SecPod

Learn Search

Search across all Learn content

SecPod Labs

Security Research

In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

Open Serv-U Vulnerabilities Expose Systems to Root Compromise
Serv-U Vulnerabilities Expose Systems to Root Compromise

CVE Research

Serv-U Vulnerabilities Expose Systems to Root Compromise

SolarWinds has released updates to address four critical security flaws in its Serv-U file transfer software that, if successfully exploited, could result in remote code execution. These vulnerabilities affect SolarWinds Serv-U version 15.5 and have been addressed in version 15.5.4.

Apr 28, 2026 • 2 min read

Open 7,000 Servers and Counting: The Rise of the SSHStalker Linux Botnet
7,000 Servers and Counting: The Rise of the SSHStalker Linux Botnet

CVE Research

7,000 Servers and Counting: The Rise of the SSHStalker Linux Botnet

Cybercriminal groups and opportunistic botnet operators continue to shift toward scale-first, persistence-driven operations that rely heavily on misconfigurations, weak authentication, and long-tail vulnerabilities rather than sophisticated zero-days. Recent analyses by Flare and other cybersecurity...

Apr 28, 2026 • 5 min read

Open Silent Scan, Stolen Secrets: Kimsuky’s QR-Code Phishing Campaign
Silent Scan, Stolen Secrets: Kimsuky’s QR-Code Phishing Campaign

CVE Research

Silent Scan, Stolen Secrets: Kimsuky’s QR-Code Phishing Campaign

A sustained quishing (QR-code phishing) campaign conducted by the North Korea–linked APT group Kimsuky (aka Larva-24005) has been actively targeting government, defense, and critical infrastructure organizations. According to a recent FBI warning, Kimsuky operators embed malicious QR codes in emails...

Apr 28, 2026 • 5 min read

Open Weaponizing CVE-2026-1731: VShell and SparkRAT in Real-World BeyondTrust Breaches
Weaponizing CVE-2026-1731: VShell and SparkRAT in Real-World BeyondTrust Breaches

CVE Research

Weaponizing CVE-2026-1731: VShell and SparkRAT in Real-World BeyondTrust Breaches

On February 6, 2026, BeyondTrust disclosed a critical pre-authentication remote code execution vulnerability, CVE-2026-1731, affecting its Remote Support and Privileged Remote Access products. The flaw, assigned a CVSS v4 score of 9.9, enables unauthenticated attackers to execute arbitrary operating...

Apr 28, 2026 • 5 min read

Open Supply Chain Risk: Critical Flaws Identified in Popular VS Code Extensions
Supply Chain Risk: Critical Flaws Identified in Popular VS Code Extensions

CVE Research

Supply Chain Risk: Critical Flaws Identified in Popular VS Code Extensions

In the modern software development ecosystem, Integrated Development Environments (IDEs) such as Microsoft Visual Studio Code have become foundational to daily engineering workflows. To extend functionality and streamline development tasks, teams frequently rely on third-party extensions from the ma...

Apr 28, 2026 • 4 min read

Open Ongoing Web Shell Attacks Hit 900+ FreePBX Systems: INJ3CTOR3 Behind EncystPHP Deployment
Ongoing Web Shell Attacks Hit 900+ FreePBX Systems: INJ3CTOR3 Behind EncystPHP Deployment

CVE Research

Ongoing Web Shell Attacks Hit 900+ FreePBX Systems: INJ3CTOR3 Behind EncystPHP Deployment

Cybercriminals continue to exploit misconfigurations and unpatched VoIP infrastructure, with over 900 Sangoma FreePBX systems confirmed compromised following widespread deployment of EncystPHP, a malicious PHP-based web shell. These intrusions have been attributed to threat activity leveraging a pos...

Apr 28, 2026 • 5 min read

Open Security Advisory: VMware Aria Operations Vulnerabilities May Lead to Remote Compromise
Security Advisory: VMware Aria Operations Vulnerabilities May Lead to Remote Compromise

CVE Research

Security Advisory: VMware Aria Operations Vulnerabilities May Lead to Remote Compromise

Broadcom has released security updates to address multiple vulnerabilities in VMware Aria Operations, an IT operations management platform that monitors and optimizes virtual, cloud, and hybrid environments. The solution provides performance monitoring, capacity planning, automated alerting, and cos...

Apr 28, 2026 • 3 min read

Open From SSO to SOS: How CVE-2026-24858 Gave Hackers the Keys to Your Fortinet Gear
From SSO to SOS: How CVE-2026-24858 Gave Hackers the Keys to Your Fortinet Gear

CVE Research

From SSO to SOS: How CVE-2026-24858 Gave Hackers the Keys to Your Fortinet Gear

Fortinet has addressed a critical authentication bypass vulnerability, CVE-2026-24858, affecting FortiOS, FortiManager, FortiAnalyzer, FortiWeb and FortiProxy. The vulnerability, with a CVSS score of 9.4, is actively exploited in the wild, making it crucial for organizations to apply the necessary p...

Apr 28, 2026 • 3 min read

Open WinRAR CVE-2025-8088: RomCom’s Doorway to Remote Code Execution
WinRAR CVE-2025-8088: RomCom’s Doorway to Remote Code Execution

CVE Research

WinRAR CVE-2025-8088: RomCom’s Doorway to Remote Code Execution

A critical vulnerability in WinRAR, identified as CVE-2025-8088, was exploited as a zero-day in targeted phishing attacks to deploy RomCom backdoors. This flaw, a directory traversal vulnerability, allows attackers to craft malicious archives that place executable files in Windows Startup folders, e...

Apr 28, 2026 • 5 min read