Ransomware – The New Fileless Ransomware
PowerWare Ransomware – The New Fileless Ransomware

CVE Research

PowerWare Ransomware – The New Fileless Ransomware

Apr 30, 2026 • 2 min read